谢谢楼上指导,请帮忙分析一下。
日志如下:
Logfile of HijackThis v1.99.1
Scan saved at 20:48:04, on 2006-11-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
e:\rising防火墙安装\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
e:\rising防火墙安装\rising\rfw\RfwMain.exe
I:\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe
I:\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
E:\木马杀客安装\木马杀客\mmsk.exe
C:\Documents and Settings\sun\桌面\000\Hijackthis\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit.exe,,rundll32 windll16.dll mymain
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\adobereader安装\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - E:\FLASHGET\FLASHGET\jccatch.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - E:\FLASHGET\FLASHGET\getflash.dll
O4 - HKLM\..\Run: [RfwMain] "E:\rising防火墙安装\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [kav] "I:\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用网际快车下载 - E:\FLASHGET\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\FLASHGET\FLASHGET\jc_all.htm
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - I:\Kaspersky Anti-Virus 6.0\scieplugin.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: 卡巴斯基反病毒6.0 (AVP) - Unknown owner - I:\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\rising防火墙安装\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\rising防火墙安装\rising\rfw\rfwsrv.exe