Logfile of HijackThis v1.99.1
Scan saved at 9:45:11, on 2007-1-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
E:\天骥外辅1.86免费破解版\天骥外辅1.86本地验证版.exe
D:\Program Files\ebscn_super\TDXW.EXE
E:\天骥外辅1.86免费破解版\Mir2tianji.dat
E:\天骥外辅1.86免费破解版\Mir2tianji.dat
E:\天骥外辅1.86免费破解版\Mir2tianji.dat
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\360safe\360Safe.exe
D:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
E:\download\ha_hijackthis_1991\HijackThis.exe
O1 - Hosts: 255.0.0.1 www.sf123.com
O1 - Hosts: 255.0.0.1 www.sf00.com
O1 - Hosts: 255.0.0.1 wg.sf123.com
O1 - Hosts: 255.0.0.1 www.yocksky.com
O1 - Hosts: 255.0.0.1 www.6657.com
O1 - Hosts: 255.0.0.1 www.waigua8.com
O1 - Hosts: 255.0.0.1 www.72z.net
O1 - Hosts: 255.0.0.1 www.fxin2008.com
O1 - Hosts: 255.0.0.1 www.chinawg.net
O1 - Hosts: 255.0.0.1 bbs.72z.net
O1 - Hosts: 255.0.0.1 waigua8.com
O1 - Hosts: 255.0.0.1 fxin2008.com
O1 - Hosts: 255.0.0.1 chinawg.net
O1 - Hosts: 255.0.0.1 yocksky.com
O1 - Hosts: 255.0.0.1 ad.chinawg.net
O1 - Hosts: 255.0.0.1 www.17wpk.com
O1 - Hosts: 255.0.0.1 17wpk.com
O1 - Hosts: 255.0.0.1 www.wanmir.com
O1 - Hosts: 255.0.0.1 www.cqsf999.com
O1 - Hosts: 255.0.0.1 www.zhaosf.com
O1 - Hosts: 255.0.0.1 www.hahawg.com
O1 - Hosts: 255.0.0.1 hahawg.com
O1 - Hosts: 255.0.0.1 www.gameswg.com
O1 - Hosts: 255.0.0.1 gameswg.com
O1 - Hosts: 255.0.0.1 www.zhaosf.com
O1 - Hosts: 255.0.0.1 www.chuanqi.com
O1 - Hosts: 255.0.0.1 www.wg999.com
O1 - Hosts: 255.0.0.1 wg999.com
O1 - Hosts: 255.0.0.1 www.512game.com
O1 - Hosts: 255.0.0.1 game.yule.com.cn
O1 - Hosts: 255.0.0.1 www.9432.com
O1 - Hosts: 255.0.0.1 www.cnsmallgame.com
O1 - Hosts: 255.0.0.1 www.wgwang.comO2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\Program Files\360safe\safemon\safemon.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: adsl.lnk = ?
O8 - Extra context menu item: 使用影音传送带下载 - D:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\Program Files\Xi\NetTransport 2\NTAddList.html
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168673493984
O17 - HKLM\System\CCS\Services\Tcpip\..\{58175340-43F4-4B74-925D-A7EF1E1878B4}: NameServer = 221.10.251.196 221.10.251.197
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe