HijackThis@Qoo的扫描日志 V1.97.7
Scan saved at 12:30:57, on 2006-1-2
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\Rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINPENJR\Win32\pphidpad.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\NIW.exe
C:\Program Files\Microsoft Office\Office\2052\OLFSNT40.EXE
C:\WINPENJR\win32\ACREMCHK.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\qq\TIMPlatform.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\1\桌面\hijackthis1.97_qoo\HijackThis.exe
O1 - Hosts: 61.152.160.137 4567.com.cn
O1 - Hosts: 61.152.160.137 www.4567.com.cn
O1 - Hosts: 61.152.160.137 49m.cn
O1 - Hosts: 61.152.160.137 www.49m.cn
O1 - Hosts: 61.152.160.137 123.xuanji8.com
O1 - Hosts: 61.152.160.137 ohkk.xuanji8.com
O1 - Hosts: 61.152.160.137 123.52lhc.com
O1 - Hosts: 61.152.160.137 df94.com
O1 - Hosts: 61.152.160.137 hao119.com
O1 - Hosts: 61.152.160.137 www.hao119.com
O1 - Hosts: 61.152.160.137 9556.net
O1 - Hosts: 61.152.160.137 www.9556.net
O1 - Hosts: 61.152.160.137 ee456.com
O1 - Hosts: 61.152.160.137 www.ee456.com
O1 - Hosts: 61.152.160.137 eachz.com
O1 - Hosts: 61.152.160.137 www.eachz.com
O1 - Hosts: 61.152.160.137 www.57666.com
O1 - Hosts: 61.152.160.137 57666.com
O1 - Hosts: 61.152.160.137 www.kk778.com
O1 - Hosts: 61.152.160.137 kk778.com
O1 - Hosts: 61.152.160.137 www.98756.net
O1 - Hosts: 61.152.160.137 98756.net
O1 - Hosts: 61.152.160.137 www.98756.com
O1 - Hosts: 61.152.160.137 98756.com
O1 - Hosts: 61.152.160.137 www.6743.net
O1 - Hosts: 61.152.160.137 6743.net
O1 - Hosts: 61.152.160.137 www.6743.com
O1 - Hosts: 61.152.160.137 6743.com
O1 - Hosts: 61.152.160.137 www.3619.com
O1 - Hosts: 61.152.160.137 3619.com
O1 - Hosts: 61.152.160.137 www.5806.com
O1 - Hosts: 61.152.160.137 5806.com
O1 - Hosts: 61.152.160.137 www.5806.net
O1 - Hosts: 61.152.160.137 9397.com
O1 - Hosts: 61.152.160.137 www.9397.com
O1 - Hosts: 61.152.160.137 5806.net
O1 - Hosts: 61.152.160.137 www.eachz.com
O1 - Hosts: 61.152.160.137 eachz.com
O1 - Hosts: 61.152.160.137 www.6284.com
O1 - Hosts: 61.152.160.137 6284.com
O1 - Hosts: 61.152.160.137 www.ok666666.com
O1 - Hosts: 61.152.160.137 ok666666.com
O1 - Hosts: 61.152.160.137 www.58v.net
O1 - Hosts: 61.152.160.137 58v.net
O1 - Hosts: 61.152.160.137 www.xg58.com
O1 - Hosts: 61.152.160.137 xg58.com
O1 - Hosts: 61.152.160.137 www.3525.net
O1 - Hosts: 61.152.160.137 3525.net
O1 - Hosts: 61.152.160.137 www.xg08.com
O1 - Hosts: 61.152.160.137 xg08.com
O1 - Hosts: 61.152.160.137 www.818ok.com
O1 - Hosts: 61.152.160.137 818ok.com
O1 - Hosts: 61.152.160.137 www.8065.com
O1 - Hosts: 61.152.160.137 8065.com
O1 - Hosts: 61.152.160.137 www.hkkkkk.com
O1 - Hosts: 61.152.160.137 hkkkkk.com
O1 - Hosts: 61.152.160.137 www.9967.com
O1 - Hosts: 61.152.160.137 9967.com
O1 - Hosts: 61.152.160.137 www.longze.net
O1 - Hosts: 61.152.160.137 longze.net
O1 - Hosts: 61.152.160.137 www.778778.com
O1 - Hosts: 61.152.160.137 778778.com
O1 - Hosts: 61.152.160.137 www.111888.net
O1 - Hosts: 61.152.160.137 111888.net
O1 - Hosts: 61.152.160.137 www.hok888.com
O1 - Hosts: 61.152.160.137 hok888.com
O1 - Hosts: 61.152.160.137 www.k56789.com
O1 - Hosts: 61.152.160.137 k56789.com
O1 - Hosts: 61.152.160.137 www.365lhc.com
O1 - Hosts: 61.152.160.137 365lhc.com
O1 - Hosts: 61.152.160.137 www.bb8888.com
O1 - Hosts: 61.152.160.137 bb8888.com
O1 - Hosts: 61.152.160.137 www.kk96.com
O1 - Hosts: 61.152.160.137 kk96.com
O1 - Hosts: 61.152.160.137 www.hkmark6.net
O1 - Hosts: 61.152.160.137 hkmark6.net
O1 - Hosts: 61.152.160.137 www.bm94.com
O1 - Hosts: 61.152.160.137 bm94.com
O1 - Hosts: 61.152.160.137 www.hk196.com
O1 - Hosts: 61.152.160.137 hk196.com
O1 - Hosts: 61.152.160.137 www.ww8888.com
O1 - Hosts: 61.152.160.137 ww8888.com
O1 - Hosts: 61.152.160.137 www.liver10.com
O1 - Hosts: 61.152.160.137 liver10.com
O1 - Hosts: 61.152.160.137 www.kkww.net
O1 - Hosts: 61.152.160.137 66uu.net
O1 - Hosts: 61.152.160.137 www.lh468.com
O1 - Hosts: 61.152.160.137 www.yzx.cn
O1 - Hosts: 61.152.160.137 yzx.cn
O1 - Hosts: 61.152.160.137 www.my118.net
O1 - Hosts: 61.152.160.137 my118.net
O1 - Hosts: 61.152.160.137 www.my128.net
O1 - Hosts: 61.152.160.137 my128.net
O1 - Hosts: 61.152.160.137 www.baidu888.com
O1 - Hosts: 61.152.160.137 baidu888.com
O1 - Hosts: 61.152.160.137 www.92222.com
O1 - Hosts: 61.152.160.137 92222.com
O1 - Hosts: 61.152.160.137 www.k333.net
O1 - Hosts: 61.152.160.137 k333.net
O1 - Hosts: 61.152.160.137 www.lt66.com
O1 - Hosts: 61.152.160.137 lt66.com
O2 - BHO: (no name) - {00000000-0000-0000-0000-C4CA9A05F1E2} - F:\PROGRA~1\PPGou\PPGIEC~1.DLL (file missing)
O2 - BHO: (no name) - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v4.dll
O2 - BHO: (no name) - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: 360so BHOHelper - {472101C2-1109-43f4-9112-31F33E3F2127} - C:\PROGRA~1\360so\360so.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: 3721
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo2\KUGOO3~1.OCX
O2 - BHO: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: (no name) - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: ????? - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - Toolbar: ????? - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O3 - Toolbar: ????? - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - F:\
O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Teclast WE-MK02 PC Camera
O4 - HKLM\..\Run: [MS-4011 Memory Patch] D:\RavSasser.exe -Patch
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O4 - HKLM\..\Run: [360Main.exe] C:\PROGRA~1\360so\360Main.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Kugoo] C:\PROGRA~1\KUGOO2\KUGOO.EXE
O4 - HKCU\..\Run: [RegBar] regsvr32.exe /u C:\progra~1\blogmark\bocaitoolbar.dll /s /i /n
O4 - HKCU\..\Run: [NIW] C:\WINDOWS\NIW.exe
O4 - HKCU\..\Run: [PPGou] F:\PROGRA~1\PPGOU\PPGOU.EXE /h
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: dbisam.lck
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用屁屁狗[PPGou]加速下载 - F:\PROGRA~1\PPGOU\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\pp2005\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\pp2005\getAllurl.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - C:\PROGRA~1\KUGOO2\KuGoo3DownX.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 解霸实时播放 - C:\HEROSOFT\Hero3000\MPURLGET.HTM
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: QQ (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\wsocket.dll' missing
O11 - Options group: [!CNS]
O11 - Options group: [CDNCLIENT]
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096092483217
O16 - DPF: {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (QQPlayer Control) - http://219.133.62.248/QQPlayer.cab
O16 - DPF: {CF85459D-DFA7-4028-A065-3C6D1356DCC8} (CertInstall Control) - http://gd.chinavnet.com/CertInstall.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B728B18B-DA82-4460-AAC3-AB3A7A5935AF}: NameServer = 202.103.176.22,202.103.176.28
请大家帮小女子找出这些垃圾,谢谢。好人有好报啊!