Logfile of HijackThis v1.99.1
Scan saved at 22:19:20 PM, on 2006-7-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
f:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
f:\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
f:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
f:\Rising\Rav\RavStub.exe
f:\rising\rfw\RfwMain.exe
F:\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
F:\Tencent\qq\QQ.exe
F:\Tencent\QQ\TIMPlatform.exe
F:\Tencent\TT\TTraveler.exe
C:\DOCUME~1\Mite\LOCALS~1\Temp\Rar$EX00.804\HijackThis.exe
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: (no name) - {54D401A3-AB64-4522-8B17-A25DC779BB3E} - C:\WINDOWS\system32\Vudeon.dll
R3 - URLSearchHook: (no name) - {B43737EE-ABAF-4D71-A3D6-B1B9C6BCB332} - C:\WINDOWS\system32\Rvfkyv.dll
R3 - URLSearchHook: (no name) - {B837365D-B918-4002-B36A-B088E5027B9B} - C:\WINDOWS\system32\Ctiwd.dll
R3 - URLSearchHook: (no name) - {3379D437-E966-48FC-AA8D-3A22E8F50E22} - C:\WINDOWS\system32\Vidq.dll
R3 - URLSearchHook: (no name) - {B64263B1-C433-49FE-B132-B2E0F2C83035} - C:\WINDOWS\system32\Navh.dll
R3 - URLSearchHook: (no name) - {925874EF-B78F-438C-B4BD-C36232CFEC34} - C:\WINDOWS\system32\Rzaii.dll
R3 - URLSearchHook: (no name) - {BB6ED577-9A78-4133-982E-F74E090DDD8D} - C:\WINDOWS\system32\Apphd.dll
R3 - URLSearchHook: (no name) - {BE7EB4DE-4262-47C5-B00D-9963B6A0CBB9} - C:\WINDOWS\system32\Ldjfq.dll
R3 - URLSearchHook: (no name) - {F0FDFFE1-9EF1-4AAD-AFFF-E5542952A25B} - C:\WINDOWS\system32\Sxztp.dll
R3 - URLSearchHook: (no name) - {1640AC28-5027-4741-A5B7-9F9A3E7443C1} - C:\WINDOWS\system32\Hlqd.dll
R3 - URLSearchHook: (no name) - {D74F6B0A-F746-4044-A697-69245F502F07} - C:\WINDOWS\system32\Ykkp.dll
R3 - URLSearchHook: (no name) - {ED3DFC33-6BFF-47A4-BAFE-2AA7C4BDF45D} - C:\WINDOWS\system32\Yqbj.dll
R3 - URLSearchHook: (no name) - {5B5DCF40-C101-4AA7-AE5E-1125D7754672} - C:\WINDOWS\system32\Hjvdkl.dll
R3 - URLSearchHook: (no name) - {C369F22A-9338-4C94-B42E-DB035B317FBF} - C:\WINDOWS\system32\Eidmx.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: (no name) - {0310AD52-C897-4DBB-97FC-576738D1EC42} - C:\WINDOWS\system32\Lgnq.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - f:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1640AC28-5027-4741-A5B7-9F9A3E7443C1} - C:\WINDOWS\system32\Hlqd.dll
O2 - BHO: (no name) - {3379D437-E966-48FC-AA8D-3A22E8F50E22} - C:\WINDOWS\system32\Vidq.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll (file missing)
O2 - BHO: (no name) - {3C3FDA41-934A-46B0-A46F-78DC690B11DC} - C:\WINDOWS\system32\Dqsatc.dll
O2 - BHO: (no name) - {54D401A3-AB64-4522-8B17-A25DC779BB3E} - C:\WINDOWS\system32\Vudeon.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {5B5DCF40-C101-4AA7-AE5E-1125D7754672} - C:\WINDOWS\system32\Hjvdkl.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL (file missing)
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\迅雷\ComDlls\XunLeiBHO_002.dll
O2 - BHO: (no name) - {925874EF-B78F-438C-B4BD-C36232CFEC34} - C:\WINDOWS\system32\Rzaii.dll
O2 - BHO: (no name) - {9E2E70B0-0CC8-4271-89C6-B929629B4F02} - C:\WINDOWS\system32\Fnwz.dll
O2 - BHO: (no name) - {B43737EE-ABAF-4D71-A3D6-B1B9C6BCB332} - C:\WINDOWS\system32\Rvfkyv.dll
O2 - BHO: (no name) - {B64263B1-C433-49FE-B132-B2E0F2C83035} - C:\WINDOWS\system32\Navh.dll
O2 - BHO: (no name) - {B837365D-B918-4002-B36A-B088E5027B9B} - C:\WINDOWS\system32\Ctiwd.dll
O2 - BHO: (no name) - {BB6ED577-9A78-4133-982E-F74E090DDD8D} - C:\WINDOWS\system32\Apphd.dll
O2 - BHO: (no name) - {BE7EB4DE-4262-47C5-B00D-9963B6A0CBB9} - C:\WINDOWS\system32\Ldjfq.dll
O2 - BHO: (no name) - {C369F22A-9338-4C94-B42E-DB035B317FBF} - C:\WINDOWS\system32\Eidmx.dll
O2 - BHO: (no name) - {D74F6B0A-F746-4044-A697-69245F502F07} - C:\WINDOWS\system32\Ykkp.dll
O2 - BHO: (no name) - {ED3DFC33-6BFF-47A4-BAFE-2AA7C4BDF45D} - C:\WINDOWS\system32\Yqbj.dll
O2 - BHO: (no name) - {F0FDFFE1-9EF1-4AAD-AFFF-E5542952A25B} - C:\WINDOWS\system32\Sxztp.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RfwMain] "F:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "f:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunOnce: [RavStub] "f:\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = F:\Tencent\QQ\QQ.exe
O8 - Extra context menu item: &使用迅雷下载 - F:\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\迅雷\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用超级解霸播放 - f:\Herosoft\Hero 9\MPURLGET.HTM
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - F:\BitSpirit\bsurl.htm
O9 - Extra button: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - f:\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - f:\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra button: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:http://www.joyo.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - url:http://www.duba.net (file missing)
O9 - Extra button: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.51eway.com
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {2BFAA61B-5C83-4865-8281-D8BDBF863061} (PGEdit Class) - https://www.gnetpg.com/PG_ATL.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - http://login.5u56.com/com/EGamesPlugin.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129441102043
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129443997289
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - f:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - f:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - f:\Rising\Rav\Ravmond.exe
úÔcç²
Ç¥bbs.ikaka.com|óÝ:HWJ