Logfile of HijackThis v1.99.1
Scan saved at 18:08:50, on 2005/08/12
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\conime.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINNT\system32\internat.exe
D:\Phone\Skype.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
D:\穝戈Ж\и瓜\Tencent\QQ\hongmei.exe
D:\穝戈Ж\и瓜\Tencent\QQ\TIMPlatform.exe
D:\穝戈Ж\и瓜\Tencent\QQ\hongmei.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\pc224\иゅン\繟柳瓜\winlinez.exe
D:\pc224\иゅン\繟柳瓜\winlinez.exe
\192.168.21.45\tools\Mysoft\hijackthis EN\HijackThis.exe
O1 - Hosts: 210.74.232.207 www.zhao114.com
O1 - Hosts: 210.74.232.207 zhao114.com
O1 - Hosts: 210.74.232.207 www.zhao114.com
O1 - Hosts: 210.74.232.207 zhao114.com
O1 - Hosts: 210.74.232.207 www.cnww.net
O1 - Hosts: 210.74.232.207 cnww.net
O1 - Hosts: 210.74.232.207 www.zhao123.com
O1 - Hosts: 210.74.232.207 zhao123.com
O1 - Hosts: 210.74.232.207 www.4399.com
O1 - Hosts: 210.74.232.207 4399.com
O1 - Hosts: 210.74.232.207 www.chinagames.net
O1 - Hosts: 210.74.232.207 chinagames.net
O1 - Hosts: 210.74.232.207 www.tiexue.net
O1 - Hosts: 210.74.232.207 tiexue.net
O1 - Hosts: 210.74.232.207 www.qq163.com
O1 - Hosts: 210.74.232.207 qq163.com
O1 - Hosts: 210.74.232.207 www.tt67.com
O1 - Hosts: 210.74.232.207 tt67.com
O1 - Hosts: 210.74.232.207 www.chinamp3.com
O1 - Hosts: 210.74.232.207 chinamp3.com
O1 - Hosts: 210.74.232.207 www.pg168.com
O1 - Hosts: 210.74.232.207 pg168.com
O1 - Hosts: 210.74.232.207 www.yymp3.com
O1 - Hosts: 210.74.232.207 yymp3.com
O1 - Hosts: 210.74.232.207 www.yy138.com
O1 - Hosts: 210.74.232.207 yy138.com
O1 - Hosts: 210.74.232.207 www.dj99.com
O1 - Hosts: 210.74.232.207 dj99.com
O1 - Hosts: 210.74.232.207 www.sogua.com
O1 - Hosts: 210.74.232.207 sogua.com
O1 - Hosts: 210.74.232.207 www.snsn.net
O1 - Hosts: 210.74.232.207 snsn.net
O1 - Hosts: 210.74.232.207 www.flash8.net
O1 - Hosts: 210.74.232.207 flash8.net
O1 - Hosts: 210.74.232.207 www.mop.com
O1 - Hosts: 210.74.232.207 mop.com
O1 - Hosts: 210.74.232.207 www.tianyaclub.com
O1 - Hosts: 210.74.232.207 tianyaclub.com
O1 - Hosts: 210.74.232.207 www.xici.net
O1 - Hosts: 210.74.232.207 xici.net
O1 - Hosts: 210.74.232.207 www.ucanlove.com
O1 - Hosts: 210.74.232.207 ucanlove.com
O1 - Hosts: 210.74.232.207 www.cmfu.com
O1 - Hosts: 210.74.232.207 cmfu.com
O1 - Hosts: 210.74.232.207 www.21red.net
O1 - Hosts: 210.74.232.207 21red.net
O1 - Hosts: 210.74.232.207 www.pconline.com.cn
O1 - Hosts: 210.74.232.207 pconline.com.cn
O1 - Hosts: 210.74.232.207 www.donews.com
O1 - Hosts: 210.74.232.207 donews.com
O1 - Hosts: 210.74.232.207 www.pcauto.com.cn
O1 - Hosts: 210.74.232.207 pcauto.com.cn
O1 - Hosts: 210.74.232.207 www.265.com
O1 - Hosts: 210.74.232.207 265.com
O1 - Hosts: 210.74.232.207 www.wo99.com
O1 - Hosts: 210.74.232.207 wo99.com
O1 - Hosts: 210.74.232.207 www.familydoctor.com.cn
O1 - Hosts: 210.74.232.207 familydoctor.com.cn
O1 - Hosts: 210.74.232.207 www.flashempire.com
O1 - Hosts: 210.74.232.207 flashempire.com
O1 - Hosts: 210.74.232.207 www.showgood.tv
O1 - Hosts: 210.74.232.207 showgood.tv
O1 - Hosts: 210.74.232.207 www.flashfan.net
O1 - Hosts: 210.74.232.207 flashfan.net
O1 - Hosts: 210.74.232.207 www.long21.net
O1 - Hosts: 210.74.232.207 long21.net
O1 - Hosts: 210.74.232.207 www.sowww.com
O1 - Hosts: 210.74.232.207 sowww.com
O1 - Hosts: 210.74.232.207 www.flashhome.net
O1 - Hosts: 210.74.232.207 flashhome.net
O1 - Hosts: 210.74.232.207 www.cnflash.net
O1 - Hosts: 210.74.232.207 cnflash.net
O1 - Hosts: 210.74.232.207 www.flashsky.com
O1 - Hosts: 210.74.232.207 flashsky.com
O1 - Hosts: 210.74.232.207 www.hunansky.com
O1 - Hosts: 210.74.232.207 hunansky.com
O1 - Hosts: 210.74.232.207 www.52flash.net
O1 - Hosts: 210.74.232.207 52flash.net
O1 - Hosts: 210.74.232.207 www.flashh.com
O1 - Hosts: 210.74.232.207 flashh.com
O1 - Hosts: 210.74.232.207 www.flashsun.com
O1 - Hosts: 210.74.232.207 flashsun.com
O1 - Hosts: 210.74.232.207 www.7k7k.com
O1 - Hosts: 210.74.232.207 7k7k.com
O1 - Hosts: 210.74.232.207 www.xuanxuan.com
O1 - Hosts: 210.74.232.207 xuanxuan.com
O1 - Hosts: 210.74.232.207 www.flash88.net
O1 - Hosts: 210.74.232.207 flash88.net
O1 - Hosts: 210.74.232.207 www.91flash.com
O1 - Hosts: 210.74.232.207 91flash.com
O1 - Hosts: 210.74.232.207 www.doingflash.com
O1 - Hosts: 210.74.232.207 doingflash.com
O1 - Hosts: 210.74.232.207 www.5see.com
O1 - Hosts: 210.74.232.207 5see.com
O1 - Hosts: 210.74.232.207 www.skyhits.com
O1 - Hosts: 210.74.232.207 skyhits.com
O1 - Hosts: 210.74.232.207 www.ting78.com
O1 - Hosts: 210.74.232.207 ting78.com
O1 - Hosts: 210.74.232.207 www.91.com
O1 - Hosts: 210.74.232.207 91.com
O1 - Hosts: 210.74.232.207 www.flashchina.net
O3 - Toolbar: @msdxmLC.dll,-1@1028,Μ诀[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Skype] "D:\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: 睰QQ﹚竡 - D:\穝戈Ж\и瓜\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 睰QQ薄 - D:\穝戈Ж\и瓜\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: ノQQ眒獺肚癳赣瓜 - D:\穝戈Ж\и瓜\Tencent\QQ\SendMMS.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: ㎝獺戈癟いみ - {07020D85-05C6-4027-B5CB-F89F1CA2B352} - \\qxfs\tools\software\pictuer\index.url (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://bbs.qxshoe.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = qxshoe.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = qxshoe.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = qxshoe.com
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe