Logfile of HijackThis v1.99.1
Scan saved at 13:01:46, on 2006-10-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
E:\杀毒软件\杀毒软件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
E:\杀毒软件\杀毒软件\Rising\Rav\Ravmond.exe
e:\杀毒软件\杀毒软件\防火墙\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
E:\杀毒软件\杀毒软件\Rising\Rav\RavStub.exe
e:\杀毒软件\杀毒软件\防火墙\rising\rfw\RfwMain.exe
E:\杀毒软件\杀毒软件\Rising\Rav\RavTask.exe
E:\杀毒软件\杀毒软件\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
D:\无聊\Memory Booster.exe
E:\下载软件\WEB迅雷\WebThunder.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\杀毒软件\修复程序\hijiackthis2\HijackThis.exe
O2 - BHO: WebThunderBHO - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - E:\下载软件\WEB迅雷\WebThunderBHO_015.dll
O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTask] "E:\杀毒软件\杀毒软件\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [Windows木马防火墙] ; E:\杀毒软件\木马专杀\Trojanwall.exe
O4 - HKLM\..\Run: [腾迅] ; E:\QQ2006\QQ.exe
O4 - HKLM\..\Run: [MemoryIdle] D:\无聊\Memory Booster.exe -PowerOn
O4 - HKLM\..\RunOnce: [RavStub] "E:\杀毒软件\杀毒软件\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [XDeskShow] D:\无聊\桌面\鱼鱼桌面秀\XDeskShow.exe
O4 - HKCU\..\Run: [MemoryZipperPlus] D:\无聊\桌面\memzipt\memzipT.exe
O8 - Extra context menu item: &使用迅雷下载 - E:\下载软件\下载工具\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\下载软件\下载工具\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\QQ2006\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - E:\下载软件\WEB迅雷\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - E:\下载软件\WEB迅雷\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\QQ2006\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ2006\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\QQ2006\SendMMS.htm
O9 - Extra button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ2006\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ2006\QQ.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = 邵媚
O17 - HKLM\Software\..\Telephony: DomainName = 邵媚
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D97ABDF-9EE5-4B23-B62C-7967341CBB47}: NameServer = 202.98.160.68 61.166.150.101
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = 邵媚
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = 邵媚
O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\杀毒软件\杀毒软件\防火墙\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\杀毒软件\杀毒软件\防火墙\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\杀毒软件\杀毒软件\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\杀毒软件\杀毒软件\Rising\Rav\Ravmond.exe