用 hijackthis v1.98.2 素描的.
( 将HijackThis.exe 改成HijackThis.com 才打得开HijackThis )
Logfile of HijackThis v1.98.2
Scan saved at 22:19:33, on 2007-3-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\user\桌面\HijackThis.com
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 18×02 期号:18×02
O1 - Hosts: 日期:2006-6-30 18×放大激情版
O2 - BHO: (no name) - {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: Add to &Teleport - H:\Teleport Pro (打开tpp文件的程序)\Teleport Pro v1.33\teleport.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\QQ2007\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://c:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\QQ2007\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\QQ2007\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\QQ2007\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - C:\比特精灵 v3.2.1.192\bsurl.htm
O8 - Extra context menu item: 网页下载器-当前链接(&X) - F:\【P2P工具】\HtmlDown\AddUrl.htm
O8 - Extra context menu item: 网页下载器-所有或选择链接 - F:\【P2P工具】\HtmlDown\AddAll.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\QQ2007\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\QQ2007\QQ.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://password.qq.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B55F0FE-2CFA-4A0F-AFC6-84AFB1B1163D}: NameServer = 202.96.128.68,202.96.128.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E31F974-C787-458E-93FB-E6B68BA2EA72}: NameServer = 202.96.128.86 202.96.128.166