Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
G:\ruixing\avp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\WINDOWS\system32\ctfmon.exe
G:\ruixing\avp.exe
G:\QQ2006\QQ.exe
G:\QQ2006\TIMPlatform.exe
G:\QQ2006\QQ.exe
G:\QQ2006\QQ.exe
D:\bt\BitComet\BitComet.exe
G:\Thunder5.3.0.220\Program\Thunder5.exe
G:\TT\TTraveler.exe
G:\扫描日记\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - G:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - G:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O4 - HKLM\..\Run: [kav] "G:\ruixing\avp.exe"
O4 - HKLM\..\Run: [Thunder] "G:\Thunder5.3.0.220\Thunder.exe" /s
O4 - HKLM\..\Run: [pdfFactory 分配器 v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - G:\Thunder5.3.0.220\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - G:\Thunder5.3.0.220\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - G:\QQ2006\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - G:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - G:\QQ2006\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - G:\QQ2006\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - G:\QQ2006\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - G:\Thunder5.3.0.220\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - G:\Thunder5.3.0.220\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\QQ2006\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\QQ2006\QQ.EXE
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E8F8588-19B0-4006-BA8F-7622CABEC0BE}: NameServer = 202.103.176.22
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: 卡巴斯基反病毒6.0 (AVP) - Kaspersky Lab - G:\ruixing\avp.exe