在浏览器地址栏输入"天涯俱乐部""太平洋电脑网"等知名网站便会被强行转至
www.50365.com
以下是扫描日志
Logfile of HijackThis v1.99.1
Scan saved at 12:17:01, on 2005-9-18
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\P4P\p2psvr.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\download\426101200522225654\HijackThis.exe
R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-
D9371ABE876E} - C:\PROGRA~1\P4P\Toolbar.dll
O1 - Hosts: 218.5.76.51 ctt900.com
O1 - Hosts: 218.5.76.51 www.ctt900.com
O1 - Hosts: 218.5.76.51 ctt900.com
O1 - Hosts: 218.5.76.51 www.ctt900.com
O1 - Hosts: 218.5.76.51 zhao123.com
O1 - Hosts: 218.5.76.51 www.zhao123.com
O1 - Hosts: 218.5.76.51 zhao123.com
O1 - Hosts: 218.5.76.51 www.zhao123.com
O1 - Hosts: 218.5.76.51 4399.com
O1 - Hosts: 218.5.76.51 www.4399.com
O1 - Hosts: 218.5.76.51 4399.com
O1 - Hosts: 218.5.76.51 www.4399.com
O1 - Hosts: 218.5.76.51 chinagames.net
O1 - Hosts: 218.5.76.51 www.chinagames.net
O1 - Hosts: 218.5.76.51 chinagames.net
O1 - Hosts: 218.5.76.51 www.chinagames.net
O1 - Hosts: 218.5.76.51 tiexue.net
O1 - Hosts: 218.5.76.51 www.tiexue.net
O1 - Hosts: 218.5.76.51 tiexue.net
O1 - Hosts: 218.5.76.51 www.tiexue.net
O1 - Hosts: 218.5.76.51 qq163.com
O1 - Hosts: 218.5.76.51 www.qq163.com
O1 - Hosts: 218.5.76.51 qq163.com
O1 - Hosts: 218.5.76.51 www.qq163.com
O1 - Hosts: 218.5.76.51 flashmi.net
O1 - Hosts: 218.5.76.51 www.flashmi.net
O1 - Hosts: 218.5.76.51 flashmi.net
O1 - Hosts: 218.5.76.51 www.flashmi.net
O1 - Hosts: 218.5.76.51 chinamp3.com
O1 - Hosts: 218.5.76.51 www.chinamp3.com
O1 - Hosts: 218.5.76.51 chinamp3.com
O1 - Hosts: 218.5.76.51 www.chinamp3.com
O1 - Hosts: 218.5.76.51 pg168.com
O1 - Hosts: 218.5.76.51 www.pg168.com
O1 - Hosts: 218.5.76.51 pg168.com
O1 - Hosts: 218.5.76.51 www.pg168.com
O1 - Hosts: 218.5.76.51 yymp3.com
O1 - Hosts: 218.5.76.51 www.yymp3.com
O1 - Hosts: 218.5.76.51 yymp3.com
O1 - Hosts: 218.5.76.51 www.yymp3.com
O1 - Hosts: 218.5.76.51 yy138.com
O1 - Hosts: 218.5.76.51 www.yy138.com
O1 - Hosts: 218.5.76.51 yy138.com
O1 - Hosts: 218.5.76.51 www.yy138.com
O1 - Hosts: 218.5.76.51 dj99.com
O1 - Hosts: 218.5.76.51 www.dj99.com
O1 - Hosts: 218.5.76.51 dj99.com
O1 - Hosts: 218.5.76.51 www.dj99.com
O1 - Hosts: 218.5.76.51 sogua.com
O1 - Hosts: 218.5.76.51 www.sogua.com
O1 - Hosts: 218.5.76.51 sogua.com
O1 - Hosts: 218.5.76.51 www.sogua.com
O1 - Hosts: 218.5.76.51 snsn.net
O1 - Hosts: 218.5.76.51 www.snsn.net
O1 - Hosts: 218.5.76.51 snsn.net
O1 - Hosts: 218.5.76.51 www.snsn.net
O1 - Hosts: 218.5.76.51 flash8.net
O1 - Hosts: 218.5.76.51 www.flash8.net
O1 - Hosts: 218.5.76.51 flash8.net
O1 - Hosts: 218.5.76.51 www.flash8.net
O1 - Hosts: 218.5.76.51 mop.com
O1 - Hosts: 218.5.76.51 www.mop.com
O1 - Hosts: 218.5.76.51 mop.com
O1 - Hosts: 218.5.76.51 www.mop.com
O1 - Hosts: 218.5.76.51 tianyaclub.com
O1 - Hosts: 218.5.76.51 www.tianyaclub.com
O1 - Hosts: 218.5.76.51 tianyaclub.com
O1 - Hosts: 218.5.76.51 www.tianyaclub.com
O1 - Hosts: 218.5.76.51 xici.net
O1 - Hosts: 218.5.76.51 www.xici.net
O1 - Hosts: 218.5.76.51 xici.net
O1 - Hosts: 218.5.76.51 www.xici.net
O1 - Hosts: 218.5.76.51 ucanlove.com
O1 - Hosts: 218.5.76.51 www.ucanlove.com
O1 - Hosts: 218.5.76.51 ucanlove.com
O1 - Hosts: 218.5.76.51 www.ucanlove.com
O1 - Hosts: 218.5.76.51 cmfu.com
O1 - Hosts: 218.5.76.51 www.cmfu.com
O1 - Hosts: 218.5.76.51 cmfu.com
O1 - Hosts: 218.5.76.51 www.cmfu.com
O1 - Hosts: 218.5.76.51 21red.net
O1 - Hosts: 218.5.76.51 www.21red.net
O1 - Hosts: 218.5.76.51 21red.net
O1 - Hosts: 218.5.76.51 www.21red.net
O1 - Hosts: 218.5.76.51 pconline.com.cn
O1 - Hosts: 218.5.76.51 www.pconline.com.cn
O1 - Hosts: 218.5.76.51 pconline.com.cn
O1 - Hosts: 218.5.76.51 www.pconline.com.cn
O1 - Hosts: 218.5.76.51 donews.com
O1 - Hosts: 218.5.76.51 www.donews.com
O1 - Hosts: 218.5.76.51 donews.com
O1 - Hosts: 218.5.76.51 www.donews.com
O1 - Hosts: 218.5.76.51 pcauto.com.cn
O1 - Hosts: 218.5.76.51 www.pcauto.com.cn
O1 - Hosts: 218.5.76.51 pcauto.com.cn
O1 - Hosts: 218.5.76.51 www.pcauto.com.cn
O1 - Hosts: 218.5.76.51 265.com
O1 - Hosts: 218.5.76.51 www.265.com
O1 - Hosts: 218.5.76.51 265.com
O1 - Hosts: 218.5.76.51 www.265.com
O1 - Hosts: 218.5.76.51 wo99.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-
1D9571695F55} - C:\WINDOWS\System32\xunleibho_v3.dll
O2 - BHO: CPub
Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} -
C:\Program Files\P4P\sodaie.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: SDObmObj Class - {D4D5C535-BA95-4327-870D-A33826FDD17A} -
C:\WINDOWS\System32\obwbkya.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-
AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: MSN 工具栏 - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -
C:\Program Files\MSN Toolbar\01.01.2607.0\zh-cn\msntb.dll
O3 - Toolbar: IE伴郎 - {B225B89D-5E95-4194-98E8-149993071B31} -
C:\PROGRA~1\COMMON~1\IETOOL~1.DLL
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} -
C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} -
C:\PROGRA~1\P4P\Toolbar.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-
Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz
Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1
\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1
\TRAYAP~1.EXE
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - Startup: hosts.exe
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KUGOO2
\KugooDownX.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - C:\PROGRA~1
\P4P\dl.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program
Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program
Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 发送图片到手机 - C:\PROGRA~1\P4P\cx.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program
Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program
Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program
Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-
E800A446447A} - D:\Program Files\浩方对战平台\GameClient.exe
O9 - Extra button: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} -
http://www.liantang.net (file missing)
O9 - Extra 'Tools' menuitem: 视频聊天 - {6924091F-CD97-41E1-B1D4-
D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra button: 寻论网--中学作业解答 - {6924091F-CD97-41E1-B1D4-
D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra 'Tools' menuitem: 中学作业 - {6924091F-CD97-41E1-B1D4-
D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra button: SoQ - {8F67DCF3-B1DF-4A39-A787-3775784BF737} -
http://www.soq.com (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage Validation Tool) - http://go.microsoft.com/fwlink/?
linkid=36467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
-
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/w
uweb_site.cab?1119574866984
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CD88A78-24D9-448C-9497-
C618CED03787}: NameServer = 219.146.0.130 219.150.32.132
O20 - AppInit_DLLs: C:\WINDOWS\System32\SoDAHK.DLL
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA
Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program
Files\P4P\p2psvr.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising
- C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology
Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术
有限公司 - C:\Program Files\Common Files\smartde\sde.exe