1   1  /  1  页   跳转

求救

求救

下面是我hijackthis报告,请高手帮忙!!!!
最后编辑2005-10-10 10:44:17
分享到:
gototop
 

Logfile of HijackThis v1.99.0
Scan saved at 10:33:42, on 2005-10-10
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\WINDOWS\system32\slserv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\CNNIC\Cdn\cdnup.exe
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\System32\conime.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
E:\巅峰3\大补贴1.82验证破解版\大补贴本地验证器.exe
E:\巅峰3\大补贴1.82验证破解版\传奇3大补贴.exe
D:\Program Files\Tencent\QQ\QQexternal.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\BitSpirit\BitSpirit.exe
D:\Program Files\Rising\Rav\RavMon.exe
D:\Documents and Settings\WANGFENGSHOU\桌面\HijackThis\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 222.83.177.22 popme.163.com
O1 - Hosts: 222.83.177.22 www.xk99.com
O1 - Hosts: 222.83.177.22 www.006.net
O1 - Hosts: 222.83.177.22 006.net
O1 - Hosts: 222.83.177.22 www.cmfu.com
O1 - Hosts: 222.83.177.22 www.free120.com
O1 - Hosts: 222.83.177.22 www.4577.com
O1 - Hosts: 222.83.177.22 www.9617.com
O1 - Hosts: 222.83.177.22 www.fjwz.com
O1 - Hosts: 222.83.177.22 partner.cpc.sohu.com
O1 - Hosts: 222.83.177.22 ad4.sina.com.cn
O1 - Hosts: 222.83.177.22 music.17o8.comer.cpc.sohu.com
O1 - Hosts: 222.83.177.22 ad.tom.com
O1 - Hosts: 222.83.177.22 search.union.3721,com
O1 - Hosts: 222.83.177.22 post.baidu.com
O1 - Hosts: 222.83.177.22 mp3.baidu.com
O1 - Hosts: 222.83.177.22 image.baidu.com
O1 - Hosts: 222.83.177.22 site.google.com
O1 - Hosts: 222.83.177.22 flash.baidu.com
O1 - Hosts: 222.83.177.22 assistant.3721,com
O1 - Hosts: 222.83.177.22 pfp.sina.com.cn
O1 - Hosts: 222.83.177.22 cn.websearch.yahoo.com
O1 - Hosts: 222.83.177.22 sms.qq.com
O1 - Hosts: 222.83.177.22 www.qq.com
O1 - Hosts: 222.83.177.22 partner.lead2.com.cn
O1 - Hosts: 222.83.177.22 ad.cn.doubleclick.net
O1 - Hosts: 222.83.177.22 auto.search.msn.com
O1 - Hosts: 222.83.177.22 www.ourgame.com
O1 - Hosts: 222.83.177.22 www.the9.com
O1 - Hosts: 222.83.177.22 www.flashempire.com
O1 - Hosts: 222.83.177.22 www.qq163.com
O1 - Hosts: 222.83.177.22 www.9sky.com
O1 - Hosts: 222.83.177.22 www.tom-1.com
O1 - Hosts: 222.83.177.22 www.17173.com
O1 - Hosts: 222.83.177.22 www.yaotou.com
O1 - Hosts: 222.83.177.22 union.3721,com
O1 - Hosts: 222.83.177.22 music.feifa.com
O1 - Hosts: 222.83.177.22 www.vodfans.com
O1 - Hosts: 222.83.177.22 www.sogua.com
O1 - Hosts: 222.83.177.22 fm974.tom.com
O1 - Hosts: 222.83.177.22 ent.tom.com
O1 - Hosts: 222.83.177.22 music.tyfo.com
O1 - Hosts: 222.83.177.22 www.wanwa.com
O1 - Hosts: 222.83.177.22 www.guang.org
O1 - Hosts: 222.83.177.22 www.wz.zj.cn
O1 - Hosts: 222.83.177.22 www.3189.net
O1 - Hosts: 222.83.177.22 music.17o8.com
O1 - Hosts: 222.83.177.22 www.99music.net
O1 - Hosts: 222.83.177.22 www.cococ.com
O1 - Hosts: 222.83.177.22 www.qqqq.cn
O1 - Hosts: 222.83.177.22 www.bnb.com.cn
O1 - Hosts: 222.83.177.22 www.z163.com
O1 - Hosts: 222.83.177.22 game.163.com
O1 - Hosts: 222.83.177.22 games.sina.com.cn
O1 - Hosts: 222.83.177.22 www.v111.com
O1 - Hosts: 222.83.177.22 music.v111.com
O1 - Hosts: 222.83.177.22 www.3tom.com
O1 - Hosts: 222.83.177.22 www.xkqq.com
O1 - Hosts: 222.83.177.22 www.verymp3.com
O1 - Hosts: 222.83.177.22 www.91look.com
O1 - Hosts: 222.83.177.22 www.168101.com
O1 - Hosts: 222.83.177.22 www.cmfu.com
O1 - Hosts: 222.83.177.22 www.woogood.com
O1 - Hosts: 222.83.177.22 www.haodx.com
O1 - Hosts: 222.83.177.22 www.yingku.com
O1 - Hosts: 222.83.177.22 www.flash51.com
O1 - Hosts: 222.83.177.22 www.17haha.com
O1 - Hosts: 222.83.177.22 www.432.cn
O1 - Hosts: 222.83.177.22 www.cnxp.com
O1 - Hosts: 222.83.177.22 www.hjsm.net
O1 - Hosts: 222.83.177.22 music.8wa.com
O1 - Hosts: 222.83.177.22 www.66vv.com
O1 - Hosts: 222.83.177.22 www.musicfbi.com
O1 - Hosts: 222.83.177.22 www.vv66.com
O1 - Hosts: 222.83.177.22 www.139mm.com
O1 - Hosts: 222.83.177.22 www.130wg.com
O1 - Hosts: 222.83.177.22 www.flashsea.com
O1 - Hosts: 222.83.177.22 movie.59178.com
O1 - Hosts: 222.83.177.22 www.wo123.com
O1 - Hosts: 222.83.177.22 www.1ya.cn
O1 - Hosts: 222.83.177.22 www.happy8.cn
O1 - Hosts: 222.83.177.22 www.s6.cn
O1 - Hosts: 222.83.177.22 www.hao123.com
O1 - Hosts: 222.83.177.22 www.qqee.com
O1 - Hosts: 222.83.177.22 imgu.21cn.com
O1 - Hosts: 222.83.177.22 www.sohu123.com
O1 - Hosts: 222.83.177.22 www.chinamp3.com
O1 - Hosts: 222.83.177.22 www.18z.net
O1 - Hosts: 222.83.177.22 www.ssxs.com
O1 - Hosts: 222.83.177.22 www.fjwz.net
O1 - Hosts: 222.83.177.22 www.wo365.com
O1 - Hosts: 222.83.177.22 www.zhao99.com
O1 - Hosts: 222.83.177.22 www.cn808.net
O1 - Hosts: 222.83.177.22 www.tt55.net
O1 - Hosts: 222.83.177.22 www.mp3tt.com
O1 - Hosts: 222.83.177.22 www.yi5.com
O1 - Hosts: 222.83.177.22 www.haozs.com
O1 - Hosts: 222.83.177.22 www.77ttt.com
O1 - Hosts: 222.83.177.22 www.77xi.com
O1 - Hosts: 222.83.177.22 13258.com
O1 - Hosts: 222.83.177.22 www.13258.com
gototop
 

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: 百度搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\WINDOWS\DOWNLO~1\BaiDuBar.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - D:\WINDOWS\DOWNLO~1\CnsHook.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - D:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - Toolbar: 百度搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\WINDOWS\DOWNLO~1\BaiDuBar.dll
O3 - Toolbar: IE伴郎 - {B225B89D-5E95-4194-98E8-149993071B31} - D:\PROGRA~1\NETMEE~1\CALLCO~1.DLL
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [迅雷4] C:\Program Files\Thunder Network\GameIssue\TDUpdate.exe
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CdnCtr] D:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe D:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [helper.dll] D:\WINDOWS\system32\rundll32.exe D:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKLM\..\RunOnce: [CnsMinKP] rundll32.exe  D:\WINDOWS\DOWNLO~1\KEEPMAIN.DLL,ReInstallKP
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: !搜一搜 - res://D:\WINDOWS\DOWNLO~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &Download by NetAnts - D:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Download &All by NetAnts - D:\PROGRA~1\NETANTS\NAGetAll.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - D:\Program Files\P4P\dl.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: 百度Flash搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM
O8 - Extra context menu item: 百度mp3搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度信息快递搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM
O8 - Extra context menu item: 百度图片搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度新闻搜索 - res://D:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 访问通用网址 - D:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=52929_1006 (file missing)
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816 (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/?source=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Unknown file in Winsock LSP: d:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {115074A0-83F0-42C0-B694-A5320628AEDE} (MeChatA Class) - http://www.zeeroo.com:6000/audio/MeChatAudio.cab
O16 - DPF: {165A9A20-EA14-4241-91F7-ED1FA184CD20} (MeChatV Class) - http://www.zeeroo.com:6000/video/MeChatVideo.cab
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/137ccacb8e73ce2e0405/netzip/RdxIE601_cn.cab
O16 - DPF: {6EC14D77-72E0-436D-8C04-3BEE5D75B2F1} (VideoOcx Control) - http://lt.2000y.net/room/roomui/videoocx.ocx
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} (Filetran Control) - http://www.bluesky.cn/download/filetran.cab
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {C07405FD-84D1-4A25-94E8-68609EA8335B} (iChatX Object) - http://www.ichat.net.cn/ichatvideo/v2_5/ichatx.dll
O16 - DPF: {EF9F1C48-1A63-495A-9317-B7B71B34A9CF} (Msp Class) - http://ddddl.dudu.com/ddd/update/plugin/sinamsp.cab
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINDOWS\System32\mbprot.dll
O23 - Service: eFilmProcessManagerNT - Unknown - D:\Program Files\eFilm Medical\eFilm\efPMNT.exe
O23 - Service: Rising Process Communication Center - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT