Logfile of HijackThis v1.99.1
Scan saved at 10:07:36, on 2005-7-22
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Symantec AntiVirus\DefWatch.exe
E:\WINDOWS\System32\svchost.exe
c:\soft\soft\MICROS~1\MSSQL\binn\sqlservr.exe
E:\Program Files\Symantec AntiVirus\SavRoam.exe
E:\Program Files\Symantec AntiVirus\Rtvscan.exe
E:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\PROGRA~1\SYMANT~1\VPTray.exe
E:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\wsearch\Search.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
E:\WINDOWS\system32\rundll32.exe
E:\Documents and Settings\Administrator.我的电脑\桌面\Windows Server2003 3389终端登录器\mstsc.exe
E:\WINDOWS\system32\wuauclt.exe
D:\soft\Tencent\qq\QQ.exe
D:\soft\Tencent\qq\TIMPlatform.exe
E:\WINDOWS\system32\rundll32.exe
E:\20050523\文件夹\426101200522225654\HijackThis.exe
O2 - BHO: MDE
object Class - {4136C3F6-7636-49bf-A122-D4DA53B1ADDF} - E:\WINDOWS\system32\meobjsdt.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\soft\soft\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\soft\soft\FLASHGET\fgiebar.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - c:\soft\win2k3\King Media Player\kmp\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] E:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MoveSearch] E:\Program Files\wsearch\Search.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = E:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Microsoft Office.lnk = D:\soft\win2k3\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: 桌面传媒.lnk = ?
O8 - Extra context menu item: 使用网际快车下载 - C:\soft\soft\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\soft\soft\FlashGet\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\soft\soft\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\soft\soft\FLASHGET\flashget.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{A39BE008-5C88-4E7A-856B-E09DC5BF2BF0}: NameServer = 202.96.64.68,202.96.69.38
O17 - HKLM\System\CS1\Services\Tcpip\..\{A39BE008-5C88-4E7A-856B-E09DC5BF2BF0}: NameServer = 202.96.64.68,202.96.69.38
O17 - HKLM\System\CS2\Services\Tcpip\..\{A39BE008-5C88-4E7A-856B-E09DC5BF2BF0}: NameServer = 202.96.64.68,202.96.69.38
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - E:\WINDOWS\system32\mbprot.dll
O20 - Winlogon Notify: dimsntfy - E:\WINDOWS\SYSTEM32\dimsntfy.dll
O20 - Winlogon Notify: NavLogon - E:\WINDOWS\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - E:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - E:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - E:\Program Files\Symantec AntiVirus\Rtvscan.exe