我电脑总是不时自动打开网页,扫描结果如下 请高手帮忙分析下 谢谢了
HijackThis_815汉化版扫描日志 V1.99.1
保存于 10:37:23, 日期 2006-10-9
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\wom\WinMem.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\阿达自动定时关机器\adtimer.exe
D:\Program Files\Cerience\RepliGo\RepliGoMon.exe
D:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Sony Handheld\Hotsync.exe
D:\Program Files\Sony Handheld\HandStory.exe
d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe
D:\Program Files\TTPlayer\TTPlayer.exe
d:\Program Files\WinRAR\WinRAR.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\lijie\LOCALS~1\Temp\Rar$EX00.313\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} -
D:\Program Files\超级兔子\haokanbar.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program files\google\googletoolbar1.dll (file missing)
O3 - IE工具栏增项: &RepliGo - {81F4066B-F330-4872-8094-3E9FBCCEC8C1} -
d:\Program Files\Cerience\RepliGo\RepliGoIEBar.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E}
- D:\Program Files\超级兔子\haokanbar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE"
/Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -
system
O4 - 启动项HKLM\\Run: [RfwMain] "d:\program files\rising\rfw\rfwmain.exe" -
startup
O4 - 启动项HKLM\\Run: [Windows内存整理] D:\Program Files\wom\WinMem.exe
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent] rundll32.exe
bthprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [ats] D:\Program Files\阿达自动定时关机器\adtimer.exe
noshow
O4 - 启动项HKLM\\Run: [RemoteControl] ; "d:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - 启动项HKLM\\Run: [nwiz] ; nwiz.exe /installquiet
O4 - 启动项HKLM\\Run: [RepliGo Assistant] "d:\Program
Files\Cerience\RepliGo\RepliGoMon.exe"
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [DAEMON Tools] "d:\Program Files\DAEMON
Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: HandStory.lnk = D:\Program Files\Sony Handheld\HandStory.exe
O4 - Global Startup: HotSync 管理器.lnk = D:\Program Files\Sony
Handheld\Hotsync.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - d:\Program Files\Thunder
Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - d:\Program Files\Thunder
Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: Google 搜索(&G) - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program
Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program
Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program
Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1
\MICROS~1\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program
Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program
Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program
Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-
0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail
(file missing)
O9 - 浏览器额外的“工具”菜单项: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-
0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail
(file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的“工具”菜单项: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-
432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao
(file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的“工具”菜单项: 雅虎助手 - {5D73EE86-05F1-49ed-B850-
E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist
(file missing)
O9 - 浏览器额外的按钮: Save To Palm - {6C8741AB-53B4-476e-BE7C-F519AD8A6494}
- D:\Program Files\Sony Handheld\HandStoryTE.htm
O9 - 浏览器额外的“工具”菜单项: Save To Palm - {6C8741AB-53B4-476e-BE7C-
F519AD8A6494} - D:\Program Files\Sony Handheld\HandStoryTE.htm
O9 - 浏览器额外的按钮: 酷热影音 - {7D73FF86-05F1-39ed-C850-A423120EC338} -
www.kuree.com/index.htm?id=00011001 (file missing)
O9 - 浏览器额外的“工具”菜单项: 酷热影音 - {7D73FF86-05F1-39ed-C850-
A423120EC338} - www.kuree.com/index.htm?id=00011001 (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -
D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}
- D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} -
D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的“工具”菜单项: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-
0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg
(file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32
\cn_api60.dll' missing
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) -
https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan
Object) -
http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) -
http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) -
https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://mlnwzj.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) -
http://upload.photo.163.com/photoup.cab
O16 - DPF: {BF8C499A-AC6E-4F58-82EA-9E5FCC41C34B} (PicUploadCtrl Class) -
http://tb.sogou.com/PicUpload.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) -
http://szdl.cmbchina.com/download/PB/pb50.cab
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} -
C:\WINDOWS\webwork\webwork.dll (file missing)
O23 - NT 服务: BlueSoleil Hid Service - Unknown owner - d:\Program Files\IVT
Corporation\BlueSoleil\BTNtService.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - NT 服务: MSCSPTISRV - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: PACSPTISVR - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - NT 服务: PDEngine - Raxco Software, Inc. - D:\Program
Files\Raxco\PerfectDisk\PDEngine.exe
O23 - NT 服务: PDScheduler (PDSched) - Raxco Software, Inc. - D:\Program
Files\Raxco\PerfectDisk\PDSched.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising
Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing
Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co.,
Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1
\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - NT 服务: SonicStage SCSI Service (SSScsiSV) - Sony Corporation -
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - NT 服务: Windows User Mode Driver Framework (UMWdf) - Unknown owner -
C:\WINDOWS\system32\wdfmgr.exe (file missing)