Logfile of HijackThis v1.99.0
Scan saved at 0:20:42, on 2007-12-22
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
F:\HijackThis\HijackThis\HijackThis.exe
F3 - REG:win.ini: load=; ?矵矐?矵? ?矵矸矘?膈
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] ;"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] ;RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVPSrv] ;C:\WINDOWS\AVPSrv.exE
O4 - HKLM\..\Run: [MsPrint32D] ;C:\WINDOWS\MsPrint32D.exe
O4 - HKLM\..\Run: [WinSysM] ;C:\WINDOWS\391231M.exe
O4 - HKLM\..\Run: [LotusHlp] ;C:\WINDOWS\LotusHlp.exe
O4 - HKLM\..\Run: [WinSysW] ;C:\WINDOWS\391231L.exe
O4 - HKLM\..\Run: [NVDispDrv] ;C:\WINDOWS\NVDispDRV.EXE
O4 - HKLM\..\Run: [RegSrv64D] ;C:\WINDOWS\RegSrv64D.exE
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\rising\AntiSpyware\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Death.exe] ;C:\WINDOWS\System32\Death.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用BitComet下载全部链接 - res://E:\BT\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &使用超级旋风下载 - F:\超级旋风\geturl.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\比特精灵\比特精灵\bsurl.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl
Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: 42234fsfsf34234 - Unknown - C:\WINDOWS\System32\fd44532dsf.exe (file missing)
O23 - Service: 9E3D3248 - Unknown - C:\WINDOWS\System32\9E8F3418.EXE
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: 卡巴斯基反病毒6.0 - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Proxy Service - Unknown - c:\program files\rising\rfw\rfwproxy.exe (file missing)
O23 - Service: Rising Personal Firewall Service - Unknown - c:\program files\rising\rfw\rfwsrv.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)
O23 - Service: Rising Process Communication Center - Unknown - C:\Program Files\rising\Rav\CCenter.exe (file missing)
O23 - Service: RsRavMon Service - Unknown - C:\Program Files\rising\Rav\Ravmond.exe (file missing)
O23 - Service: WinWLServiceNow - Unknown - C:\DOCUME~1\ghnvb\LOCALS~1\Temp\RAVWL.EXE (file missing)
O23 - Service: WinZXServiceNow - Unknown - C:\DOCUME~1\ghnvb\LOCALS~1\Temp\RAVZX.EXE (file missing)
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Poco 0.31; iebar; acc=baadshah; acc=none; TencentTraveler ; (R1 1.3); .NET CLR 1.1.4322)