来咯~~
保存于 9:24:32, 日期 2005-8-14
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
M:\WINNT\System32\smss.exe
M:\WINNT\system32\winlogon.exe
M:\WINNT\system32\services.exe
M:\WINNT\system32\lsass.exe
M:\WINNT\system32\svchost.exe
M:\WINNT\system32\svchost.exe
M:\WINNT\system32\spoolsv.exe
c:\windows\system32\dllcache\MSSvc.EXE
c:\windows\system32\dllcache\MSSvc.EXE
c:\WINdows\system32\dllcache\CCVSTS.exe
M:\WINNT\system32\nvsvc32.exe
M:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
M:\WINNT\system32\regsvc.exe
M:\WINNT\system32\MSTask.exe
M:\WINNT\System32\WBEM\WinMgmt.exe
M:\WINNT\system32\svchost.exe
M:\WINNT\Explorer.EXE
M:\WINNT\system32\RUNDLL32.EXE
M:\WINNT\system32\internat.exe
M:\PROGRA~1\EFFICI~1\ENTERN~1\app\EnterNet.exe
M:\WINNT\system32\IInfo\InfoNet.exe
c:\WINdows\system32\dllcache\DDVSTS.exe
M:\Program Files\MSN Messenger\msnmsgr.exe
M:\WINNT\system32\taskmgr.exe
M:\Program Files\Internet Explorer\IEXPLORE.EXE
P:\杀毒工具集\HijackThis1991zww.exe
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - M:\WINNT\system32\BOCAIT~1.DLL (file missing)
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - M:\WINNT\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE M:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE M:\WINNT\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] M:\Documents and Settings\Administrator\桌面\RavSasser.exe -Patch
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - F:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - F:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - M:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - M:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - M:\Program Files\Tencent\qq\SendMMS.htm
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - M:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - M:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O10 - 未知的文件在 Winsock LSP: m:\winnt\system32\ws2_64.dll
O10 - 未知的文件在 Winsock LSP: m:\winnt\system32\ws2_64.dll
O10 - 未知的文件在 Winsock LSP: m:\winnt\system32\ws2_64.dll
O10 - 未知的文件在 Winsock LSP: m:\winnt\system32\ws2_64.dll
O10 - 未知的文件在 Winsock LSP: m:\winnt\system32\ws2_64.dll
O16 - DPF: {3A2B370C-BA0A-11D1-B137-0000F8753F5D} (Microsoft Chart Control 6.0 (SP4) (OLEDB)) - http://www.fangdi.com.cn/mschart.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O23 - NT 服务: MSSvc DataService (DataService) - Unknown owner - c:\windows\system32\dllcache\MSSvc.EXE
O23 - NT 服务: MSSvc DataStorage (DataStorage) - Unknown owner - c:\windows\system32\dllcache\MSSvc.EXE
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - M:\WINNT\System32\dmadmin.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - M:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: PPPoE Service (PPPoEService) - Unknown owner - M:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe