StartupList report, 2005-11-10, 21:14:42
StartupList version: 1.52
Started from : E:\11111\hijackthis1.97_qoo\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rfw\RfwMain.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\新建文~1\RAV\RAVTIMER.EXE
C:\WINDOWS\System32\ctfmon.exe
E:\新建文件夹\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\conime.exe
E:\新建文件夹\RAV\Ravmond.exe
E:\新建文件夹\RAV\RavStub.exe
e:\新建文件夹\rav\RAVMON.EXE
D:\Program Files\QQ.exe
E:\RealOne Player\TIMPlatform.exe
D:\TT\TTraveler.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\新建文件夹\Rav\Rav.exe
E:\11111\hijackthis1.97_qoo\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
internat.exe = internat.exe
SystemTray = SysTray.Exe
SoundMan = SOUNDMAN.EXE
AtiPTA = atiptaxx.exe
REGRUN = C:\freexxx.exe
RfwMain = "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
BigDogPath = C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
NMGameX_AutoRun = C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
RavTimer = E:\新建文~1\RAV\RAVTIMER.EXE
RavMon = E:\新建文~1\RAV\RAVMON.EXE -SYSTEM
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
winnt DNS ident = wuamgrd32.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Compaq Service Drivers = msgsmsng.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=EXPLORER.EXE
SCRNSAVE.EXE=C:\WINDOWS\System32\sstext3d.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper
Objects:
Tencent Browser Helper - C:\WINDOWS\Downloaded Program Files\TBHMain.dll - {0C7C23EF-A848-485B-873C-0ED954731014}
(no name) - C:\WINDOWS\Downlo~1\ddtinit.dll - {15DDE989-CD45-4561-BF99-D22C0D5C2B74}
viviband - C:\WINDOWS\Downlo~1\vivimin.dll - {15DDE989-CD45-4561-BF99-D22C0D5C2B85}
(no name) - C:\WINDOWS\System32\CdnIEHlp.dll - {35980F6E-A137-4E50-953D-813BB8556899}
QQIEHelper - E:\RealOne Player\QQIEHelper.dll - {54EBD53A-9BC1-480B-966A-843A333CA162}
(no name) - C:\WINDOWS\Downlo~1\ddtkillw.ocx - {66C28884-4E5D-494B-80C9-CAA27528FD6D}
(no name) - C:\Program Files\LtUcx\1002\c0.dll - {78C21EFD-53BA-406C-AF1A-33A38ABD3958}
(no name) - c:\program files\google\googletoolbar2.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
--------------------------------------------------
Enumerating Task Scheduler jobs:
启用 Application Start.job
--------------------------------------------------
Enumerating Download Program Files:
[Win32 Classes]
[新浪ViVi收藏夹]
InProcServer32 = C:\WINDOWS\Downlo~1\vivimin.dll
CODEBASE = http://image2.sina.com.cn/pfp/iweb/vivimin.cab
[WebActivater Control]
InProcServer32 = C:\WINDOWS\System32\WEBACT~1.OCX
CODEBASE = http://game.qq.com/QQGame2.cab
[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc2.cab
[WEBChatRoomOCX Control]
InProcServer32 = E:\我的音乐\UCWEBChatRoom\UCWEBChatRoom.ocx
CODEBASE = http://www.51uc.com/cab/WEBChatRoom_1_39.cab
[IMCv1 Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\imcv1.dll
CODEBASE = http://61.153.48.61:1995/talk.cab
[CNNIC_IDN]
InProcServer32 = C:\WINDOWS\System32\cdn.dll
CODEBASE = http://client.jogo.cn/cdnClient/cab/cdn.cab
[QQPlayer Control]
InProcServer32 = C:\WINDOWS\System32\QQMusic3\VQQPLA~1.OCX
CODEBASE = http://imgcache.qq.com/music/QQMusicSetup.exe
[Shockwave Flash
Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINDOWS\Downlo~1\ddttmp\ddtinit.dll => C:\WINDOWS\Downlo~1\ddtinit.dll|C:\WINDOWS\Downlo~1\ddttmp\ddtinit.dll => C:\WINDOWS\Downlo~1\ddtinit.dll|C:\WINDOWS\Downlo~1\ddttmp\ddtinit.dll => C:\WINDOWS\Downlo~1\ddtinit.dll|C:\WINDOWS\Downlo~1\ddttmp\ddtinit.dll => C:\WINDOWS\Downlo~1\ddtinit.dll|C:\WINDOWS\Downlo~1\ddttmp\ddtinit.dll => C:\WINDOWS\Downlo~1\ddtinit.dll|||
--------------------------------------------------
Enumerating ShellService
ObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\st
object.dll
--------------------------------------------------
End of report, 7,295 bytes
Report generated in 0.110 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only