以下是我朋友扫描的日志,请高手帮忙看一下,该如何解决?
HijackThis_815汉化版扫描日志 V1.99.1
保存于 17:36:26, 日期 2005-11-25
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
E:\及时通\MRUpdate\AutoClient.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\SYSTEM32\MRCARD.EXE
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\conime.exe
E:\及时通\MRICU.exe
E:\工具包\迅雷下载\Thunder.exe
D:\WINDOWS\System32\svchost.exe
E:\工具包\qq\QQ.exe
E:\工具包\qq\TIMPlatform.exe
E:\工具包\Office2003\OFFICE11\WINWORD.EXE
E:\工具包\Winamp\Winamp.exe
D:\WINDOWS\system32\wuauclt.exe
E:\工具包\下载文件\4842302005817230232\HijackThis1991zww.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: (no name) - {6BDE1669-B490-48E3-B668-456314F2D6C3} - (no file)
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - D:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - E:\工具包\FlashFXP\IEFlash.dll
O2 - BHO: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - E:\工具包\超级魔法兔子\HaokanBar.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - E:\工具包\金山快译\IEBand.dll
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - E:\工具包\超级魔法兔子\HaokanBar.dll
O3 - IE工具栏增项: 东方卫士 - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} - D:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - 启动项HKLM\\Run: [IMSCMig] D:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [MRUpdateClient] E:\及时通\MRUpdate\AutoClient.exe
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] E:\工具包\超级魔~1\SRRest.exe /autosave
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [KAVPersonal50] "E:\工具包\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\Run: [Thunder] "E:\工具包\迅雷下载\ThunderShell.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MrCard] D:\WINDOWS\SYSTEM32\MRCARD.EXE
O4 - HKCU\..\Run: [a6a9b3af6335addb5cc4fdaedd68d786] "E:\工具包\下载文件\d120dbpfw.821.0.exe" -t 821.0
O4 - Global Startup: 桌面传媒.lnk = ?
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - E:\工具包\迅雷下载\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - E:\工具包\迅雷下载\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\工具包\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\工具包\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\工具包\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\工具包\qq\SendMMS.htm
O9 - 浏览器额外的按钮: (no name) - {35980F6E-A137-4E50-953D-813BB8556899} - (no file)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\WINDOWS\System32\shdocvw.dll
O11 - Options group: [!CNS] 网络实名
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O15 - “受信任的站点”中添加项: http://oaserver2.dg.cnpc.com.cn
O16 - DPF: SnowCity - http://www.mychinamap.com/webgis/SnowCity.CAB
O16 - DPF: {042C4C55-4FB7-45E2-B956-773A8D3FC212} (WebPostil Control) - http://oaserver2.dg.cnpc.com.cn/WebPostil.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B851E8B9-CC88-479C-8F58-F1C9E21E3E7B} (Handwriting Remark Control) - http://oaserver2.dg.cnpc.com.cn/HRemark.ocx
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} - http://download.ourgame.com/IEDown2.cab
O16 - DPF: {FD44D72B-E01D-435C-8CAB-EF68843C2A12} (Ming-WebReport Viewer) - http://10.76.1.24:9080/reports/Viewer/MRViewer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{707249A7-AB98-4AAE-92AA-DDE6568D3B5C}: NameServer = 10.76.1.1,0.0.0.0
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINDOWS\system32\mbprot.dll
O20 - Winlogon Notify: NavLogon - D:\WINDOWS\system32\NavLogon.dll
O23 - NT 服务: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: DefWatch - Unknown owner - E:\SYMANT~1\DefWatch.exe (file missing)
O23 - NT 服务: kavsvc - Kaspersky Lab - E:\工具包\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Unknown owner - E:\SYMANT~1\Rtvscan.exe (file missing)
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - D:\WINDOWS\system32\OOD2000.exe