Logfile of HijackThis v1.99.1
Scan saved at 16:55:26, on 2005-8-3
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\3721\assistse.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\Program Files\Rising\Rave\RavTimer.exe
C:\Program Files\Rising\Rave\RavMon.exe
D:\Program Files\Sandai Technologies Inc\Thunder\Thunder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\RISING\RAVE\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAVE\Ravmond.exe
D:\Program Files\Sandai Technologies Inc\Thunder\TDUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Founder\Emergency Center\Hotkey.exe
D:\Program Files\Sandai Technologies Inc\Thunder\MediaIssue\Issue.exe
C:\WINDOWS\System32\ctfmon.exe
D:\北京城市热点资讯有限公司\Dr.COM 宽带客户端\ishare_user.exe
D:\Program Files\fjdzj\ske\TrojanAssistant.exe
D:\Program Files\Tencent\tt\TTraveler.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rave\CopyRun\RavCopy.exe
D:\Program Files\fjdzj\HijackThis.exe
O1 - Hosts: 218.85.133.109www.vodfans.com
O1 - Hosts: 218.85.133.109vodfans.com
O1 - Hosts: 218.85.133.109www.k234.com
O1 - Hosts: 218.85.133.109k234.com
O1 - Hosts: 218.85.133.109www.goodwww.com
O1 - Hosts: 218.85.133.109goodwww.com
O1 - Hosts: 218.85.133.109www.tv66.org
O1 - Hosts: 218.85.133.109tv66.org
O1 - Hosts: 218.85.133.109www.w555.com
O1 - Hosts: 218.85.133.109w555.com
O1 - Hosts: 218.85.133.109www.tkfilm.com
O1 - Hosts: 218.85.133.109tkfilm.com
O1 - Hosts: 218.85.133.109www.163.zhao117.com
O1 - Hosts: 218.85.133.109163.zhao117.com
O1 - Hosts: 218.85.133.109www.v.wg818.com
O1 - Hosts: 218.85.133.109v.wg818.com
O1 - Hosts: 218.85.133.109www.7122.com
O1 - Hosts: 218.85.133.1097122.com
O1 - Hosts: 218.85.133.109www.v.wg818.com
O1 - Hosts: 218.85.133.109v.wg818.com
O1 - Hosts: 218.85.133.109www.hot.3721.com
O1 - Hosts: 218.85.133.109hot.3721.com
O1 - Hosts: 218.85.133.109www.99770.com
O1 - Hosts: 218.85.133.10999770.com
O1 - Hosts: 218.85.133.109www.kk369.net
O1 - Hosts: 218.85.133.109kk369.net
O1 - Hosts: 218.85.133.109www.xunlei.com
O1 - Hosts: 218.85.133.109xunlei.com
O1 - Hosts: 218.85.133.109www.92bt.com
O1 - Hosts: 218.85.133.10992bt.com
O1 - Hosts: 218.85.133.109www.search.onlinedown.net
O1 - Hosts: 218.85.133.109search.onlinedown.net
O1 - Hosts: 218.85.133.109www.ent.da163.net
O1 - Hosts: 218.85.133.109ent.da163.net
O1 - Hosts: 218.85.133.109www.lbxx.net
O1 - Hosts: 218.85.133.109lbxx.net
O1 - Hosts: 218.85.133.109www.44489.com
O1 - Hosts: 218.85.133.10944489.com
O1 - Hosts: 218.85.133.109www.avvip.com
O1 - Hosts: 218.85.133.109avvip.com
O1 - Hosts: 218.85.133.109www.film21cn.com
O1 - Hosts: 218.85.133.109film21cn.com
O1 - Hosts: 218.85.133.109www.y256.com
O1 - Hosts: 218.85.133.109y256.com
O1 - Hosts: 218.85.133.109www.newsw.net
O1 - Hosts: 218.85.133.109newsw.net
O1 - Hosts: 218.85.133.109www.vod99.com
O1 - Hosts: 218.85.133.109vod99.com
O1 - Hosts: 218.85.133.109www.80666666.com
O1 - Hosts: 218.85.133.10980666666.com
O1 - Hosts: 218.85.133.109www.88ty.com
O1 - Hosts: 218.85.133.10988ty.com
O1 - Hosts: 218.85.133.109www.xinglove.com
O1 - Hosts: 218.85.133.109xinglove.com
O1 - Hosts: 218.85.133.109www.99755.com
O1 - Hosts: 218.85.133.10999755.com
O1 - Hosts: 218.85.133.109www.loveba.com
O1 - Hosts: 218.85.133.109loveba.com
O1 - Hosts: 218.85.133.109www.fx120.net
O1 - Hosts: 218.85.133.109fx120.net
O1 - Hosts: 218.85.133.109www.feifanyu.com
O1 - Hosts: 218.85.133.109feifanyu.com
O1 - Hosts: 218.85.133.109www.wg818.com
O1 - Hosts: 218.85.133.109wg818.com
O1 - Hosts: 218.85.133.109www.shan-hua.com.cn
O1 - Hosts: 218.85.133.109shan-hua.com.cn
O1 - Hosts: 218.85.133.109www.7122.com
O1 - Hosts: 218.85.133.1097122.com
O1 - Hosts: 218.85.133.109www.pic21.net
O1 - Hosts: 218.85.133.109pic21.net
O1 - Hosts: 218.85.133.109www.9see.com
O1 - Hosts: 218.85.133.1099see.com
O1 - Hosts: 218.85.133.109www.pztu.com
O1 - Hosts: 218.85.133.109pztu.com
O1 - Hosts: 218.85.133.109www.xunlei.com
O1 - Hosts: 218.85.133.109xunlei.com
O1 - Hosts: 218.85.133.109www.image.yisou.com
O1 - Hosts: 218.85.133.109image.yisou.com
O1 - Hosts: 218.85.133.109www.yes358.com
O1 - Hosts: 218.85.133.109yes358.com
O1 - Hosts: 218.85.133.109www.supsky.com
O1 - Hosts: 218.85.133.109supsky.com
O1 - Hosts: 218.85.133.109www.7c8.com
O1 - Hosts: 218.85.133.1097c8.com
O1 - Hosts: 218.85.133.109www.ccliao.com
O1 - Hosts: 218.85.133.109ccliao.com
O1 - Hosts: 218.85.133.109www.tvliao.com
O1 - Hosts: 218.85.133.109tvliao.com
O1 - Hosts: 218.85.133.109www.dreamdate.com
O1 - Hosts: 218.85.133.109dreamdate.com
O1 - Hosts: 218.85.133.109www.dreamdate.com
O1 - Hosts: 218.85.133.109dreamdate.com
O1 - Hosts: 218.85.133.109www.readnovel.com
O1 - Hosts: 218.85.133.109readnovel.com
O1 - Hosts: 218.85.133.109www.3tom.com
O1 - Hosts: 218.85.133.1093tom.com
O1 - Hosts: 218.85.133.109www.126ww.com
O1 - Hosts: 218.85.133.109126ww.com
O1 - Hosts: 218.85.133.109www.fa123.net
O1 - Hosts: 218.85.133.109fa123.net
O1 - Hosts: 218.85.133.109www.kk119.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\重厍庆煳维普兆资恃讯禱\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: WebMiscItem Class - {3CD4296F-6CC3-11D9-B888-000C299AA719} - C:\WINDOWS\system32\WebMisc.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\qinqingqq\Tencent\QQIEHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\assist\asbar.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll