Logfile of HijackThis v1.99.1
Scan saved at 13:22:36, on 2005-10-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
运行进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\VM_STI.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\user\桌面\其他工具\木马克星绿色7-12\木马克星.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Antiy Labs\Alive\AliveCenter.exe
C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
D:\卡巴斯基\Kaspersky Anti-Hacker\KAVPF.exe
C:\Program Files\Ansys Inc\Shared Files\Licensing\intel\ansyslmd.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
D:\qq\TT\TTraveler.exe
C:\Documents and Settings\user\桌面\HijackThis v1.99.1 汉化版\HijackThis.exe
O1 - Hosts: 61.172.250.87 www.cn5566.com
O1 - Hosts: 218.90.161.93 www.jujumao.com
O1 - Hosts: 218.90.161.93 www.jujumao.net
O1 - Hosts: 207.46.20.30 www.microsoft.com
O1 - Hosts: 218.78.213.207 www.sbtop.com
O1 - Hosts: 202.101.42.96 www.imagegarden.net
O1 - Hosts: 218.1.14.145 bbs.163down.com
O1 - Hosts: 220.168.143.144 www.taishen.org
O1 - Hosts: 61.183.15.90 friends.mop.com
O1 - Hosts: 207.46.20.30 www.microsoft.com
O1 - Hosts: 211.142.183.40 tomatolei.com
O1 - Hosts: 202.96.140.34 www.bliao.com
O1 - Hosts: 202.112.0.36 www.cer.net
O1 - Hosts: 218.199.102.210 bt.5qzone.net
O1 - Hosts: 202.103.134.20 www.avl.com.cn
O1 - Hosts: 61.152.145.79 bbs.btbbt.com
O1 - Hosts: 218.199.102.217 pplive.com
O1 - Hosts: 219.153.18.133 bbs.leobbs.com
O1 - Hosts: 210.192.120.102 road-bridge.com
O1 - Hosts: 210.51.25.156 okok.org
O1 - Hosts: 218.5.72.53 www.tranbbs.com
O1 - Hosts: 219.153.10.56 www.lagoo.com.cn
O1 - Hosts: 202.120.189.87 bbs.tongji.edu.cn
O1 - Hosts: 61.152.188.140 www.doctorbridge.com
O1 - Hosts: 211.90.248.135 www.mjtd.com
O1 - Hosts: 211.90.248.135 www.mjtd.com
O1 - Hosts: 210.51.2.152 www.sinoaec.com
O1 - Hosts: 61.152.93.93 www.9to.com
O1 - Hosts: 218.16.125.54 www.abbs.com.cn
O1 - Hosts: 222.36.40.245 bt.tjgame.enorth.com.cn
O1 - Hosts: 218.75.102.149 bbs.511vcd.com
O1 - Hosts: 61.152.145.79 bbs.btbbt.com
O1 - Hosts: 210.51.188.126 www.manfen.net
O1 - Hosts: 61.152.108.56 bbs.btchina.net
O1 - Hosts: 61.172.250.87 www.cn5566.com
O1 - Hosts: 211.152.55.74 bbs.dvdspring.com
O1 - Hosts: 218.8.252.141 www.egame365.com
O1 - Hosts: 61.136.55.167 www.gamesir.com
O1 - Hosts: 218.25.253.6 www.mtvktv.net
O1 - Hosts: 218.16.119.105 bbs.sogua.com
O1 - Hosts: 210.51.214.74 www.100kan.com
O1 - Hosts: 61.135.159.125 www.btcube.com
O1 - Hosts: 218.75.79.195 city.9sky.com
O1 - Hosts: 67.15.35.48 www.tsmovie.com
O1 - Hosts: 222.34.111.250 www.aspking.com
O1 - Hosts: 61.132.112.154 bbs.cnxp.com
O1 - Hosts: 219.153.15.150 bbs.17yy.com
O1 - Hosts: 61.187.191.27 bt.ep8.net
O1 - Hosts: 70.85.49.10 www.upcn.com
O1 - Hosts: 219.145.107.56 bbs.btpig.com
O1 - Hosts: 218.83.153.2 bt.greedland.net
O1 - Hosts: 62.129.131.34 www.baiwan.tk
O1 - Hosts: 61.139.126.52 bbs.3gbbs.com
O1 - Hosts: 222.186.8.43 bbs.365see.net
O1 - Hosts: 218.200.117.35 www.okftp.net
O1 - Hosts: 218.200.117.35 www.okftp.net
O1 - Hosts: 61.152.144.209 www.nbeat.net
O1 - Hosts: 61.143.144.120 www.120k.net
O1 - Hosts: 210.51.168.31 www.qiqishe.com
O1 - Hosts: 210.51.168.31 www.qiqishe.com
O1 - Hosts: 202.102.201.125 www.ao-network.net
O1 - Hosts: 219.149.195.3 www.bingpo.com
O1 - Hosts: 221.136.90.1 bbs.qqip.com
O1 - Hosts: 61.172.244.83 www.taolun.com
O1 - Hosts: 61.153.19.95 www.bbmpg.com
O1 - Hosts: 61.153.19.95 www.bbmpg.com
O1 - Hosts: 202.107.225.38 bbs.sx163.com
O1 - Hosts: 61.153.224.98 www.txkd.com
O1 - Hosts: 61.152.188.162 bbs.linkboat.com
O1 - Hosts: 64.235.246.143 www.ry520.com
O1 - Hosts: 207.46.20.30 www.microsoft.com
O1 - Hosts: 207.46.20.30 www.microsoft.com
O1 - Hosts: 207.46.20.30 www.microsoft.com
O1 - Hosts: 207.46.20.30 www.microsoft.com
O2 - BHO: (no name) - Edit - (没有文件)
O2 - BHO: (no name) - Script - (没有文件)
O2 - BHO: (no name) - zqc - (没有文件)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\aberdr\ActiveX\AcroIEHelper.dll
O2 - BHO: TeachingHandler - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - C:\WINDOWS\system32\TPHANDLE.dll
O2 - BHO: (no name) - {3E422F49-1566-40D3-B43D-077EF739AC32} - (没有文件)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\qq\QQIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSAssist\MMSAssist.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\System32\stdup.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\FlashGet\jccatch.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll (文件故障)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FlashGet\fgiebar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [rx] rem C:\WINDOWS\rundll32.exe
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBClient\hbast.exe
O4 - HKLM\..\Run: [MsWinb] D:\白猫清理工\MsWinb.exe
O4 - HKLM\..\Run: [iparmor] C:\Documents and Settings\user\桌面\其他工具\木马克星绿色7-12\木马克星.exe mini
O4 - HKLM\..\Run: [KAVPersonal50] "D:\卡巴斯基\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [MsWinb] D:\白猫清理工\MsWinb.exe
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: >> 彩信发送 << - res://C:\Program Files\MMSAssist\MMSAssist.dll/mms.htm
O8 - Extra context menu item: 下载页面上的ED2(&K)链接 - d:\eMule\ed2k.html
O8 - Extra context menu item: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - d:\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - d:\SSREADER36\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Program Files\baidu\bar\BDBar_tmp\BaiduBar.dll/BAIDU_DIC.HTM
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSAssist\MMSAssist.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSAssist\MMSAssist.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\qq\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB4C4FE5-C595-4306-8AF1-447308C0047C}: NameServer = 61.232.202.158,61.134.1.4
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O20 - AppInit_DLLs: apihookdll.dll