Logfile of HijackThis v1.99.1
Scan saved at 12:05:47, on 2006-5-8
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞星\杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞星\杀毒\Rising\Rav\Ravmond.exe
d:\瑞星\防火墙\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞星\杀毒\Rising\Rav\RavStub.exe
C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
d:\瑞星\防火墙\rising\rfw\RfwMain.exe
C:\WINDOWS\LHotkey.exe
C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\lenovo\StateChange\QuakeII.exe
D:\瑞星\杀毒\Rising\Rav\RavTask.exe
D:\瑞星\杀毒\Rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
D:\QQ相关\QQ\QQ.exe
D:\QQ相关\QQ\TIMPlatform.exe
C:\WINDOWS\System32\wuauclt.exe
D:\播放器\realone安装程序\RealPlay.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\瑞星\杀毒\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\迅雷\Thunder.exe
D:\瑞星\杀毒\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\瑞星\反浏览器劫持\248783200522382732\HijackThis.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55}
- C:\WINDOWS\System32\xunleibho_v14.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} -
C:\WINDOWS\System32\microapmddt.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-
90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LHotkey] LHotkey.exe
O4 - HKLM\..\Run: [Lcc] C:\Program Files\Lenovo\联想键盘驱动
\LCC.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StateChange] C:\Program
Files\lenovo\StateChange\QuakeII.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32
\NeroCheck.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common
Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1
\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RavTask] "D:\瑞星\杀毒\Rising\Rav\RavTask.exe"
-system
O4 - HKLM\..\Run: [RfwMain] "D:\瑞星\防火墙
\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program
Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1
\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite
6\PcSync2.exe /NoDialog
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program
Files\VIA\RAID\raid_tool.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\迅雷\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\迅雷
\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ相关
\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ相关
\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ相关
\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ相关
\QQ\SendMMS.htm
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} -
http://www.lenovo.com (file missing)
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-
3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d
-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-
D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-
D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{02039830-9F96-4F19-8ED2-
0D2EF5B1843A}: NameServer = 202.102.134.68,202.102.152.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{02039830-9F96-4F19-8ED2-
0D2EF5B1843A}: NameServer = 202.102.134.68,202.102.152.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{02039830-9F96-4F19-8ED2-
0D2EF5B1843A}: NameServer = 202.102.134.68,202.102.152.3
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) -
Advanced Micro Devices - C:\Program
Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing
Rising Technology Co., Ltd. - d:\瑞星\防火墙
\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) -
Beijing Rising Technology Co., Ltd. - d:\瑞星\防火墙
\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) -
Beijing Rising Technology Co., Ltd. - D:\瑞星\杀毒
\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising
Technology Co., Ltd. - D:\瑞星\杀毒\Rising\Rav\Ravmond.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe