Logfile of HijackThis v1.99.1
Scan saved at 14:51:04, on 2005-7-6
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
D:\Program Files\EasyShutDownPro\EasyShutDownPro.exe
C:\WINDOWS\System32\ctfmon.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\System32\conime.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
d:\program files\rising\rav\RAVMON.EXE
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\余泽勇\LOCALS~1\Temp\Rar$EX32.318\HijackThis.exe
O1 - Hosts: 202.101.180.185 www.cardsky.net
O1 - Hosts: 66.128.67.16 www.phonehog.com
O1 - Hosts: 61.129.32.9 www.71616.com
O1 - Hosts: 219.140.78.51 free6.kaxiu.com
O1 - Hosts: 210.15.62.21 www.51xia.net
O1 - Hosts: 61.159.224.132 apps.km169.net
O1 - Hosts: 218.30.114.23 www.ip29.com
O1 - Hosts: 219.133.55.103 www.cnc-voip.com
O1 - Hosts: 218.89.0.238 www.v158.com
O1 - Hosts: 66.94.233.46 babelfish.altavista.com
O1 - Hosts: 61.151.239.221 www.gwbn.com
O1 - Hosts: 219.238.233.238 www.ikaka.com
O1 - Hosts: 61.142.238.94 ipseeker.cn
O1 - Hosts: 61.151.255.102 download.pchome.net
O1 - Hosts: 209.66.123.8 www.stayinvisible.com
O1 - Hosts: 210.22.12.246 openext.com
O1 - Hosts: 210.51.170.56 www.xeasy.net
O1 - Hosts: 61.151.248.18 www.rongshuxia.com
O1 - Hosts: 202.96.140.55 bookmark.silversand.net
O1 - Hosts: 219.129.239.5 www.liaoliao.com
O1 - Hosts: 202.106.185.241 finance.sina.com.cn
O1 - Hosts: 204.13.83.253 www.worldlingo.com
O1 - Hosts: 221.0.174.147 it.qingdaonews.com
O1 - Hosts: 69.93.128.57 www.rewardingtraffic.com
O1 - Hosts: 70.84.100.172 www.clickingcrazy.com
O1 - Hosts: 69.93.128.58 www.randomriches.com
O1 - Hosts: 64.246.48.15 www.clicksmatrix.com
O1 - Hosts: 63.126.0.62 www.hitharvester.com
O1 - Hosts: 67.15.52.20 autohitsnow.com
O1 - Hosts: 63.246.150.62 www.moneyandhits.com
O1 - Hosts: 218.108.44.60 www.zjrs.gov.cn
O1 - Hosts: 61.153.3.43 www.zjks.gov.cn
O1 - Hosts: 218.108.43.44 www.zjuyc.com
O1 - Hosts: 211.155.235.163 www.zqa.org.cn
O1 - Hosts: 218.75.120.151 www.zjzk.cn
O1 - Hosts: 210.51.172.25 www.edu-edu.com.cn
O1 - Hosts: 202.99.177.60 www.hengshui.com
O1 - Hosts: 218.201.35.201 www.zjse.com
O1 - Hosts: 61.153.22.161 bbs.52samsung.com
O1 - Hosts: 211.94.190.235 forum.younet.com
O1 - Hosts: 219.153.14.245 club.joyes.com
O1 - Hosts: 222.94.248.10 www.zhuomeng.com
O1 - Hosts: 61.132.112.201 sms.monitors.com.cn
O1 - Hosts: 208.254.3.160 www.tastelife.net
O1 - Hosts: 61.172.244.151 www.sron.net
O1 - Hosts: 218.5.76.168 www.chinahacker.com
O1 - Hosts: 61.156.17.241 zblz.html.533.net
O1 - Hosts: 64.235.246.143 www.fire8.net
O1 - Hosts: 221.195.41.235 www.77169.com
O1 - Hosts: 207.46.19.60 www.microsoft.com
O1 - Hosts: 61.152.93.188 rav.www37.cnidc.cn
O1 - Hosts: 219.238.233.202 www.rising.com.cn
O1 - Hosts: 193.138.204.70 www.worldwide-cash.net
O1 - Hosts: 195.22.10.108 www.clixies.com
O1 - Hosts: 66.98.242.36 leapcash.com
O1 - Hosts: 205.214.88.231 www.uniqpaid.com
O1 - Hosts: 202.107.35.254 map8.banruo.net
O1 - Hosts: 61.153.3.151 www.hzcy.com
O1 - Hosts: 222.36.40.224 www.51120.net
O1 - Hosts: 218.108.246.38 www.hangzhou.gov.cn
O1 - Hosts: 218.108.250.243 www.hzcnc.com
O1 - Hosts: 218.108.248.40 hangzhou.hzcnc.com
O1 - Hosts: 61.241.82.101 www.xpay.cn
O1 - Hosts: 61.130.8.169 www.hzbus.com.cn
O1 - Hosts: 202.107.35.254 map8.banruo.net
O1 - Hosts: 218.108.12.136 www.hzfc.gov.cn
O1 - Hosts: 218.75.110.158 hangzhou.chinese.com
O1 - Hosts: 202.101.163.2 www.hz.zj.cn
O1 - Hosts: 218.108.248.124 www.hangzhou.com.cn
O1 - Hosts: 218.108.246.38 www.hangzhou.gov.cn
O1 - Hosts: 218.108.248.40 hangzhou.hzcnc.com
O1 - Hosts: 61.130.8.133 www.zj315.org
O1 - Hosts: 211.90.216.47 www.verycall.com
O1 - Hosts: 61.241.81.60 www.easy-living.com.cn
O1 - Hosts: 61.129.48.154 www.51job.com
O1 - Hosts: 202.160.251.132 www.csc.globalsources.com
O1 - Hosts: 218.108.45.19 www.hzrc.com
O1 - Hosts: 207.219.111.23 www.jobchn.com
O1 - Hosts: 211.155.231.239 www.zjhr.com
O1 - Hosts: 61.153.3.21 www.zjrc.com
O1 - Hosts: 202.101.165.79 www.hhrc.com.cn
O1 - Hosts: 83.149.90.224 www.b-a-p.net
O1 - Hosts: 202.104.212.57 leadexchanger.*************
O1 - Hosts: 70.84.29.180 www.deepspaceclicks.com
O1 - Hosts: 70.84.29.180 www.earningshare.com
O1 - Hosts: 70.84.29.180 www.rapidcashlinks.com
O1 - Hosts: 66.111.39.170 www.starclicker.com
O1 - Hosts: 211.233.39.247 etc.mediakernel.com
O1 - Hosts: 202.101.165.67 oye.zj.com
O1 - Hosts: 212.227.34.3 www.3500wonbozi.com
O1 - Hosts: 207.46.19.60 www.microsoft.com
O1 - Hosts: 219.129.20.126 www.qqst.com
O1 - Hosts: 219.149.232.197 www.tk4479.com
O1 - Hosts: 219.149.232.200 www.zfvod.com
O1 - Hosts: 202.101.100.249 awenok.com
O1 - Hosts: 221.230.31.11 www.*****.com
O1 - Hosts: 207.46.19.60 www.microsoft.com
O1 - Hosts: 218.107.207.63 www.xscnc.com
O1 - Hosts: 61.235.71.2 www.powervod.com
O1 - Hosts: 218.108.248.179 ehome.ispace.cn
O1 - Hosts: 220.170.79.16 www.mofile.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINDOWS\System32\AlxTB2.dll (file missing)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Clixies Bar - {E39FEDC3-8B80-428f-A2DE-6A09D67704EF} - C:\Program Files\Internet Explorer\PLUGINS\Clixies.dll
O3 - Toolbar: 686search - {D39C15E6-6091-4ed6-9A35-34F52967DAA3} - C:\Program Files\Internet Explorer\PLUGINS\toolbar72364905.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [ESDPro] D:\Program Files\EasyShutDownPro\EasyShutDownPro.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: Customize Menu -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: RoboForm Toolbar -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Clixies Bar - {6C810694-6589-4534-8F82-DE5DCC72C64B} - C:\Program Files\Internet Explorer\PLUGINS\Clixies.dll
O9 - Extra 'Tools' menuitem: Clixies Bar - {6C810694-6589-4534-8F82-DE5DCC72C64B} - C:\Program Files\Internet Explorer\PLUGINS\Clixies.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} -
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 686search - {F9E027F5-BD65-42bc-B3ED-C93E38DF65BF} - C:\Program Files\Internet Explorer\PLUGINS\toolbar72364905.dll
O9 - Extra 'Tools' menuitem: 686search - {F9E027F5-BD65-42bc-B3ED-C93E38DF65BF} - C:\Program Files\Internet Explorer\PLUGINS\toolbar72364905.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {5B61629D-CD18-43D4-BCE0-E07BDE5D927B} (doip Class) - http://www.verycall.com/downnew.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107341996004
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {8819C261-5B61-4628-908C-9BE795EABEC3} (IE Class) - http://www.95599.cn/download/ABC.cab
O16 - DPF: {9F0C93AD-2F03-4825-9009-F4763213D926} - http://www.verycall.com/DaDa.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildAppNonUS.cab
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: winuuple - Unknown owner - C:\WINDOWS\winuuple.exe