Logfile of HijackThis v1.99.1
Scan saved at 11:31:14, on 2006-12-31
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP4 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\drivers\spoclsv.exe
C:\WINNT\system32\conime.exe
H:\冲击波2000补丁\Windows2000-KB835732-x86-CHS.EXE
d:\30d951d188cf8bb4a6\update\UPDATE.EXE
H:\HijackThis.exe
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINNT\Downloaded Program Files\barsmall24.dll
O2 - BHO: 优客扩展 - {FA6EBA7B-7ADB-4860-8C42-F5296A2343DC} - C:\WINNT\system32\yokcol.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINNT\Downloaded Program Files\iesmall24.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTimer] C:\Program Files\Rising\Rav\RavTimer.exe
O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINNT\system32\hpnra.exe
O4 - HKLM\..\Run: [_KAVImmuniteSasser] LsassPatch.EXE
O4 - HKLM\..\Run: [RavTray] C:\Program Files\Rising\Rav\RavTray.exe
O4 - HKLM\..\Run: [RavMon] C:\Program Files\Rising\Rav\RavMon.exe -system
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKCU\..\Run: [svcshare] C:\WINNT\system32\drivers\spoclsv.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [myMh2] C:\DOCUME~1\cyl\LOCALS~1\Temp\mh2\iexpl0re.EXE
O4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\cyl\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 优客 - {A23817F2-733B-4BC5-8DED-C1B9B4BBF93C} - C:\WINNT\system32\yokbar.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {32C2F9F5-C91E-4DDF-85D7-3BC1BF8E6F5B} (首页更新V2.0) - http://10.124.128.5/afxUpdateProj.ocx
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {5F8BD092-EF5D-4D44-B556-9AC4307CB1A1} (FlowWeb Control) - http://10.124.226.7/jjhdfx/FlowWebProj.ocx
O16 - DPF: {A23817F2-733B-4BC5-8DED-C1B9B4BBF93C} (YOK 搜索(&Y) F8) - http://bar.yok.com/yokbar.cab
O16 - DPF: {BA506413-BC66-4842-ADAE-7EB68693D6BD} (EFControls.EFWord) - http://10.124.128.12/EFControls.CAB
O20 - AppInit_DLLs: 75976M.BMP
O23 - Service: Application Layer Gateway Services - Unknown owner - C:\WINNT\alg.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MSEXECW - Unknown owner - C:\WINNT\msexecw.exe
O23 - Service: nvidGUIv (nvidGUIv2) - Unknown owner - C:\WINNT\nvidGUIv.exe (file missing)
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Smart Card Helper (SCardDrv) - Unknown owner - C:\WINNT\system32\scardsvr32.exe (file missing)
O23 - Service: Server Advance (ServerAC) - Unknown owner - C:\WINNT\system32\Security.exe
O23 - Service: Windows explorer - Unknown owner - C:\WINNT\explore.exe


多谢了
&dec{wos°j6(¯bbs.ikaka.comÖNöÕ*N(Ìâ