Logfile of HijackThis v1.99.1
Scan saved at 12:49:24, on 2006-9-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\Program Files\Rising\Rav\rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Thunder\Program\Thunder5.exe
E:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder\Program\getAllurl.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{03A1FFCD-E993-4A4A-8B4E-A81775AF91B8}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{C202A86F-72DD-43CA-9149-B03C5421B2E5}: NameServer = 61.128.128.68 61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{03A1FFCD-E993-4A4A-8B4E-A81775AF91B8}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{03A1FFCD-E993-4A4A-8B4E-A81775AF91B8}: NameServer = 61.128.128.68,61.128.192.68
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Unknown owner - D:\Program Files\Rising\Rav\CCenter.exe (file missing)
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe