最近感觉电脑的运行速度太慢
而且开网页很卡 不知道是不是中了病毒和木马 请大虾们帮检查下我日志 谢谢~!
Logfile of HijackThis v1.99.1
Scan saved at 18:14:12, on 2006-7-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Rising\Rfw\rfwmain.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\LHotkey.exe
C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\新建文件夹\248783200522382732\HijackThis.exe
R3 - URLSearchHook: (no name) - {DDD53BCE-DC51-4C6D-A1C3-58D550571E53} - C:\WINDOWS\system32\Vush.dll (file missing)
R3 - URLSearchHook: (no name) - {DCB70AC8-C4B6-46D6-A8C5-59B98C59B81A} - C:\WINDOWS\system32\Wgjp.dll (file missing)
R3 - URLSearchHook: (no name) - {5439CA9A-4BBC-439B-8862-B8307DC187B7} - C:\WINDOWS\system32\Fwxgm.dll (file missing)
R3 - URLSearchHook: (no name) - {36F1CB8C-D28E-4214-9C54-D3546B9E9F9C} - C:\WINDOWS\system32\Uqha.dll
R3 - URLSearchHook: (no name) - {59AA1089-608A-4D78-8737-C749282B28D6} - C:\WINDOWS\system32\Bqpj.dll
R3 - URLSearchHook: (no name) - {B96E429E-D6A7-42CB-B3EC-A7D5AFE2A83B} - C:\WINDOWS\system32\Yuiiui.dll
R3 - URLSearchHook: (no name) - {C37013A7-2A44-4760-B8F2-86FC3F66A20A} - C:\WINDOWS\system32\Ujag.dll
R3 - URLSearchHook: (no name) - {3916F7C6-222B-40E3-B30C-07FF23ABB742} - C:\WINDOWS\system32\Ctpu.dll
R3 - URLSearchHook: (no name) - {4A67D10F-0BA0-474E-A134-6FC41F15D482} - C:\WINDOWS\system32\Bknyv.dll
R3 - URLSearchHook: (no name) - {24EA7A67-AB17-4227-8BEB-5D198A993759} - C:\WINDOWS\system32\Zpyzau.dll
R3 - URLSearchHook: (no name) - {0414A4A7-AFD2-4850-BABE-018918EBFF94} - C:\WINDOWS\system32\Zjalgx.dll
R3 - URLSearchHook: (no name) - {DFD83C17-93F9-4E87-84F4-42B0DBD37B2D} - C:\WINDOWS\system32\Uviryg.dll
R3 - URLSearchHook: (no name) - {1EFA06F0-C462-4F56-BE25-501D47215F5F} - C:\WINDOWS\system32\Ibhwys.dll
R3 - URLSearchHook: (no name) - {708B0A00-FDC3-46E3-9921-DC38A39B5B89} - C:\WINDOWS\system32\Cmpqe.dll
R3 - URLSearchHook: (no name) - {6BF96058-B9E3-4AE2-A2AB-A2624A9BAD44} - C:\WINDOWS\system32\Rhhn.dll
R3 - URLSearchHook: (no name) - {EFEB8C1C-9ADB-4AC3-8ACE-FF827A0D8A2C} - C:\WINDOWS\system32\Hvsvan.dll
R3 - URLSearchHook: (no name) - {BFD9EA9A-9181-4777-8653-782AD1F0A117} - C:\WINDOWS\system32\Trkhdc.dll
R3 - URLSearchHook: (no name) - {43D13A49-8FAD-47F5-853A-60243B5666D8} - C:\WINDOWS\system32\Yvqsac.dll
R3 - URLSearchHook: (no name) - {C74CB5A8-1AAC-4E5A-BABA-A67F64F5434D} - C:\WINDOWS\system32\Yzzq.dll
R3 - URLSearchHook: (no name) - {D0D61DCB-B525-4DFB-A0B0-F5DE16C08AE7} - C:\WINDOWS\system32\Gdmqum.dll
R3 - URLSearchHook: SrchHook Class - {EED92A43-CFCE-4548-BD73-B0A405470ED5} - C:\PROGRA~1\CNNIC\Cdn\iesrch.dll (file missing)
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: (no name) - {0414A4A7-AFD2-4850-BABE-018918EBFF94} - C:\WINDOWS\system32\Zjalgx.dll
O2 - BHO: (no name) - {04F43E17-A38B-46E0-8776-08C4E4144F27} - C:\WINDOWS\system32\Mjxa.dll (file missing)
O2 - BHO: (no name) - {1EFA06F0-C462-4F56-BE25-501D47215F5F} - C:\WINDOWS\system32\Ibhwys.dll
O2 - BHO: (no name) - {24EA7A67-AB17-4227-8BEB-5D198A993759} - C:\WINDOWS\system32\Zpyzau.dll
O2 - BHO: MdkXfyxi Class - {34AAD461-8A43-477D-6EF2-363D04255AD3} - C:\WINDOWS\DOWNLO~1\ocsigtxv.dll
O2 - BHO: (no name) - {36F1CB8C-D28E-4214-9C54-D3546B9E9F9C} - C:\WINDOWS\system32\Uqha.dll
O2 - BHO: (no name) - {3916F7C6-222B-40E3-B30C-07FF23ABB742} - C:\WINDOWS\system32\Ctpu.dll
O2 - BHO: (no name) - {43D13A49-8FAD-47F5-853A-60243B5666D8} - C:\WINDOWS\system32\Yvqsac.dll
O2 - BHO: (no name) - {4A67D10F-0BA0-474E-A134-6FC41F15D482} - C:\WINDOWS\system32\Bknyv.dll
O2 - BHO: (no name) - {5439CA9A-4BBC-439B-8862-B8307DC187B7} - C:\WINDOWS\system32\Fwxgm.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: (no name) - {59AA1089-608A-4D78-8737-C749282B28D6} - C:\WINDOWS\system32\Bqpj.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: (no name) - {6BF96058-B9E3-4AE2-A2AB-A2624A9BAD44} - C:\WINDOWS\system32\Rhhn.dll
O2 - BHO: (no name) - {708B0A00-FDC3-46E3-9921-DC38A39B5B89} - C:\WINDOWS\system32\Cmpqe.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - E:\新建文件夹\ComDlls\XunLeiBHO_001.dll
O2 - BHO: (no name) - {B96E429E-D6A7-42CB-B3EC-A7D5AFE2A83B} - C:\WINDOWS\system32\Yuiiui.dll
O2 - BHO: (no name) - {BFD9EA9A-9181-4777-8653-782AD1F0A117} - C:\WINDOWS\system32\Trkhdc.dll
O2 - BHO: (no name) - {C37013A7-2A44-4760-B8F2-86FC3F66A20A} - C:\WINDOWS\system32\Ujag.dll
O2 - BHO: (no name) - {C74CB5A8-1AAC-4E5A-BABA-A67F64F5434D} - C:\WINDOWS\system32\Yzzq.dll
O2 - BHO: (no name) - {D0D61DCB-B525-4DFB-A0B0-F5DE16C08AE7} - C:\WINDOWS\system32\Gdmqum.dll
O2 - BHO: (no name) - {DCB70AC8-C4B6-46D6-A8C5-59B98C59B81A} - C:\WINDOWS\system32\Wgjp.dll (file missing)
O2 - BHO: (no name) - {DDD53BCE-DC51-4C6D-A1C3-58D550571E53} - C:\WINDOWS\system32\Vush.dll (file missing)
O2 - BHO: (no name) - {DFD83C17-93F9-4E87-84F4-42B0DBD37B2D} - C:\WINDOWS\system32\Uviryg.dll
O2 - BHO: (no name) - {EFEB8C1C-9ADB-4AC3-8ACE-FF827A0D8A2C} - C:\WINDOWS\system32\Hvsvan.dll
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LHotkey] LHotkey.exe
O4 - HKLM\..\Run: [Lcc] C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: !搜一搜(&S) - res://C:\Program Files\YiSou\yisou.dll/232
O8 - Extra context menu item: &使用迅雷下载 - E:\新建文件夹\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\新建文件夹\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 解霸实时播放 - C:\HEROSOFT\Hero3000\MPURLGET.HTM
O9 - Extra button: 解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - Extra 'Tools' menuitem: 超级解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [CDNCLIENT] 中文上网
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {E2D9AF38-368E-427B-B621-80DFBF89FFCA} (Download Class) - http://client.jogo.cn/download/cnnic/online/download.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{150278A0-5CD0-41BB-98D5-6645A3DE8543}: NameServer = 202.103.225.68 202.103.224.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{150278A0-5CD0-41BB-98D5-6645A3DE8543}: NameServer = 202.103.225.68 202.103.224.68
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINDOWS\system32\DLMain.dll (file missing)
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Server2.0 - Unknown owner - C:\WINDOWS\Server2.0.exe (file missing)