Logfile of HijackThis v1.99.1
Scan saved at 18:27:46, on 2006-1-29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\WINDOWS\system32\rundll32.exe
C:\HERO2000\SysExplr.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\program files\rising\rfw\ScanBD.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\use\LOCALS~1\Temp\Rar$EX03.975\HijackThis.exe
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
O1 - Hosts: <meta name="ProgId" content="FrontPage.Editor.Document">
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=gb2312">
O1 - Hosts: <title>成人美少女性爱电影</title>
O1 - Hosts: <SCRIPT language=javascript src="http://12san.com/v/yule_right.js"></SCRIPT>
O1 - Hosts: <SCRIPT language=javascript src="http://12san.com/v/float_left.js"></SCRIPT>
O1 - Hosts: </head>
O1 - Hosts: <body bgcolor="#000000">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <table height="20" cellSpacing="0" cellPadding="0" width="750" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="52" style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: <center>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="752" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n155.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n156.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n157.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n158.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n159.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n160.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img height="60" src="images/n161.jpg" width="80" border="0"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n162.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px"><br>
O1 - Hosts: <img src="images/n163.jpg" border="0" width="80" height="60">
O1 - Hosts: <font size="2" style="font-size: 12px; font-family: 宋体; text-decoration: none" color="#ffffff">
O1 - Hosts: </font></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </center>
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"><br>
O1 - Hosts: <p align="center">
O1 - Hosts: <font color="#ffff00" size="3" style="font-size: 12px; font-family: 宋体; text-decoration: none">
O1 - Hosts: 由于注册人数过多,显示不正常请刷新本页</font><img src="images/input.gif" width="700" height="80"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/l.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td background="images/mobile.gif" height="50" style="font-size: 12px"> </td>
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/r.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O2 - BHO: CNav Class - {1954558D-BD14-420A-BC38-7F41F7A1DDBB} - C:\WINDOWS\System32\NAVIGA~1.DLL
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} - C:\WINDOWS\System32\hap.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: Wbho Class - {40E3A34A-3282-41F8-AD2C-051BAB96AD4A} - C:\WINDOWS\System32\Usign.dll
O2 - BHO: 360搜 - {472101C2-1109-43f4-9112-31F33E3F2127} - C:\PROGRA~1\360so\360so.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\System32\winhtp.dll
O2 - BHO: 3721中文邮 - {6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} - C:\PROGRA~1\3721\Ces\cesweb.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\YiSou\yisou.dll