被劫持了 请高手帮分析下

我电脑总是不时自动打开网页,扫描结果如下 请高手帮忙分析下 谢谢了

HijackThis_815汉化版扫描日志 V1.99.1
保存于      10:37:23, 日期 2006-10-9
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\wom\WinMem.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\阿达自动定时关机器\adtimer.exe
D:\Program Files\Cerience\RepliGo\RepliGoMon.exe
D:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Sony Handheld\Hotsync.exe
D:\Program Files\Sony Handheld\HandStory.exe
d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe
D:\Program Files\TTPlayer\TTPlayer.exe
d:\Program Files\WinRAR\WinRAR.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\lijie\LOCALS~1\Temp\Rar$EX00.313\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} -

D:\Program Files\超级兔子\haokanbar.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -

c:\program files\google\googletoolbar1.dll (file missing)
O3 - IE工具栏增项: &RepliGo - {81F4066B-F330-4872-8094-3E9FBCCEC8C1} -

d:\Program Files\Cerience\RepliGo\RepliGoIEBar.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E}

- D:\Program Files\超级兔子\haokanbar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE"

/Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32

\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32

\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -

system
O4 - 启动项HKLM\\Run: [RfwMain] "d:\program files\rising\rfw\rfwmain.exe" -

startup
O4 - 启动项HKLM\\Run: [Windows内存整理] D:\Program Files\wom\WinMem.exe
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent] rundll32.exe

bthprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [ats] D:\Program Files\阿达自动定时关机器\adtimer.exe

noshow
O4 - 启动项HKLM\\Run: [RemoteControl] ; "d:\Program

Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - 启动项HKLM\\Run: [nwiz] ; nwiz.exe /installquiet
O4 - 启动项HKLM\\Run: [RepliGo Assistant] "d:\Program

Files\Cerience\RepliGo\RepliGoMon.exe"
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [DAEMON Tools] "d:\Program Files\DAEMON

Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: HandStory.lnk = D:\Program Files\Sony Handheld\HandStory.exe
O4 - Global Startup: HotSync 管理器.lnk = D:\Program Files\Sony

Handheld\Hotsync.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - d:\Program Files\Thunder

Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - d:\Program Files\Thunder

Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: Google 搜索(&G) - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program

Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program

Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program

Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1

\MICROS~1\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program

Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program

Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program

Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-

0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail

(file missing)
O9 - 浏览器额外的“工具”菜单项: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-

0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail

(file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的“工具”菜单项: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-

432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao

(file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的“工具”菜单项: 雅虎助手 - {5D73EE86-05F1-49ed-B850-

E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist

(file missing)
O9 - 浏览器额外的按钮: Save To Palm - {6C8741AB-53B4-476e-BE7C-F519AD8A6494}

- D:\Program Files\Sony Handheld\HandStoryTE.htm
O9 - 浏览器额外的“工具”菜单项: Save To Palm - {6C8741AB-53B4-476e-BE7C-

F519AD8A6494} - D:\Program Files\Sony Handheld\HandStoryTE.htm
O9 - 浏览器额外的按钮: 酷热影音 - {7D73FF86-05F1-39ed-C850-A423120EC338} -

www.kuree.com/index.htm?id=00011001 (file missing)
O9 - 浏览器额外的“工具”菜单项: 酷热影音 - {7D73FF86-05F1-39ed-C850-

A423120EC338} - www.kuree.com/index.htm?id=00011001 (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -

D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}

- D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} -

D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的“工具”菜单项: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-

0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg

(file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32

\cn_api60.dll' missing
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) -

https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) -

http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) -

https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://mlnwzj.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) -

http://upload.photo.163.com/photoup.cab
O16 - DPF: {BF8C499A-AC6E-4F58-82EA-9E5FCC41C34B} (PicUploadCtrl Class) -

http://tb.sogou.com/PicUpload.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) -

http://szdl.cmbchina.com/download/PB/pb50.cab
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} -

C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} -

C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} -

C:\WINDOWS\webwork\webwork.dll (file missing)
O23 - NT 服务: BlueSoleil Hid Service - Unknown owner - d:\Program Files\IVT

Corporation\BlueSoleil\BTNtService.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision

Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32

\IDriverT.exe
O23 - NT 服务: MSCSPTISRV - Sony Corporation - C:\Program Files\Common

Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: PACSPTISVR - Sony Corporation - C:\Program Files\Common

Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - NT 服务: PDEngine - Raxco Software, Inc. - D:\Program

Files\Raxco\PerfectDisk\PDEngine.exe
O23 - NT 服务: PDScheduler (PDSched) - Raxco Software, Inc. - D:\Program

Files\Raxco\PerfectDisk\PDSched.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising

Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing

Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co.,

Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1

\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - NT 服务: SonicStage SCSI Service (SSScsiSV) - Sony Corporation -

C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - NT 服务: Windows User Mode Driver Framework (UMWdf) - Unknown owner -

C:\WINDOWS\system32\wdfmgr.exe (file missing)

最后编辑2006-10-09 11:14:26