Logfile of HijackThis v1.99.1 Scan saved at 20:10:32, on 2011-6-5 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v4.08 SP3 (4.08.0000.0760) Running processes: C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe D:\Program Files\360\360Safe\deepscan\ZhuDongFangYu.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE D:\Program Files\360\360Safe\safemon\360Tray.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\WINDOWS\Mgr.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files\360\360SD\360sd.exe C:\WINDOWS\system32\hasplms.exe d:\lubansoft\lubankeyboard\Lbkeybsc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\360\360SD\360rps.exe D:\Program Files\Tencent\QQ\Bin\QQ.exe d:\Program Files\Tencent\QQ\Bin\TXPlatform.exe d:\Program Files\SogouInput\5.2.0.5374\SogouCloud.exe D:\Program Files\Tencent\TT\bin\TTraveler.exe C:\Program Files\360\360SD\360rp.exe d:\Program Files\Tencent\QQ旋风\QQDownload.exe C:\Documents and Settings\Administrator\桌面\hijackthis\HijackThis.exe O2 - BHO: QQCyclon - {00000000-12C9-4305-82F9-43058F20E8D2} - (no file) O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll O2 - BHO: BOC ProcessProtect Class - {776B71E2-B4CC-4C94-BC7C-09103AA690B6} - C:\WINDOWS\system32\ProcessProtection.dll O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\Program Files\360\360Safe\safemon\safemon.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [360Safetray] "D:\Program Files\360\360Safe\safemon\360Tray.exe" /start O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [qQ] C:\WINDOWS\Mgr.exe O4 - HKLM\..\Run: [360safeman] C:\Documents and Settings\All Users\Documents\My Videos\Vanvcd.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [360sd] "C:\Program Files\360\360SD\360sdrun.exe" O8 - Extra context menu item: 使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - d:\Program Files\Thunder Network\Thunder\Thunder.exe O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - d:\Program Files\Thunder Network\Thunder\Thunder.exe O15 - Trusted Zone: http://www.bankofchina.com O15 - Trusted Zone: http://www.boc.cn O15 - Trusted Zone: http://*.pps.tv O15 - Trusted Zone: http://*.ppstream.com O15 - Trusted Zone: http://*.webscache.com O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/2121/aliedit.cab O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (QQPasswordCtrl Class) - https://www.tenpay.com/download/tenpaycert_xp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{38266434-965F-438D-90AE-F91D24300EF0}: NameServer = 202.99.160.68,202.99.166.4 O17 - HKLM\System\CS1\Services\Tcpip\..\{38266434-965F-438D-90AE-F91D24300EF0}: NameServer = 202.99.160.68,202.99.166.4 O18 - Protocol: mbox - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O23 - Service: 360 杀毒实时防护服务 (360rp) - 360.cn - C:\Program Files\360\360SD\360rps.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Sentinel HASP License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe O23 - Service: Lbkeybsc - Unknown owner - d:\lubansoft\lubankeyboard\Lbkeybsc.exe O23 - Service: PIPIStartSvr - PIPI - C:\Program Files\pipi\PIPIStartSvr.exe O23 - Service: 主动防御 (ZhuDongFangYu) - 360.cn - D:\Program Files\360\360Safe\deepscan\ZhuDongFangYu.exe