HijackThis@Qoo的扫描日志 V1.97.7
Scan saved at 15:22:49, on 2006-9-15
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
D:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\WinMgmt.exe
C:\WINNT\system32\iexplorer.exe
D:\Program Files\Rising\Rav\RavService.exe
D:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\system32\MsgGhost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Rising\Rav\RavTray.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\explorer.exe
C:\Program Files\Real\RealOne Player\RealPlay.exe
C:\Documents and Settings\lyt1\桌面\hijackthis1.97_qoo\HijackThis.exe
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTray] "D:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: acad.err
O4 - Startup: AdobeWeb.log
O4 - Startup: Client.log
O4 - Startup: intlname.ols
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: sys_log_129086409.upt
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O4 - Global Startup: ntuser.pol
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Unknown file in Winsock LSP: c:\winnt\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\quartz32.dll
O11 - Options group: [!CNS]
O14 - IERESET.INF: START_PAGE_URL=
about:blank
O14 - IERESET.INF: MS_START_PAGE_URL=
about:blank
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://account.qq.com/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9C2A45D7-D67A-427B-B658-E6DDB8AF22A2}: NameServer = 60.191.134.204,60.191.134.197
O17 - HKLM\System\CS1\Services\Tcpip\..\{9C2A45D7-D67A-427B-B658-E6DDB8AF22A2}: NameServer = 60.191.134.204,60.191.134.197
O17 - HKLM\System\CS2\Services\Tcpip\..\{9C2A45D7-D67A-427B-B658-E6DDB8AF22A2}: NameServer = 60.191.134.204,60.191.134.197