【回复“天使之剑”的帖子】Logfile of HijackThis v1.99.1
Scan saved at 23:39:46, on 2005-9-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
E:\rixing专用\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
e:\rixing专用\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\cisvc.exe
E:\rixing专用\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
E:\rixing专用\Rising\Rfw\rfwmain.exe
F:\网络游戏\lala\QQ.exe
F:\网络游戏\lala\TIMPlatform.exe
F:\网络游戏\lala\qqpet\qqpet.exe
F:\网络游戏\lala\QQexternal.exe
F:\网络游戏\TT\TTraveler.exe
F:\HijackThis.exe
O1 - Hosts: 61.177.56.251 popme.163.com
O1 - Hosts: 61.177.56.251 www.xk99.com
O1 - Hosts: 61.177.56.251 www.006.net
O1 - Hosts: 61.177.56.251 006.net
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.free120.com
O1 - Hosts: 61.177.56.251 www.4577.com
O1 - Hosts: 61.177.56.251 www.9617.com
O1 - Hosts: 61.177.56.251 www.fjwz.com
O1 - Hosts: 61.177.56.251 partner.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad4.sina.com.cn
O1 - Hosts: 61.177.56.251 music.17o8.comer.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad.tom.com
O1 - Hosts: 61.177.56.251 search.union.3721,com
O1 - Hosts: 61.177.56.251 post.baidu.com
O1 - Hosts: 61.177.56.251 mp3.baidu.com
O1 - Hosts: 61.177.56.251 image.baidu.com
O1 - Hosts: 61.177.56.251 site.google.com
O1 - Hosts: 61.177.56.251 flash.baidu.com
O1 - Hosts: 61.177.56.251 assistant.3721,com
O1 - Hosts: 61.177.56.251 pfp.sina.com.cn
O1 - Hosts: 61.177.56.251 cn.websearch.yahoo.com
O1 - Hosts: 61.177.56.251 sms.qq.com
O1 - Hosts: 61.177.56.251 www.qq.com
O1 - Hosts: 61.177.56.251 partner.lead2.com.cn
O1 - Hosts: 61.177.56.251 ad.cn.doubleclick.net
O1 - Hosts: 61.177.56.251 auto.search.msn.com
O1 - Hosts: 61.177.56.251 www.ourgame.com
O1 - Hosts: 61.177.56.251 www.the9.com
O1 - Hosts: 61.177.56.251 www.flashempire.com
O1 - Hosts: 61.177.56.251 www.qq163.com
O1 - Hosts: 61.177.56.251 www.9sky.com
O1 - Hosts: 61.177.56.251 www.tom-1.com
O1 - Hosts: 61.177.56.251 www.17173.com
O1 - Hosts: 61.177.56.251 www.yaotou.com
O1 - Hosts: 61.177.56.251 union.3721,com
O1 - Hosts: 61.177.56.251 music.feifa.com
O1 - Hosts: 61.177.56.251 www.vodfans.com
O1 - Hosts: 61.177.56.251 www.sogua.com
O1 - Hosts: 61.177.56.251 fm974.tom.com
O1 - Hosts: 61.177.56.251 ent.tom.com
O1 - Hosts: 61.177.56.251 music.tyfo.com
O1 - Hosts: 61.177.56.251 www.wanwa.com
O1 - Hosts: 61.177.56.251 www.guang.org
O1 - Hosts: 61.177.56.251 www.wz.zj.cn
O1 - Hosts: 61.177.56.251 www.3189.net
O1 - Hosts: 61.177.56.251 music.17o8.com
O1 - Hosts: 61.177.56.251 www.99music.net
O1 - Hosts: 61.177.56.251 www.cococ.com
O1 - Hosts: 61.177.56.251 www.qqqq.cn
O1 - Hosts: 61.177.56.251 www.bnb.com.cn
O1 - Hosts: 61.177.56.251 www.z163.com
O1 - Hosts: 61.177.56.251 game.163.com
O1 - Hosts: 61.177.56.251 games.sina.com.cn
O1 - Hosts: 61.177.56.251 www.v111.com
O1 - Hosts: 61.177.56.251 music.v111.com
O1 - Hosts: 61.177.56.251 www.3tom.com
O1 - Hosts: 61.177.56.251 www.xkqq.com
O1 - Hosts: 61.177.56.251 www.verymp3.com
O1 - Hosts: 61.177.56.251 www.91look.com
O1 - Hosts: 61.177.56.251 www.168101.com
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.woogood.com
O1 - Hosts: 61.177.56.251 www.haodx.com
O1 - Hosts: 61.177.56.251 www.yingku.com
O1 - Hosts: 61.177.56.251 www.flash51.com
O1 - Hosts: 61.177.56.251 www.17haha.com
O1 - Hosts: 61.177.56.251 www.432.cn
O1 - Hosts: 61.177.56.251 www.cnxp.com
O1 - Hosts: 61.177.56.251 www.hjsm.net
O1 - Hosts: 61.177.56.251 music.8wa.com
O1 - Hosts: 61.177.56.251 www.66vv.com
O1 - Hosts: 61.177.56.251 www.musicfbi.com
O1 - Hosts: 61.177.56.251 www.vv66.com
O1 - Hosts: 61.177.56.251 www.139mm.com
O1 - Hosts: 61.177.56.251 www.130wg.com
O1 - Hosts: 61.177.56.251 www.flashsea.com
O1 - Hosts: 61.177.56.251 movie.59178.com
O1 - Hosts: 61.177.56.251 www.wo123.com
O1 - Hosts: 61.177.56.251 www.1ya.cn
O1 - Hosts: 61.177.56.251 www.happy8.cn
O1 - Hosts: 61.177.56.251 www.s6.cn
O1 - Hosts: 61.177.56.251 www.hao123.com
O1 - Hosts: 61.177.56.251 www.qqee.com
O1 - Hosts: 61.177.56.251 imgu.21cn.com
O1 - Hosts: 61.177.56.251 www.sohu123.com
O1 - Hosts: 61.177.56.251 www.chinamp3.com
O1 - Hosts: 61.177.56.251 www.18z.net
O1 - Hosts: 61.177.56.251 www.ssxs.com
O1 - Hosts: 61.177.56.251 www.fjwz.net
O1 - Hosts: 61.177.56.251 www.wo365.com
O1 - Hosts: 61.177.56.251 www.zhao99.com
O1 - Hosts: 61.177.56.251 www.cn808.net
O1 - Hosts: 61.177.56.251 www.tt55.net
O1 - Hosts: 61.177.56.251 www.mp3tt.com
O1 - Hosts: 61.177.56.251 www.yi5.com
O1 - Hosts: 61.177.56.251 www.haozs.com
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: IEMenu Class - {5D8B0CBC-6A8F-4495-96F0-631BAEEC93A6} - C:\WINDOWS\System32\hookie.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\brinsthd.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 东方卫士 - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [dddclient] "C:\Program Files\DuDu\DddClient\DuDuAcc.exe" /m0
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [internet.exe] C:/WINDOWS/systems.hta
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\网络猪\Search.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] F:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [KvXP] C:\Program Files\KV2005\KvXP.kxp /ScanBoot /ScanSys
O4 - Startup: 腾讯QQ.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - F:\网络游戏\新建文件夹\pp2005\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\网络游戏\新建文件夹\pp2005\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - Extra context menu item: 1.秀字转换 - res://C:\WINDOWS\System32\esagent.dll/open.html
O8 - Extra context menu item: 2.表情插入 - res://C:\WINDOWS\System32\esagent.dll/emot.html
O8 - Extra context menu item: 3.插入QQ表情 - res://C:\WINDOWS\System32\esagent.dll/openqqemot.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\网络游戏\lala\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\网络游戏\lala\AddEmotion.htm