Logfile of HijackThis v1.99.1
Scan saved at 17:32:34, on 2005-8-13
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
F:\Tencent\qq\QQ.exe
F:\Tencent\qq\TIMPlatform.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\zsy\LOCALS~1\Temp\Rar$EX00.422\HijackThis.exe
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [StormCodec_Helper] "F:\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: 使用Kugoo下载 - F:\KuGoo2\KugooDownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Tencent\qq\SendMMS.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wintcp.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {59CCB4A0-727D-11CF-AC36-00AA00A47DD2} (Timer
Object) - http://www.xintv.com/download/ietimer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097082115716
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://61.153.48.246:1995/talk.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://pcastdl.dudu.com/files/pCastCtl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7762D1B7-5810-46D9-A3CC-E2D2D1B3A9E4}: NameServer = 202.96.209.6 202.96.209.133
O20 - Winlogon Notify: WB - F:\AlienGUIse\fastload.dll
O23 - Service: Messenger - Unknown owner - C:\WINDOWS\System32\3838.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe