麻烦两位大侠帮忙看一下,谢谢撒~~
下面是hijackthis 的log
StartupList report, 2006-2-1, 23:45:14
StartupList version: 1.52
Started from : C:\Documents and Settings\morog_hou\桌面\morog\迅雷\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\wincon.exe
C:\Program Files\racer-henan-cnc\racer.exe
D:\Program Files\TheWorld.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
C:\alc.exe
C:\Documents and Settings\morog_hou\桌面\morog\迅雷\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
KAVPersonal50 = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
helper.dll = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
桌面图标文字自动透明 = D:\Program Files\Wom\WinMem.exe XP
DialGenius = d:\Program Files\DialGenius\ADSL拨号计费精灵\dialgenius.exe
Anti-Virus Update Scheduler V1.39.12R = C:\alc.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
ComDlg32.ocx = regsvr32.exe /s C:\WINDOWS\System32\ComDlg32.ocx
MSCOMCT2.OCX = regsvr32.exe /s C:\WINDOWS\System32\MSCOMCT2.OCX
Msvbvm60.dll = regsvr32.exe /s C:\WINDOWS\System32\Msvbvm60.dll
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper
Objects:
(no name) - C:\WINDOWS\System32\xunleibho_v13.dll - {0005A87D-D626-4B3A-84F9-1D9571695F55}
TeachingHandler - C:\Program Files\Common Files\Collegesoft\Share Components\TPHANDLE.dll - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5}
QQIEHelper - d:\Program Files\Tencent\QQ\QQIEHelper.dll - {54EBD53A-9BC1-480B-966A-843A333CA162}
(no name) - C:\WINDOWS\System32\aclayer.dll - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84}
MMSAssist - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll - {6671A431-5C3D-463d-A7CF-5587F9B7E191}
(no name) - D:\PROGRA~1\FLASHGET\jccatch.dll - {A5366673-E8CA-11D3-9CD9-0090271D075B}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Infofo Bar\infofobar.dll - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D}
YiSou - C:\PROGRA~1\YiSou\yisoub.dll - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB}
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: d:\Program Files\DialGenius\ADSL \dialgenius.exe||d:\Program Files\DialGenius\ADSL \db\||d:\Program Files\DialGenius\ADSL \||d:\Program Files\DialGenius\||C:\DOCUME~1\MOROG_~1\LOCALS~1\Temp\{b32cd5a2-1fca-4003-90c8-fab271d2a34b}\isrt.dll||C:\DOCUME~1\MOROG_~1\LOCALS~1\Temp\{c042838c-5eba-4904-8e30-9abc1e22e0c9}\isrt.dll||C:\DOCUME~1\MOROG_~1\LOCALS~1\Temp\{F78CE609-191F-4FD3-A5CF-DE6F032206CB}\isrt.dll||C:\WINDOWS\System32\suf13.tmp => C:\WINDOWS\System32\ComDlg32.ocx|C:\WINDOWS\System32\suf14.tmp => C:\WINDOWS\System32\MSCOMCT2.OCX|C:\WINDOWS\System32\suf15.tmp => C:\WINDOWS\System32\Msvbvm60.dll|C:\DOCUME~1\MOROG_~1\LOCALS~1\Temp\irsetup.exe||C:\DOCUME~1\MOROG_~1\LOCALS~1\Temp\irsetup.exe
--------------------------------------------------
Enumerating ShellService
ObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\st
object.dll
--------------------------------------------------
End of report, 5,760 bytes
Report generated in 0.100 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only