日记如下:
Logfile of HijackThis v1.99.1
Scan saved at 13:56:50, on 2005-8-6
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\WSEARCH\SEARCH.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\RISING\RAV\RAVTIMER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE
D:\WINAMP2\WINAMP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MAXTHON\MAXTHON.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE
C:\PROGRAM FILES\MAXTHON\MAXTHON.EXE
C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
C:\WINDOWS\FAVORITES\DESKTOP\504499200586121920\HIJACKTHIS.EXE
R3 - Default URLSearchHook is missing
O1 - Hosts: 219.153.0.122 233331.com
O1 - Hosts: 219.153.0.122 www.kk866.com
O1 - Hosts: 219.153.0.122 kk866.com
O1 - Hosts: 219.153.0.122 www.55665.com
O1 - Hosts: 219.153.0.122 55665.com
O1 - Hosts: 219.153.0.122 www.tk1819.com
O1 - Hosts: 219.153.0.122 tk1819.com
O1 - Hosts: 219.153.0.122 www.lhcok.com
O1 - Hosts: 219.153.0.122 lhcok.com
O1 - Hosts: 219.153.0.122 www.hy448.com
O1 - Hosts: 219.153.0.122 hy448.com
O1 - Hosts: 219.153.0.122 www.pk668.net
O1 - Hosts: 219.153.0.122 pk668.net
O1 - Hosts: 219.153.0.122 www.pk668.net
O1 - Hosts: 219.153.0.122 pk668.net
O1 - Hosts: 219.153.0.122 www.ok3899.com
O1 - Hosts: 219.153.0.122 ok3899.com
O1 - Hosts: 219.153.0.122 www.vv567.com
O1 - Hosts: 219.153.0.122 vv567.com
O1 - Hosts: 219.153.0.122 www.77858.net
O1 - Hosts: 219.153.0.122 77858.net
O1 - Hosts: 219.153.0.122 www.45898.com
O1 - Hosts: 219.153.0.122 45898.com
O1 - Hosts: 219.153.0.122 www.qt888.com
O1 - Hosts: 219.153.0.122 qt888.com
O1 - Hosts: 219.153.0.122 www.hty688.com
O1 - Hosts: 219.153.0.122 hty688.com
O1 - Hosts: 219.153.0.122 www.222yyy.com
O1 - Hosts: 219.153.0.122 222yyy.com
O1 - Hosts: 219.153.0.122 www.ok3389.com
O1 - Hosts: 219.153.0.122 ok3389.com
O1 - Hosts: 219.153.0.122 www.six007.com
O1 - Hosts: 219.153.0.122 six007.com
O1 - Hosts: 219.153.0.122 www.xg588.net
O1 - Hosts: 219.153.0.122 xg588.net
O1 - Hosts: 219.153.0.122 www.60883.com
O1 - Hosts: 219.153.0.122 60883.com
O1 - Hosts: 219.153.0.122 www.30772.com
O1 - Hosts: 219.153.0.122 30772.com
O1 - Hosts: 219.153.0.122 www.58gg.com
O1 - Hosts: 219.153.0.122 58gg.com
O1 - Hosts: 219.153.0.122 www.y999.hk
O1 - Hosts: 219.153.0.122 y999.hk
O1 - Hosts: 219.153.0.122 www.798136.com
O1 - Hosts: 219.153.0.122 798136.com
O1 - Hosts: 219.153.0.122 www.ab8899.com
O1 - Hosts: 219.153.0.122 ab8899.com
O1 - Hosts: 219.153.0.122 www.556788.com
O1 - Hosts: 219.153.0.122 556788.com
O1 - Hosts: 219.153.0.122 www.qq5678.com
O1 - Hosts: 219.153.0.122 qq5678.com
O1 - Hosts: 219.153.0.122 www.y5555.com
O1 - Hosts: 219.153.0.122 y5555.com
O1 - Hosts: 219.153.0.122 www.49uu.com
O1 - Hosts: 219.153.0.122 49uu.com
O1 - Hosts: 219.153.0.122 www.hongkongsixbxj.com
O1 - Hosts: 219.153.0.122 hongkongsixbxj.com
O1 - Hosts: 219.153.0.122 www.4778.com
O1 - Hosts: 219.153.0.122 4778.com
O1 - Hosts: 219.153.0.122 www.www.26.hk
O1 - Hosts: 219.153.0.122 www.26.hk
O1 - Hosts: 219.153.0.122 www.k5566.net
O1 - Hosts: 219.153.0.122 k5566.net
O1 - Hosts: 219.153.0.122 www.qq887.com
O1 - Hosts: 219.153.0.122 qq887.com
O1 - Hosts: 219.153.0.122 www.12kk.com
O1 - Hosts: 219.153.0.122 12kk.com
O1 - Hosts: 219.153.0.122 www.868kk.com
O1 - Hosts: 219.153.0.122 868kk.com
O1 - Hosts: 219.153.0.122 www.my7177.com
O1 - Hosts: 219.153.0.122 my7177.com
O1 - Hosts: 219.153.0.122 www.hao16.com
O1 - Hosts: 219.153.0.122 hao16.com
O1 - Hosts: 219.153.0.122 www.58558.net
O1 - Hosts: 219.153.0.122 58558.net
O1 - Hosts: 219.153.0.122 www.kktkk.com
O1 - Hosts: 219.153.0.122 kktkk.com
O1 - Hosts: 219.153.0.122 www.9983.net
O1 - Hosts: 219.153.0.122 9983.net
O1 - Hosts: 219.153.0.122 www.lt163.com
O1 - Hosts: 219.153.0.122 lt163.com
O1 - Hosts: 219.153.0.122 www.xg90.com
O1 - Hosts: 219.153.0.122 xg90.com
O1 - Hosts: 219.153.0.122 www.8827.com
O1 - Hosts: 219.153.0.122 8827.com
O1 - Hosts: 219.153.0.122 www.ok68168.com
O1 - Hosts: 219.153.0.122 ok68168.com
O1 - Hosts: 219.153.0.122 www.774477.com
O1 - Hosts: 219.153.0.122 774477.com
O1 - Hosts: 219.153.0.122 www.ba118.com
O1 - Hosts: 219.153.0.122 ba118.com
O1 - Hosts: 219.153.0.122 www.tu100.com
O1 - Hosts: 219.153.0.122 tu100.com
O1 - Hosts: 219.153.0.122 www.ma999.com
O1 - Hosts: 219.153.0.122 ma999.com
O1 - Hosts: 219.153.0.122 www.333bbb.com
O1 - Hosts: 219.153.0.122 333bbb.com
O1 - Hosts: 219.153.0.122 www.ggcyy.com
O1 - Hosts: 219.153.0.122 ggcyy.com
O1 - Hosts: 219.153.0.122 www.avvip.com
O1 - Hosts: 219.153.0.122 avvip.com
O2 - BHO: IE Accessibility Helper - {D0CF128D-6D31-4989-959F-62758166A46C} - C:\PROGRA~1\INTERN~1\NETBUS\IE_AD.DLL (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL
O2 - BHO: (no name) - {9EB0B159-B048-45C7-8CE3-B1908944436B} - C:\WINDOWS\DOWNLO~1\IEUB899.DLL (file missing)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CNSMIN.DLL,Rundll32
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [EPSON Stylus C41 Seri (复制 2)] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P30 "EPSON Stylus C41 Seri (复制 2)" /O5 "LPT1:" /M "Stylus C41"
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [netbus] C:\\netbus.exe
O4 - HKLM\..\Run: [Super Rabbit SRRestore] D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRREST.exe /autosave
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [MoveSearch] C:\PROGRAM FILES\WSEARCH\SEARCH.EXE
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\RunServices: [RsCcenter] C:\PROGRA~1\RISING\RAV\CCENTER.EXE
O4 - HKLM\..\RunServices: [RavMond] C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
O4 - HKLM\..\RunServices: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\CnsMinEx.dll/1003
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_fh666_5427 (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS] 网络实名
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
O16 - DPF: {CF85459D-DFA7-4028-A065-3C6D1356DCC8} (CertInstall Control) - http://gd.chinavnet.com/CertInstall.cab
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://ol.db.kingsoft.com/antiscan/setup/KAVClean.CAB
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab