启动项报告: 22/8/2006, PM 1:00:20
启动项扫描器版本: 1.52.2
开始于: D:\Hijackthis1991zww\HijackThis1991zww.EXE
系统检测: Windows XP SP2 (WinNT 5.01.2600)
系统检测: Unable to get Internet Explorer version!
* 使用默认选项
==================================================
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
E:\Program Files\Rising\Rav\CCenter.exe
E:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\PROXYL~1\ProxyCap\ProxyCap.exe
C:\Program Files\Nexon\NexonPlug\NexonPlug.exe
E:\Program Files\Rising\Rav\Ravmon.exe
E:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nexon\Common\NMService.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\system32\conime.exe
E:\Program Files\Rising\Rav\Rav.exe
E:\Program Files\Rising\Rav\RsLogVw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Hijackthis1991zww\HijackThis1991zww.exe
--------------------------------------------------
文件夹中的启动项
Shell folders Startup:
[C:\Documents and Settings\jerry\「开始」菜单\程序\启动]
瑞星监控中心.lnk = E:\Program Files\Rising\Rav\RavMon.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\SYSTEM32\Userinit.exe,
--------------------------------------------------
注册表中的启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
ATIPTA = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
RavTask = "E:\Program Files\Rising\Rav\RavTask.exe" -system
IMSCMIG40W = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
ProxyThorn = ; E:\Program Files\ProxyThorn\ProxyThorn.exe
DAEMON Tools = ; "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
Logitech Utility = ; LOGI_MWX.EXE
PCSuiteTrayApplication = ; E:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~2.EXE -startup
StormCodec_Helper = ; "E:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
zBrowser Launcher = ; E:\Program Files\Logitech\iTouch\iTouch.exe
--------------------------------------------------
注册表中的启动项:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
ProxyCap = E:\PROGRA~1\PROXYL~1\ProxyCap\ProxyCap.exe
NexonPlug = C:\Program Files\Nexon\NexonPlug\NexonPlug.exe
PcSync = ; E:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=* 未找到INI相关项目值 *
run=* 未找到INI相关项目值 *
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKLM\..\Windows\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKLM\..\Windows\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKCU\..\Windows\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=* 未找到相关注册表键值 *
HKLM\..\Windows NT\CurrentVersion\Windows: load=* 未找到相关注册表键值 *
HKLM\..\Windows NT\CurrentVersion\Windows: run=* 未找到相关注册表键值 *
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
--------------------------------------------------
外壳扩展和屏幕保护程序的键值 从 C:\WINDOWS\SYSTEM.INI:
Shell=* 未找到INI相关项目值 *
SCRNSAVE.EXE=* 未找到INI相关项目值 *
drivers=* 未找到INI相关项目值 *
外壳扩展和屏幕保护程序的键值 从 注册表
Shell=EXPLORER.EXE
SCRNSAVE.EXE=* 未找到相关注册表键值 *
drivers=* 未找到相关注册表键值 *
Policies Shell key:
HKCU\..\Policies: Shell=* 未找到相关注册表键值 *
HKLM\..\Policies: Shell=* 未找到相关注册表键值 *
--------------------------------------------------
列举IE浏览器辅助对象(BHO模块):
(no name) - C:\PROGRA~1\baidu\bar\BaiduBar.dll - {77FEF28E-EB96-44FF-B511-3185DEA48697}
--------------------------------------------------
列举下载的程序文件:
[Nexon Package Manager Control]
InProcServer32 = C:\WINDOWS\nxpm.ocx
CODEBASE = http://file.nx.com/activex/public_new/nxpm.cab
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156173475652
[AxInputControl Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL
CODEBASE = https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
[WinlessActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WINLES~1.OCX
CODEBASE = http://www.pangya.com/PangyaLauncher/PangyaLauncher.cab
[NlsComm Component Class]
InProcServer32 = C:\WINDOWS\system32\hanbiton\NLS_Comm1_0_2.dll
CODEBASE = http://login.hanbiton.com/cab/NLSnSSO.cab
--------------------------------------------------
列举 Winsock LSP 文件:
Protocol #1: w2pxdrv.dll (file MISSING)
Protocol #2: w2pxdrv.dll (file MISSING)
Protocol #3: w2pxdrv.dll (file MISSING)
Protocol #4: w2pxdrv.dll (file MISSING)
Protocol #23: w2pxdrv.dll (file MISSING)
--------------------------------------------------
列举 ShellService
ObjectDelayLoad 项目:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\st
object.dll
--------------------------------------------------
报告完毕,共 7,090 字节
报告生成用时:0.070秒
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only