Logfile of HijackThis v1.99.1
Scan saved at 12:58:39, on 2006-7-25
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\kxmixer.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\dnsijczc.exe
C:\BitComet_0.70\BitComet.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\System32\spooIsv.exe
D:\155847200541134207\HijackThis.exe
O4 - HKLM\..\Run: [kX Mixer] C:\WINDOWS\System32\kxmixer.exe --startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{712121C1-DE1C-4907-A79D-EF8ED8823730}: NameServer = 210.77.168.5,210.77.160.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{808C7528-44D0-4D66-8453-AAC3A70EE75B}: NameServer = 61.166.150.101 61.166.15.170
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
上网时系统遭到攻击后进多了两个进程:
C:\WINDOWS\system32\dnsijczc.exe
C:\WINDOWS\System32\spooIsv.exe
这两个是什么东西,为什么瑞星没有报警