斑竹各位高手帮我看看,这是我用jackThis_zww汉化版扫描出来日志
HijackThis_zww汉化版扫描日志 V1.99.1
& G# \; @8 F! u0 U h( [保存于 11:25:47, 日期 2005-8-19
3 s1 W; I; g' a" l' j/ H$ K操作系统: Windows XP SP1 (WinNT 5.01.2600)
1 L" e. d; C2 z2 l: Y. z9 w浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106); u5 x+ ]. U8 h+ A y
当前运行的进程: ! _1 s9 F% \. J# ?* H! ~
C:\WINDOWS\System32\smss.exe! O% |4 k. [* T& q
C:\WINDOWS\system32\winlogon.exe; {* ^* W1 Y% B9 C" ]) k' }
C:\WINDOWS\system32\services.exe
: Z% V' |. E& ]( _+ JC:\WINDOWS\system32\lsass.exe
% h! x: r6 i. |: d4 K+ x* FC:\WINDOWS\system32\svchost.exe+ z# A; L; A: @# A5 I2 T# C# b
C:\WINDOWS\System32\svchost.exe
4 K7 a0 r F8 K' b. pC:\WINDOWS\Explorer.EXE- S' i0 [( u9 \; `7 u
C:\WINDOWS\System32\ctfmon.exe
* K1 y& k/ \! b4 w( S; sC:\KAV2005\KWatch.EXE+ j0 b, o5 M1 R! e( C3 s4 n
C:\WINDOWS\system32\spoolsv.exe
6 Q5 T6 _( b1 G W, rC:\Program Files\Qyule\qyule.exe8 w" {8 s+ f# C) j$ G$ k% J
C:\Program Files\Common Files\Real\Update_OB\realsched.exe+ A, ^; y5 |4 @; M. @# o: s
C:\WINDOWS\System32\conime.exe; J& Q; A/ N7 m! D5 D# q3 O
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
* X# v: M" o2 j- C4 J5 }C:\KAV2005\KPfwSvc.EXE' |% b, B: ?" V4 p# u% b
C:\WINDOWS\netinfo.exe' d, w% M- Z% s- J* S7 t
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe3 g/ m% M) B$ m# U% L
C:\WINDOWS\System32\Rpcmon.exe
) K2 H' n, ~4 i. X' o* MC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
: [( ^. q' T* v7 P0 U3 R- JC:\Program Files\ChinaNet\VnetClient.exe
" U$ E% j8 F- `C:\Program Files\Internet Explorer\iexplore.exe
3 j5 W4 ]8 N) A% qC:\WINDOWS\system32\cmd.exe
\: n7 g5 X2 w" p, w; yD:\软件\hijackthisV1.99.1.exe
( h6 K' z, V/ b: h+ _C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe A5 u/ A/ R+ t8 Q7 F) ?
C:\WINDOWS\Edit.exe- ]* |8 E1 q. G% F4 j% s
R3 - 默认的URLSearchHook丢失。用HijackThis修复
; W1 v$ D6 c9 z; {( XF2 - REG:system.ini: UserInit=userinit.exe,
. D( D0 R/ [ G& DO2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
# D8 K9 B) R! k* V. Q6 r: t8 B0 kO2 - BHO: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
! [, c! k6 E3 LO2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
7 o! G7 h, o. P. W( n& nO2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll. f) v) Q" X" H* R5 N& b
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll7 N7 s: Y( g1 p6 O& P/ k) s
O4 - 启动项HKLM\\Run: [ClientQyule] C:\Program Files\Qyule\qyule.exe
6 u6 N0 N$ ?/ p6 ]O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll325 m: P! n m7 q0 q
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe9 ~* ?! U8 A) U N! |+ k2 V
O4 - 启动项HKLM\\Run: [KvMonXP] C:\PROGRA~1\KV2005\KVMonXP.kxp /auto
0 r0 O8 x- f. y# S9 t8 _& @O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot/ @/ D6 n" F7 b2 x
O4 - HKCU\..\Run: [ClientQyule] C:\Program Files\Qyule\qyule.exe. k5 p9 A# ~/ F$ @3 T3 k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe" e: l6 v7 ~$ Q4 g
O4 - Startup: run.bat& e, Y( q' |( y9 ?9 U
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present9 i1 s) Z$ J& r7 O) e" Q6 _# t' p
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present K* t" _# q& ~3 f$ N( {0 _5 p
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
& v8 R3 w/ X( d }9 MO8 - IE右键菜单中的新增项目: !搜一搜(&S) - res://C:\Program Files\yisou\yisou.dll/232
* q; {! Q$ _: y9 \, Y( T1 p3 KO8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm$ D/ A; u! X( t& H& f- e7 x
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Sandai Technologies Inc\Thunder\getAllurl.htm
7 b: o" x- y9 bO8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
5 F E; R2 t) [% T3 gO8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
( T5 f1 A% _) C# @O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
2 m( T$ N8 `5 o! f) h( b* @O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll: t8 G5 ?0 ?0 g. z" B
O11 - Options group: [!CNS] 上网助手-地址栏搜索/ t- y/ j1 X8 T8 ?) W, o O
O11 - Options group: [CDNCLIENT] 中文上网
$ f; C0 C! D pO14 - IERESET.INF: SEARCH_PAGE_URL=
& ^% {6 s' F! ~: PO14 - IERESET.INF: START_PAGE_URL=6 l+ I( s9 S+ e _# n; b
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE953536-F19E-49D0-ADF3-8400D02D22B8}: NameServer = 202.96.144.47 202.96.128.1664 @ [. ^0 B5 S- r' u
O23 - NT 服务: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe+ j7 A& H3 Q/ R! A* t" c( @1 \. g
O23 - NT 服务: hexadecimal (HexadecimaRepresentation) - Unknown owner - C:\WINDOWS\Edit.exe
1 H9 s. `- m: f; G9 A7 \8 o; o5 LO23 - NT 服务: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft Corporation - C:\KAV2005\KPfwSvc.EXE
: C: {) [* _1 F2 @4 b9 Y0 }O23 - NT 服务: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - C:\KAV2005\KWatch.EXE- A0 \9 W$ E" n; [9 N. T
O23 - NT 服务: Windows lsass Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)2 L# F9 Y4 @. {) P( `- X
O23 - NT 服务: MAPI Mail Client (MAPI) - Unknown owner - C:\WJNG.exe (file missing)# L( ]* |5 [$ }) }8 `/ h
O23 - NT 服务: netinfo - Unknown owner - C:\WINDOWS\netinfo.exe0 Q- w3 p4 _4 W' \1 H1 e8 b6 @
O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
7 T' c, y* U0 yO23 - NT 服务: Remote Procedure Call (RPC) Monitoring (Rpcmon) - Unknown owner - C:\WINDOWS\System32\Rpcmon.exe
3 p; p% e3 ]1 X9 m6 u3 Z, OO23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe' N3 A0 D4 G: c. z1 P
O23 - NT 服务: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
4 _! @: F* t& v. j9 W |