12   1  /  2  页   跳转

用兔子后不能上网了!求助!

用兔子后不能上网了!求助!

我今天中午下载了兔子,下午安装,并清理修复了一下系统,删了几个不用的软件,重启后电脑就上不了网了,用控制面班卸载兔子,依然如故。这是我用卡卡助手扫描的日志,拜托大家帮我诊断一下,谢谢了!
ogfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 14:56:58, on 2006-07-14
Platform: Microsoft Windows 2000 Professional Service Pack 4 (Build 2195)
MSIE: Internet Explorer v6.00 SP1;Q832894;Q867801;Q823353;Q833989; (6.00.2800.1106)


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINNT\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINNT\system32\services.exe

[lsass.exe]
CommandLine = C:\WINNT\system32\lsass.exe

[Ati2evxx.exe]
CommandLine = C:\WINNT\System32\Ati2evxx.exe

[CCENTER.EXE]
CommandLine = "D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"

[Ravmond.exe]
CommandLine = "d:\Program Files\Rising\Rav\Ravmond.exe"

[rfwsrv.exe]
CommandLine = "d:\program files\rising\rfw\rfwsrv.exe"

[svchost.exe]
CommandLine = C:\WINNT\system32\svchost -k rpcss

[spoolsv.exe]
CommandLine = C:\WINNT\system32\spoolsv.exe

[CDANTSRV.EXE]
CommandLine = C:\WINNT\System32\DRIVERS\CDANTSRV.EXE

[svchost.exe]
CommandLine = C:\WINNT\System32\svchost.exe -k netsvcs

[regsvc.exe]
CommandLine = C:\WINNT\system32\regsvc.exe

[WinMgmt.exe]
CommandLine = C:\WINNT\System32\WBEM\WinMgmt.exe

[RavStub.exe]
CommandLine = "d:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[Explorer.EXE]
CommandLine = C:\WINNT\Explorer.EXE

[RfwMain.exe]
CommandLine =  -StartUp

[SOUNDMAN.EXE]
CommandLine = "C:\WINNT\SOUNDMAN.EXE"

[rlvknlg.exe]
CommandLine = "C:\winnt\system32\rlvknlg.exe" -boot

[RavTask.exe]
CommandLine = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[Internat.exe]
CommandLine = "C:\WINNT\system32\Internat.exe"

[Ravmon.exe]
CommandLine = "D:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.163.com/
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKCU\..\Run: [Internat.exe] Internat.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RelevantKnowledge] c:\winnt\system32\rlvknlg.exe -boot
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [mwinstart] D:\PROGRA~1\mapgis66\program\MWINST~1.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Adobe Reader7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra Button: 相关站点 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: 相关站点 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINNT\Java\classes\dajava.cab
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://ca3.ccb.com.cn/app/jhca/dll/xenroll.cab
O16 - DPF: {165D83D3-359C-4783-9BF0-6FA6DC42A3F1} (XDownload Class) - http://203.192.15.100/exe/ssdownload.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {62561858-71D1-11D4-B2EC-00105A8340B5} (VITEGPlayerCtrl Class) - http://www.jsbdj.net/jsbdj/control/VTPlayer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143088664218
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://zs.kingsoft.com/duba/OCX/KAVClean.CAB
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{91B21166-EFB0-4651-992C-94F0F506855C}: NameServer = 219.150.32.132,211.98.2.4
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\System32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\System32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\System32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINNT\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\System32\msdxm.ocx
O20 - Winlogon Notify: wzcnotif
O21 - SSODL: SysTrays - {590498A3-4131-4D8F-BA4B-36791A9803B1} - C:\WINNT\System32\DLMain.dll
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINNT\System32\DLMain.dll
O23 - Service: Adobe LM Service (Adobe LM Service) - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: Ati HotKey Poller (Ati HotKey Poller) -  - C:\WINNT\system32\ati2evxx.exe
O23 - Service: Autodesk Licensing Service (Autodesk Licensing Service) - Autodesk, Inc. - "C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"
O23 - Service: C-DillaSrv (C-DillaSrv) - C-Dilla Ltd - C:\WINNT\system32\drivers\cdantsrv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe /com
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "d:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: Indexing Manager (Templates) -  - C:\WINNT\system32\svchost.exe -k netsvcs
最后编辑2006-07-14 16:42:39
分享到:
gototop
 

卸了哪些文件?
gototop
 

卸载的是几个专业软件
gototop
 

而且禁止了几个启动项,比如ADOBE READER、REALPLAY等,都是我熟知的项目
gototop
 

还有一个症状:瑞星监控我明明设置的是全部打开,但右下角图标却是黄色的,并提示“邮件接收和邮件发送监控禁用”,郁闷死了
本来以为下载个兔子就方便管理电脑了,谁知出这茬啊!
gototop
 

另:局域网正常

用卡卡助手修复,也还是那样;用瑞星杀毒,也没检测到病毒。

高手帮帮忙啊
gototop
 

O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\NewDotNet\newdotnet7_22.dll


把这几个用LSPfix修复后就可以上网了.
如果不行,重装上网程序
gototop
 

O23 - Service: Indexing Manager (Templates) - - C:\WINNT\system32\svchost.exe -k netsvcs
可疑服务
gototop
 

FixLSP是什么?是一个专杀工具吗?
gototop
 

O23 - Service: Indexing Manager (Templates) - - C:\WINNT\system32\svchost.exe -k netsvcs
可疑服务

这个可疑服务是不是在管理工具里禁用就行了?
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT