大哥有劳了!!!!!!!!!
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 17:27:05, 日期 05-9-3
操作系统: Windows 98 SE (Win9x 4.10.2222A)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\3721\DLACCEL\YDOWNLOADER.EXE
C:\WINDOWS\LOADQM.EXE
D:\DOWNLOADS\新建文件夹\DFVSX\DFVSX.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\W98EJECT.EXE
C:\PROGRAM FILES\3721\DLACCEL\TDUPDATE.EXE
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\TDUPDATE.EXE
C:\PROGRAM FILES\HELLONET\HNMAINUI.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\GAME\浩方对战平台\GAMECLIENT.EXE
D:\GAME\帝国时代之罗马复兴\EMPIRESX.EXE
C:\WINDOWS\SYSTEM\DPLAYSVR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\BT\HIJACKTHIS1991汉化版\COPYLOCK109ZWW.EXE
D:\BT\HIJACKTHIS1991汉化版\HIJACKTHIS1991ZWW.EXE
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\SYSTEM\XUNLEIBHO_V5.DLL
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YISOU\YISOUB.DLL
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\PROGRA~1\KINGSOFT\FASTAIT\IEBAND.DLL
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
O3 - IE工具栏增项: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - C:\KAV5\KAIEPLUS.DLL (file missing)
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
O3 - IE工具栏增项: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\SYSTEM\DOCNTROP.DLL (file missing)
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - IE工具栏增项: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\HMTOOLBAR.DLL
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRAM FILES\YISOU\YISOU.DLL
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [LoadPowerProfile] ; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - 启动项HKLM\\Run: [KAVRun] C:\KAV5\KAVRun.EXE
O4 - 启动项HKLM\\Run: [KAVSvc9X.exe] C:\KAV5\KAVSvc9X.exe
O4 - 启动项HKLM\\Run: [kpcdst] ; D:\game\cdsprite.exe
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [assistse] ; "C:\PROGRAM FILES\3721\ASSISTSE.EXE"
O4 - 启动项HKLM\\Run: [SiS Tray] ; C:\DOWNLOADS\MAINBOARD_SIS_630E_9X\SIS630E\UTILITY\SISTRAY.EXE
O4 - 启动项HKLM\\Run: [systhread] ; C:\WINDOWS\SYSTEM\winkernal.exe
O4 - 启动项HKLM\\Run: [Logitech Utility] ; Logi_MwX.Exe
O4 - 启动项HKLM\\Run: [MyIMLite_UpDate] ; rundll32 C:\WINDOWS\SYSTEM\MyIMLite\Update.dll,UpdateFirst
O4 - 启动项HKLM\\Run: [MyIMLite] ; C:\WINDOWS\SYSTEM\MyIMLite\MyIMLite.exe -h
O4 - 启动项HKLM\\Run: [KnightIII] ;
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [dl_accel] C:\PROGRAM FILES\3721\DLACCEL\YDownloader.exe
O4 - 启动项HKLM\\Run: [LoadQM] loadqm.exe
O4 - 启动项HKLM\\Run: [dfvsx] "D:\DOWNLOADS\新建文件夹\DFVSX\DFVSX.EXE" -Min
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - 启动项HKLM\\RunServices: [SCardSvr] ; C:\WINDOWS\SYSTEM\SCardSvr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: 迅雷4.lnk = C:\Program Files\Thunder Network\Thunder\Thunder.exe
O4 - Startup: w98Eject.lnk = C:\WINDOWS\System\w98eject.exe
O4 - Startup: 腾讯TM.lnk = C:\My Documents\My Music\TMShell.exe
O4 - User Startup: 迅雷4.lnk = C:\Program Files\Thunder Network\Thunder\Thunder.exe
O4 - User Startup: w98Eject.lnk = C:\WINDOWS\System\w98eject.exe
O4 - User Startup: 腾讯TM.lnk = C:\My Documents\My Music\TMShell.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\MY DOCUMENTS\MY MUSIC\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\MY DOCUMENTS\MY MUSIC\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\MY DOCUMENTS\MY MUSIC\SendMMS.htm
O8 - IE右键菜单中的新增项目: &使用下载加速专家下载 - C:\PROGRAM FILES\3721\DLACCEL\geturl.htm
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL/BAIDU_DIC.HTM
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\getAllurl.htm
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:
http://www.joyo.com (file missing)
O9 - 浏览器额外的按钮: 金山毒霸网站 - {fe054a95-e2b5-4240-8e22-695c62ff45ac} - url:
http://www.duba.net (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\My Documents\My Music\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\My Documents\My Music\QQ.EXE
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\GAME\浩方对战平台\GAMECLIENT.EXE
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} -
http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} -
http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} -
http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} -
http://sms.3721.com/ie/index.htm?pid=U_superrsoft_62756 (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} -
http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} -
http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O11 - Options group: [!CNS] 上网助手-地址栏搜索
O16 - DPF: {733652F9-53EF-4BF1-B391-375980675D6F} (V3PROXL Control) -
http://download.3721.com/download/myv3/plugin/myv3light.cabO16 - DPF: {8135EF31-FE8C-4C6E-A18A-F59944C3A488} (Spocx Class) -
http://ddddl.dudu.com/ddd/channel/spockx-channel.cabO16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) -
http://download.ourgame.com/IEDown2.cabO16 - DPF: {C37FBD87-3AA7-4640-9A8D-19AFC10B15B2} (Netease Chat Control) -
http://room.chat.163.com/xchat/chat.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cabO16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) -
http://game.qq.com/QQGame2.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = lj
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,195.225.176.37
O18 - 列举现有的协议: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\SYSTEM\MBPROT.DLL