StartupList report, 2007-8-16, 下午 10:01:29
StartupList version: 1.52.2
Started from : D:\提示杀毒\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.5730.0011)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\瑞星\Rising\Rav\CCenter.exe
C:\WINDOWS\system32\svchost.exe
C:\瑞星\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\瑞星\RISING\RAV\RavStub.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\IME\Styler\Styler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\11\D-Tools\daemon.exe
C:\WINDOWS\domino.EXE
C:\WINDOWS\VMSnap5.EXE
C:\瑞星\Rising\Rav\RavTask.exe
C:\Program Files\OCINS\idnsvr.exe
C:\瑞星\Rising\Rav\Ravmon.exe
C:\WINDOWS\Vista\Spctool\UberIcon\UberIcon Manager.exe
C:\WINDOWS\Vista\Spctool\Taskbar\Taskbar.exe
D:\14\UC talk\UCtalk.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\提示杀毒\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Administrator\「开始」菜单\程序\启动]
QQ游戏启动加速程序.lnk = C:\Program Files\11\QQGame\Accel.exe
新浪UC talk.lnk = D:\14\UC talk\UCtalk.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Styler = C:\WINDOWS\system32\IME\Styler\Styler.exe
Vistadrv = C:\WINDOWS\Vista\vip\VistaDrv\vsdrv.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
RTHDCPL = RTHDCPL.EXE
SkyTel = SkyTel.EXE
Alcmtr = ALCMTR.EXE
DAEMON Tools-2052 = "C:\Program Files\11\D-Tools\daemon.exe" -lang 2052
domino = C:\WINDOWS\domino.EXE
VMSnap5 = C:\WINDOWS\VMSnap5.EXE
BigDog305 = C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
RavTask = "C:\瑞星\Rising\Rav\RavTask.exe" -system
IdnSvr = C:\Program Files\OCINS\idnsvr.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
bgswitch = C:\WINDOWS\system32\bgswitch.exe
UberIcon = "C:\WINDOWS\Vista\Spctool\UberIcon\UberIcon Manager.exe"
Taskbar = C:\WINDOWS\Vista\Spctool\Taskbar\Taskbar.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper
Objects:
(no name) - C:\Program Files\FlashGet\jccatch.dll - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
(no name) - C:\PROGRA~1\OCINS\ieaux.dll - {7605CC7C-00FD-4A5F-BAFD-828342DE6279}
(no name) - C:\Program Files\FlashGet\getflash.dll - {F156768E-81EF-470C-9057-481BA8380DBA}
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #5: C:\WINDOWS\system32\cdnns.dll (file MISSING)
--------------------------------------------------
Enumerating ShellService
ObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\st
object.dll
--------------------------------------------------
End of report, 4,861 bytes
Report generated in 0.016 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)