日志文件: 趋势科技 HijackThis v2.0.0 (BETA)
保存时间: 16:45:13, on 2007-6-10
操作系统: Windows XP SP2 (WinNT 5.01.2600)
启动模式: 正常
正在运行的进程:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
E:\tools\Rising\Rav\CCenter.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
E:\tools\淘宝网\淘宝旺旺\WangWang.EXE
D:\WINDOWS\system32\ctfmon.exe
E:\tools\MSI\VCenter\VCenter.exe
D:\WINDOWS\ATKKBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
E:\TOOLS\RISING\RAV\Ravmond.exe
e:\tools\Rising\Rav\RAVMON.EXE
e:\tools\Rising\Rav\Rav.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\regedit.exe
D:\WINDOWS\notepad.exe
F:\补丁\HiJackThis_v2.exe
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - E:\tools\FlashGet\jccatch.dll
O3 - 工具栏: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - 工具栏: 快车(FlashGet) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - e:\tools\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [WangWang] "e:\tools\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RavTask] "e:\tools\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 腾讯QQ.lnk = E:\tools\Tencent\qq\QQ.exe
O4 - Global Startup: VCenter.lnk = E:\tools\MSI\VCenter\VCenter.exe
O8 - 扩展右键菜单项: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - 扩展右键菜单项: &使用快车(FlashGet)下载 - E:\tools\FlashGet\jc_link.htm
O8 - 扩展右键菜单项: &使用快车(FlashGet)下载全部链接 - E:\tools\FlashGet\jc_all.htm
O8 - 扩展右键菜单项: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - 扩展右键菜单项: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - 扩展右键菜单项: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - 扩展右键菜单项: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - 扩展右键菜单项: 上传到QQ网络硬盘 - E:\tools\Tencent\qq\AddToNetDisk.htm
O8 - 扩展右键菜单项: 添加到QQ自定义面板 - E:\tools\Tencent\qq\AddPanel.htm
O8 - 扩展右键菜单项: 添加到QQ表情 - E:\tools\Tencent\qq\AddEmotion.htm
O8 - 扩展右键菜单项: 用QQ彩信发送该图片 - E:\tools\Tencent\qq\SendMMS.htm
O8 - 扩展右键菜单项: 豪杰超级解霸V8实时播放 - e:\tools\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\tools\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\tools\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - e:\tools\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - e:\tools\Tencent\QQ\QQ.EXE
O9 - Extra button: 快车 - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - e:\tools\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: 快车(FlashGet) - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - e:\tools\FlashGet\FlashGet.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.icbc.com.cn
O17 - HKLM\System\CCS\Services\Tcpip\..\{949EA817-4CFA-436D-B35A-A512E06E1A22}: NameServer = 202.99.160.68 202.99.166.4
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\tools\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\TOOLS\RISING\RAV\Ravmond.exe
--
文件结束 - 4682 字节
¹ù·ki¿É½¦bbs.ikaka.comµ´ÐR8¾*@4