HijackThis_815汉化版扫描日志 V1.99.1
保存于 18:23:44, 日期 2006-2-22
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
D:\soft\use\高强度文件夹加密大师 V9000 Build 1005 绿色特别版\Setong\SVOHOST.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\system32\khooker.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\soft\system\memzipT\memzipT.exe
C:\WINNT\system32\conime.exe
C:\Program Files\JJOL\IME\JJSvr.EXE
C:\WINNT\system32\NOTEPAD.EXE
F:\新建文件夹 (2)\HijackThis1991汉化版\CopyLock109zww.exe
F:\新建文件夹 (2)\HijackThis1991汉化版\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,,"D:\高强度文件夹加密大师 V9000 Build 1005 绿色特别版\Setong\SVOHOST.EXE" un userinit.exe,"D:\soft\use\高强度文件夹加密大师 V9000 Build 1005 绿色特别版\Setong\SVOHOST.EXE" un userinit.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v4.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
O4 - 启动项HKLM\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [CM-SmWizard] C:\WINNT\System\SmWizard.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - 启动项HKLM\\Run: [pdfFactory Pro 分配器 v2] ; C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - 启动项HKLM\\Run: [SVOH0ST] C:\Program Files\strongly\SVOH0ST.EXE un
O4 - 启动项HKLM\\Run: [res] ; C:\WINNT\system32\res.exe
O4 - 启动项HKLM\\Run: [ScanSoft PDF Professional 3.0-reminder] ; "C:\Program Files\ScanSoft\PDF Professional 3.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Professional\3\Ereg\ereg.ini"
O4 - HKCU\..\Run: [MemoryZipperPlus] D:\soft\system\memzipT\memzipT.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\soft\DOWNLOAD\flashget165\flashget165\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\soft\DOWNLOAD\flashget165\flashget165\jc_all.htm
O8 - IE右键菜单中的新增项目: 查看 Exif 信息(&V) - res://C:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINNT\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINNT\system32\shdocvw.dll
O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/star (file missing) (HKCU)
O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU)
O16 - DPF: {48038521-20FB-11D8-BC64-00B0D07A8A19} (PortalCom Control 2.0) - http://221.208.250.138/PortalAX02.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://pcastdl.dudu.com/files/pCastCtl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4261FBAC-C061-43C5-AB24-EA02A5138312}: NameServer = 202.103.0.117,202.103.24.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{4261FBAC-C061-43C5-AB24-EA02A5138312}: NameServer = 202.103.0.117,202.103.24.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{4261FBAC-C061-43C5-AB24-EA02A5138312}: NameServer = 202.103.0.117,202.103.24.68
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
谢谢