HijackThis_zww汉化版扫描日志 V1.99.1
保存于 18:56:16, 日期 2007-3-29
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\Program Files\NCR\Teradata Warehouse Builder\bin\portmap.exe
E:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\NCR\Teradata Warehouse Builder\bin\pipcd.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\SMSC\Seticon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
F:\工具集\数据照片处理软件\iSee\iSee\iSee\iSee.exe
E:\Program Files\Rising\Rav\RavTask.exe
C:\Syswm1i\svchost.exe
C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Rising\Rav\Ravmon.exe
E:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~1\iesnap\navplay.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - 默认的URLSearchHook丢失。用HijackThis修复
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 61.188.38.107 www.9605899.com
O1 - Hosts: 61.188.38.107 hyap98.com
O1 - Hosts: 61.188.38.107 www.hyap98.com
O1 - Hosts: 61.188.38.107 82087871.com
O1 - Hosts: 61.188.38.107 www.82087871.com
O1 - Hosts: 61.188.38.107 47555.cn
O1 - Hosts: 61.188.38.107 nc.47555.cn
O1 - Hosts: 61.188.38.107 cn.47555.cn
O1 - Hosts: 61.188.38.107 crsky.47555.cn
O1 - Hosts: 61.188.38.107 www.47555.cn
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\Thunder Network\Thunder\xunleibho_v5.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ZqzElius Class - {06F5BF07-DCEE-7940-8D93-B474004967EF} - C:\WINDOWS\DOWNLO~1\ezaib.dll
O2 - BHO: Sodui Search - {35EC0410-555E-4402-B372-D9A6E0BF6795} - C:\WINDOWS\system32\winudv85.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: Advance Helper - {8E25AC4A-B129-451B-BEE2-3B510BB751DA} - C:\WINDOWS\system32\NTDLL32.dll
O2 - BHO: IE Browser Helper - {D0903A3B-F0EA-434a-9742-98C5335C7946} - C:\WINDOWS\system32\IEHelper.dll
O2 - BHO: SysShellKernel - {E04B27AA-3973-4D68-8F42-B7C2FC8C6CF7} - C:\WINDOWS\system32\SysShellKernel.dll (file missing)
O2 - BHO: cnwin Class - {EC497BD8-460F-44F0-B2A4-8C2B2198035B} - C:\WINDOWS\system32\cnwin.dll (file missing)
O2 - BHO: MyFavor Web - {F7F49040-389C-4f1f-A825-06D5328EAE59} - C:\WINDOWS\system32\MyFavor.dll (file missing)
O3 - IE工具栏增项: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - e:\Program Files\CyberArticle\CAExp.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [SetIcon] \Program Files\SMSC\Seticon.exe
O4 - 启动项HKLM\\Run: [FinePrint 分配器 v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - 启动项HKLM\\Run: [RavTimeXP] \HELP\IGGDE.exe
O4 - 启动项HKLM\\Run: [RavTimXP] \Mstray.exe
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [iSeeTray] F:\工具集\数据照片处理软件\iSee\iSee\iSee\iSee.exe FT 0
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] D:\Program Files\SkyNet\FireWall\PFWmain.exe
O4 - 启动项HKLM\\Run: [upxdnd] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3.exe.exe
O4 - 启动项HKLM\\Run: [winform] C:\WINDOWS\winform.exe
O4 - 启动项HKLM\\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - 启动项HKLM\\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - 启动项HKLM\\Run: [Internet] "C:\WINDOWS\system32\internet.exe"
O4 - 启动项HKLM\\Run: [RavTask] "E:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [MSCalsClocks] C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\system32\DrvMon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [svc] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ie777.exe
O4 - Global Startup: WanSo.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 保存: 完整网页... - e:\Program Files\CyberArticle\script\Save.htm
O8 - IE右键菜单中的新增项目: 保存: 更多保存内容... - e:\Program Files\CyberArticle\script\SaveAuto.htm
O8 - IE右键菜单中的新增项目: 定位查看 GPS 卫星地图 - d:\Program Files\Opanda\IExif 2.25\IExifMap.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 查看 Exif/GPS/IPTC 信息 - d:\Program Files\Opanda\IExif 2.25\IExifCom.htm
O8 - IE右键菜单中的新增项目: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O15 - “受信任的站点”中添加项: *.zjtelecom.cn
O15 - 添加的受信任的 IP 地址范围: http://134.98.152.2
O16 - DPF: {5D8B72ED-75CC-4311-BA2C-6EDCBAD3F2DD} (Hmdcx Control) - http://134.103.69.225/BAOBIAO/hmdqianfei/HmdcxProj1.inf
O16 - DPF: {7BD7A34E-F3EE-44B1-95A7-E04C2B7FB90C} (IDFlowViewX Control) - http://zjod.zjtelecom.cn/csscfg.nsf/AttachFile/IDFlowView/$FILE/IDFlowView.cab
O16 - DPF: {7F8626CA-48AD-4875-BDA1-83FD7CFD3C22} (Windows.WindowsUc) - http://www.9rong.com/hello.CAB
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - http://www.icbc.com.cn/dongtaiyanshi/personalbank/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {AB70C611-DE79-4DB5-B637-CCA50876E4D8} (passport.File
ObjectCtrl) - http://zjod.zjtelecom.cn/csscfg.nsf/AttachFile/passport/$FILE/passport.CAB
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2007/OL2006.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://account.qq.com/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A49BCF3-8316-4AC3-8343-B859EF9FA4F8}: NameServer = 60.191.134.196,134.96.32.26
O20 - AppInit_DLLs: C:\WINDOWS\system32\NTDLL32.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Gray_Pigeon_Server1.23 (GrayPigeonServer1.23) - Unknown owner - C:\WINDOWS\G_Server1.23.exe (file missing)
O23 - NT 服务: Visibroker Activation Daemon (oad) - Unknown owner - d:\PROGRA~1\Borland\vbroker\bin\oad.exe
O23 - NT 服务: ONC RPC Portmapper - Unknown owner - C:\Program Files\NCR\Teradata Warehouse Builder\bin\portmap.exe
O23 - NT 服务: OracleMTSRecoveryService - Oracle Corporation - E:\oracle\ora92\bin\omtsreco.exe
O23 - NT 服务: OracleOraHome92ClientCache - Unknown owner - E:\oracle\ora92\BIN\ONRSD.EXE
O23 - NT 服务: VisiBroker Smart Agent (osagent) - Unknown owner - d:\PROGRA~1\Borland\vbroker\bin\osagent.exe
O23 - NT 服务: PIPC Daemon - Unknown owner - C:\Program Files\NCR\Teradata Warehouse Builder\bin\pipcd.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: TDQM Server (TdqmServerService) - NCR - C:\Program Files\NCR\Teradata DQM\server\tdqmserv.exe