电脑B:
再次说明,今天突然杀不出毒了,不知道怎么回事情,不过还是请各位大大分析下日志,谢谢
Logfile of HijackThis v1.99.1
Scan saved at 18:13:13, on 2006-7-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
f:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
f:\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
F:\SyGate\SHN\Sygate.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Rising\Rav\RavTask.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\System32\ctfmon.exe
F:\Rising\Rav\Ravmon.exe
f:\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
f:\SyGate\SHN\sgserv.exe
E:\方羽公\下载\ha_hijackthis_1991\HijackThis.exe
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - {0064AE8F-BEAB-4AF3-9A05-C1898E223504} - C:\WINDOWS\System32\Mvbbo.dll (file missing)
O2 - BHO: (no name) - {030A18BA-CC64-4BF1-99B7-24C9F3BE80E8} - C:\WINDOWS\System32\Tfafmp.dll
O2 - BHO: (no name) - {0D2E53DE-B5C9-44B9-9811-FABC04A65D24} - C:\WINDOWS\System32\Zmrxpg.dll
O2 - BHO: (no name) - {122AFB34-DA76-4C51-B45D-137CBCF421EC} - C:\WINDOWS\System32\Zrcx.dll
O2 - BHO: (no name) - {162EF72C-16AC-4A05-B485-25402AE08601} - C:\WINDOWS\System32\Ozktsc.dll (file missing)
O2 - BHO: (no name) - {1F51C6A7-F024-4340-8759-C81C5CFE53A9} - C:\WINDOWS\System32\Atzrdm.dll (file missing)
O2 - BHO: (no name) - {23D0CCE4-72DC-4DC7-817D-38958A5CA6D1} - C:\WINDOWS\System32\Glnx.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\3721\Assist\Angling.dll
O2 - BHO: (no name) - {4AF4BB84-16C8-40E1-A804-1AB5F16D9B65} - C:\WINDOWS\System32\Nixqo.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\Tencent\qq\QQIEHelper.dll
O2 - BHO: (no name) - {5B548C3A-3719-481B-8980-4DAACB16AB59} - C:\WINDOWS\System32\Yvms.dll (file missing)
O2 - BHO: (no name) - {5FC7D72B-DC73-441A-8F35-60B2ECFDB98B} - C:\WINDOWS\System32\Yrxh.dll (file missing)
O2 - BHO: (no name) - {627A2289-B8F3-4BFA-8A41-53F4E670F460} - C:\WINDOWS\System32\Nyher.dll (file missing)
O2 - BHO: (no name) - {6A7F503D-1933-4576-888C-2485A3EC9833} - C:\WINDOWS\System32\Wnzlxx.dll (file missing)
O2 - BHO: (no name) - {6BA4933F-04A4-4942-98E8-AD5F2A3874B6} - C:\WINDOWS\System32\Yaomx.dll (file missing)
O2 - BHO: (no name) - {77E71D14-1D2A-4A82-9F13-1BE6C0D0D956} - C:\WINDOWS\System32\Yciwr.dll (file missing)
O2 - BHO: (no name) - {8C86D2ED-B3A0-44A4-A250-C5405D64C3D4} - C:\WINDOWS\System32\Gjosv.dll (file missing)
O2 - BHO: (no name) - {9258299D-9687-460C-8F14-8057A822D0F4} - C:\WINDOWS\System32\Rxyn.dll (file missing)
O2 - BHO: (no name) - {97D8D780-0FD4-473A-8DB5-722C6CD6E004} - C:\WINDOWS\System32\Altxu.dll
O2 - BHO: (no name) - {AFA4468A-E3C7-4982-A78E-8F73A6CA18F6} - C:\WINDOWS\System32\Kzpq.dll (file missing)
O2 - BHO: (no name) - {B2F90C74-318D-4C25-BD31-E74F5307539D} - C:\WINDOWS\System32\Qjrbdq.dll (file missing)
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O2 - BHO: (no name) - {BCEA0D98-D3E3-48EC-BFC1-E8FA6006460D} - C:\WINDOWS\System32\Kczxm.dll (file missing)
O2 - BHO: (no name) - {BE422A5A-3405-4062-8393-FEF57C8B6B69} - C:\WINDOWS\System32\Pqfnad.dll (file missing)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - f:\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\qylhelper.dll
O2 - BHO: (no name) - {D0F5590E-F2E4-4333-9412-954678FF22BC} - C:\WINDOWS\System32\Dlzi.dll (file missing)
O2 - BHO: (no name) - {D781011A-D52E-4241-84A2-8BDFB3D8D1F5} - C:\WINDOWS\System32\Mcsibo.dll (file missing)
O2 - BHO: (no name) - {E03809C7-5CED-4ABC-A419-8B2196293184} - C:\WINDOWS\System32\Wfgutm.dll
O2 - BHO: (no name) - {E20067A3-D759-4861-BDD9-5C0ACBE4F991} - C:\WINDOWS\System32\Xssw.dll
O2 - BHO: (no name) - {E4912D79-72F4-4388-A18E-6B9D56F67653} - C:\WINDOWS\System32\Ffucf.dll (file missing)
O2 - BHO: (no name) - {ECC2C24F-8844-4209-9B25-2D61E7F97B49} - C:\WINDOWS\System32\Mjbrb.dll (file missing)
O2 - BHO: (no name) - {F3A50230-A015-4367-9C08-AD27E2CD8465} - C:\WINDOWS\System32\Plehaz.dll (file missing)
O2 - BHO: (no name) - {FB9605D6-1976-421C-9373-E736CE7BA026} - C:\WINDOWS\System32\Gkrfpz.dll
O2 - BHO: (no name) - {FDEBAB28-C97A-4528-A743-358B1EE484A1} - C:\WINDOWS\System32\Bjedau.dll (file missing)
O2 - BHO: (no name) - {FF28FB95-936C-4BCB-AEE6-6C5FF7A8B2C9} - C:\WINDOWS\System32\Wsey.dll (file missing)
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SyGateManager] f:\SyGate\SHN\Sygate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTask] "f:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - F:\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - F:\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - F:\BitSpirit\bsurl.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_3721_assist (file missing)
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\浩方对战平台\GameClient.exe
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - f:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - f:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\Tencent\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\Tencent\qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\Tencent\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\Tencent\qq\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - http://www.epson.com.cn/selftest/selftest/Prg/ESTPTest.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A9E58728-1FA7-46CE-845D-44694EB11602} (XGiboView Control) - http://www.sinago.com/giboview/giboview.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE27DA7A-DA64-45C4-9F89-E2EDC7819CBF}: NameServer = 202.101.172.46 202.101.172.47
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - f:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - f:\Rising\Rav\Ravmond.exe
O23 - Service: SyGateService (SaService) - Sygate technologies Inc. - f:\SyGate\SHN\sgserv.exe