ogfile of HijackThis v1.99.1
Scan saved at 20:46:17, on 2005-8-21
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\IAMAPP.EXE
C:\Program Files\rising\rav\CCenter.exe
C:\Program Files\rising\rav\RavMonD.exe
C:\Program Files\rising\rav\RavMon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
D:\Program Files\rili\CalSprite\CalSprite.exe
C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe
C:\WINDOWS\SYSTEM\4C0B6.com
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
D:\Program Files\认证\8021x.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\RealonePlayer\realplay.exe
C:\Documents and Settings\Windows XP\桌面\新建文件夹\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\svch0st_.exe
O1 - Hosts: 218.7.124.88 www.wwwggg.com
O1 - Hosts: 218.7.124.88 www.1717333.com
O1 - Hosts: 218.7.124.88 www.bb999.com
O1 - Hosts: 218.7.124.88 www.5073.com
O1 - Hosts: 218.7.124.88 www.wg999.com
O1 - Hosts: 218.7.124.88 www.txwg.com
O1 - Hosts: 218.7.124.88 www.d186.com
O1 - Hosts: 218.7.124.88 www.51wg.com
O1 - Hosts: 218.7.124.88 www.77wg.com
O1 - Hosts: 218.7.124.88 www.365sky.com
O1 - Hosts: 218.7.124.88 www.gameswg.com
O1 - Hosts: 218.7.124.88 www.5dgame.com
O1 - Hosts: 218.7.124.88 www.ttee.com
O1 - Hosts: 218.7.124.88 www.comv9.com
O1 - Hosts: 218.7.124.88 www.95wg.com
O1 - Hosts: 218.7.124.88 www.jxwg.com
O1 - Hosts: 218.7.124.88 www.wgwang.com
O1 - Hosts: 218.7.124.88 www.wgxz.com
O1 - Hosts: 218.7.124.88 www.91333.com
O1 - Hosts: 218.7.124.88 www.wg86.com
O1 - Hosts: 218.7.124.88 www.skyxz.com
O1 - Hosts: 218.7.124.88 www.tywg.com
O1 - Hosts: 218.7.124.88 www.py126.com
O1 - Hosts: 218.7.124.88 www.banbancq.com
O1 - Hosts: 218.7.124.88 www.92wg.com
O1 - Hosts: 218.7.124.88 www.9wg.com
O1 - Hosts: 218.7.124.88 www.jxtool.com
O1 - Hosts: 218.7.124.88 www.wg-xz.com
O1 - Hosts: 218.7.124.88 www.7ywg.com
O1 - Hosts: 218.7.124.88 www.hahawg.com
O1 - Hosts: 218.7.124.88 www.comv8.com
O1 - Hosts: 218.7.124.88 www.andown.com
O1 - Hosts: 218.7.124.88 www.gm169.com
O1 - Hosts: 218.7.124.88 www.wgshop.com
O1 - Hosts: 218.7.124.88 www.wolvip.com
O1 - Hosts: 218.7.124.88 www.9csf.com
O1 - Hosts: 218.7.124.88 www.mir222.com
O1 - Hosts: 218.7.124.88 www.py999.com
O1 - Hosts: 218.7.124.88 www.pycq.com
O1 - Hosts: 218.7.124.88 www.newpy.com
O1 - Hosts: 218.7.124.88 www.py173.com
O1 - Hosts: 218.7.124.88 www.wggame.com
O1 - Hosts: 218.7.124.88 www.wgzzz.com
O1 - Hosts: 218.7.124.88 www.117799.com
O1 - Hosts: 218.7.124.88 www.wgsky.com
O1 - Hosts: 218.7.124.88 www.wg00.com
O1 - Hosts: 218.7.124.88 www.wg8.com
O1 - Hosts: 218.7.124.88 www.wgx8.com
O1 - Hosts: 218.7.124.88 www.139wg.com
O1 - Hosts: 218.7.124.88 www.wgdd.com
O1 - Hosts: 218.7.124.88 www.lxwg.com
O1 - Hosts: 218.7.124.88 www.ly888.com
O1 - Hosts: 218.7.124.88 www.heiyun.com
O1 - Hosts: 218.7.124.88 www.mir888.com
O1 - Hosts: 218.7.124.88 www.chiyue.com
O1 - Hosts: 218.7.124.88 www.waigua8.com
O1 - Hosts: 218.7.124.88 www.wwwggg.net
O1 - Hosts: 218.7.124.88 www.1717333.net
O1 - Hosts: 218.7.124.88 www.bb999.net
O1 - Hosts: 218.7.124.88 www.5073.net
O1 - Hosts: 218.7.124.88 www.wg999.net
O1 - Hosts: 218.7.124.88 www.txwg.net
O1 - Hosts: 218.7.124.88 www.d186.net
O1 - Hosts: 218.7.124.88 www.51wg.net
O1 - Hosts: 218.7.124.88 www.77wg.net
O1 - Hosts: 218.7.124.88 www.365sky.net
O1 - Hosts: 218.7.124.88 www.gameswg.net
O1 - Hosts: 218.7.124.88 www.5dgame.net
O1 - Hosts: 218.7.124.88 www.ttee.net
O1 - Hosts: 218.7.124.88 www.comv9.net
O1 - Hosts: 218.7.124.88 www.95wg.net
O1 - Hosts: 218.7.124.88 www.jxwg.net
O1 - Hosts: 218.7.124.88 www.wgwang.net
O1 - Hosts: 218.7.124.88 www.wgxz.net
O1 - Hosts: 218.7.124.88 www.91333.net
O1 - Hosts: 218.7.124.88 www.wg86.net
O1 - Hosts: 218.7.124.88 www.skyxz.net
O1 - Hosts: 218.7.124.88 www.tywg.net
O1 - Hosts: 218.7.124.88 www.py126.net
O1 - Hosts: 218.7.124.88 www.banbancq.net
O1 - Hosts: 218.7.124.88 www.92wg.net
O1 - Hosts: 218.7.124.88 www.9wg.net
O1 - Hosts: 218.7.124.88 www.jxtool.net
O1 - Hosts: 218.7.124.88 www.wg-xz.net
O1 - Hosts: 218.7.124.88 www.7ywg.net
O1 - Hosts: 218.7.124.88 www.hahawg.net
O1 - Hosts: 218.7.124.88 www.comv8.net
O1 - Hosts: 218.7.124.88 www.andown.net
O1 - Hosts: 218.7.124.88 www.gm169.net
O1 - Hosts: 218.7.124.88 www.wgshop.net
O1 - Hosts: 218.7.124.88 www.wolvip.net
O1 - Hosts: 218.7.124.88 www.9csf.net
O1 - Hosts: 218.7.124.88 www.mir222.net
O1 - Hosts: 218.7.124.88 www.py999.net
O1 - Hosts: 218.7.124.88 www.pycq.net
O1 - Hosts: 218.7.124.88 www.newpy.net
O1 - Hosts: 218.7.124.88 www.py173.net
O1 - Hosts: 218.7.124.88 www.wggame.net
O1 - Hosts: 218.7.124.88 www.wgzzz.net
O1 - Hosts: 218.7.124.88 www.117799.net
O1 - Hosts: 218.7.124.88 www.wgsky.net
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v4.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\qq\QQIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~2\flashget\FLASHGET\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\qylhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~2\flashget\FLASHGET\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\YiSou\yisou.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~1\IAMAPP.EXE
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RavTimer] C:\Program Files\rising\rav\RavTimer.exe
O4 - HKLM\..\Run: [RavMon] C:\Program Files\rising\rav\RavMon.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [CalSprite] D:\Program Files\rili\CalSprite\CalSprite.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [MINI_BFYY] C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe
O4 - HKLM\..\Run: [startkey] C:\WINDOWS\System32\server.exe
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKLM\..\Run: [TempCom] C:\WINDOWS\SYSTEM\4C0B6.com
O4 - HKLM\..\RunServices: [RavMon] C:\Program Files\rising\rav\RavMon.exe /AUTO
O4 - HKLM\..\RunOnce: [C:\PROGRA~1\3721\alrex.dll] regsvr32 /s C:\PROGRA~1\3721\alrex.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [startkey] C:\WINDOWS\System32\server.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: 腾讯QQ.lnk = D:\Program Files\qq\QQ.exe