以下是扫描的日志
Logfile of HijackThis v1.99.1
Scan saved at 16:25:19, on 2006-9-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\windows\system32\svchost.exe
C:\WINDOWS\system32\iscsiexe.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\Program Files\soft\SYN.exe
C:\windows\system32\Clsmn.exe
C:\WINDOWS\soft\NoARP.exe
C:\windows\system32\internat.exe
C:\windows\system32\svchost.exe
C:\windows\system32\conime.exe
C:\windows\system32\rundll32.exe
E:\netgame\跑跑卡丁车\M01\KartRider.exe
E:\netgame\跑跑卡丁车\M01\NMService.exe
C:\windows\system32\NOTEPAD.EXE
E:\sysbak\hijackthis\HijackThis.exe
O1 - Hosts: www.letscool.cn 127.0.0.1
O4 - HKLM\..\Run: [SENetBar] C:\Program Files\soft\SYN.exe
O4 - HKLM\..\Run: [wxClient] C:\windows\system32\Clsmn.exe
O4 - HKLM\..\Run: [noarp] C:\WINDOWS\soft\NoARP.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\localgame\浩方对战平台\GameClient.exe
O15 - Trusted IP range: 10.0.5.254
O15 - Trusted IP range: 10.0.5.252
O15 - Trusted IP range: 10.0.5.251
O15 - Trusted IP range: 10.0.5.200
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136629685859
O17 - HKLM\System\CCS\Services\Tcpip\..\{80C4DE1F-8B20-448B-AC22-2F804925927D}: NameServer = 10.0.5.250,202.96.69.38
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {83DFBFF3-1455-4538-8036-39D2057787DF} - C:\WINDOWS\gsSecurity1.dll
O20 - Winlogon Notify: DfLogon - C:\windows\SYSTEM32\LogonDll.dll
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe