parthia - 2007-1-20 1:21:00
朋友的电脑,系统是windows2000,进入桌面,即将启动完毕之后,会出现蓝屏,然后是如下信息,每次都如此。
--------------
STOP:0X000000D1(0X77E60B00,0X000000FF,0X000001,0XF75D8639)
DRIVER_IRQL_NOT_LESS_OR_EQUAL
Address F75D8639 base at F75d8000,
Datestamp 45652489 -xpa.sys
--------------
能进入windows的安全模式。在安全模式中,发现winnt/temp目录下有xpa.sys文件,3点多k大小;在注册表中,发现有"xpa.sys"的键值。
删除有关的文件和注册表键值,重启,进入普通模式,依然是在启动差不多完成(可以看到桌面背景和图标)的时候出现蓝屏,出现同样的错误提示信息。
再进入安全模式,发现原先已经删除的xpa.sys文件和注册表项依然存在。
怀疑是流氓软件所为,在普通模式下企图加载某些东西而导致系统的崩溃。但无法删除,而且瑞星无法查杀。
不知道这个究竟是什么东西,该如何处理,希望大家能帮帮我。
UFO不幸外人 - 2007-1-20 2:16:00
扫描一个日志 SRE的 http://www4.skycn.com/soft/23312.html
满天飞雪 - 2007-1-20 2:50:00
在那边就跟你说了,让你扫描个日志发上来。用sreng扫描保存日志,粘贴上来。
满天飞雪 - 2007-1-20 2:53:00
http://www.kztechs.com/sreng/index.html
这里是sreng的官方下载地址。
parthia - 2007-1-20 10:18:00
扫描结果如下,请帮忙看看。
[CODE]
2007-01-20,08:52:15
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<internat><internat.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TrackPointSrv><tp4mon.exe> [IBM]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<IMSCMIG40W><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll> [Microsoft Corporation]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><stobject.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nwprovau]
<WinlogonNotify: nwprovau><nwprovau.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
<WinlogonNotify: wzcnotif><wzcdlg.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[ThinkPad Modem Copyright]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\ThinkPad Modem Copyright.lnk --> C:\WINNT\MWW32\manager\mwcpyrt.exe [IBM Corporation]><N>
==================================
服务
[Security Machine Manager / BRGNS][Stopped/Auto Start]
<C:\WINNT\SYSTEM32\RUNDLL32.EXE C:\WINNT\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
[Indexing Service / cisvc][Stopped/Manual Start]
<C:\WINNT\System32\cisvc.exe><Microsoft Corporation>
[Remote Registry Protect / ClipArt][Stopped/Auto Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\uzelo.dll><Microsoft Corporation>
[ClipBook / ClipSrv][Stopped/Manual Start]
<C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[Comeputer Browser / Comeputer Browser][Stopped/Auto Start]
<C:\WINNT\G_Server2006.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[EventLog / EventLog ][Stopped/Auto Start]
<C:\Program Files\1.txt><N/A>
[GrayPigeonServer / GrayPigeonServer][Stopped/Auto Start]
<C:\WINNT\G_Server2006.exe><N/A>
[Gray_Pigeon_Server2.03 / GrayPigeonServer2.03][Stopped/Auto Start]
<C:\WINNT\G_Server2.03.exe><N/A>
[IEXPLORE.dat / IEXPLORE.dat][Stopped/Auto Start]
<C:\WINNT\IEXPLORE.dat><N/A>
[Infrared Monitor / Irmon][Stopped/Auto Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\irmon.dll><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
<C:\WINNT\System32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC][Stopped/Manual Start]
<C:\WINNT\System32\msdtc.exe><Microsoft Corporation>
[Removable Storage / NtmsSvc][Stopped/Auto Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\NtmsSvc.dll><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><Microsoft Corporation>
[Rayion / Rayion][Stopped/Auto Start]
<C:\WINNT\Edhtb.exe><N/A>
[Remote Droceduae Call (RDC) / RdcSca Droceduae Call (RDC)][Stopped/Auto Start]
<C:\WINNT\G_Server1.23.exe><N/A>
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><Microsoft Corporation>
[Remote Registry Service / RemoteRegistry][Stopped/Auto Start]
<C:\WINNT\system32\regsvc.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
<C:\WINNT\System32\locator.exe><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Stopped/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[QoS RSVP / RSVP][Stopped/Manual Start]
<C:\WINNT\System32\rsvp.exe -s><Microsoft Corporation>
[Smart Card Helper / SCardDrv][Stopped/Manual Start]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Manual Start]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[System Event Notification / SENS][Stopped/Auto Start]
<C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><Microsoft Corporation>
[Still Image Service / StiSvc][Stopped/Auto Start]
<C:\WINNT\system32\stisvc.exe><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
<C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS][Stopped/Manual Start]
<C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan][Stopped/Manual Start]
<C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[Windows Adnin / Windows Adnin][Stopped/Auto Start]
<C:\Program Files\HgzServer\G_Server2006.exe><N/A>
[Windows Management Instrumentation / WinMgmt][Running/Auto Start]
<C:\WINNT\System32\WBEM\WinMgmt.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
[Automatic Updates / wuauserv][Stopped/Auto Start]
<C:\WINNT\system32\svchost.exe -k wugroup-->C:\WINNT\system32\wuauserv.dll><Microsoft Corporation>
[Wireless Configuration / WZCSVC][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wzcsvc.dll><Microsoft Corporation>
[Backgryound Inteiigent Transfe / 提供软件安装服务,诸如分派,发][Stopped/Auto Start]
<C:\WINNT\G_Server2006.exe><N/A>
parthia - 2007-1-20 10:20:00
==================================
驱动程序
[696413 / 696413][Stopped/Manual Start]
<\SystemRoot\system32\drivers\696413.sys><N/A>
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\ACPI.sys><Microsoft Corporation>
[Microsoft Embedded Controller Driver / ACPIEC][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\ACPIEC.sys><Microsoft Corporation>
[ADProt / ADProt][Stopped/System Start]
<system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Intel AGP Bus Filter / agp440][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\agp440.sys><Microsoft Corporation>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
<System32\DRIVERS\asyncmac.sys><Microsoft Corporation>
[Standard IDE/ESDI Hard Disk Controller / atapi][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\atapi.sys><Microsoft Corporation>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
<System32\DRIVERS\atmarpc.sys><Microsoft Corporation>
[atssse / atssse][Stopped/Manual Start]
<\??\C:\WINNT\system32\sosdrp.sys><N/A>
[Audio Stub Driver / audstub][Stopped/Manual Start]
<System32\DRIVERS\audstub.sys><Microsoft Corporation>
[Rising TDI Base Driver / BaseTDI][Stopped/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[HelloNet PPPoE 虚拟网卡 / BRPPPOE][Stopped/Manual Start]
<system32\DRIVERS\brpppoe.sys><N/A>
[Closed Caption Decoder / ccdecode][Stopped/Manual Start]
<system32\drivers\ccdecode.sys><Microsoft Corporation>
[CD-ROM Driver / Cdrom][Running/System Start]
<System32\DRIVERS\cdrom.sys><Microsoft Corporation>
[Xircom Ethernet + Modem 56 Network Driver / cem56][Stopped/Manual Start]
<System32\DRIVERS\cem56n5.sys><N/A>
[Microsoft ACPI Control Method Battery Driver / CmBatt][Stopped/Manual Start]
<System32\DRIVERS\CmBatt.sys><Microsoft Corporation>
[Microsoft Composite Battery Driver / Compbatt][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\compbatt.sys><Microsoft Corporation>
[Crystal WDM MPU-401 UART Driver / cwbmidi_device][Stopped/Manual Start]
<system32\drivers\cwbmidi.sys><Microsoft Corporation>
[Crystal WDM Audio Codec Driver / cwbwdm_device][Stopped/Manual Start]
<system32\drivers\cwbwdm.sys><Microsoft Corporation>
[Disk Driver / Disk][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\disk.sys><Microsoft Corporation>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Stopped/Disabled]
<System32\drivers\dmload.sys><VERITAS Software Corp.>
[Microsoft DirectMusic SW Synth (WDM) / DMusic][Stopped/Manual Start]
<system32\drivers\DMusic.sys><Microsoft Corporation>
[edigtbs / edigtbs][Running/Boot Start]
<\SystemRoot\system32\drivers\edigtbs.sys><>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[Floppy Disk Controller Driver / Fdc][Running/Manual Start]
<System32\DRIVERS\fdc.sys><Microsoft Corporation>
[Floppy Disk Driver / Flpydisk][Running/Manual Start]
<System32\DRIVERS\flpydisk.sys><Microsoft Corporation>
[FsVga / FsVga][Stopped/System Start]
<System32\DRIVERS\fsvga.sys><N/A>
[Game Port Enumerator / gameenum][Stopped/Manual Start]
<System32\DRIVERS\gameenum.sys><Microsoft Corporation>
[WAN Miniport Driver For PPPoE Protocol / GNetPPPoE][Stopped/Manual Start]
<system32\DRIVERS\PPPoE.SYS><Guangdong Gnet Application R & D Center>
[Generic Packet Classifier / Gpc][Stopped/Manual Start]
<System32\DRIVERS\msgpc.sys><Microsoft Corporation>
[Microsoft HID Class Driver / HidUsb][Stopped/Auto Start]
<System32\DRIVERS\hidusb.sys><Microsoft Corporation>
[HookCont / HookCont][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[i8042 Keyboard and PS/2 Mouse Port Driver / i8042prt][Running/System Start]
<System32\DRIVERS\i8042prt.sys><Microsoft Corporation>
[icddrv / icddrv][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\icddrv.sys><N/A>
[IntelIde / IntelIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\intelide.sys><Microsoft Corporation>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
<System32\DRIVERS\ipfltdrv.sys><Microsoft Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<System32\DRIVERS\ipinip.sys><Microsoft Corporation>
[IrDA Protocol / irda][Stopped/Auto Start]
<System32\DRIVERS\irda.sys><Microsoft Corporation>
[IR Enumerator Service / IRENUM][Stopped/Manual Start]
<System32\DRIVERS\irenum.sys><Microsoft Corporation>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Keyboard Class Driver / Kbdclass][Running/System Start]
<System32\DRIVERS\kbdclass.sys><Microsoft Corporation>
[Microsoft Kernel Wave Audio Mixer / kmixer][Stopped/Manual Start]
<system32\drivers\kmixer.sys><Microsoft Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mf / mf][Stopped/Manual Start]
<System32\DRIVERS\mf.sys><Microsoft Corporation>
[Unimodem Streaming Filter Device / MODEMCSA][Stopped/Manual Start]
<system32\drivers\MODEMCSA.sys><Microsoft Corporation>
[Mouse Class Driver / Mouclass][Running/System Start]
<System32\DRIVERS\mouclass.sys><Microsoft Corporation>
[Mouse HID Driver / mouhid][Stopped/Manual Start]
<System32\DRIVERS\mouhid.sys><Microsoft Corporation>
[Microsoft Streaming Service Proxy / MSKSSRV][Stopped/Manual Start]
<system32\drivers\MSKSSRV.sys><Microsoft Corporation>
[Microsoft Streaming Clock Proxy / MSPCLOCK][Stopped/Manual Start]
<system32\drivers\MSPCLOCK.sys><Microsoft Corporation>
[Microsoft Streaming Quality Manager Proxy / MSPQM][Stopped/Manual Start]
<system32\drivers\MSPQM.sys><Microsoft Corporation>
[Microsoft Streaming Tee/Sink-to-Sink Converter / MSTEE][Stopped/Manual Start]
<system32\drivers\MSTEE.sys><Microsoft Corporation>
[Remote Access NDIS TAPI Driver / NdisTapi][Stopped/Manual Start]
<System32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NDIS 用户模式 I/O 协议 / Ndisuio][Stopped/Manual Start]
<System32\DRIVERS\ndisuio.sys><Microsoft Corporation>
[Remote Access NDIS WAN Driver / NdisWan][Stopped/Manual Start]
<System32\DRIVERS\ndiswan.sys><Microsoft Corporation>
[neo20xx / neo20xx][Stopped/Manual Start]
<System32\DRIVERS\neo20xx.sys><NeoMagic Corporation>
[NetBIOS Interface / NetBIOS][Stopped/System Start]
<System32\DRIVERS\netbios.sys><Microsoft Corporation>
[NetDetect / NetDetect][Stopped/Manual Start]
<\SystemRoot\system32\drivers\netdtect.sys><Microsoft Corporation>
[New0 / New0][Stopped/Auto Start]
<\??\C:\WINNT\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\C:\Program Files\Tencent\qq\npkcrypt.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA][Stopped/Manual Start]
<System32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
<System32\DRIVERS\nwlnkflt.sys><Microsoft Corporation>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
<System32\DRIVERS\nwlnkfwd.sys><Microsoft Corporation>
[paasweq / paasweq][Stopped/Manual Start]
<\??\C:\WINNT\system32\sosdrp.sys><N/A>
[Parallel class driver / Parallel][Running/Manual Start]
<System32\DRIVERS\parallel.sys><Microsoft Corporation>
[Parallel port driver / Parport][Stopped/System Start]
<System32\DRIVERS\parport.sys><Microsoft Corporation>
[PCI Bus Driver / PCI][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\pci.sys><Microsoft Corporation>
[Pcmcia / Pcmcia][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\pcmcia.sys><Microsoft Corporation>
[WAN Miniport (PPTP) / PptpMiniport][Stopped/Manual Start]
<System32\DRIVERS\raspptp.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink][Stopped/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Remote Access Auto Connection Driver / RasAcd][Stopped/System Start]
<System32\DRIVERS\rasacd.sys><Microsoft Corporation>
[WAN Miniport (IrDA Modem) / Rasirda][Stopped/Manual Start]
<System32\DRIVERS\rasirda.sys><Microsoft Corporation>
[WAN Miniport (L2TP) / Rasl2tp][Stopped/Manual Start]
<System32\DRIVERS\rasl2tp.sys><Microsoft Corporation>
[Direct Parallel / Raspti][Stopped/Manual Start]
<System32\DRIVERS\raspti.sys><Microsoft Corporation>
[Microsoft Streaming Network Raw Channel Access / RCA][Stopped/Manual Start]
<system32\drivers\RCA.sys><Microsoft Corporation>
[Digital CD Audio Playback Filter Driver / redbook][Stopped/System Start]
<System32\DRIVERS\redbook.sys><Microsoft Corporation>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
parthia - 2007-1-20 10:20:00
[Serenum Filter Driver / serenum][Stopped/Manual Start]
<System32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Stopped/System Start]
<System32\DRIVERS\serial.sys><Microsoft Corporation>
[SVKP / SVKP][Stopped/Auto Start]
<\??\C:\WINNT\system32\SVKP.sys><AntiCracking>
[Software Bus Driver / swenum][Running/Manual Start]
<System32\DRIVERS\swenum.sys><Microsoft Corporation>
[Microsoft Kernel GS Wavetable Synthesizer / swmidi][Stopped/Manual Start]
<system32\drivers\swmidi.sys><Microsoft Corporation>
[Microsoft System Audio Device / sysaudio][Stopped/Manual Start]
<system32\drivers\sysaudio.sys><Microsoft Corporation>
[ThinkPad DSP Driver Service / ThinkPadDSP][Stopped/Manual Start]
<System32\DRIVERS\mwwdm.sys><IBM Corporation>
[IBM PS/2 TrackPoint Filter Driver / TwoTrack][Running/Manual Start]
<System32\DRIVERS\TwoTrack.sys><Microsoft Corporation>
[Microsoft USB Universal Host Controller Driver / uhcd][Running/Manual Start]
<System32\DRIVERS\uhcd.sys><Microsoft Corporation>
[Microcode Update Driver / Update][Running/Manual Start]
<System32\DRIVERS\update.sys><Microsoft Corporation>
[Microsoft USB Standard Hub Driver / usbhub][Running/Manual Start]
<System32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB Scanner Driver / usbscan][Stopped/Manual Start]
<System32\DRIVERS\usbscan.sys><Microsoft Corporation>
[USB Mass Storage Driver / USBSTOR][Running/Manual Start]
<System32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[vbppdryu / vbppdryu][Stopped/Manual Start]
<\??\C:\WINNT\system32\sosdrp.sys><N/A>
[VgaSave / VgaSave][Running/System Start]
<\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Stopped/Manual Start]
<System32\DRIVERS\wanarp.sys><Microsoft Corporation>
[Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Stopped/Manual Start]
<system32\drivers\wdmaud.sys><Microsoft Corporation>
[Windows 套接字 2 .0 Non-IFS 服务提供程序支持环境 / WS2IFSL][Stopped/Auto Start]
<\SystemRoot\System32\drivers\ws2ifsl.sys><Microsoft Corporation>
[VIMICRO USB PC Camera 301x / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
浏览器加载项
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINNT\system32\ssup.dll, TENCENT>
[Schedule Class]
{8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\WINNT\system32\sscli.dll, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[CibaCtrl Class]
{8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
{C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[PGEdit Class]
{2BFAA61B-5C83-4865-8281-D8BDBF863061} <C:\WINNT\Downloaded Program Files\PG_ATL_Edit.dll, 中国银联广州分公司>
[WebActivater Control]
{3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINNT\system32\WEBACT~1.OCX, QQ>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Ravonline]
{DA984A6D-508E-11D6-AA49-0050FF3C628D} <C:\WINNT\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<C:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 108][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 136][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 156][\??\C:\WINNT\SYSTEM32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997]
[C:\WINNT\SYSTEM32\APIHookDll.dll] [N/A, N/A]
[C:\WINNT\SYSTEM32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINNT\SYSTEM32\tsd32.dll] [N/A, N/A]
[C:\WINNT\SYSTEM32\iac25_32.ax] [Ligos Corporation, 2.05.54]
[C:\WINNT\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINNT\SYSTEM32\sl_anet.acm] [Sipro Lab Telecom Inc., 3.02]
[C:\WINNT\SYSTEM32\vct3216.acm] [Voxware, Inc., 1.6.0.17]
[C:\WINNT\SYSTEM32\vct3216.dll] [Voxware, Inc., 1.6.0.12]
[C:\WINNT\system32\msms001.vwp] [Voxware, Inc., 2.0.2.61]
[C:\WINNT\system32\mvoice.vwp] [Voxware, Inc., 2.0.0.12.01]
[C:\WINNT\SYSTEM32\vorbis.acm] [HMS http://hp.vector.co.jp/authors/VA012897/, 0, 0, 3, 6]
[PID: 184][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.7035]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 196][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.7011]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[PID: 344][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[PID: 384][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[C:\WINNT\SYSTEM32\APIHookDll.dll] [N/A, N/A]
[PID: 224][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 496][C:\软件\Sreng\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP UDP Service Provider
C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
RSVP TCP Service Provider
C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] SEQPACKET 3
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] DATAGRAM 3
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] SEQPACKET 0
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] DATAGRAM 0
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] SEQPACKET 1
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] DATAGRAM 1
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] SEQPACKET 2
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] DATAGRAM 2
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
[/CODE]
crgg - 2007-1-20 13:16:00
该用户帖子内容已被屏蔽
parthia - 2007-1-20 16:55:00
有没有人能看懂?帮帮忙。
woainijhdd - 2007-1-28 19:56:00
我电脑现在也经常蓝屏啊!!!我是菜尿郁闷啊 ````有时候一些程序都打不开来!!!老是出错!!!!!老是要调试``怎么办啊~~~~~~~~懂的+我QQ452956830A 谢谢````
© 2000 - 2026 Rising Corp. Ltd.