Logfile of HijackThis v1.99.2
Scan saved at 14:30:11, on 2006-7-10
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\logonui.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\ftc\Trojanwall.exe
E:\WINDOWS\System32\ctfmon.exe
F:\Program Files dayly\真正的windows xp任务管理器增强版\1taskmgr.exe
E:\Program Files\Filseclab\xfilter\xfilter.exe
E:\Program Files\Rising\Rfw\rfwmain.exe
E:\WINDOWS\System32\CTsvcCDA.exe
E:\WINDOWS\System32\NMSSvc.exe
F:\Program Files copy\NOD32.Admin.v2.50.25.CN.全功能免安装版\NOD32.Admin.v2.50.25.CN.全功能免安装版\nod32krn.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\wdfmgr.exe
e:\program files\rising\rfw\rfwsrv.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files copy\HijackThis1.99.2干净版HijackThis\HijackThis.exe
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - E:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [NvMediaCenter] ; RUNDLL32.EXE E:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows木马防火墙] E:\Program Files\ftc\Trojanwall.exe
O4 - HKLM\..\Run: [TROJANWALL.EXE] ; E:\PROGRAM FILES\FTC\TROJANWALL.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - F:\Program Files copy\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Program Files copy\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Add to &Teleport - F:\program files www\Teleport Pro\teleport.htm
O8 - Extra context menu item: 使用 IDM 下载(&I) - F:\Program Files\Internet Download Manager v4.03.2 绿色汉化版\IDMan4.03\IEExt.htm
O8 - Extra context menu item: 使用网际快车下载 - F:\Program Files\网际快车 FlashGet v1.65 美化版\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - F:\Program Files\网际快车 FlashGet v1.65 美化版\jc_all.htm
O8 - Extra context menu item: 保存: 完整网页... - F:\program files www\CyberArticle 网文快捕 V4.361 肚朝前\CyberArticle\script\Save.htm
O8 - Extra context menu item: 保存: 更多保存内容... - F:\program files www\CyberArticle 网文快捕 V4.361 肚朝前\CyberArticle\script\SaveAuto.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\AddEmotion.htm
O8 - Extra context menu item: 黄河&Flash播放器 - F:\Program Files dayly\黄河Flash播放器\geturl.htm
O10 - Unknown file in Winsock LSP: e:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: e:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: e:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: e:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: e:\program files\filseclab\xfilter\xfilter.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{112DFCBD-C073-4681-90BE-30278EF8A581}: NameServer = 202.106.46.151 202.106.0.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{112DFCBD-C073-4681-90BE-30278EF8A581}: NameServer = 202.106.46.151 202.106.0.20
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: F-Prot Antivirus Update Monitor - Unknown owner - E:\WINDOWS\
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - E:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - F:\Program Files copy\NOD32.Admin.v2.50.25.CN.全功能免安装版\NOD32.Admin.v2.50.25.CN.全功能免安装版\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwsrv.exe |