日志文件: 趋势科技 HijackThis v2.0.0 (BETA)
保存时间: 11:57:06, on 2008-6-23
操作系统: Windows XP SP2 (WinNT 5.01.2600)
启动模式: 正常
正在运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
F:\软件\RIXING\Rising\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
F:\软件\RIXING\RISING\RISING\RAV\ravmond.exe
F:\软件\RIXING\Rising\Rising\Rfw\rfwsrv.exe
F:\软件\RIXING\Rising\Rising\Rfw\rfwstub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
F:\软件\RIXING\RISING\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wdfmgr.exe
F:\软件\RIXING\Rising\Rising\Rfw\rfwProxy.exe
C:\WINDOWS\System32\alg.exe
F:\大智慧\河北财达证券大智慧\internet\hypmain.exe
C:\Program Files\TTPlayer\TTPlayer.exe
F:\软件\RIXING\Rising\Rising\Rfw\RfwMain.exe
F:\大智慧\河北财达证券大智慧\internet\hypwise.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\软件\RIXING\HA_HijackThisv2_PP\HiJackThis_v2.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
O2 - BHO: QQCycloneHelper - {00000000-12C9-4305-82F9-43058F20E8D2} - F:\下载工具\超级旋风\QQIEHelper01.dll
O2 - BHO: WebThunderBHO - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - F:\下载工具\WED讯雷\WebThunderBHO_013.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\下载工具\讯雷\ComDlls\XunLeiBHO_002.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "F:\软件\RIXING\Rising\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "F:\软件\RIXING\Rising\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [KKDelay] F:\软件\RIXING\卡卡安全助手\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - 扩展右键菜单项: &使用BitComet下载 - res://F:\下载工具\bt0.64\BitComet.exe/AddLink.htm
O8 - 扩展右键菜单项: &使用BitComet下载全部链接 - res://F:\下载工具\bt0.64\BitComet.exe/AddAllLink.htm
O8 - 扩展右键菜单项: &使用BitComet下载本页视频 - res://F:\下载工具\bt0.64\BitComet.exe/AddVideo.htm
O8 - 扩展右键菜单项: &使用迅雷下载 - F:\下载工具\讯雷\Program\GetUrl.htm
O8 - 扩展右键菜单项: &使用迅雷下载全部链接 - F:\下载工具\讯雷\Program\GetAllUrl.htm
O8 - 扩展右键菜单项: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - 扩展右键菜单项: 添加到QQ表情 - F:\软件\官方QQ\AddEmotion.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - F:\下载工具\讯雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - F:\下载工具\讯雷\Thunder.exe
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\浩方对战\platform\GameClient.exe
O9 - Extra button: JUJU猫 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} -
http://www.jujumao.com (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: f:\
O10 - Unknown file in Winsock LSP: f:\
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fwansdrv.dll
O10 - Unknown file in Winsock LSP: f:\
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156070122671O17 - HKLM\System\CCS\Services\Tcpip\..\{05EA5356-9360-46BA-8882-5D07E7F13D1C}: NameServer = 202.99.160.68 202.99.166.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{05EA5356-9360-46BA-8882-5D07E7F13D1C}: NameServer = 202.99.160.68 202.99.166.4
O18 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O20 - AppInit_DLLs: ieprot.dll
O22 - SharedTaskScheduler: Browseui 预加载程序 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: 组件类别缓存程序 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - F:\软件\RIXING\Rising\Rising\Rfw\rfwProxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - F:\软件\RIXING\Rising\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - F:\软件\RIXING\Rising\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - F:\软件\RIXING\RISING\RISING\RAV\Ravmond.exe
是不是数字 -010 那个有问题?????
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; (R1 1.5))