Logfile of HijackThis v1.99.1
Scan saved at 21:03:49, on 2008-8-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\usnsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\nuzoe\hovfs.exe
C:\WINDOWS\AGRSMMSG.exe
D:\电脑优化软件\MagicSet\memdef.exe
C:\WINDOWS\system32\usmsvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\ARP防火墙\AntiARP.exe
C:\WINDOWS\system32\ctfmon.exe
D:\电脑优化软件\MagicSet\SRIECLI.EXE
C:\搜狗\SogouInput\OlympicNews.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\iexplore.exe
C:\QQ\QQ.exe
C:\QQ\TXPlatform.exe
C:\QQ\QQ.exe
D:\酷我音乐盒\KWMUSIC\KwMusic.exe
D:\酷我音乐盒\KWMUSIC\kwmv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\迅雷\Program\Thunder5.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.093\HijackThis.exe
D:\HijackThis V2.0.2 Beta\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\迅雷\ComDlls\TDAtOnce_Now.dll
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:\电脑优化软件\MagicSet\haokanbar.dll (file missing)
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\迅雷\ComDlls\xunleiBHO_Now.dll
O3 - Toolbar: QQToolbar - {29CF293A-1E7D-4069-9E11-E39698D0AF95} - C:\Program Files\Tencent\QQToolbar\IEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:\电脑优化软件\MagicSet\haokanbar.dll (file missing)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [Super Rabbit Memory] D:\电脑优化软件\MagicSet\memdef.exe /LOAD
O4 - HKLM\..\Run: [usmsvc] C:\WINDOWS\system32\usmsvc.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Super Rabbit SafeEdit] C:\超级兔子\MagicSet\SRFC.EXE /Load
O4 - HKLM\..\Run: [AntiARPStandalone] D:\ARP防火墙\AntiARP.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\电脑优化软件\MagicSet\SRIECLI.EXE /LOAD
O4 - HKCU\..\Run: [OlympicExpress] "C:\搜狗\SogouInput\OlympicNews.exe"
O4 - Startup: PP网络电视.lnk = ?
O4 - Startup: QQ游戏启动加速程序.lnk = C:\QQGame\Accel.exe
O4 - Global Startup: 蓝牙控制盘.lnk = ?
O8 - Extra context menu item: 使用UUSee下载 - D:\uusee成人\uusee\geturltodown.htm
O8 - Extra context menu item: 使用UUSee加速播放 - D:\uusee成人\uusee\geturltoplay.htm
O8 - Extra context menu item: 使用迅雷下载 - C:\迅雷\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\迅雷\Program\getallurl.htm
O8 - Extra context menu item: 发送到 Bluetooth(&B) - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - C:\QQ\AddEmotion.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\迅雷\Thunder.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) -
https://img.alipay.com/download/1101/aliedit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ARP防火墙加载程序 (AntiARPClientLoader) - Unknown owner - D:\ARP防火墙\AntiARPClientLoader.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Error Log Check (erlc) - Unknown owner - C:\Program Files\Common Files\nuzoe\nescas.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Remote Procedure Call Locator (RpcUsnsvc) - Unknown owner - C:\WINDOWS\usnsvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe