Logfile of HijackThis v1.99.1
Scan saved at 10:10:26, on 2007-6-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\3f0f1.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\3G-FAX数码传真机\Monclt.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\3G-FAX数码传真机\Comlink.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
F:\SOFT\杀毒组合\HijackThis.exe
O2 - BHO: LpkHlpr Class - {00C104F7-0F5C-470C-ABCF-A5B2E70752F1} - C:\WINDOWS\system32\wpphlp.dll
O2 - BHO: windows 信息管理 - {B1B9CA6E-D469-4501-9ADC-90DC1F1EE841} - C:\WINDOWS\system32\serverhelp.dll
O2 - BHO: ff Class - {FAAAC0F6-94BE-4466-934B-7C53666A2F41} - C:\WINDOWS\system32\f3f1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [TgfMonclt] C:\3G-FAX数码传真机\Monclt.exe
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sysmppcv] "C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\SysTdSvr.dll",Start
O4 - HKLM\..\Run: [System] C:\Program Files\Common Files\system\Updaterun.exe
O4 - HKLM\..\RunOnce: [bblid] %systemroot%\system32\Rundll32.exe %systemroot%\system32\bblid.dll,DllUnregisterServer
O4 - HKLM\..\RunOnce: [pszjrk] %systemroot%\system32\Rundll32.exe %systemroot%\system32\pszjrk.dll,DllUnregisterServer
O4 - HKLM\..\RunOnce: [npplur] %systemroot%\system32\Rundll32.exe %systemroot%\system32\npplur.dll,DllUnregisterServer
O4 - HKLM\..\RunOnce: [ipfvhz] %systemroot%\system32\Rundll32.exe %systemroot%\system32\ipfvhz.dll,DllUnregisterServer
O4 - HKLM\..\RunOnce: [dblapdrv] %systemroot%\system32\regsvr32.exe /s %systemroot%\system32\wpphlp.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] F:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O8 - Extra context menu item: &使用迅雷下载 - F:\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ\QQ.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O16 - DPF: {A3CD7F74-93C9-4BC4-B892-CCDF1514F714} (Submit Class) - https://pbank.95559.com.cn/personbank/ocx/safe.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gpec.cn
O17 - HKLM\Software\..\Telephony: DomainName = gpec.cn
O17 - HKLM\System\CCS\Services\Tcpip\..\{75F5096B-497D-449E-8DF6-CA91758650DB}: NameServer = 128.0.0.1,202.96.128.68
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: msv1_1 - C:\WINDOWS\SYSTEM32\msv1_1.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Fax 2Client (ms_2fax) - Unknown owner - C:\WINDOWS\system32\3f0f1.exe