Logfile of HijackThis v1.99.1
Scan saved at 12:53:07, on 2006-11-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
g:\瑞星\防火墙 \rising\rfw\rfwsrv.exe
C:\WINDOWS.0\system32\spoolsv.exe
G:\卡巴\avp.exe
G:\Ewido Security Suite Plus(防木马软件)\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS.0\Explorer.EXE
G:\瑞星\防火墙 \Rising\Rfw\rfwmain.exe
G:\Ewido Security Suite Plus(防木马软件)\ewido anti-spyware 4.0\ewido.exe
E:\飞车\虚拟光驱\daemon.exe
C:\WINDOWS.0\system32\RUNDLL32.EXE
G:\卡巴\avp.exe
C:\WINDOWS.0\system32\ctfmon.exe
G:\QQ2006\QQ\QQ.exe
G:\QQ2006\QQ\TIMPlatform.exe
C:\WINDOWS.0\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
G:\HijackThis\HijackThis.exe
R3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
O1 - Hosts: 59.34.148.190 www.369mu.com
O1 - Hosts: 59.34.148.190 www.vzidc.com
O1 - Hosts: 59.34.148.190 www.xnidc.cn
O1 - Hosts: 59.34.148.190 www.2858168.com
O1 - Hosts: 59.34.148.190 www.idcmu.com
O1 - Hosts: 59.34.148.190 www.khwl.cn
O1 - Hosts: 59.34.148.190 www.see4f.net
O1 - Hosts: 59.34.148.190 www.idcke.com
O1 - Hosts: 59.34.148.190 www.lay0.com
O1 - Hosts: 59.34.148.190 www.idcke.com
O1 - Hosts: 59.34.148.190 bbs.17ez.com
O1 - Hosts: 59.34.148.190 bbs.vzkj.com
O1 - Hosts: 59.34.148.190 www.vzkj.com
O1 - Hosts: 59.34.148.190 muqiao.host.idc163.cn
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll
O4 - HKLM\..\Run: [RfwMain] "G:\瑞星\防火墙 \Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [!ewido] "G:\Ewido Security Suite Plus(防木马软件)\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [StormCodec_Helper] "F:\暴风\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe
O4 - HKLM\..\Run: [Vistadrv] C:\Program Files\Vista\Vistadrive\vsdrv.exe
O4 - HKLM\..\Run: [DAEMON Tools-2052] "E:\飞车\虚拟光驱\daemon.exe" -lang 2052
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS.0\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [lplgfq22] C:\WINDOWS.0\system32\rundll32.exe C:\WINDOWS.0\system32\lplgfq22.dll,DllCanUnloadNow
O4 - HKLM\..\Run: [kis] "G:\卡巴\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - G:\卡巴\scieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.17173.com
O15 - Trusted Zone: http://2006.sohu.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{81E61FDD-401C-4AFB-8EFE-26D49AD50297}: NameServer = 202.103.24.68 202.103.44.150
O17 - HKLM\System\CCS\Services\Tcpip\..\{82434C58-602B-4A1C-96E7-E596B820A4C9}: NameServer = 192.168.62.1
O20 - Winlogon Notify: klogon - C:\WINDOWS.0\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS.0\system32\WPDShServiceObj.dll
O23 - Service: 卡巴斯基互联网安全套装 6.0 (AVP) - Kaspersky Lab - G:\卡巴\avp.exe
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - G:\Ewido Security Suite Plus(防木马软件)\ewido anti-spyware 4.0\guard.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - g:\瑞星\防火墙 \rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - g:\瑞星\防火墙 \rising\rfw\rfwsrv.exe
