可以上QQ,打不开网页,瑞星2008连不上服务器,无法升级,后附HijackThis扫描日志!请高手帮忙解决!
日志文件 Trend Micro HijackThis v 2.0.2
日志保存时间: 8:01:05,2008-03-29
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
IE版本: Internet Explorer v6.00 SP1 (6.00.2800.1106)
启动模式: 正常
正在运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\PROGRAM FILES\RISING\RAV\ravmond.exe
D:\Program Files\Rising\Rfw\rfwsrv.exe
D:\Program Files\Rising\Rfw\rfwProxy.exe
D:\Program Files\Rising\Rfw\rfwstub.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
D:\CCProxy\CCProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nhsrvice.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\llssrv.exe
D:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
D:\Program Files\Rising\Rav\CCenter.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ServerNT.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\system32\AlertService.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
D:\Program Files\Rising\Rfw\RfwMain.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\360safe\safemon\360Tray.exe
C:\Program Files\Rising\AntiSpyware\runiep.exe
D:\DBMailPro\aamailsvr.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\WinPoET Broadband Connection\winpppoverethernet.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\UfSvrMgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.609\HijackThis.exe
O2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\Thunder Network\WebThunder\WebThunderBHO_Now.dll
O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\Program Files\360safe\safemon\safemon.dll
O3 - IE 工具栏: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [360Safetray] D:\Program Files\360safe\safemon\360Tray.exe /start
O4 - HKLM\..\Run: [runeip] "C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup
O4 - HKLM\..\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [AAMailServer] D:\DBMailPro\aamailsvr.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband Connection\winpppoverethernet.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\.DEFAULT\..\Run: [Internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Intec Service Drivers] cdservice.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Server Daemon Host Manager] C:\WINNT\system32\inetsrv\sdhost.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Corporation Svchost Service] mswsc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Intec Service Drivers] cdservice.exe (User 'Default user')
O4 - Startup: RsAutorunsDisabled
O4 - Global Startup: U8管理服务.lnk = C:\WINNT\system32\UfSvrMgr.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - 扩展右键菜单项: 使用WEB迅雷下载 - D:\Thunder Network\WebThunder\GetUrl.htm
O8 - 扩展右键菜单项: 使用WEB迅雷下载全部链接 - D:\Thunder Network\WebThunder\GetAllUrl.htm
O8 - 扩展右键菜单项: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - 扩展右键菜单项: 设为 Messenger Live 头像 - \SetMSNDP.htm
O9 - 额外的按钮: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe(文件不存在)
O9 - 额外的“工具”菜单项目: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe(文件不存在)
O9 - 额外的按钮: 启动WEB迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com(文件不存在)
O9 - 额外的“工具”菜单项目: 启动WEB迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com(文件不存在)
O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) -
O16 - DPF: {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} (Tencent Safety Online Base Module) - http://safe.qq.com/cgi-bin/tso/TSOBase.ocx
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) -
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (PasswordEditCtrl Class) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {E847C78C-C210-4195-8799-FBF3BF89797D} (金山毒霸在线产品升级) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{33A6AD90-93B4-41C2-939B-FBE3C1CE3F2C}: NameServer = 192.168.21.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{902DCC1D-2C3E-4A49-BF28-35A6621B6CD5}: NameServer = 219.150.32.132 219.146.0.130
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: Automatic Updatess - Unknown owner - C:\WINNT\L_Server2.03.exe(文件不存在)
O23 - NT 服务: CCProxy - Unknown owner - D:\CCProxy\CCProxy.exe