【回复“卧龙传说”的帖子】
杀毒后的:
HijackThis_815汉化版扫描日志 V1.99.1
保存于 10:32:18, 日期 2006-1-12
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\sheng\桌面\4842302005817230232\HijackThis1991zww.exe
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
O1 - Hosts: <meta name="ProgId" content="FrontPage.Editor.Document">
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=gb2312">
O1 - Hosts: </head>
O1 - Hosts: <body bgcolor="#000000">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <table height="20" cellSpacing="0" cellPadding="0" width="750" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="52" style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: <center>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="752" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n155.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n156.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n157.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n158.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n159.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n160.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img height="60" src="images/n161.jpg" width="80" border="0"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n162.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px"><br>
O1 - Hosts: <img src="images/n163.jpg" border="0" width="80" height="60">
O1 - Hosts: <font size="2" style="font-size: 12px; font-family: 宋体; text-decoration: none" color="#ffffff">
O1 - Hosts: </font></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </center>
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"><br>
O1 - Hosts: <p align="center">
O1 - Hosts: <font color="#ffff00" size="3" style="font-size: 12px; font-family: 宋体; text-decoration: none">
O1 - Hosts: 由于注册人数过多,显示不正常请刷新本页</font><img src="images/input.gif" width="700" height="80"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/l.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td background="images/mobile.gif" height="50" style="font-size: 12px"> </td>
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/r.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [RfwMain] "c:\program files\rising\rfw\rfwmain.exe" -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O23 - NT 服务: internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe