Logfile of HijackThis v1.99.1
Scan saved at 18:38:26, on 2006-5-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Chinanet\VnetClient.exe
C:\WINDOWS\SERVICES.EXE
c:\windows\alg.exe
C:\boot.exe
C:\WINDOWS\system32\mshta.exe
D:\Tencent\QQ\QQ.exe
D:\Tencent\QQ\TIMPlatform.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.426\HijackThis.exe
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
F3 - REG:win.ini: load=c:\windows\alg.exe
O1 - Hosts: This is 4489.CN Setting file!!!
O1 - Hosts: 61.152.252.24 53900.com
O1 - Hosts: 61.152.252.24 www.53900.com
O1 - Hosts: 61.152.252.24 tm286.com
O1 - Hosts: 61.152.252.24 www.tm286.com
O1 - Hosts: 61.152.252.24 555567.com
O1 - Hosts: 61.152.252.24 www.555567.com
O1 - Hosts: 61.152.252.24 k3333.net
O1 - Hosts: 61.152.252.24 www.k3333.net
O1 - Hosts: 61.152.252.24 556633.com
O1 - Hosts: 61.152.252.24 www.556633.com
O1 - Hosts: 61.152.252.24 t9666.com
O1 - Hosts: 61.152.252.24 www.t9666.com
O1 - Hosts: 61.152.252.24 0085200852.com
O1 - Hosts: 61.152.252.24 www.0085200852.com
O1 - Hosts: 61.152.252.24 tm466.com
O1 - Hosts: 61.152.252.24 www.tm466.com
O1 - Hosts: 61.152.252.24 ok8088.com
O1 - Hosts: 61.152.252.24 www.ok8088.com
O1 - Hosts: 61.152.252.24 y636.com
O1 - Hosts: 61.152.252.24 www.y636.com
O1 - Hosts: 61.152.252.24 777568.com
O1 - Hosts: 61.152.252.24 www.777568.com
O1 - Hosts: 61.152.252.24 22261.com
O1 - Hosts: 61.152.252.24 www.22261.com
O1 - Hosts: 61.152.252.24 22799.net
O1 - Hosts: 61.152.252.24 www.22799.net
O1 - Hosts: 61.152.252.24 34511.com
O1 - Hosts: 61.152.252.24 www.34511.com
O1 - Hosts: 61.152.252.24 87765.com
O1 - Hosts: 61.152.252.24 www.87765.com
O1 - Hosts: 61.152.252.24 557888.com
O1 - Hosts: 61.152.252.24 www.557888.com
O1 - Hosts: 61.152.252.24 k667.net
O1 - Hosts: 61.152.252.24 www.k667.net
O1 - Hosts: 61.152.252.24 t6668.com
O1 - Hosts: 61.152.252.24 www.t6668.com
O1 - Hosts: 61.152.252.24 38144.com
O1 - Hosts: 61.152.252.24 www.38144.com
O1 - Hosts: 61.152.252.24 00338.net
O1 - Hosts: 61.152.252.24 www.00338.net
O1 - Hosts: 61.152.252.24 58567.net
O1 - Hosts: 61.152.252.24 www.58567.net
O1 - Hosts: 61.152.252.24 000666.net
O1 - Hosts: 61.152.252.24 www.000666.net
O1 - Hosts: 61.152.252.24 00448.net
O1 - Hosts: 61.152.252.24 www.00448.net
O1 - Hosts: 61.152.252.24 8888789.com
O1 - Hosts: 61.152.252.24 www.8888789.com
O1 - Hosts: 61.152.252.24 263789.com
O1 - Hosts: 61.152.252.24 www.263789.com
O1 - Hosts: 61.152.252.24 160061.com
O1 - Hosts: 61.152.252.24 www.160061.com
O1 - Hosts: 61.152.252.24 138600.com
O1 - Hosts: 61.152.252.24 www.138600.com
O1 - Hosts: 61.152.252.24 09198.com
O1 - Hosts: 61.152.252.24 www.09198.com
O1 - Hosts: 61.152.252.24 kdy2008.com
O1 - Hosts: 61.152.252.24 www.kdy2008.com
O1 - Hosts: 61.152.252.24 3d757.com
O1 - Hosts: 61.152.252.24 www.3d757.com
O1 - Hosts: 61.152.252.24 568cp.com
O1 - Hosts: 61.152.252.24 www.568cp.com
O1 - Hosts: 61.152.252.24 658668.com
O1 - Hosts: 61.152.252.24 www.658668.com
O1 - Hosts: 61.152.252.24 cp2166.com
O1 - Hosts: 61.152.252.24 www.cp2166.com
O1 - Hosts: 61.152.252.24 cp34567.com
O1 - Hosts: 61.152.252.24 www.cp34567.com
O1 - Hosts: 61.152.252.24 48699.com
O1 - Hosts: 61.152.252.24 www.48699.com
O1 - Hosts: 61.152.252.24 56598.com
O1 - Hosts: 61.152.252.24 www.56598.com
O1 - Hosts: 61.152.252.24 258268.com
O1 - Hosts: 61.152.252.24 www.258268.com
O1 - Hosts: 61.152.252.24 345333.com
O1 - Hosts: 61.152.252.24 www.345333.com
O1 - Hosts: 61.152.252.24 454455.com
O1 - Hosts: 61.152.252.24 www.454455.com
O1 - Hosts: 61.152.252.24 82567.com
O1 - Hosts: 61.152.252.24 www.82567.com
O1 - Hosts: 61.152.252.24 10585.com
O1 - Hosts: 61.152.252.24 www.10585.com
O1 - Hosts: 61.152.252.24 tm4936.com
O1 - Hosts: 61.152.252.24 www.tm4936.com
O1 - Hosts: 61.152.252.24 kk4949.com
O1 - Hosts: 61.152.252.24 www.kk4949.com
O1 - Hosts: 61.152.252.24 332338.com
O1 - Hosts: 61.152.252.24 www.332338.com
O1 - Hosts: 61.152.252.24 00858.cc
O1 - Hosts: 61.152.252.24 www.00858.cc
O1 - Hosts: 61.152.252.24 992998.com
O1 - Hosts: 61.152.252.24 www.992998.com
O1 - Hosts: 61.152.252.24 444345.com
O1 - Hosts: 61.152.252.24 www.444345.com
O1 - Hosts: 61.152.252.24 55770.com
O1 - Hosts: 61.152.252.24 www.55770.com
O1 - Hosts: 61.152.252.24 611688.com
O1 - Hosts: 61.152.252.24 www.611688.com
O1 - Hosts: 61.152.252.24 772778.com
O1 - Hosts: 61.152.252.24 www.772778.com
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\KuGoo3\KuGoo3DownXControl.ocx
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll