Logfile of HijackThis v1.99.1
Scan saved at 17:14:13, on 2006-8-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
运行进程:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\ibmpmsvc.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Rising\Rav\CCenter.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\S24EvMon.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\SYSTEM32\RUNDLL32.EXE
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\WinMgmt.exe
E:\WINDOWS\system32\iexplorer.exe
E:\WINDOWS\System32\QCONSVC.EXE
E:\WINDOWS\system32\RegSrvc.exe
E:\PROGRA~1\baigoo\bgoomain.exe
E:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
E:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\Program Files\Rising\Rav\RavTask.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\TpKmpSVC.exe
E:\WINDOWS\system32\ctfmon.exe
E:\WINDOWS\System32\alg.exe
E:\WINDOWS\system32\rundll32.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\WinRAR\WinRAR.exe
E:\DOCUME~1\周建颂\LOCALS~1\Temp\Rar$EX02.738\HijackThis v1.99.1 汉化版\HijackThis.exe
R3 - URLSearchHook: YOK Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - E:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
F2 - REG:system.ini: UserInit=E:\WINDOWS\system32\userinit.exe,E:\WINDOWS\system32\mouser.exe
O1 - Hosts: .
O1 - Hosts: .
O1 - Hosts: .
O1 - Hosts: .
O1 - Hosts: .
O1 - Hosts: .
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55}? - (没有文件)
O2 - BHO: Shockwave Flash
Object - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - E:\WINDOWS\system32\smflash.ocx
O2 - BHO: (no name) - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F}? - (没有文件)
O2 - BHO: (no name) - {1D49D58D-5C84-4B50-8359-D9809BEB2B32}? - (没有文件)
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB}? - (没有文件)
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410}? - (没有文件)
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - E:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (没有文件)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B}? - (没有文件)
O2 - BHO: YOK超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - E:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: (no name) - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688}? - (没有文件)
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - E:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: (no name) - {77FEF28E-EB96-44FF-B511-3185DEA48697}? - (没有文件)
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - E:\Program Files\baigoo\BGooBHO.dll
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005}? - (没有文件)
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61}? - (没有文件)
O2 - BHO: (no name) - {9E1E1371-9D8F-4421-81B9-F8D2E1773A59}? - (没有文件)
O2 - BHO: XBTP03129 - {B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3}? - (没有文件)
O2 - BHO: (no name) - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}? - (没有文件)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (没有文件)
O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} - (没有文件)
O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF}? - (没有文件)
O2 - BHO: (no name) - {EA4BC1B6-C454-157F-1C8D-8CA71B6E8498}? - (没有文件)
O2 - BHO: (no name) - {F2E37336-BFDB-409B-8D0E-6F013C438B20}? - (没有文件)
O2 - BHO: (no name) - {F5824EFB-728A-4726-A5A5-85A68B20EDC3}? - (没有文件)
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8}? - (没有文件)
O3 - Toolbar: (no name) - {6B2455FD-3669-4555-8DF8-69FD5BC846F8}? - (没有文件)
O3 - Toolbar: (no name) - {F869BB38-FFEF-4589-B986-610B7AD0ADA2}? - (没有文件)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (没有文件)
O3 - Toolbar: (no name) - {406F94F0-504F-4A40-8DFD-58B0666ABEBD}? - (没有文件)
O3 - Toolbar: (no name) - {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89}? - (没有文件)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - E:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - E:\Progra~1\Baidu\bar\BaiDuBar.dll
O3 - Toolbar: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - E:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O4 - HKLM\..\Run: [CdnCtr] E:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [RavTask] ; "E:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [YOKAssiant] ; Rundll32.exe E:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [ATIPTA] ; E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [bgoomain.exe] ; E:\PROGRA~1\baigoo\bgoomain.exe
O4 - HKLM\..\Run: [BigDogPath] ; E:\WINDOWS\VM_STI.EXE FAMETECH USB PC CAMERA
O4 - HKLM\..\Run: [BMMLREF] ; E:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] ; rundll32.exe E:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [CnsMHlp.exe] ; E:\WINDOWS\Downloaded Program files\CnsMHlp.exe
O4 - HKLM\..\Run: [EZEJMNAP] ; E:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [helper.dll] ; E:\WINDOWS\system32\rundll32.exe E:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [IESAddr] ; E:\WINDOWS\system32\rundll32.exe E:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [inetsvr] ; E:\Program Files\ieup\inetsvr.exe
O4 - HKLM\..\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PHIME2002A] ; E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [popo2004] ; E:\Program Files\Netease\popo2004\Start.exe
O4 - HKLM\..\Run: [QCWLIcon] ; E:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [res] ; rem E:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [SoundMAX] ; "E:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] ; E:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [spoolsv] ;
O4 - HKLM\..\Run: [StormCodec_Helper] ; "E:\Program Files\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [SynTPEnh] ; E:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPLpr] ; E:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [Thunder] ; "E:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [TkBellExe] ; rem "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TPHOTKEY] ; E:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] ; E:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [Update] ; E:\Program Files\Common Files\UPDAT\Update.exe
O4 - HKLM\..\Run: [WinampAgent] ; rem E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [yassistse] ; rem "E:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [YLive.exe] ; rem E:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [娱乐助手] ; E:\PROGRA~1\ylzs\ylzs.exe
O4 - HKLM\..\Run: [娱乐助手升级程序] ; E:\PROGRA~1\COMMON~1\ylzs\upylzs.exe
O4 - HKCU\..\Run: [ctfmon.exe] ; E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] ; "E:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Google Desktop Search] ; "E:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] ; "E:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Instant Access] ; E:\WINDOWS\system32\procia.exe /run
O4 - HKCU\..\Run: [MSMSGS] ; "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [msq] ; E:\WINDOWS\system32\iExplorer.exe