又改主页又弹很多网站,救命~

Logfile of HijackThis v1.99.0
Scan saved at 15:40:18, on 2006-9-15
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\csrss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\WINNT\system32\svchost.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\VKTServ.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\hkcmd.exe
C:\USBStorage\USBDetector.exe
D:\WINNT\system32\Server.exe
D:\WINNT\command\rundll32.exe
D:\WINNT\Intel\rundll32.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\WINNT\system32\internat.exe
D:\Program Files\ha-hijackthis199-xqb\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe ntio.exe
F2 - REG:system.ini: UserInit=D:\WINNT\system32\Userinit.exe
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - c:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll
O3 - Toolbar: TT33定向搜索 - {D940F380-49C7-4A05-9E33-53930AF5768F} - D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tbu179\Toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] D:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [Systems32] D:\WINNT\system32\Server.exe
O4 - HKLM\..\Run: [Tray] D:\WINNT\command\rundll32.exe
O4 - HKLM\..\Run: [zt] D:\WINNT\Intel\rundll32.exe
O4 - HKLM\..\Run: [Realplayer.exe] D:\WINNT\system32\Realplayer.exe
O4 - HKLM\..\Run: [Start] Start.exe
O4 - HKLM\..\Run: [kav] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Realplayer.exe] D:\WINNT\system32\Realplayer.exe
O4 - HKCU\..\Run: [Start] Start.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O10 - Unknown file in Winsock LSP: d:\winnt\system32\cn_spiex.dll
O16 - DPF: {1D5D391B-61F7-4E8E-AC8A-2C8B205DF30C} (DSFC.RSFC) - http://192.168.1.234/U8WebSO/ywweb/report/DSFC.CAB
O16 - DPF: {22D8388C-DF27-49DA-8E56-A456B1D001C7} (DHWJC.RHWJC) - http://192.168.1.234/U8WebSO/ywweb/report/DHWJC.CAB
O16 - DPF: {2599C4A2-8192-4E21-A4B7-9B62EE0F1312} (DXCL.RXCL) - http://192.168.1.234/U8WebSO/ywweb/report/DXCL.CAB
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {5067F136-3F21-43CB-ADE6-5968FDACFBF3} (FourStateTreeViewControl Control) - http://192.168.1.234/U8Portal//WebTreeView.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128758922953
O16 - DPF: {712C614A-5A42-46C8-97D8-2642D5C29E07} (PortalEventAgent.ctlEventAgent) - http://192.168.1.234/u8portal/PortalEventAgent.CAB
O16 - DPF: {78D8450D-E0E4-4440-8FDD-2098A8AC81EE} (DKCTZ.RKCTZ) - http://192.168.1.234/U8WebSO/ywweb/report/DKCTZ.CAB
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - http://www.icbc.com.cn/dongtaiyanshi/personalbank/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} (Settings Class) - http://192.168.1.234/u8portal/capicom.cab
O16 - DPF: {C3474273-859B-444A-AA12-FA4BF8D0DCD7} (U8WebClient.clsClient) - http://192.168.1.234/u8portal/U8WebClient.CAB
O16 - DPF: {E614E74A-A4C0-45A6-96A2-2824C2672E65} (DLSZ.RLSZ) - http://192.168.1.234/U8WebSO/ywweb/report/DLSZ.CAB
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - D:\WINNT\system32\DLMain.dll (file missing)
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - D:\WINNT\Downloaded Program Files\AfxEdit.dll
O23 - Service: 卡巴斯基反病毒软件6.0 - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Gray_Pigeon_Server1.23 - Unknown - D:\WINNT\G_Server1.23.exe
O23 - Service: Svchost Service For Windows - Unknown - D:\WINNT\svchost.exe (file missing)
O23 - Service: Servers - Unknown - D:\WINNT\ervers.exe (file missing)
O23 - Service: WintUPp - Unknown - D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wt\wt.exe (file missing)

最后编辑2006-09-15 16:21:00.483000000