神不知鬼不觉 - 2006-8-30 9:39:00
以下是进程报告:
Logfile of Kaka v2. 0. 0. 1 Scan Module v2. 0. 0. 0
Scan saved at 09:26:29, on 2006-08-30
Platform: Microsoft Windows 2000 Professional Service Pack 2 (Build 2195)
MSIE: Internet Explorer v6.00 SP1; (6.00.2800.1106)
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINNT\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINNT\system32\services.exe
[lsass.exe]
CommandLine = C:\WINNT\system32\lsass.exe
[rfwsrv.exe]
CommandLine = "c:\program files\rising\rfw\rfwsrv.exe"
[svchost.exe]
CommandLine = C:\WINNT\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
[spoolsv.exe]
CommandLine = C:\WINNT\system32\spoolsv.exe
[svchost.exe]
CommandLine = C:\WINNT\System32\svchost.exe -k netsvcs
[nvsvc32.exe]
CommandLine = C:\WINNT\System32\nvsvc32.exe
[regsvc.exe]
CommandLine = C:\WINNT\system32\regsvc.exe
[MSTask.exe]
CommandLine = C:\WINNT\system32\MSTask.exe
[stisvc.exe]
CommandLine = C:\WINNT\system32\stisvc.exe
[WinMgmt.exe]
CommandLine = C:\WINNT\System32\WBEM\WinMgmt.exe
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[Explorer.EXE]
CommandLine = C:\WINNT\Explorer.EXE
[RfwMain.exe]
CommandLine = -StartUp
[HPWuSchd2.exe]
CommandLine = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
[WebThunder.exe]
CommandLine = "C:\Program Files\Thunder Network\WebThunder\WebThunder.exe"
[RAVTASK.EXE]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RAVMON.EXE]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[RAV.EXE]
CommandLine = "C:\Program Files\Rising\Rav\Rav.exe"
[RsAgent.exe]
CommandLine = "C:\Program Files\Rising\Rav\RsAgent.exe"
[AgentSvr.exe]
CommandLine = C:\WINNT\msagent\AgentSvr.exe -Embedding
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
R3 - Default URLSearchHook is missing
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4613.dll
O2 - BHO: C:\WINNT\system32\NBBHO.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavScanBD] "G:\Tools\ScanBD.exe" /INST
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - Startup: office文件检索.exe =
O9 - Extra Button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O10 - Unknown file in Winsock LSP: C:\WINNT\System32\cdnns.dll
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINNT\Java\classes\dajava.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://www.mydrivers.com/swflash.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINNT\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\System32\msdxm.ocx
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINNT\system\906d6470.dll
O23 - Service: Adobe LM Service (Adobe LM Service) - - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe /com
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
那位大侠救救我 感激万分
秋日里的蓝天 - 2006-8-30 12:51:00
O10 - Unknown file in Winsock LSP: C:\WINNT\System32\cdnns.dll
请下载LSPFix和WinsockXPFix这两个软件,
小软件下载
http://free5.ys168.com/?ufwihgu168
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
重新启动电脑, 进入安全模式。运行LSPFix.exe,删除:
quartz32.dll
说明:
LSPFix这个软件主要用来辅助修复HijackThis扫描发现的O10项。使用时,请关闭所有IE界面和文件夹界面后运行LSPFix。运行后,把要修复的那一个O10项从左边转到右边,点“Finish”即可。修复后重启计算机,如果无法上网,请运行WinsockXPFix,让它修复一下。
请下载1.99.1汉化版
http://free5.ys168.com/?ufwihgu168
运行hijackthis,把下面的选中打上钩,修复
R3 - Default URLSearchHook is missing
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4613.dll
O2 - BHO: C:\WINNT\system32\NBBHO.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINNT\system\906d6470.dll
修复后:下载sreng2,使用智能扫描,将日志保存多分两次粘贴上来,日志不要修改
神不知鬼不觉 - 2006-8-30 15:47:00
【回复“秋日里的蓝天”的帖子
2006-08-30,15:28:16
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 2 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HP Software Update><C:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RavScanBD><"G:\Tools\ScanBD.exe" /INST> []
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<NvCplDaemon><RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> []
==================================
启动文件夹
[office文件检索]
<C:\Documents and Settings\DT\「开始」菜单\程序\启动\office文件检索.exe><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[MyIEHelper Class]
{16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4613.dll, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\System32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
神不知鬼不觉 - 2006-8-30 15:47:00
正在运行的进程
[PID: 108][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.2901>
[PID: 136][\??\C:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.2581>
[PID: 156][\??\C:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6898>
[PID: 184][C:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.2780>
[C:\WINNT\system32\dmserver.dll] <VERITAS Software Corp.><2195.2778.297.3>
[PID: 196][C:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.6902>
[PID: 332][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 372][C:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0029>
[PID: 476][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3315.2846>
[C:\WINNT\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 428][C:\Program Files\Windows NT\Accessories\WORDPAD.EXE] <Microsoft Corporation><5.00.2170.1>
[PID: 440][F:\新建文件夹\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINNT\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP Error. [winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [notepad.exe %1]
.VBS Error. [wscript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
神不知鬼不觉 - 2006-8-30 15:52:00
【回复“神不知鬼不觉”的帖子】
我没找到quartz32.dll 这个后面的都是照你说的做的
重起那个该死的主页还在那笑呢
秋日里的蓝天 - 2006-8-30 20:16:00
C:\WINNT\System32\cdnns.dll
请下载LSPFix和WinsockXPFix这两个软件,
重新启动电脑, 进入安全模式。运行LSPFix.exe,删除:
cdnns.dll
说明:
LSPFix这个软件主要用来辅助修复HijackThis扫描发现的O10项。使用时,请关闭所有IE界面和文件夹界面后运行LSPFix。运行后,把要修复的那一个O10项从左边转到右边,点“Finish”即可。修复后重启计算机,如果无法上网,请运行WinsockXPFix,让它修复一下。
应该是这个,上面是我搞错了,实在抱歉
© 2000 - 2026 Rising Corp. Ltd.