ogfile of HijackThis v1.99.1
Scan saved at 14:59:12, on 2005-7-25
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
G:\KAV2005\KWatch.EXE
C:\WINDOWS\System32\svchost.exe
G:\KAV2005\KPfwSvc.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
G:\KAV2005\KAVStart.exe
G:\KAV2005\KMailMon.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
G:\KAV2005\KavPFW.exe
G:\qq\QQ.exe
G:\qq\TIMPlatform.exe
D:\Program Files\KuGoo2\KuGoo.exe
F:\新建文件夹\HijackThis.exe
O1 - Hosts: 218.30.29.42 www.3721,com
O1 - Hosts: 218.30.29.42 3721.com
O1 - Hosts: 218.30.29.42 www.wenxuecity.com
O1 - Hosts: 218.30.29.42 wenxuecity.com
O1 - Hosts: 218.30.29.42 www.tom.com
O1 - Hosts: 218.30.29.42 tom.com
O1 - Hosts: 218.30.29.42 www.chinaren.com
O1 - Hosts: 218.30.29.42 chinaren.com
O1 - Hosts: 218.30.29.42 www.atnext.com
O1 - Hosts: 218.30.29.42 atnext.com
O1 - Hosts: 218.30.29.42 www.hkbn.net
O1 - Hosts: 218.30.29.42 hkbn.net
O1 - Hosts: 218.30.29.42 www.pchome.com.tw
O1 - Hosts: 218.30.29.42 pchome.com.tw
O1 - Hosts: 218.30.29.42 www.china.com
O1 - Hosts: 218.30.29.42 china.com
O1 - Hosts: 218.30.29.42 www.allyes.com
O1 - Hosts: 218.30.29.42 allyes.com
O1 - Hosts: 218.30.29.42 www.eachnet.com
O1 - Hosts: 218.30.29.42 eachnet.com
O1 - Hosts: 218.30.29.42 www.chinatimes.com
O1 - Hosts: 218.30.29.42 chinatimes.com
O1 - Hosts: 218.30.29.42 www.showhappy.net
O1 - Hosts: 218.30.29.42 showhappy.net
O1 - Hosts: 218.30.29.42 www.lycos.com.cn
O1 - Hosts: 218.30.29.42 lycos.com.cn
O1 - Hosts: 218.30.29.42 www.ctn.com.cn
O1 - Hosts: 218.30.29.42 ctn.com.cn
O1 - Hosts: 218.30.29.42 www.tencent.com
O1 - Hosts: 218.30.29.42 tencent.com
O1 - Hosts: 218.30.29.42 www.the-sun.com.hk
O1 - Hosts: 218.30.29.42 the-sun.com.hk
O1 - Hosts: 218.30.29.42 www.881903.com
O1 - Hosts: 218.30.29.42 881903.com
O1 - Hosts: 218.30.29.42 www.tvb.com
O1 - Hosts: 218.30.29.42 tvb.com
O1 - Hosts: 218.30.29.42 www.nease.net
O1 - Hosts: 218.30.29.42 nease.net
O1 - Hosts: 218.30.29.42 www.yisou.com
O1 - Hosts: 218.30.29.42 yisou.com
O1 - Hosts: 218.30.29.42 www.online.sh.cn
O1 - Hosts: 218.30.29.42 online.sh.cn
O1 - Hosts: 218.30.29.42 www.hkgolden.com
O1 - Hosts: 218.30.29.42 hkgolden.com
O1 - Hosts: 218.30.29.42 www.qianlong.com
O1 - Hosts: 218.30.29.42 qianlong.com
O1 - Hosts: 218.30.29.42 www.2000fun.com
O1 - Hosts: 218.30.29.42 2000fun.com
O1 - Hosts: 218.30.29.42 www.gamer.com.tw
O1 - Hosts: 218.30.29.42 gamer.com.tw
O1 - Hosts: 218.30.29.42 www.sogua.com
O1 - Hosts: 218.30.29.42 sogua.com
O1 - Hosts: 218.30.29.42 www.51.net
O1 - Hosts: 218.30.29.42 51.net
O1 - Hosts: 218.30.29.42 www.hc360.com
O1 - Hosts: 218.30.29.42 hc360.com
O1 - Hosts: 218.30.29.42 www.she.com
O1 - Hosts: 218.30.29.42 she.com
O1 - Hosts: 218.30.29.42 www.bdchina.com
O1 - Hosts: 218.30.29.42 bdchina.com
O1 - Hosts: 218.30.29.42 www.mingpao.com
O1 - Hosts: 218.30.29.42 mingpao.com
O1 - Hosts: 218.30.29.42 www.soufun.com
O1 - Hosts: 218.30.29.42 soufun.com
O1 - Hosts: 218.30.29.42 www.gznet.com
O1 - Hosts: 218.30.29.42 gznet.com
O1 - Hosts: 218.30.29.42 www.homeway.com.cn
O1 - Hosts: 218.30.29.42 homeway.com.cn
O1 - Hosts: 218.30.29.42 www.pchome.net
O1 - Hosts: 218.30.29.42 pchome.net
O1 - Hosts: 218.30.29.42 www.timway.com
O1 - Hosts: 218.30.29.42 timway.
O1 - Hosts: 218.30.29.42 www.qq.com
O1 - Hosts: 218.30.29.42 qq.com
O1 - Hosts: 218.30.29.42 www.polyu.edu.hk
O1 - Hosts: 218.30.29.42 polyu.edu.hk
O1 - Hosts: 218.30.29.42 www.rongshuxia.com
O1 - Hosts: 218.30.29.42 rongshuxia.com
O1 - Hosts: 218.30.29.42 www.orientaldaily.com.hk
O1 - Hosts: 218.30.29.42 orientaldaily.com.hk
O1 - Hosts: 218.30.29.42 www.hinet.net
O1 - Hosts: 218.30.29.42 hinet.net
O1 - Hosts: 218.30.29.42 www.pc365.com.cn
O1 - Hosts: 218.30.29.42 pc365.com.cn
O1 - Hosts: 218.30.29.42 www.ebay.com.cn
O1 - Hosts: 218.30.29.42 ebay.com.cn
O1 - Hosts: 218.30.29.42 www.chinamobile.com
O1 - Hosts: 218.30.29.42 chinamobile.com
O1 - Hosts: 218.30.29.42 www.hko.gov.hk
O1 - Hosts: 218.30.29.42 hko.gov.hk
O1 - Hosts: 218.30.29.42 www.so-net.com.hk
O1 - Hosts: 218.30.29.42 so-net.com.hk
O1 - Hosts: 218.30.29.42 www.chinacars.com
O1 - Hosts: 218.30.29.42 chinacars.com
O1 - Hosts: 218.30.29.42 www.esdlife.com
O1 - Hosts: 218.30.29.42 esdlife.com
O1 - Hosts: 218.30.29.42 www.hongkongjockeyclub.com
O1 - Hosts: 218.30.29.42 hongkongjockeyclub.com
O1 - Hosts: 218.30.29.42 www.6to23.com
O1 - Hosts: 218.30.29.42 6to23.com
O1 - Hosts: 218.30.29.42 www.bbvod.net
O2 - BHO: KOSIE HelperInternet Explorer Web Content Guard - {1B2F92A1-CDAF-4511-9382-91E3F5CE0880} - G:\Kos\KOSIEBar.dll
O3 - Toolbar: 金山毒霸安全助手 - {EF72500A-C234-46C4-BF0A-9AA6913DDF34} - G:\Kos\KOSIEBar.dll
O4 - HKLM\..\Run: [KavStart] "G:\KAV2005\KAVStart.exe" -startup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: 使用Kugoo下载 - D:\Program Files\KuGoo2\KugooDownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - G:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - G:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - G:\qq\SendMMS.htm
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\qq\QQIEHelper.dll
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS] 网络实名
O16 - DPF: {C22D6D40-47D8-40FE-825A-CC7F4D88B3B8} - http://download.3721.com/download/inst.ca_
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEEBE684-2C1A-4802-8F60-E3BEDC3AC841}: NameServer = 202.96.128.166 202.96.128.86
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft Corporation - G:\KAV2005\KPfwSvc.EXE
O23 - Service: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - G:\KAV2005\KWatch.EXE