【回复“邱枫你知道吗”的帖子】
用HijackThis 1.99.1扫描出来的
HijackThis_815汉化版扫描日志 V1.99.1
保存于 21:15:45, 日期 2005-9-15
操作系统: Windows XP (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 (6.00.2600.0000)
当前运行的进程:
D:\WINDOWS.0\System32\smss.exe
D:\WINDOWS.0\system32\csrss.exe
D:\WINDOWS.0\system32\winlogon.exe
D:\WINDOWS.0\system32\services.exe
D:\WINDOWS.0\system32\lsass.exe
D:\WINDOWS.0\system32\svchost.exe
D:\WINDOWS.0\System32\svchost.exe
D:\WINDOWS.0\System32\svchost.exe
D:\WINDOWS.0\System32\svchost.exe
F:\瑞星杀毒\RISING\RAV\Ravmond.exe
F:\瑞星杀毒\RISING\RAV\RavStub.exe
D:\WINDOWS.0\system32\spoolsv.exe
D:\WINDOWS.0\Explorer.EXE
D:\WINDOWS.0\esscw10.exe
D:\WINDOWS.0\VM_STI.EXE
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\wsearch\Search.exe
F:\瑞星杀毒\RISING\RAV\RAVTIMER.EXE
F:\瑞星杀毒\RISING\RAV\RAVMON.EXE
D:\WINDOWS.0\system32\rundll32.exe
F:\影音风暴\Storm Downloader\StormDownloader.exe
D:\WINDOWS.0\System32\ctfmon.exe
D:\WINDOWS.0\system32\rundll32.exe
E:\PSP游戏\TTPlayer.exe
D:\WINDOWS.0\System32\alg.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\DuDu\DddClient\dudupros.exe
D:\WINDOWS.0\System32\nvsvc32.exe
F:\瑞星杀毒\RISING\RAV\CCENTER.EXE
D:\WINDOWS.0\System32\svchost.exe
F:\QQ2005\TT\TTraveler.exe
D:\Program Files\WinRAR\WinRAR.exe
F:\HijackThis 1.99.1\HijackThis1991zww.exe
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS.0\System32\xunleibho_v8.dll
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - F:\UC\UC\UCddt\ddtinit.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - D:\Program Files\3721\Assist\Angling.dll
O2 - BHO: WebMiscItem Class - {3CD4296F-6CC3-11D9-B888-000C299AA719} - D:\WINDOWS.0\system32\WebMisc.dll
O2 - BHO: Anti Fish - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - D:\WINDOWS.0\System32\aclayer.dll (file missing)
O2 - BHO: 3721中文邮 - {6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} - (no file)
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - F:\UC\UC\UCddt\ddtkillw.ocx
O2 - BHO: DDDMon Class - {6BDE1669-B490-48E3-B668-456314F2D6C3} - D:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - F:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - D:\PROGRA~1\YiSou\yisoub.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS.0\System32\msdxm.ocx
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - F:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - IE工具栏增项: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - F:\UC\UC\UCddt\DDTONG~1.DLL
O3 - IE工具栏增项: MSN 工具栏 - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Toolbar\01.01.2607.0\zh-cn\msntb.dll
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - D:\Program Files\YiSou\yisou.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] D:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [EssSpkPhone] esscw10.exe
O4 - 启动项HKLM\\Run: [kpcdst] E:\cdsprite.exe
O4 - 启动项HKLM\\Run: [rfw] D:\Program Files\rising\Rfw\Rfw.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS.0\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [PHIMETIPSYNC] D:\Program Files\Common Files\Microsoft Shared\IME\IMTC60\Phonetic\TINTLCFG.EXE /PHIMETIPSync
O4 - 启动项HKLM\\Run: [BigDogPath] D:\WINDOWS.0\VM_STI.EXE USB PC Camera VM301+
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] D:\WINDOWS.0\System32\Rundll32.exe nmgamex.dll,LiveProcess /aa
O4 - 启动项HKLM\\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [MoveSearch] D:\Program Files\wsearch\Search.exe
O4 - 启动项HKLM\\Run: [RavTimer] F:\瑞星杀毒\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] F:\瑞星杀毒\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [ExFilter] Rundll32.exe "D:\PROGRA~1\CNNIC\Cdn\cdnspie.dll,ExecFilter solo"
O4 - 启动项HKLM\\Run: [helper.dll] D:\WINDOWS.0\system32\rundll32.exe D:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "F:\影音风暴\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [MINI_BFYY] F:\影音风暴\Storm Downloader\StormDownloader.exe
O4 - 启动项HKLM\\Run: [Thunder] "F:\讯雷5\ThunderShell.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS.0\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MessengerHelperWatch] E:\MESSEN~1\MSNHEL~1.EXE
O4 - HKCU\..\Run: [GameBuddy] D:\Program Files\Softnyx\GameBuddy\GameBuddy.exe
O4 - HKCU\..\Run: [VXP] "F:\可视通\VXP.EXE" start
O4 - HKCU\..\Run: [Kugoo] F:\kugoo\KUGOO\kugoo.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\雅虎通\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [eMuleAutoStart] F:\电驴\eMule\eMule.exe -AutoStart
O4 - Startup: 新浪UC.lnk = F:\UC\UC\uc.exe
O4 - Global Startup: 桌面传媒.lnk = ?