Logfile of HijackThis v1.99.1
Scan saved at 5:17:51, on 2005-9-30
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
E:\PROGRAM FILES\RISING\RAV\RavStub.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
E:\Program Files\Rising\Rav\RavMon.exe
D:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Rising\Rav\RavService.exe
E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Documents and Settings\Test\桌面\IEXPLORE.EXE
F:\新建文件夹\HijackThis.exe
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - D:\Program Files\3721\Assist\asbar.dll
O1 - Hosts: 218.83.158.198 7m.cn
O1 - Hosts: 218.83.158.198 www.7m.cn
O1 - Hosts: 218.83.158.198 www.57666.com
O1 - Hosts: 218.83.158.198 57666.com
O1 - Hosts: 218.83.158.198 www.98756.net
O1 - Hosts: 218.83.158.198 www.u88.cn
O1 - Hosts: 218.83.158.198 98756.net
O1 - Hosts: 218.83.158.198 www.98756.com
O1 - Hosts: 218.83.158.198 98756.com
O1 - Hosts: 218.83.158.198 www.6743.net
O1 - Hosts: 218.83.158.198 51238.com
O1 - Hosts: 218.83.158.198 www.51238.com
O1 - Hosts: 218.83.158.198 699.com
O1 - Hosts: 218.83.158.198 www.699.com
O1 - Hosts: 218.83.158.198 323.cn
O1 - Hosts: 218.83.158.198 www.323.cn
O1 - Hosts: 218.83.158.198 wo111.com
O1 - Hosts: 218.83.158.198 www.wo111.com
O1 - Hosts: 218.83.158.198 cn9898.com
O1 - Hosts: 218.83.158.198 www.cn9898
O1 - Hosts: 218.83.158.198 98988.net
O1 - Hosts: 218.83.158.198 www.98988.net
O1 - Hosts: 218.83.158.198 www.haozs.com
O1 - Hosts: 218.83.158.198 haozs.com
O1 - Hosts: 218.83.158.198 www.souou.com
O1 - Hosts: 218.83.158.198 souou.com
O1 - Hosts: 218.83.158.198 www.souou.com
O1 - Hosts: 218.83.158.198 souou.com
O1 - Hosts: 218.83.158.198 www.tt135.com
O1 - Hosts: 218.83.158.198 tt135.com
O1 - Hosts: 218.83.158.198 www.liu6.com
O1 - Hosts: 218.83.158.198 liu6.com
O1 - Hosts: 218.83.158.198 www.789.com.cn
O1 - Hosts: 218.83.158.198 789.com.cn
O1 - Hosts: 218.83.158.198 www.wz345.com
O1 - Hosts: 218.83.158.198 789.com.cn
O1 - Hosts: 218.83.158.198 www.wo555.com
O1 - Hosts: 218.83.158.198 wo555.com
O1 - Hosts: 218.83.158.198 www.18dy.com
O1 - Hosts: 218.83.158.198 18dy.com
O1 - Hosts: 218.83.158.198 www.35935.com
O1 - Hosts: 218.83.158.198 35935.com
O1 - Hosts: 218.83.158.198 www.12san.com
O1 - Hosts: 218.83.158.198 12san.com
O1 - Hosts: 218.83.158.198 wz345.com
O1 - Hosts: 218.83.158.198 www7.admin88.com
O1 - Hosts: 218.83.158.198 www6.admin88.com
O1 - Hosts: 218.83.158.198 www8.admin88.com
O1 - Hosts: 218.83.158.198 www9.admin88.com
O1 - Hosts: 218.83.158.198 www10.admin88.com
O1 - Hosts: 218.83.158.198 www11.admin88.com
O1 - Hosts: 218.83.158.198 www12.admin88.com
O1 - Hosts: 218.83.158.198 www13.admin88.com
O1 - Hosts: 218.83.158.198 www20.admin88.com
O1 - Hosts: 218.83.158.198 www8.66036.com
O1 - Hosts: 218.83.158.198 www6.66036.com
O1 - Hosts: 218.83.158.198 www10.66036.com
O1 - Hosts: 218.83.158.198 www9.66036.com
O1 - Hosts: 218.83.158.198 tj1.mytongji.com
O1 - Hosts: 218.83.158.198 tj2.mytongji.com
O1 - Hosts: 218.83.158.198 tj3.mytongji.com
O1 - Hosts: 218.83.158.198 tj4.mytongji.com
O1 - Hosts: 218.83.158.198 tj5.mytongji.com
O1 - Hosts: 218.83.158.198 tj6.mytongji.com
O1 - Hosts: 218.83.158.198 3721.com
O1 - Hosts: 218.83.158.198 www.3721,com
O1 - Hosts: 218.83.158.198 count1.zhao123.com
O1 - Hosts: 218.83.158.198 count2.zhao123.com
O1 - Hosts: 218.83.158.198 count3.zhao123.com
O1 - Hosts: 218.83.158.198 count4.zhao123.com
O1 - Hosts: 218.83.158.198 count5.zhao123.com
O1 - Hosts: 218.83.158.198 count6.zhao123.com
O1 - Hosts: 218.83.158.198 hao123.com
O1 - Hosts: 218.83.158.198 www.hao123.com
O1 - Hosts: 218.83.158.198 516.com
O1 - Hosts: 218.83.158.198 www.516.com
O1 - Hosts: 218.83.158.198 gg444.com
O1 - Hosts: 218.83.158.198 www.gg444.com
O1 - Hosts: 218.83.158.198 www.3619.com
O1 - Hosts: 218.83.158.198 3619.com
O1 - Hosts: 218.83.158.198 www.5806.com
O1 - Hosts: 218.83.158.198 5806.com
O1 - Hosts: 218.83.158.198 www.5806.net
O1 - Hosts: 218.83.158.198 9397.com
O1 - Hosts: 218.83.158.198 www.9397.com
O1 - Hosts: 218.83.158.198 5806.net
O1 - Hosts: 218.83.158.198 www.gg444.com
O1 - Hosts: 218.83.158.198 www.zhugetan.com
O1 - Hosts: 218.83.158.198 www.6284.com
O1 - Hosts: 218.83.158.198 6284.com
O1 - Hosts: 218.83.158.198 www.ok666666.com
O1 - Hosts: 218.83.158.198 ok666666.com
O1 - Hosts: 218.83.158.198 www.58v.net
O1 - Hosts: 218.83.158.198 58v.net
O1 - Hosts: 218.83.158.198 www.xg58.com
O1 - Hosts: 218.83.158.198 xg58.com
O1 - Hosts: 218.83.158.198 zhugetan.com
O1 - Hosts: 218.83.158.198 33449.com
O1 - Hosts: 218.83.158.198 www.xg08.com
O1 - Hosts: 218.83.158.198 xg08.com
O1 - Hosts: 218.83.158.198 www.818ok.com
O2 - BHO: 新浪ViVi收藏夹 - {15DDE989-CD45-4561-BF99-D22C0D5C2B85} - D:\WINDOWS\Downlo~1\vivimin.dll
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - D:\Program Files\3721\Assist\Angling.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\logs\QQIEHelper.dll (file missing)
O2 - BHO: DDDMon Class - {6BDE1669-B490-48E3-B668-456314F2D6C3} - D:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - E:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - D:\WINDOWS\DOWNLO~1\CnsHook.dll (file missing)
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - D:\WINDOWS\System32\AlxTB1.dll
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - D:\WINDOWS\System32\SHDOCVW.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 新浪ViVi收藏夹 - {15DDE989-CD45-4561-BF99-D22C0D5C2B85} - D:\WINDOWS\Downlo~1\vivimin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CnsMin] rem Rundll32.exe D:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RavMon] E:\Program Files\Rising\Rav\RavMon.exe -system
O4 - HKLM\..\Run: [YLive.exe] D:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [KV_HOST] D:\WINDOWS\System32\msdev.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunServices: [smss] D:\WINDOWS\smss.exe
O4 - Startup: ET 4.0.lnk = HRZR_EHACNGU:R:\XI2004\HaVafgnyy.xkc
O8 - Extra context menu item: Alexa Web Search - http://client.alexa.com/holiday/script/actions/search.htm
O8 - Extra context menu item: Get Alexa Data - http://client.alexa.com/holiday/script/actions/sitedata.htm
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: See Related Links - http://client.alexa.com/holiday/script/actions/related.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
O8 - Extra context menu item: 使用网际快车下载 - E:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=viviband
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\QQ\SendMMS.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_flashget_62580 (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - http://www.7115580.com (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS] 网络实名
O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:
file://C:oo.mht!http://209.190.137.32/web.chm::/win32.exe
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/aliedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{581AA848-B2F4-4DEC-BD66-C85869138F12}: NameServer = 202.101.112.55,202.101.98.55
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINDOWS\System32\mbprot.dll
O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - D:\WINDOWS\G_Server.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RSVPS (QoS RSVPS) - Unknown owner - D:\WINDOWS\spoolvs.exe (file missing)
O23 - Service: RavService - Unknown owner - E:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: ZESOFT - Unknown owner - D:\WINDOWS\zeta.exe (file missing)