瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 我犯大错误了么,汉字输入怎么不在右下角显示了
水和面 - 2006-7-13 21:04:00
感觉电脑运行超曼,用Hijack this修复了一下,大概齐看着没用的都修复了,之后发现平在右下角显示的汉字输入法不见了,怎么办呢?
水和面 - 2006-7-13 21:07:00
Logfile of HijackThis v1.99.1
Scan saved at 20:45:09, on 2006-7-13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\PROGRA~1\EFFICI~1\ENTERN~2\app\pppoeservice.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
D:\江海燕\pc\HFEE\SVOHOST.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
D:\江海燕\pc\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINNT\system32\socul.dll
F2 - REG:system.ini: UserInit=C:\WINNT\SYSTEM32\Userinit.exe,,"D:\江海燕\pc\HFEE\SVOHOST.EXE" un userinit.exe
O2 - BHO: CPub Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - d:\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: (no name) - {FEDF637B-F631-4583-A210-33CC828D42DB} - (no file)
O3 - Toolbar: 搜狗工具条 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\Program Files\P4P\ToolBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TradeManager] C:\PROGRA~1\Alibaba\TRADEM~1\TradeManager -hideframe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Officep\Office10\OSA.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - C:\Program Files\P4P\dl.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 发送图片到手机 - C:\Program Files\P4P\cx.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到“我的订阅” - C:\Program Files\P4P\rss.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\江海燕\pc\Bitspirit\BitSpirit\bsurl.htm
O9 - Extra button: 我的订阅 - {8755CE6E-0BF7-4441-8751-FB728941B0B4} - C:\Program Files\P4P\rss.dll
O16 - DPF: {276BF72D-CA22-4237-9BCF-593B4E490DE9} (DownLoad Class) - http://img.china.alibaba.com/club/upload/cy2101/onlinesetupimg/atdownload.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {53AF6E02-F18F-4228-AC13-3E79773FBE50} (CMCBooter Object) - http://download.mysee.com/plugin/booter.cab
O16 - DPF: {6F101641-AFFE-4E1F-9BF1-E8976A646549} (AlbumP Control) - http://album.ent.tom.com/scripts/AlbumPProj1.ocx
O16 - DPF: {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} (LiveMediaOcx Control) - http://dl_dir.qq.com/qqtv/QQLiveOcxSetup.exe
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{69CD8F8A-9711-4840-BAA5-3CFFC6AFD77C}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O20 - AppInit_DLLs: C:\WINNT\system32\SoDAHK.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\EFFICI~1\ENTERN~2\app\pppoeservice.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: WinkldUP - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wz\wz.exe (file missing)

这是修复前的,
ddel - 2006-7-13 21:07:00
不知道是不是这个:
右健点任务栏-工具栏-语言栏
ADL - 2006-7-13 21:11:00
1

附件: 293892006713210340.JPG
叶·幽思 - 2006-7-13 21:13:00
查看备份列表,选中后   恢复!
漂亮妹妹1989 - 2006-7-13 21:15:00
如果2楼的方法不奏效,就试试这个:
如图所示

附件: 5908992006713210723.jpg
漂亮妹妹1989 - 2006-7-13 21:17:00
晕S!
ADL你的这张图发了不下100次了吧,利用率也太高了
ADL - 2006-7-13 21:20:00
不用搞了!

改造吧!

将xp输入法指示放在系统托盘.rar 0.2MB
http://free5.ys168.com/?anding _常用软件

附件: 293892006713211222.gif
水和面 - 2006-7-13 21:24:00
修复后的:
Logfile of HijackThis v1.99.1
Scan saved at 21:15:55, on 2006-7-13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\PROGRA~1\EFFICI~1\ENTERN~2\app\pppoeservice.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
D:\江海燕\pc\HFEE\SVOHOST.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\PROGRA~1\EFFICI~1\ENTERN~2\app\EnterNet.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Tencent\QQ\QQ.exe
D:\江海燕\pc\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINNT\system32\socul.dll
F2 - REG:system.ini: UserInit=C:\WINNT\SYSTEM32\Userinit.exe,,"D:\江海燕\pc\HFEE\SVOHOST.EXE" un userinit.exe
O2 - BHO: CPub Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TradeManager] C:\PROGRA~1\Alibaba\TRADEM~1\TradeManager -hideframe
O4 - Global Startup: AutoCAD 启动加速器.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Officep\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{69CD8F8A-9711-4840-BAA5-3CFFC6AFD77C}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{393803B2-3647-40B9-90FB-E8645CBB3E6D}: NameServer = 202.99.96.68,202.99.8.1
O20 - AppInit_DLLs: C:\WINNT\system32\SoDAHK.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\EFFICI~1\ENTERN~2\app\pppoeservice.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: WinkldUP - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wz\wz.exe (file missing)

太复杂了,我想给系统减负,有时间大家指点一下  那些可以删掉 谢谢
漂亮妹妹1989 - 2006-7-13 21:25:00
引用:
【ADL的贴子】不用搞了!

改造吧!

将xp输入法指示放在系统托盘.rar 0.2MB
_常用软件
...........................


知你者莫过俺也哦!
刚才还没人回帖时俺就在想 ADL看了这帖子一定会出这一招
小笨鱼 - 2006-7-13 21:33:00
ADL 提供的软件很好,谢谢。
叶·幽思 - 2006-7-13 21:42:00
这个D:\江海燕\pc\HFEE\SVOHOST.EXE可能有点问题.

地区性 - 2006-7-13 21:47:00
D:\江海燕\pc\HFEE\SVOHOST.EXE

病毒
叶·幽思 - 2006-7-13 21:53:00
如果LZ不认识这个"D:\江海燕\pc\HFEE"就删了吧!

估计不是个什么好...
水和面 - 2006-7-13 21:56:00
呵呵,那是个文件夹加密软件,应该不是病毒,我刚刚把它删掉了
水和面 - 2006-7-13 21:59:00
记得这里有关于Hijackthis的帮助文章,我去找找

又知道地址的请告诉我
叶·幽思 - 2006-7-13 22:01:00
你认为没有必要安装的软件就删了吧!

看清楚了,LZ不应该把什么都装C盘改装别的盘吧!安全模式下移动软件,开机按F8选择安全模式或者Safemode.

C盘最好只装系统文件
zgr稳得起 - 2006-7-13 22:45:00
引用:
【叶·幽思的贴子】你认为没有必要安装的软件就删了吧!

看清楚了,LZ不应该把什么都装C盘改装别的盘吧!安全模式下移动软件,开机按F8选择安全模式或者Safemode.

C盘最好只装系统文件
...........................

首先在启动项里钩选上它,参见下图所示

附件: 6919462006713223740.JPG
水和面 - 2006-10-21 15:23:00
谢谢大家,虽然我的控制面板里显示的和大家说得不一样,但多亏大家的指点才找回了汉字输入  非常感谢
不可再生的缘 - 2006-10-21 15:57:00
看看是不是关闭了高级文字服务。。。。。。。。。。。。。。。。。。。。。

附件: 31406320061021154908.JPG
昨夜西风凋碧树 - 2006-10-21 19:32:00
其实在msconfig中加上ctfmon也行,或者在任务管理器中运行这个也行
1
查看完整版本: 我犯大错误了么,汉字输入怎么不在右下角显示了