HijackThis_zww汉化版扫描日志 V1.99.1
保存于 15:43:10, 日期 2006-6-7
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\BenQ\QMusic2\QMAgent.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HuaCi\huaci\zsearch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ServeHost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\Documents and Settings\tcl\桌面\2535952005811174944\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {2C5AA40E-8814-4EB6-876E-7EFB8B3F9662} - (no file)
R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
R3 - URLSearchHook: 上网助手 - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr1.dll
R3 - URLSearchHook: (no name) - {419C38AC-42AD-4824-B447-3E9BFBB818C7} - C:\WINDOWS\system32\Mzzxv.dll
R3 - URLSearchHook: (no name) - {16C0204E-5044-4659-9F16-435AB2E5FC66} - C:\WINDOWS\system32\Vavca.dll
R3 - URLSearchHook: (no name) - {0597BC00-7790-4ECF-B00C-7B6F07324A44} - C:\WINDOWS\system32\Gxfbqm.dll
R3 - URLSearchHook: (no name) - {789DDAEE-A978-4483-9378-844CB82B1E3B} - C:\WINDOWS\system32\Xfnea.dll
R3 - URLSearchHook: (no name) - {03D1B3F9-1181-443B-A769-280036ED85A6} - C:\WINDOWS\system32\Yxdjl.dll
R3 - URLSearchHook: (no name) - {2A517A8C-5A1C-499B-BC2D-BBB2DBDDB455} - C:\WINDOWS\system32\Zfnzei.dll
R3 - URLSearchHook: (no name) - {5454B9AC-1736-4D30-87AA-8874F714C0EF} - C:\WINDOWS\system32\Kxgr.dll
R3 - URLSearchHook: (no name) - {0C48F77F-D686-48B5-85B5-DE7D95A042BE} - C:\WINDOWS\system32\Nmlcws.dll
O2 - BHO: (no name) - {03D1B3F9-1181-443B-A769-280036ED85A6} - C:\WINDOWS\system32\Yxdjl.dll
O2 - BHO: (no name) - {0597BC00-7790-4ECF-B00C-7B6F07324A44} - C:\WINDOWS\system32\Gxfbqm.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll
O2 - BHO: (no name) - {0C48F77F-D686-48B5-85B5-DE7D95A042BE} - C:\WINDOWS\system32\Nmlcws.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr1.dll
O2 - BHO: ChajianHelper Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\WINDOWS\system32\SYSREA~1.DLL
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: (no name) - {16C0204E-5044-4659-9F16-435AB2E5FC66} - C:\WINDOWS\system32\Vavca.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: (no name) - {2A517A8C-5A1C-499B-BC2D-BBB2DBDDB455} - C:\WINDOWS\system32\Zfnzei.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\f6a.dll
O2 - BHO: (no name) - {419C38AC-42AD-4824-B447-3E9BFBB818C7} - C:\WINDOWS\system32\Mzzxv.dll
O2 - BHO: Kmedia - {42D25F15-CF07-4A72-B191-DB0792BF310C} - C:\WINDOWS\system32\Kmedia.dll
O2 - BHO: (no name) - {5454B9AC-1736-4D30-87AA-8874F714C0EF} - C:\WINDOWS\system32\Kxgr.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: (no name) - {789DDAEE-A978-4483-9378-844CB82B1E3B} - C:\WINDOWS\system32\Xfnea.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\hbclient\tbhelper.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - IE工具栏增项: 东方网译 - {AB6BEAD2-325B-4729-BB13-DB24509EFA54} - d:\Dfkc3000\DFWYBand.dll
O3 - IE工具栏增项: 铭泰在线词语解释 - {CAEEE31B-6844-479C-ADAA-73B6D482E782} - d:\Dfkc3000\WebCBand.dll
O3 - IE工具栏增项: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - C:\KAV6\KAIEPlus.DLL (file missing)
O3 - IE工具栏增项: 上网助手 - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll (file missing)
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [!BD] ; Rundll32 C:\WINDOWS\DOWNLO~1\BDPlugin.dll,Rundll32
O4 - 启动项HKLM\\Run: [KnightIII] ; x?
O4 - 启动项HKLM\\Run: [Virtual Drive] ; "C:\Program Files\FarStone\VirtualDrive\vdtask.exe"
O4 - 启动项HKLM\\Run: [100bao] ; C:\PROGRA~1\100bao\Client.exe
O4 - 启动项HKLM\\Run: [ppdvdsomovie] ; D:\PROGRA~1\PPDVDS~1\Client.exe
O4 - 启动项HKLM\\Run: [Kulansyn] ; C:\KAV6\Kulansyn.EXE
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] ; D:\RavSasser.exe -Patch
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] ; "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - 启动项HKLM\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [QMusic2] "C:\Program Files\BenQ\QMusic2\QMAgent.exe"
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] ; "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [Desktop] C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop