![](icon/face12.gif)
没人理我啊,大家帮我看下日志啊,我刚把那个病毒文件在360里给粉碎掉了,帮我看看好没?
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 22:16:21, 日期 2008-4-14
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
G:\瑞星\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
G:\瑞星\RISING\RAV\ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
G:\瑞星\RISING\RAV\RavStub.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
G:\瑞星\Rising\Rav\RavTask.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\360安全卫士\360safe\safemon\360Tray.exe
G:\瑞星\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\四海互动\四海互动游戏加速器\SpeedNet.exe
E:\qq2008bata\QQ.exe
E:\qq2008bata\TXPlatform.exe
C:\WINDOWS\system32\conime.exe
G:\TT\TTraveler.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.437\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - G:\讯雷\xunlei\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - G:\讯雷\xunlei\ComDlls\xunleiBHO_Now.dll
O2 - BHO: Adobe Common
Objects - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} - C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2048.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [RavTask] "G:\瑞星\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [360Safetray] G:\360安全卫士\360safe\safemon\360Tray.exe /start
O4 - 启动项HKLM\\RunOnce: [KKDelay] E:\卡卡\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O8 - IE右键菜单中的新增项目: 使用迅雷下载 - G:\讯雷\xunlei\Program\geturl.htm
O8 - IE右键菜单中的新增项目: 使用迅雷下载全部链接 - G:\讯雷\xunlei\Program\getallurl.htm
O8 - IE右键菜单中的新增项目: 复制到我的QQ记事本 - http://mail.qq.com/cgi-bin/loginpage?r=1&templatename=note_copy
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://E:\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\qq2008bata\AddEmotion.htm
O9 - 浏览器额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的按钮: 一起来音乐社区 - {7DBC6ADB-5788-4FB9-AEC3-B40A58AC11DF} - http://www.yiqilai.com (file missing)
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\OFFICE~1\OFFICE11\REFIEBAR.DLL
O10 - 未知的文件在 Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O16 - DPF: {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} (PhotoDraw Class) - http://imgcache.qq.com/qzone/client/photo/pages/QQPhotoDrawSetup.exe
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/1101/aliedit.cab
O16 - DPF: {B4D9857D-8A55-4442-A577-6B3ED5D4E41B} (ScreenCapture Class) - http://mail.qq.com/zh_CN/activex/TencentMailActiveX.cab
O16 - DPF: {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} (ScreenCapture Class) - http://m53.mail.qq.com/zh_CN/activex/TencentMailActiveX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{26628A7A-C33A-4727-9CB8-C2C5A474CC56}: NameServer = 211.98.2.4 211.98.4.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{82EED9A8-AE22-4449-9DD3-0F6010C2F9A6}: NameServer = 211.98.2.4 211.98.4.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{87FE686F-2AE3-4C70-B12A-DAF7BACE69DA}: NameServer = 211.98.2.4 211.98.4.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{26628A7A-C33A-4727-9CB8-C2C5A474CC56}: NameServer = 211.98.2.4 211.98.4.1
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - NT 服务: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - NT 服务: portablemsi - Unknown owner - C:\WINDOWS\system32\lantian.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - G:\瑞星\Rising\Rav\CCenter.exe
O23 - NT 服务: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - G:\瑞星\RISING\RAV\Ravmond.exe