在这里先谢了!!
Logfile of HijackThis v1.99.1
Scan saved at 22:33:23, on 2006-8-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\conime.exe
D:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe
D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\gougou\桌面\HijackThis.exe
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll (file missing)
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5002.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\Program Files\BaiDu\bar\BaiduBar.dll
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Program Files\BaiDu\bar\BaiduBar.dll
O3 - Toolbar: 实用搜索工具条V2.0 - {75D82598-4A3C-419e-99D2-3EB56D09CFD0} - C:\Program Files\UtilToolBar\utilbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O11 - Options group: [CDNCLIENT] 中文上网
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {3676996C-D8C6-4356-B4BE-3A80400C606E} ({3676996C-D8C6-4356-B4BE-3A80400C606E}) - http://www.vod588.com/BoBo_ActiveX_1.19b.ocx
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://password.qq.com/download/qqedit.cab
O16 - DPF: {E9707834-5BF7-4CFF-A639-398427DE1991} (IcbcSslCacheCleanerCtrl Class) - http://www.icbc.com.cn/left/IcbcSslCacheCleaner.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
进程列表:
Process list saved on 22:34:45, on 2006-8-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
[pid] [full path to filename] [file version] [company name]
452 C:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation
524 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 Microsoft Corporation
568 C:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation
580 C:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation
732 C:\WINDOWS\system32\Ati2evxx.exe 6.14.10.4105
748 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
880 C:\Program Files\Rising\Rav\CCenter.exe 18.0.0.3 Beijing Rising Technology Co., Ltd.
904 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1220 c:\program files\rising\rfw\rfwsrv.exe 4.0.0.32 Beijing Rising Technology Co., Ltd.
1336 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.2696 Microsoft Corporation
1660 C:\WINDOWS\system32\drivers\CDAC11BA.EXE 4.20.30.0 Macrovision
1764 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
996 C:\WINDOWS\Explorer.EXE 6.0.2900.2180 Microsoft Corporation
1356 c:\program files\rising\rfw\RfwMain.exe 4.0.0.52 Beijing Rising Technology Co., Ltd.
272 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
372 C:\Program Files\Rising\Rav\RavTask.exe 18.0.0.22 Beijing Rising Technology Co., Ltd.
404 C:\Program Files\Rising\Rav\Ravmon.exe 18.0.1.33 Beijing Rising Technology Co., Ltd.
1188 C:\WINDOWS\system32\ctfmon.exe 5.1.2600.2180 Microsoft Corporation
1784 C:\Program Files\Rising\Rav\Ravmond.exe 18.0.1.35 Beijing Rising Technology Co., Ltd.
2128 C:\Program Files\Rising\Rav\RavStub.exe 18.0.0.16 Beijing Rising Technology Co., Ltd.
2332 C:\Program Files\Rising\Rav\Rav.exe 18.0.0.75 Beijing Rising Technology Co., Ltd.
2356 C:\Program Files\Rising\Rav\RsAgent.exe 18.0.0.12 Beijing Rising Technology Co., Ltd.
2376 C:\WINDOWS\msagent\AgentSvr.exe 2.0.0.3422 Microsoft Corporation
2664 C:\WINDOWS\system32\conime.exe 5.1.2600.2180 Microsoft Corporation
2712 D:\Program Files\Tencent\TT\TTraveler.exe 3.0.0.250 腾讯公司
3020 D:\Program Files\Tencent\QQ\QQ.exe 0.0.0.0 TENCENT
3056 D:\Program Files\Tencent\QQ\TIMPlatform.exe 0.3.1.8 tencent
344 D:\Program Files\Tencent\QQ\QQ.exe 0.0.0.0 TENCENT
2252 D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe 1.6.6.529 淘宝(中国)软件有限公司
2632 D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe 1.6.6.529 淘宝(中国)软件有限公司
2836 C:\WINDOWS\system32\rundll32.exe 5.1.2600.2180 Microsoft Corporation
1112 C:\Documents and Settings\gougou\桌面\HijackThis.exe 1.99.0.1 Soeperman Enterprises Ltd.
1428 C:\WINDOWS\system32\NOTEPAD.EXE 5.1.2600.2180 Microsoft Corporation
不知道有什么问题~ !请帮忙看一下~