HijackThis_zww汉化版扫描日志 V1.99.1
保存于 9:45:21, 日期 2006-09-22
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\msdtc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\system32\KDCOM\KDSvrMgrService.exe
C:\WINNT\System32\llssrv.exe
g:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
g:\PROGRA~1\MICROS~1\MSSQL\binn\sqlagent.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\DrvMon.exe
D:\YDZFNEW\银海升级软件\autodownload.exe
C:\WINNT\system32\conime.exe
C:\Program Files\Iparmor\Iparmor.exe
E:\电脑部工具\病毒木马相关\HijackThis1991zww.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5003.dll (file missing)
O3 - IE工具栏增项: Micrsoft SearchBar - {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - C:\Program Files\Micrsoft SearchBar\SearchBar.dll (file missing)
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - 启动项HKLM\\Run: [spoolsv] C:\WINNT\system32\spoolsv\spoolsv.exe -printer
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [MSConfig] E:\电脑部工具\系统相关\msconfig.exe /auto
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINNT\system32\DrvMon.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O8 - IE右键菜单中的新增项目: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\qq\SendMMS.htm
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\quartz32.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\quartz32.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CE65AD8-06E2-466F-A721-C14495A3F3D1}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CE65AD8-06E2-466F-A721-C14495A3F3D1}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0CE65AD8-06E2-466F-A721-C14495A3F3D1}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS3\Services\Tcpip\..\{0CE65AD8-06E2-466F-A721-C14495A3F3D1}: NameServer = 61.128.128.68,61.128.192.68
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\system32\itss.dll
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINNT\system32\inetcomm.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - 列举现有的协议: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\system32\itss.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - 列举现有的协议: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: Internet Settings - C:\WINNT\system32\nawrsja.dll (file missing)
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: DameWare Mini Remote Control (DWMRCS) - Unknown owner - C:\WINNT\SYSTEM32\DWRCS.EXE (file missing)
O23 - NT 服务: KDDelegateService - KINGDEE - d:\Kingdee\K3ERP\KDDelegateService.exe
O23 - NT 服务: KDSvrMgrService - KINGDEE - C:\WINNT\system32\KDCOM\KDSvrMgrService.exe
O23 - NT 服务: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
O23 - NT 服务: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: OracleOraHome81Agent - Unknown owner - d:\oracle\ora81\bin\dbsnmp.exe (file missing)
O23 - NT 服务: OracleOraHome81ClientCache - Unknown owner - d:\oracle\ora81\BIN\ONRSD.EXE (file missing)
O23 - NT 服务: OracleOraHome81DataGatherer - Unknown owner - d:\oracle\ora81\bin\vppdc.exe (file missing)
O23 - NT 服务: OracleOraHome81HTTPServer - Unknown owner - d:\oracle\ora81\Apache\Apache\Apache.exe (file missing)
O23 - NT 服务: OracleOraHome81PagingServer - Unknown owner - d:\oracle\ora81/bin/pagntsrv.exe (file missing)
O23 - NT 服务: OracleOraHome81TNSListener - Unknown owner - d:\oracle\ora81\BIN\TNSLSNR.exe
O23 - NT 服务: OracleServiceORACLE - Oracle Corporation - d:\oracle\ora81\bin\ORACLE.EXE
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: Remote Administrator Service (r_server) - Unknown owner - C:\WINNT\system32\r_server.exe" /service (file missing)
O23 - NT 服务: Print Spooler (Spooler) - Unknown owner - C:\WINNT\system32\spoolsv.exe (file missing)