HijackThis_815汉化版扫描日志 V1.99.1
保存于 20:46:59, 日期 2006-9-11
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\command\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\工具\网络工具\DuDu\DuDuAcc.exe
D:\Program Files\工具\网络工具\DuDu\dudupros.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\娱乐\聊天\Tencent\QQ\QQ.exe
D:\Program Files\娱乐\聊天\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\娱乐\聊天\Tencent\QQ\QQ.exe
C:\WINDOWS\system32\conime.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\Program Files\Rising\Rfw\RfwMain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\工具\压缩工具WinRAR\WinRAR.exe
C:\DOCUME~1\dr.DU\LOCALS~1\Temp\Rar$EX01.359\HijackThis1991.exe
O2 - BHO: DuDu.com - {00018593-C6BD-46F7-9349-DBA1AA674C90} - D:\Program Files\工具\网络工具\DuDu\dddiemon.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\娱乐\聊天\Tencent\QQ\QQIEHelper.dll
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [zt] C:\WINDOWS\Intel\rundll32.exe
O4 - 启动项HKLM\\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: DuDu下载加速器.lnk = ?
O8 - IE右键菜单中的新增项目: &使用DuDu下载 - res://D:\Program Files\工具\网络工具\DuDu\dddmext.dll/202
O8 - IE右键菜单中的新增项目: &使用DuDu下载全部链接 - res://D:\Program Files\工具\网络工具\DuDu\dddmext.dll/203
O8 - IE右键菜单中的新增项目: &使用DuDu下载选择链接 - res://D:\Program Files\工具\网络工具\DuDu\dddmext.dll/204
O8 - IE右键菜单中的新增项目: &使用DuDu捕获页面视频 - res://D:\Program Files\工具\网络工具\DuDu\dddmext.dll/205
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\娱乐\聊天\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\娱乐\聊天\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{BEBDE21D-0132-4FD9-96EE-1AC1D96EF73B}: NameServer = 61.134.1.4 218.30.19.40
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
âØµÒTcÌbbs.ikaka.comU¥Ç¦
1