Logfile of HijackThis v1.99.1
Scan saved at 13:56:23, on 2005-12-7
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
D:\KAV2005\KWatch.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\KAV2005\KPfwSvc.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\rundll32.exe
D:\Program Files\Common Files\SAND\client.exe
D:\KAV2005\KAVStart.exe
D:\WINDOWS\rundll32.exe
D:\Program Files\Ahead\InCD\InCD.exe
D:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
D:\WINDOWS\System32\rundll32.exe
D:\WINDOWS\System32\ctfmon.exe
D:\KAV2005\KMailMon.EXE
D:\WINDOWS\System32\Rundll32.exe
D:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
D:\Program Files\TTPlayer\TTPlayer.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\rundll32.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\IE修复专家\IE修复专家.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\QQexternal.exe
D:\Documents and Settings\hdc\Local Settings\Temp\hijackthis.zip 的临时
目录 1\HijackThis.exe
D:\Program Files\Kingsoft\FastAIT 2005\FastAIT.exe
R3 - Default URLSearchHook is missing
O1 - Hosts: 205.177.72.132 www.32012.com/1/2.htm
O1 - Hosts: 205.177.72.132 www.16700.net/189.htm
O1 - Hosts: 205.177.72.132 www.32012.com/1/1.htm
O1 - Hosts: 205.177.72.132 www.fc987.com/cp135.htm
O1 - Hosts: 205.177.72.132 www.34111.com/dy8.htm
O1 - Hosts: 205.177.72.132 1.334456.com/i.htm
O1 - Hosts: 205.177.72.132 www.60066.com/666.htm
O1 - Hosts: 205.177.72.132 www.mark68.net/3.htm
O1 - Hosts: 205.177.72.132 www.fc987.com/cp134.htm
O1 - Hosts: 205.177.72.132 www.4894.com/l.htm
O1 - Hosts: 205.177.72.132 www.55399.com/65.asp
O1 - Hosts: 205.177.72.132 www.34111.com/dy.htm
O1 - Hosts: 205.177.72.132 www.66823.com/11.htm
O1 - Hosts: 205.177.72.132 www.66823.com/33.htm
O1 - Hosts: 205.177.72.132 www1.31339.com
O1 - Hosts: 205.177.72.132 www.v8885.cn/222.htm
O1 - Hosts: 205.177.72.132 www.fc987.com/cp136.htm
O1 - Hosts: 205.177.72.132 2.31339.com
O1 - Hosts: 205.177.72.132 www.60066.com/63.asp
O1 - Hosts: 205.177.72.132 www.v088.com/index1.htm
O1 - Hosts: 205.177.72.132 www.kai888.com/www.kai888.com
O1 - Hosts: 205.177.72.132 k3838338.com/donghua.htm
O1 - Hosts: 205.177.72.132 www.55399.com/64.asp
O1 - Hosts: 205.177.72.132 www.97118.com/3000.htm
O1 - Hosts: 205.177.72.132 www.kai888.com/www.kai888.com/www.kai888.com
O1 - Hosts: 205.177.72.132 k3838338.com/donghua1.htm
O1 - Hosts: 205.177.72.132 www.60066.com/64.asp
O1 - Hosts: 205.177.72.132 55399.com/63.asp
O1 - Hosts: 205.177.72.132 www.60066.com/66.htm
O1 - Hosts: 205.177.72.132 www.118y.com/33.htm
O1 - Hosts: 205.177.72.132 www.v8885.cn/111.htm
O1 - Hosts: 205.177.72.132 www.q3721.com/index1.htm
O1 - Hosts: 205.177.72.132 www.fc987.com/cp133.htm
O1 - Hosts: 205.177.72.132 58665.com/1.htm
O1 - Hosts: 205.177.72.132 www.hk256.com/6.htm
O1 - Hosts: 205.177.72.132 www.389988.com/ab.htm
O1 - Hosts: 205.177.72.132 www.66823.com/44.htm
O1 - Hosts: 205.177.72.132 www.mark68.net/1.htm
O1 - Hosts: 205.177.72.132 www.mt007.com
O1 - Hosts: 205.177.72.132 www.v088.com
O1 - Hosts: 205.177.72.132 www.118y.com/11.htm
O1 - Hosts: 205.177.72.132 www.xg169.com
O1 - Hosts: 205.177.72.132 www.hk6777.com/index6.htm
O1 - Hosts: 205.177.72.132 www.hk8777.com/index6.htm
O1 - Hosts: 205.177.72.132 www.hk6777.com
O1 - Hosts: 205.177.72.132 www.hk3777.com/index3.htm
O1 - Hosts: 205.177.72.132 www.920888.com
O1 - Hosts: 205.177.72.132 hk256.com
O1 - Hosts: 205.177.72.132 100049.com/66.htm
O1 - Hosts: 205.177.72.132 www.hk256.com/66.htm
O1 - Hosts: 205.177.72.132 www.mark68.net/5.htm
O1 - Hosts: 205.177.72.132 www.118y.com/44.htm
O1 - Hosts: 205.177.72.132 www.60066.com/61.asp
O1 - Hosts: 205.177.72.132 www.hk256.com
O1 - Hosts: 205.177.72.132 qq665.com/1.htm
O1 - Hosts: 205.177.72.132 004466.com/htm31.htm
O1 - Hosts: 205.177.72.132 it889.com/101.htm
O1 - Hosts: 205.177.72.132 yao38.com/index1.htm
O1 - Hosts: 205.177.72.132 www.60066.com/62.asp
O1 - Hosts: 205.177.72.132 389988.com/88.htm
O1 - Hosts: 205.177.72.132 www.hk723.com/44.htm
O1 - Hosts: 205.177.72.132 www.4894.com/l.htm
O1 - Hosts: 205.177.72.132 www.mark68.net/2.htm
O1 - Hosts: 205.177.72.132 www.mt007.com/ring
O1 - Hosts: 205.177.72.132 55399.com/62.asp
O1 - Hosts: 205.177.72.132 www.hk8777.com
O1 - Hosts: 205.177.72.132 www.xg169.com
O1 - Hosts: 205.177.72.132 www.vv166.com/4.htm
O1 - Hosts: 205.177.72.132 www.138130.com/dy/168.htm
O1 - Hosts: 205.177.72.132 www.66823.com/22.htm
O1 - Hosts: 205.177.72.132 www.hk723.com/11.htm
O1 - Hosts: 205.177.72.132 004466.com/htm34.htm
O1 - Hosts: 205.177.72.132 004466.com/htm32.htm
O1 - Hosts: 205.177.72.132 55399.com/61.asp
O1 - Hosts: 205.177.72.132 60066.com/6.asp
O1 - Hosts: 205.177.72.132 www.mark68.net/4.htm
O1 - Hosts: 205.177.72.132 hk6777.com
O1 - Hosts: 205.177.72.132 www.1396.net/indexl.htm
O1 - Hosts: 205.177.72.132 www.hk723.com/33.htm
O1 - Hosts: 205.177.72.132 www.58665.com/1.htm
O1 - Hosts: 205.177.72.132 www.so516.com/ls.htm
O1 - Hosts: 205.177.72.132 www.hk723.com/22.htm
O1 - Hosts: 205.177.72.132 004466.com/htm35.htm
O1 - Hosts: 205.177.72.132 it889.com/101.htm
O1 - Hosts: 205.177.72.132 004466.com/htm33.htm
O1 - Hosts: 205.177.72.132 www.hk256.com/666.htm
O1 - Hosts: 205.177.72.132 www.h828.net/yi88
O1 - Hosts: 205.177.72.132 www.hk3777.com/index3.htm
O1 - Hosts: 205.177.72.132 hk8777.com
O1 - Hosts: 205.177.72.132 www.hk256.com/6666.htm
O1 - Hosts: 205.177.72.132 225568.com/01.htm
O1 - Hosts: 205.177.72.132 www.118y.com/22.htm
O1 - Hosts: 205.177.72.132 www1.53777.com
O1 - Hosts: 205.177.72.132 www.xgccc.com
O1 - Hosts: 205.177.72.132 3953.com/2
O1 - Hosts: 205.177.72.132 tk9933.com/d.htm
O1 - Hosts: 205.177.72.132 www1.53777.com
O1 - Hosts: 205.177.72.132 www.vv166.com/5.htm
O1 - Hosts: 205.177.72.132 hao339.com/tu/index.htm
O1 - Hosts: 205.177.72.132 tk399.net/07.htm
O1 - Hosts: 205.177.72.132 www.68q.net/44.htm
O2 - BHO: QQBrowserHelper
Object Class - {54EBD53A-9BC1-480B-966A-
843A333CA162} - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} -
D:\WINDOWS\System32\aclayer.dll
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} -
D:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} -
D:\PROGRA~1\MMSASS~1\MMSASS~2.DLL
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -
D:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} -
D:\PROGRA~1\HBClient\hapast.dll
O2 - BHO: IEHlprObj Class - {EE7C3CF0-4B15-11D1-ABED-709549C10000} -
D:\PROGRA~1\INTERN~1\hmapi.dll (file missing)
O2 - BHO: AdSwpr - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -
D:\PROGRA~1\IE修复~1\IERBar.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -
D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} -
D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - Toolbar: &IE修复专家 - {123249EB-F891-44C4-946F-450064F9080E} -
D:\PROGRA~1\IE修复~1\IERBar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KavStart] "D:\KAV2005\KAVStart.exe" -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - HKLM\..\Run: [Update] D:\Program Files\Common
Files\UPDATE\Update.exe
O4 - HKLM\..\Run: [hbpassport] D:\PROGRA~1\HBClient\hbast.exe
O4 - HKLM\..\Run: [rx] D:\WINDOWS\rundll32.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "D:\PROGRA~1
\CNNIC\Cdn\cdnspie.dll,ExecFilter solo"
O4 - HKLM\..\Run: [DataLayer] D:\PROGRA~1\COMMON~1\PCSuite\DATALA~1
\DATALA~1.EXE
O4 - HKLM\..\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KsgUpdateRun] D:\Program Files\Common
Files\kingsoft\KSG\Client.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - HKCU\..\Run: [KavPFW] "D:\KAV2005\KAVPFW.EXE"
O4 - Startup: 腾讯QQ.lnk = D:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft
Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions
present
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program
Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program
Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program
Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} -
D:\PROGRA~1\MMSASS~1\MMSASS~2.DLL
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d
-A7CF-5587F9B7E191} - D:\PROGRA~1\MMSASS~1\MMSASS~2.DLL
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) -
http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O23 - Service: .Net Boot Service - Unknown owner - D:\WINDOWS\System32
\big5_gb2312.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - D:\Program
Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG -
D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft
Corporation - D:\KAV2005\KPfwSvc.EXE
O23 - Service: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft
Corporation - D:\KAV2005\KWatch.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA
Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Print Controller (Universal Disk Manager) - Unknown
owner - D:\Program Files\Common Files\SAND\client.exe