斑竹、各位大哥大姐:这两天我的网络连接连图标都不见了;网络邻居拒绝操作;QQ关闭对话框时提示“库文件未注册”;控制面板的用户帐户无法进入,我用hijackthis和kaka助手扫描,结果不一样,kaka助手中扫描到的问题比较多,但是hijackthis没有显示,而且hijackthis中的018项无法修复,再次扫描的时候仍然存在;用优化大师扫描发现1027 Trjan.huigezi.e\1029 SubSARI的提示。这是文件丢失还是灰鸽子造成的?
拜托赐教!
这是KAKA日志
Logfile of Kaka v2. 0. 0. 5 Scan Module v2. 0. 0. 1
Scan saved at 21:26:19, on 2006-01-07
Platform: Microsoft Windows XP Professional Service Pack 1 (Build 2600)
MSIE: Internet Explorer v6.00 SP1; (6.00.2800.1106 (xpsp1.020828-1920))
Running processes:
[SMSS.EXE]
CommandLine =
[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\CCenter.exe"
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\Ravmond.exe"
[rfwsrv.exe]
CommandLine = "f:\program files\rising\rfw\rfwsrv.exe"
[RavStub.exe]
CommandLine = F:\ruixing\Rising\Rising\Rav\RavStub.exe /RAVMOND
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc
[wdfmgr.exe]
CommandLine = C:\WINDOWS\System32\wdfmgr.exe
[Explorer.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[RfwMain.exe]
CommandLine = -StartUp
[RavTask.exe]
CommandLine = "F:\RUIXING\RISING\RISING\RAV\RAVTASK.EXE" -SYSTEM
[CTFMON.EXE]
CommandLine = "C:\WINDOWS\System32\ctfmon.exe"
[RavMon.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\Ravmon.exe" -SYSTEM
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "F:\电脑清理\KAKA助手\KkScan.exe"
O1 - Hosts: 127.0.0.1 localhost
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKLM\..\Run: [RavTask] "F:\ruixing\Rising\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "F:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\什么都有\QQ2005\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\什么都有\QQ2005\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\什么都有\QQ2005\qq\SendMMS.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes -
file://C:\WINDOWS\Java\classes\dajava.cab
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Microsoft MessangerServer (Microsoft MessangerServer) - - C:\WINDOWS\Microsoft MessangerServer.exe
O23 - Service: nServer (nServer) - - C:\WINDOWS\sgester.bat
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "F:\ruixing\Rising\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "F:\ruixing\Rising\Rising\Rav\Ravmond.exe"
HijackThis_815汉化版扫描日志 V1.99.1
保存于 21:25:57, 日期 2006-1-7
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
F:\ruixing\Rising\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
F:\ruixing\Rising\Rising\Rav\Ravmond.exe
f:\program files\rising\rfw\rfwsrv.exe
F:\ruixing\Rising\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
f:\program files\rising\rfw\RfwMain.exe
F:\ruixing\Rising\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
F:\ruixing\Rising\Rising\Rav\Ravmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\电脑清理\hijackthis\HijackThis1991汉化版\HijackThis1991zww.exe
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - 启动项HKLM\\Run: [RavTask] "F:\ruixing\Rising\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "F:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - F:\什么都有\QQ2005\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - F:\什么都有\QQ2005\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - F:\什么都有\QQ2005\qq\SendMMS.htm
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - F:\ruixing\Rising\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - F:\ruixing\Rising\Rising\Rav\Ravmond.exe