Logfile of HijackThis v1.99.1
Scan saved at 16:25:46, on 2005-12-11
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\系统工具\RISING\RAV\Ravmond.exe
D:\系统工具\RISING\RAV\RavStub.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINNT\System32\svchost.exe
D:\系统工具\RISING\RAV\CCENTER.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
D:\系统工具\RISING\RAV\RAVTIMER.EXE
D:\系统工具\RISING\RAV\RAVMON.EXE
D:\播放工具\SysExplr.EXE
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
D:\系统工具\MagicSet\DS.EXE
D:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
C:\WINNT\system32\Internat.exe
D:\系统工具\MagicSet\SRIECLI.EXE
D:\系统工具\Thunder.exe
C:\WINNT\system32\conime.exe
D:\系统工具\ske\TrojanAssistant.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\mlcm\LOCALS~1\Temp\Rar$EX00.110\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\系统工具\MagicSet\HaokanBar.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\系统工具\MagicSet\HaokanBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Thunder] "D:\系统工具\ThunderShell.exe" /s
O4 - HKLM\..\Run: [RavTimer] D:\系统工具\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\系统工具\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [SysExplr] D:\播放工具\SysExplr.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Super Rabbit SRRestore] D:\系统工具\MagicSet\srrest.exe /autosave
O4 - HKLM\..\Run: [EPSON Stylus C41 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C41 Series" /O6 "USB001" /M "Stylus C41"
O4 - HKLM\..\Run: [WinampAgent] ; D:\播放工具\Winamp\winampa.exe
O4 - HKLM\..\Run: [Super Rabbit Desktop Set] D:\系统工具\MagicSet\DS.EXE /Load
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\RunOnce: [RavStub] "D:\系统工具\RISING\RAV\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [Internat.exe] Internat.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\系统工具\MagicSet\SRIECLI.EXE /LOAD
O4 - Global Startup: AudioDeck.lnk = C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\系统工具\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\系统工具\getallurl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\游戏\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\游戏\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\游戏\qq\SendMMS.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\系统工具\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\系统工具\RISING\RAV\Ravmond.exe