瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 防火墙显示灰鸽子,按日志上没可疑项啊【求助】

123   2  /  3  页   跳转

防火墙显示灰鸽子,按日志上没可疑项啊【求助】

老大请详细把操作步骤贴出来,我是菜鸟看了半天帖子没弄懂,

谢谢了。
gototop
 

[TV Stream Source]
  {ADB6CBDA-2792-4C09-B269-7C1A36251DAD} <e:\Program Files\GAOV\XTV\Chaos.ax, Gaov>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <E:\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[Messenger Object]
  {B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[Kingsoft DUBA OnlineScan]
  {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} <C:\WINDOWS\system32\Kingsoft\ONLINE~1\KAVClean.OCX, kingsoft>
[AUDIO__MID Moniker Class]
  {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[FlashFXP Helper for Internet Explorer]
  {E5A1691B-D188-4419-AD02-90002030B8EE} <C:\PROGRA~1\FlashFXP\IEFlash.dll, IniCom Networks, Inc.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[好看123上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <D:\MagicSet\HaokanBar.dll, 超级兔子>
[&使用迅雷下载]
  <d:\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <d:\Thunder\getallurl.htm, N/A>
[Google 搜索(&G)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <C:\QQ2005\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <E:\KuGoo3\KuGoo3DownX.htm, N/A>
[使用网络传送带下载]
  <C:\Documents and Settings\shanghalei\桌面\NetTransport\NXAddLink.html, N/A>
[使用网络传送带下载全部链接]
  <C:\Documents and Settings\shanghalei\桌面\NetTransport\NXAddList.html, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[保存: 完整网页...]
  <C:\Program Files\CyberArticle\script\Save.htm, N/A>
[保存: 更多保存内容...]
  <C:\Program Files\CyberArticle\script\SaveAuto.htm, N/A>
[反向链接]
  <res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A>
[添加到QQ表情]
  <C:\QQ2005\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\qq\SendMMS.htm, N/A>
[类似网页]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A>
[缓存的网页快照]
  <res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A>

==================================
正在运行的进程
[PID: 588][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 736][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 760][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 808][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 820][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 976][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 1060][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 1180][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1196][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 1224][C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe]  <><0, 20, 0, 3000>
[PID: 1300][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 1412][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 1432][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 6>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ScanNet.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1532][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 25>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 10>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 19>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [c:\program files\rising\rfw\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1692][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 2024][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\mp3infp.dll]  <win32lab.com><2.50.5.0>
    [E:\KV2006\KVBHO.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [E:\KV2006\KVAddrDb.dll]  <Jiangmin Co.Ltd><9, 0, 0, 1018>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [E:\KV2006\KvShell.dll]  <Jiangmin Co.Ltd><9, 0, 5, 830>
    [E:\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 913>
gototop
 

[E:\KV2006\lang\Kvxp0804.lng]  <N/A><N/A>
    [E:\KV2006\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.0.2003051500>
[PID: 248][C:\WINDOWS\system32\crypserv.exe]  <Kenonic Controls Ltd.><5.4.0>
[PID: 328][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 40>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 516][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1980][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 1232][C:\WINDOWS\SYSTEM32\SVCH0ST.EXE]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
[PID: 1264][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2149 (xpsp_sp2_rc2.040610-1520)>
    [c:\program files\google\googletoolbar2.dll]  <Google Inc.><3, 0, 128, 1>
    [D:\MagicSet\HaokanBar.dll]  <超级兔子><1.0.6.8>
    [C:\WINDOWS\system32\kakatool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 3>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.0.2003051500>
    [E:\KV2006\KVBHO.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [E:\KV2006\KVAddrDb.dll]  <Jiangmin Co.Ltd><9, 0, 0, 1018>
    [e:\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [E:\KV2006\KvShell.dll]  <Jiangmin Co.Ltd><9, 0, 5, 830>
    [E:\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 913>
    [E:\KV2006\lang\Kvxp0804.lng]  <N/A><N/A>
    [E:\KV2006\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\JPWB.IME]  <常诚研制><4.00.950>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 2584][D:\Winamp2\Winamp.exe]  <Nullsoft><5,1,1,168>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_cdda.dll]  <N/A><N/A>
    [D:\Winamp2\pxsdkpls.dll]  <Sonic Solutions><1.06.14h>
    [D:\Winamp2\PX.dll]  <Sonic Solutions><1.06.14h>
    [C:\WINDOWS\system32\PXMAS.DLL]  <Sonic Solutions><1.06.14h>
    [C:\WINDOWS\system32\PXWAVE.DLL]  <Sonic Solutions><1.06.14h>
    [C:\WINDOWS\system32\PXDRV.DLL]  <Sonic Solutions><1.00.47a>
    [D:\Winamp2\Plugins\in_CDReader.dll]  <N/A><N/A>
    [D:\Winamp2\wnaspi32.dll]  <Ahead Software AG
im Stoeckmaedle 18
76307 Karlsbad, Germany
Fax: ++49-7248-911-888
e-mail: info@nero.com><2.0.1.74>
    [D:\Winamp2\Plugins\in_ape.dll]  <Matthew T. Ashland><3.99>
    [D:\Winamp2\Plugins\in_cue.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_asfs.dll]  <AudioSoft><1.30>
    [D:\Winamp2\Plugins\in_midi.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\read_file.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_mod.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_mp3.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_mp4.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_linein.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_wave.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_wm.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_wm_a.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_flac.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_vorbis.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_tara.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_vqf.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_mpg123sse.dll]  <Beleaf Software Studio><2, 0, 0, 0>
    [D:\Winamp2\Plugins\in_mpc.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_dshow.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_nsv.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\in_flic.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_lame.dll]  <MUKOLI><1.6.3>
    [D:\Winamp2\Plugins\out_null.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_xf.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\Out_AAC.dll]  <N/A><1, 5, 0, 0>
    [D:\Winamp2\id3lib.dll]  <http://www.id3lib.org/><3.8.3>
    [D:\Winamp2\Plugins\out_ds.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_ds_ssrc.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_wave.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_wave_ssrc.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_disk.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_filewrite.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\out_sqr.dll]  <SqrSoft?><1, 7, 5, 0>
    [D:\Winamp2\Plugins\out_asio(dll)sse.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\dsp_omxw.dll]  <N/A><N/A>
    [D:\Winamp2\dsp_omxe.dll]  <Octiv Inc.><1, 5, 0, 0>
    [D:\Winamp2\Plugins\gen_ff.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_ml.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\ml_gusb_us.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\ml_wire.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_MiniLyrics.dll]  <N/A><N/A>
    [C:\Program Files\MiniLyrics\MiniLyrics.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_saveas.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_find_on_disk.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_b4s2m3u.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_toaster.dll]  <Shane Hird><0, 7, 4, 0>
    [D:\Winamp2\Plugins\gen_tips.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_tray.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_hotkeys.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_jumpex.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_timerestore.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_tfp.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_pyqq.dll]  <N/A><N/A>
    [D:\Winamp2\Plugins\gen_cue.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 3264][d:\Thunder\Thunder.exe]  <Thunder Networking Technologies,LTD><5.0.6.98>
    [d:\Thunder\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [d:\Thunder\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [d:\Thunder\log4cplus.dll]  <><1, 0, 2, 1>
    [d:\Thunder\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [d:\Thunder\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 73>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [d:\Thunder\iThunder.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 30>
    [d:\Thunder\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 4>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 3900][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 3940][C:\DOCUME~1\SHANGH~1\LOCALS~1\Temp\Rar$EX00.734\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\SYSTEM32\ntdll32.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [E:\KV2006\KVSock_3.dll]  <Jiangmin Co. Ltd.><1, 2, 24, 51208>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  Error. [C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
Jiangmin-MSAFD Tcpip [TCP/IP]
    E:\KV2006\KVSock_3.dll(Jiangmin Co. Ltd., A winsock layer)
Jiangmin-MSAFD Tcpip [UDP/IP]
    E:\KV2006\KVSock_3.dll(Jiangmin Co. Ltd., A winsock layer)
Jiangmin-RSVP UDP Service Provider
    E:\KV2006\KVSock_3.dll(Jiangmin Co. Ltd., A winsock layer)
Jiangmin-RSVP TCP Service Provider
    E:\KV2006\KVSock_3.dll(Jiangmin Co. Ltd., A winsock layer)
Jiangmin_Filter
    E:\KV2006\KVSock_3.dll(Jiangmin Co. Ltd., A winsock layer)

==================================
gototop
 

本来想到置顶贴中的版主的网络硬盘去下System Repair Engineer的,可是进去后点不开文件目录,这个问题昨天在新浪邮箱里也这样的点那未读邮件,收件箱等按钮也点不开,IE下栏提示javascript:parent.mlkq("14263");什么的,如果可能,帮俺也解决下这个问题,郁闷
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      11:43:58, 日期 2005-12-22
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\KaKaToolBar\KkScan.exe
d:\WinRAR\WinRAR.exe
C:\DOCUME~1\longzo\LOCALS~1\Temp\Rar$EX00.469\HijackThis1991zww.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\FlashGet\jccatch.dll
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\金山快译\IEBand.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FlashGet\fgiebar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - 浏览器额外的按钮: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - D:\金鹕山酱词拾霸診\XDictExB.dll (file missing)
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C37FBD87-3AA7-4640-9A8D-19AFC10B15B2} (Netease Chat Control) - http://room.chat.163.com/xchat/chat.cab
O16 - DPF: {DE3496D2-AFB9-47EB-A8C2-C3B330222513} (PhotoUpload Control) - http://www.photo.163.com/PhotoUpload.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F48F582-7760-4166-BE88-D9284C3D2E63}: NameServer = 202.99.166.4 202.99.160.68
O18 - 列举现有的协议: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - D:\金鹕山酱词拾霸診\XDictExB.dll (file missing)
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
gototop
 

EXE Error. [C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %*]
从日志中上一项中可以看到
C:\WINDOWS\SYSTEM32\SVCH0ST.EXE 已经关连了EXE文件

为了方便解决问题
建议楼主下载SysInfoCollect导出“文件关连”日志
gototop
 

System Information Collect Tool - Designed By Smallfrogs


20051222-12:02
Windows XP Service Pack 2, v.2622
Internet Explorer: 6.0.2900.2149


*****************************************************************
      File association information
*****************************************************************
------------------------------------------------------------
0:HKEY_CLASSES_ROOT\.exe
------------------------------------------------------------
<DEFAULT> = exefile, 正常!
------------------------------------------------------------
1:HKEY_CLASSES_ROOT\exefile\shell\open\command
------------------------------------------------------------
<DEFAULT> = C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %*, 不正常!正常值:"%1" %*。请使用RegFix修复关联!软件可以到 http://www.KZTechs.com 下载。
------------------------------------------------------------
2:HKEY_CLASSES_ROOT\exefile\shell\runas\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
3:HKEY_CLASSES_ROOT\.txt
------------------------------------------------------------
<DEFAULT> = txtfile, 正常!
------------------------------------------------------------
4:HKEY_CLASSES_ROOT\txtfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = %SystemRoot%\system32\NOTEPAD.EXE %1, 正常!
------------------------------------------------------------
5:HKEY_CLASSES_ROOT\.reg
------------------------------------------------------------
<DEFAULT> = regfile, 正常!
------------------------------------------------------------
6:HKEY_CLASSES_ROOT\regfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = regedit.exe "%1", 正常!
------------------------------------------------------------
7:HKEY_CLASSES_ROOT\.bat
------------------------------------------------------------
<DEFAULT> = batfile, 正常!
------------------------------------------------------------
8:HKEY_CLASSES_ROOT\batfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
9:HKEY_CLASSES_ROOT\.com
------------------------------------------------------------
<DEFAULT> = comfile, 正常!
------------------------------------------------------------
10:HKEY_CLASSES_ROOT\comfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
11:HKEY_CLASSES_ROOT\.scr
------------------------------------------------------------
<DEFAULT> = scrfile, 正常!
------------------------------------------------------------
12:HKEY_CLASSES_ROOT\scrfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" /S, 正常!
------------------------------------------------------------
13:HKEY_CLASSES_ROOT\.pif
------------------------------------------------------------
<DEFAULT> = piffile, 正常!
------------------------------------------------------------
14:HKEY_CLASSES_ROOT\piffile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
gototop
 

解决方案如下:

首先建议如下操作前先备份一下那个SVCH0ST.EXE 病毒文件<以防万一>

1,结束SVCH0ST.EXE<注意0是数字0> 进程

2,开始--运行,输入regedit,进入注册表
修改HKEY_CLASSES_ROOT\exefile\shell\open\command
---------------------------------------------
<DEFAULT> = C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %为"%1" %*
然后按F5刷新一下,查看是否修改成功

3,删除
C:\WINDOWS\SYSTEM32\SVCH0ST.EXE <注意0是数字0>
C:\WINDOWS\system32\SeedServ.exe
C:\WINDOWS\system32\big5_gb2312.exe
C:\WINDOWS\system32\ServeHost.exe
C:\WINDOWS\system32.exe

4,搜索system32key.dll,system32_hook.dll,system32.dll
找到后全部删除

============
若上述方法不行
请参考:
1,结束SVCH0ST.EXE<注意0是数字0> 进程

2,将regedit.exe改为regedit.com
开始--运行--输入regedit.com
进入注册表
修改HKEY_CLASSES_ROOT\exefile\shell\open\command
---------------------------------------------
<DEFAULT> = C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %为"%1" %*
然后按F5刷新一下,查看是否修改成功

3,删除
C:\WINDOWS\SYSTEM32\SVCH0ST.EXE <注意0是数字0>
C:\WINDOWS\system32\SeedServ.exe
C:\WINDOWS\system32\big5_gb2312.exe
C:\WINDOWS\system32\ServeHost.exe
C:\WINDOWS\system32.exe

4,搜索system32key.dll,system32_hook.dll,system32.dll
找到后全部删除

5,操作成功后将regedit.com改为regedit.exe
gototop
 

<DEFAULT> = C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %*, 不正常!正常值:"%1" %*。请使用RegFix修复关联!软件可以到 http://www.KZTechs.com 下载。

我按它说的下载修复了~然后按你说的删了SVCHOST.
gototop
 

引用:
【冷水银光的贴子】<DEFAULT> = C:\WINDOWS\SYSTEM32\SVCH0ST.EXE %1 %*, 不正常!正常值:"%1" %*。请使用RegFix修复关联!软件可以到 http://www.KZTechs.com 下载。

我按它说的下载修复了~然后按你说的删了SVCHOST.
...........................


现在问题解决没有啊
用工具修复可能不成功
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT