![]()
日志
Logfile of HijackThis v1.99.1
Scan saved at 16:32:42, on 2007-2-2
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
d:\program files\rising\rfw\rfwsrv.exe
D:\Program Files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Unlocker\UnlockerAssistant.exe
D:\Program Files\Rising\Rfw\rfwmain.exe
D:\Program Files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\QQ\QQ.exe
D:\Program Files\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\安装工具\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: TuoTuHelper.LDown - {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} - D:\Program Files\Tuotu\TuoTuHelper.dll
O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [AVP] "D:\Program Files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用脱兔下载 - D:\Program Files\Tuotu\TT_one.htm
O8 - Extra context menu item: 使用脱兔下载全部链接 - D:\Program Files\Tuotu\TT_all.htm
O9 - Extra button: 网页监控 统计 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\kaspersky lab\kaspersky anti-virus 6.0\scieplugin.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{39F315FF-15D9-4BF3-A36E-E4B1748A216E}: NameServer = 202.99.160.68,202.99.160.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB890633-B667-438B-AB5E-555C16BEB39D}: NameServer = 202.99.160.68 202.99.166.4
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - D:\Program Files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe" -r (file missing)
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
欢迎光临 热点科技 (http://www.itheat.com/activity/) | Powered by Discuz! X3.2 |