http://www.wxku.com/mms/chanels/chanel_1/index.html?uid=178&luid=92&upa=&upb=&advno=chanel_1N
http://u.u8u.com/zt/4/?c=475&a=14474&b=0&d=0&e=
Logfile of HijackThis v1.99.1
Scan saved at 20:00:27, on 2006-9-20
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\瑞星文件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\瑞星文件\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\瑞星文件\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\瑞星文件\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\瑞星文件\Rising\Rav\Ravmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ossvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\ieaus.exe
D:\腾讯QQ安装文件\腾讯2006\新建文件夹\QQ.exe
D:\腾讯QQ安装文件\腾讯2006\新建文件夹\TIMPlatform.exe
C:\Program Files\傲游Maxthon 1.5.6 build 42\Maxthon\Maxthon.exe
E:\HijackThis V1.99.1\HijackThis V1.99.1汉化版\HijackThis.exe
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - E:\迅雷5 ( V 5.4.0.226)\ComDlls\XunLeiBHO_002.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] ; C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SKYNET Personal FireWall] ; C:\Program Files\SkyNet\FireWall\PFW.exe
O4 - HKLM\..\Run: [poco] ; E:\poco 2005 文件\poco\Poco2004.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Mysee Alert] "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\瑞星文件\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &使用迅雷下载 - E:\迅雷5 ( V 5.4.0.226)\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\迅雷5 ( V 5.4.0.226)\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\比特精灵\BitSpirit\bsurl.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - E:\迅雷5 ( V 5.4.0.226)\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - E:\迅雷5 ( V 5.4.0.226)\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\腾讯QQ安装文件\腾讯2006\新建文件夹\QQ.EXE (file missing)
O16 - DPF: {05DA48C8-AECE-4CF7-BE58-7D52883A7FAD} (ClearAX Control) - http://pcclear.co.kr/app/Active/ClearAX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} - http://www.ycdy.com/PSWEdit.CAB
O16 - DPF: {243C3672-9526-40AA-BE22-988F92CFA591} (Nclean_activex Control) - http://nclean.co.kr/install/nclean.cab
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} (WEBChatRoomOCX Control) - http://www.51uc.com/cab/WEBChatRoom_1_46.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124536791572
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124536719290
O16 - DPF: {733EC486-134E-450B-8894-16426CE2DFB8} (ecleanerActX Control) - http://www.ecleaner.co.kr/pc/ecleaner.cab
O16 - DPF: {A8497454-CB7D-4877-A633-3932BF776A6A} (Webinstall Control) - http://211.214.161.198/downloads/hana/hana150/Webinstall.cab
O16 - DPF: {E36BEEF0-E18D-4FCB-9AD4-F9A643232027} (spykeepax Control) - http://down.spykeep.com/down/spykeepatx.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08DB4FBD-F27C-43BD-B13D-38181F725253}: NameServer = 202.98.0.68 202.106.196.115
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Open Search Keyword Services (ossvc) - Brainnames - C:\WINDOWS\system32\ossvc.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\瑞星文件\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\瑞星文件\Rising\Rav\Ravmond.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Ineterner Explorer Add Update Services (updatecheck) - Brainnames - C:\WINDOWS\system32\ieaus.exe
O23 - Service: UsbScaner Service (UsbScaner) - Unknown owner - E:\cctv网络直播插件\uusee\mp4\usbscaner.exe (file missing)