以下是我的扫描日志
Logfile of HijackThis v1.99.1
Scan saved at 16:26:09, on 2006-6-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\svchost.exe
E:\Tencent\QQ\TMDlls\TM.exe
E:\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\Rav.exe
R3 - Default URLSearchHook is missing
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v9.dll
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - e:\Program Files\NetXfer\NXIEHelper.dll
O2 - BHO: XBTP00162 - {EBA8FC1C-C7BB-4306-B019-99AA73D1021C} - C:\WINDOWS\DOWNLO~1\CONFLICT.1\5460.dll (file missing)
O3 - Toolbar: (no name) - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - (no file)
O4 - HKLM\..\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 使用网络传送带下载 - E:\Program Files\NetXfer\NXAddLink.html
O8 - Extra context menu item: 使用网络传送带下载全部链接 - E:\Program Files\NetXfer\NXAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\QQ\AddEmotion.htm
O16 - DPF: {0A43613C-9F79-4E96-BEED-799045B3B753} (YGCWBG Control) -
file://C:\Inetpub\wwwroot\YGBGClt20.inf
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {228CAD06-0A4A-11D5-B58B-0080C8D36FF1} (远光财务2.0-系统管理) - http://10.229.234.172/YGXTClt20.inf
O16 - DPF: {29AE8351-3844-11D2-8278-001088016936} (远光财务20-工资核算) - http://10.229.234.172/YGGZClt20.inf
O16 - DPF: {498BC605-8894-11D2-A1C0-0888C84BCE44} (远光财务20 -- 文件信息) - http://10.229.234.172/YGWJClt20.inf
O16 - DPF: {646976A9-28C4-11D2-8C62-0080C843C179} (远光财务20-帐务处理) - http://10.229.234.204/YGZWClt20.inf
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c15.cab
O16 - DPF: {C1AF8F7B-5E5E-11D1-AE9E-44455354000F} (远光财务2.0--集团报表2.1) -
file://C:\Inetpub\wwwroot\YGBBCLT20.inf
O16 - DPF: {E51C4AE5-2C78-11D2-A159-0080C843C4B3} (远光财务20-固定资产) - http://10.229.234.172/YGGDClt20.inf
O17 - HKLM\System\CCS\Services\Tcpip\..\{6ACBF356-D717-4A66-8924-D89925C397B3}: NameServer = 10.229.234.2
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Windows Media Player Services - Unknown owner - C:\WINDOWS\alerts.exe
用瑞星每次杀了,下次重启进时又再次出现,烦燥中。。。。。