C:\WINDOWS\System32\conime.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
c:\program files\rising\rav\RAVMON.EXE
C:\WINDOWS\System32\WISPTIS.EXE
C:\WINDOWS\System32\mdm.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\Program Files\Thunder Network\Thunder\MediaIssue\Issue.exe
C:\Program Files\rising\rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.594\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 218.85.139.121 www.zhao123.com
O1 - Hosts: 218.85.139.121 zhao123.com
O1 - Hosts: 218.85.139.121 www.4399.com
O1 - Hosts: 218.85.139.121 4399.com
O1 - Hosts: 218.85.139.121 www.chinagames.net
O1 - Hosts: 218.85.139.121 chinagames.net
O1 - Hosts: 218.85.139.121 www.tiexue.net
O1 - Hosts: 218.85.139.121 tiexue.net
O1 - Hosts: 218.85.139.121 www.qq163.com
O1 - Hosts: 218.85.139.121 qq163.com
O1 - Hosts: 218.85.139.121 www.flashmi.net
O1 - Hosts: 218.85.139.121 flashmi.net
O1 - Hosts: 218.85.139.121 www.chinamp3.com
O1 - Hosts: 218.85.139.121 chinamp3.com
O1 - Hosts: 218.85.139.121 www.pg168.com
O1 - Hosts: 218.85.139.121 pg168.com
O1 - Hosts: 218.85.139.121 www.yymp3.com
O1 - Hosts: 218.85.139.121 yymp3.com
O1 - Hosts: 218.85.139.121 www.yy138.com
O1 - Hosts: 218.85.139.121 yy138.com
O1 - Hosts: 218.85.139.121 www.dj99.com
O1 - Hosts: 218.85.139.121 dj99.com
O1 - Hosts: 218.85.139.121 www.sogua.com
O1 - Hosts: 218.85.139.121 sogua.com
O1 - Hosts: 218.85.139.121 www.snsn.net
O1 - Hosts: 218.85.139.121 snsn.net
O1 - Hosts: 218.85.139.121 www.flash8.net
O1 - Hosts: 218.85.139.121 flash8.net
O1 - Hosts: 218.85.139.121 www.mop.com
O1 - Hosts: 218.85.139.121 mop.com
O1 - Hosts: 218.85.139.121 www.tianyaclub.com
O1 - Hosts: 218.85.139.121 tianyaclub.com
O1 - Hosts: 218.85.139.121 www.xici.net
O1 - Hosts: 218.85.139.121 xici.net
O1 - Hosts: 218.85.139.121 www.ucanlove.com
O1 - Hosts: 218.85.139.121 ucanlove.com
O1 - Hosts: 218.85.139.121 www.cmfu.com
O1 - Hosts: 218.85.139.121 cmfu.com
O1 - Hosts: 218.85.139.121 www.21red.net
O1 - Hosts: 218.85.139.121 21red.net
O1 - Hosts: 218.85.139.121 www.pconline.com.cn
O1 - Hosts: 218.85.139.121 pconline.com.cn
O1 - Hosts: 218.85.139.121 www.donews.com
O1 - Hosts: 218.85.139.121 donews.com
O1 - Hosts: 218.85.139.121 www.pcauto.com.cn
O1 - Hosts: 218.85.139.121 pcauto.com.cn
O1 - Hosts: 218.85.139.121 www.265.com
O1 - Hosts: 218.85.139.121 265.com
O1 - Hosts: 218.85.139.121 www.wo99.com
O1 - Hosts: 218.85.139.121 wo99.com
O1 - Hosts: 218.85.139.121 www.familydoctor.com.cn
O1 - Hosts: 218.85.139.121 familydoctor.com.cn
O1 - Hosts: 218.85.139.121 www.flashempire.com
O1 - Hosts: 218.85.139.121 flashempire.com
O1 - Hosts: 218.85.139.121 www.showgood.tv
O1 - Hosts: 218.85.139.121 showgood.tv
O1 - Hosts: 218.85.139.121 www.flashfan.net
O1 - Hosts: 218.85.139.121 flashfan.net
O1 - Hosts: 218.85.139.121 www.long21.net
O1 - Hosts: 218.85.139.121 long21.net
O1 - Hosts: 218.85.139.121 www.sowww.com
O1 - Hosts: 218.85.139.121 sowww.com
O1 - Hosts: 218.85.139.121 www.flashhome.net
O1 - Hosts: 218.85.139.121 flashhome.net
O1 - Hosts: 218.85.139.121 www.cnflash.net
O1 - Hosts: 218.85.139.121 cnflash.net
O1 - Hosts: 218.85.139.121 www.flashsky.com
O1 - Hosts: 218.85.139.121 flashsky.com
O1 - Hosts: 218.85.139.121 www.hunansky.com
O1 - Hosts: 218.85.139.121 hunansky.com
O1 - Hosts: 218.85.139.121 www.52flash.net
O1 - Hosts: 218.85.139.121 52flash.net
O1 - Hosts: 218.85.139.121 www.flashh.com
O1 - Hosts: 218.85.139.121 flashh.com
O1 - Hosts: 218.85.139.121 www.flashsun.com
O1 - Hosts: 218.85.139.121 flashsun.com
O1 - Hosts: 218.85.139.121 www.7k7k.com
O1 - Hosts: 218.85.139.121 7k7k.com
O1 - Hosts: 218.85.139.121 www.xuanxuan.com
O1 - Hosts: 218.85.139.121 xuanxuan.com
O1 - Hosts: 218.85.139.121 www.flash88.net
O1 - Hosts: 218.85.139.121 flash88.net
O1 - Hosts: 218.85.139.121 www.91flash.com
O1 - Hosts: 218.85.139.121 91flash.com
O1 - Hosts: 218.85.139.121 www.doingflash.com
O1 - Hosts: 218.85.139.121 doingflash.com
O1 - Hosts: 218.85.139.121 www.5see.com
O1 - Hosts: 218.85.139.121 5see.com
O1 - Hosts: 218.85.139.121 www.skyhits.com
O1 - Hosts: 218.85.139.121 skyhits.com
O1 - Hosts: 218.85.139.121 www.ting78.com
O1 - Hosts: 218.85.139.121 ting78.com
O1 - Hosts: 218.85.139.121 www.91.com
O1 - Hosts: 218.85.139.121 91.com
O1 - Hosts: 218.85.139.121 www.flashchina.net
O1 - Hosts: 218.85.139.121 flashchina.net
O1 - Hosts: 218.85.139.121 www.flash8.com.cn
O1 - Hosts: 218.85.139.121 flash8.com.cn
O1 - Hosts: 218.85.139.121 www.f130.net
O1 - Hosts: 218.85.139.121 f130.net
O1 - Hosts: 218.85.139.121 www.chinanim.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\download\QQIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\webpst2.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRA~1\YiSou\yisou.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SysExplr] C:\HEROSOFT\Hero3000\SYSEXPLR.EXE
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [EnglishElf] C:\PROGRA~1\ENGLIS~1\englishelf.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WlN32] regedit -s C:\$NtUninstallQ887678$\WINSYS.cer
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll",ExecFilter solo
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = F:\download\QQ.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: !搜一搜(&S) - res://C:\Program Files\YiSou\yisou.dll/232
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\download\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\download\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\download\SendMMS.htm
O8 - Extra context menu item: 解霸实时播放 - C:\HEROSOFT\Hero3000\MPURLGET.HTM
O9 - Extra button: 解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - Extra 'Tools' menuitem: 超级解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\download\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\download\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\download\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\download\QQIEHelper.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED9CC01A-C3AF-4A6D-A661-9677E8CB21BD}: NameServer = 61.137.94.196 202.103.96.112
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe