.Rdk269
在进程中出现陌生的进程:
00228_netapi.exe没有办法中止.结束进程后又自动生成.在ewido软件中显示启动项有两条:
应用程序 位置 路径
exe File\SystemIni explorer.exe 00228_netapi.exe
Ms Java for Windows NT Reg\HKLM\RunServices 00228_netapi.exe
搜索到用killbox强行删除;
或扫个日志看看
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 16:35:35, 日期 2006-8-23
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
E:\EWIDO3\EWIDO3.5\ewidoguard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
本文来自 www.dngz.net
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\service.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\dns.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
E:\CMailServer\CMailServer.exe
C:\WINNT\system32\internat.exe
C:\WINNT\System32\svchost.exe
E:\EWIDO3\EWIDO3.5\securitysuite.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\mdm.exe
C:\WINNT\explorer.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.516\tightvnc-1.2.9-setup.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\INS7E.tmp
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.703\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,00228_netapi.exe 本文来自(www.dngz.net)
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll (file missing)
O3 - IE工具栏增项: (no name) - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - (no file)
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O4 - 启动项HKLM\\Run: [CMailServer] E:\CMailServer\CMailServer.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - 启动项HKCU\\RunServices: [Ms Java for Windows NT] 00228_netapi.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\AddEmotion.htm ;
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\SendMMS.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\wshcon32.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\wshcon32.dll
O11 - Options group: [!IESearch] !IESearch
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - “受信任的站点”中添加项: http://www.126.com
O15 - “受信任的站点”中添加项: http://www.163.com
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://www.0577.tv/plugin/PowerPlr.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趋势科技在线扫毒程序) - http://www.trendmicro.com.cn/housecall/xscan53.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11A7702C-DA31-48D9-A28A-A0CBD696099A}: NameServer = 61.153.177.197,61.153.177.198
欢迎来到(www.dngz.net)
O17 - HKLM\System\CCS\Services\Tcpip\..\{8DC2A13A-0FD1-4CC4-A730-7807CD326295}: NameServer = 61.153.177.197,61.153.177.198
O17 - HKLM\System\CS1\Services\Tcpip\..\{11A7702C-DA31-48D9-A28A-A0CBD696099A}: NameServer = 61.153.177.197,61.153.177.198
O17 - HKLM\System\CS2\Services\Tcpip\..\{11A7702C-DA31-48D9-A28A-A0CBD696099A}: NameServer = 61.153.177.197,61.153.177.198
O21 - SSODL: SysTray - {E61B5E20-DE35-11CF-9C87-1579005127ED} - C:\WINNT\system32\msc.cpl (file missing)
O21 - SSODL: msp.cpl - {E21B5E20-DE35-11CF-9C87-157900512701} - C:\WINNT\system32\msp.cpl
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: ewido security suite guard - ewido networks - E:\EWIDO3\EWIDO3.5\ewidoguard.exe
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing) dngz.net您的电脑医生
O23 - NT 服务: 卡巴斯基防病毒服务 (klfsblogic) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing)
O23 - NT 服务: Windows Network Security Management Service (nsms) - Unknown owner - C:\WINNT\system32\17.tmp (file missing)
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - NT 服务: Remote File Copy (网络文件拷贝) - Unknown owner - C:\WINNT\service.exe
C:\WINNT\service.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.516\tightvnc-1.2.9-setup.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\INS7E.tmp
以上进程须结束,问题所在;清空所有临时文件夹,关闭系统还原(包括其服务);
修复以下:
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,00228_netapi.exe
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll (file missing)
,
O3 - IE工具栏增项: (no name) - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - (no file)
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O4 - 启动项HKLM\\Run: [CMailServer] E:\CMailServer\CMailServer.exe
O4 - 启动项HKCU\\RunServices: [Ms Java for Windows NT] 00228_netapi.exe
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\wshcon32.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\wshcon32.dll
O11 - Options group: [!IESearch] !IESearch
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - NT 服务: Remote File Copy (网络文件拷贝) - Unknown owner - C:\WINNT\service.exe
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing)
O23 - NT 服务: 卡巴斯基防病毒服务 (klfsblogic) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing) ,
O23 - NT 服务: Windows Network Security Management Service (nsms) - Unknown owner - C:\WINNT\system32\17.tmp (file missing)
卡巴服务有问题,重装卡巴6
能帮我看看吗?正在等
不好办,还是重装吧朋友
010项请用LSPFix软件修复!
我是新手,学习一下!
我刚加入多多关照
ddddddddddd
wshcon32.dll请问是什么程序啊?