瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【求助】瑞星防火墙文件被损坏,自动关机,不明进程A0380mon.exe,有日志
pzbhallow - 2007-12-22 20:33:00
我用的正版瑞星,一直以来都很好。而且总是在第一时间将其升级为最新版本。防护应该可以了。最近下载了几个视频播放软件如Mplayer与pplive,也在武汉热线上下载了客户端播放软件。本来一直看的很好,但是今天居然不能正常在线观看电影,主要表现为出现自动关机现象,看电影只有声音没有图像。而观看本地电影则没有这类问题。随即马上升级瑞星软件,防火墙升级成功以后却提示文件rsconfig被损坏,并自行关闭。这期间出现了几次关机提示,最后电脑终于自己关机。
重新开机后,马上卸载了以上视频播放软件,但是瑞星防火墙仍然无法启动。请各位大侠指点。

[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0(Compatible Mozilla/4.0(Compatible-EmbeddedWB 14.59 http://bsalsa.com/ EmbeddedWB- 14.59  from: http://bsalsa.com/ ; Mozilla/4.0(Compatible Mozilla/4.0EmbeddedWB- 14.59  from: http://bsalsa.com/ ; Maxthon)


附件: 64486820071223101227.txt
pzbhallow - 2007-12-22 20:38:00
方才查看了一下进程,发现了两个以前从来没有看到过的(我经常查看进程):一个是A0380mon.exe,一个是TIMPlatform.exe,还有一个是DHTray.exe的进程与应用程序。请版主指点迷津
pzbhallow - 2007-12-22 21:35:00
紧急求助!!!!!!!!!
pzbhallow - 2007-12-22 22:05:00
现上传刚用卡卡安全助手扫描的日志

附件: 64486820071222215349.txt
pzbhallow - 2007-12-22 22:08:00
瑞星卡卡电脑诊断日志 v1.30 (2007-12-22 21:30:19)  北京瑞星科技股份有限公司

注释:    [A]表示该文件存在自启动关联;
    [M]表示该文件在内存中;

+ 注册表自运行项目
  + 系统服务
    + HKLM\System\CurrentControlSet\Services
      ose
        [A ] 1. c:\program files\common files\microsoft shared\source engine\ose.exe


      RfwProxySrv
        [A ] 2. c:\program files\rising\rfw\rfwproxy.exe


      RfwService
        [A ] 3. c:\program files\rising\rfw\rfwsrv.exe


      RsCCenter
        [AM] 4. c:\program files\rising\rav\ccenter.exe


      RsRavMon
        [AM] 5. c:\program files\rising\rav\ravmond.exe


      UMWdf
        [AM] 6. c:\windows\system32\wdfmgr.exe


      UPHClean
        [AM] 7. c:\program files\uphclean\uphclean.exe


      WudfSvc
        [A ] 8. c:\windows\system32\wudfsvc.dll




  + 内核驱动
    + HKLM\System\CurrentControlSet\Services
      A0380VID
        [A ] 9. c:\windows\system32\drivers\a0380vid.sys


      BaseTDI
        [A ] 10. c:\windows\system32\drivers\basetdi.sys


      dtscsi
        [A ] 11. c:\windows\system32\drivers\dtscsi.sys


      FETNDISB
        [A ] 12. c:\windows\system32\drivers\fetnd5b.sys


      HdAudAddService
        [A ] 13. c:\windows\system32\drivers\hdaudio.sys


      HDAudBus
        [A ] 14. c:\windows\system32\drivers\hdaudbus.sys


      HookCont
        [A ] 15. c:\windows\system32\drivers\hookcont.sys


      HookNtos
        [A ] 16. c:\windows\system32\drivers\hookntos.sys


      HookReg
        [A ] 17. c:\windows\system32\drivers\hookreg.sys


      HookSys
        [A ] 18. c:\windows\system32\drivers\hooksys.sys


      HookUrl
        [A ] 19. c:\program files\rising\rfw\hookurl.sys


      HWiNFO32
        [A ] 20. c:\program files\hwinfo32\hwinfo32.sys


      ialm
        [A ] 21. c:\windows\system32\drivers\ialmnt5.sys


      IntcAzAudAddService
        [A ] 22. c:\windows\system32\drivers\rtkhdaud.sys


      IPHOOK
        [A ] 23. c:\program files\rising\rfw\iphook.sys


      kmsinput
        [A ] 24. c:\windows\system32\drivers\kmsinput.sys


      MegaIDE
        [A ] 25. c:\windows\system32\drivers\megaide.sys


      New0
        [A ] 26. c:\windows\system32\new.sys


      NPF
        [A ] 27. c:\windows\system32\drivers\npf.sys


      npkcrypt
        [A ] 28. d:\program files\tencent\qq\npkcrypt.sys


      NTSIM
        [A ] 29. c:\windows\system32\ntsim.sys


      RfwBase
        [A ] 30. c:\windows\system32\drivers\rfwbase.sys


      RsAntiSpyware
        [A ] 31. c:\windows\system32\drivers\rsboot.sys


      RsFwDrv
        [A ] 32. c:\program files\rising\rfw\rsfwdrv.sys


      RsNTGDI
        [A ] 33. c:\windows\system32\drivers\rsntgdi.sys


      RTL8023xp
        [A ] 34. c:\windows\system32\drivers\rtlnicxp.sys


      Secdrv
        [A ] 35. c:\windows\system32\drivers\secdrv.sys


      sfdrv01
        [A ] 36. c:\windows\system32\drivers\sfdrv01.sys


      sfhlp02
        [A ] 37. c:\windows\system32\drivers\sfhlp02.sys


      sfsync02
        [A ] 38. c:\windows\system32\drivers\sfsync02.sys


      SMBios
        [A ] 39. c:\windows\system32\drivers\smbios.sys


      sptd
        [A ] 40. c:\windows\system32\drivers\sptd.sys


      TDIHOOK
        [A ] 41. c:\program files\rising\rfw\tdihook.sys


      w810bus
        [A ] 42. c:\windows\system32\drivers\w810bus.sys


      w810mdfl
        [A ] 43. c:\windows\system32\drivers\w810mdfl.sys


      w810mdm
        [A ] 44. c:\windows\system32\drivers\w810mdm.sys


      w810mgmt
        [A ] 45. c:\windows\system32\drivers\w810mgmt.sys


      w810obex
        [A ] 46. c:\windows\system32\drivers\w810obex.sys


      WudfPf
        [A ] 47. c:\windows\system32\drivers\wudfpf.sys


      WudfRd
        [A ] 48. c:\windows\system32\drivers\wudfrd.sys




  + 文件系统驱动
    + HKLM\System\CurrentControlSet\Services
      ATE_PROCMON
        [A ] 49. d:\program files\anti trojan elite\atepmon.sys




  + 系统登陆自运行
    + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
      igfxcui
        [A ] 50. c:\windows\system32\igfxsrvc.dll




  + IE浏览器加载模块
    + HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
      {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
        [AM] 51. c:\windows\system32\ieframe.dll



    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
      {0005A87D-D626-4B3A-84F9-1D9571695F55}
        [AM] 52. c:\windows\system32\xunleibho_v8.dll


      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
        [A ] 53. c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll


      {4E83D567-4697-4F7B-B1F0-A513B01DB89A}
        [A ] 54. c:\program files\chinanet\vnettransfer.dll


      {A9930D97-9CF0-42A0-A10D-4F28836579D5}
        [A ] 55. d:\program files\kugoo3\kugoo3downxcontrol.ocx



    + HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
      Exec
        [A ] 56. c:\windows\network diagnostic\xpnetdiag.exe




  + 资源管理器加载模块
    + HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
      text/xml
        [A ] 57. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll



    + HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
      KuGoo
        [A ] 58. c:\windows\system32\kugoo3downxcontrol.ocx


      KuGoo3
        [A ] 58. c:\windows\system32\kugoo3downxcontrol.ocx


      mso-offdap11
        [A ] 59. c:\program files\common files\microsoft shared\web components\11\owc11.dll



    + HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
      <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
        [A ] 60. c:\windows\system32\ieudinit.exe



    + HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
      {F9DB5320-233E-11D1-9F84-707F02C10627}
        [AM] 61. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll



    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
      Web Folders
        [A ] 62. c:\program files\common files\microsoft shared\web folders\msonsext.dll


      WinRAR shell extension
        [A ] 63. c:\program files\winrar\rarext.dll


      Shell Extensions for RealOne Player
        [A ] 64. c:\program files\real\realone player\rpshell.dll


      PicaView
        [A ] 65. d:\program files\acdsee\picaview.dll


      Microsoft Office Outlook Desktop Icon Handler
        [A ] 66. d:\microsoft office\office11\mlshext.dll


      Microsoft Office Outlook Custom Icon Handler
        [A ] 67. d:\microsoft office\office11\olkfstub.dll


      Microsoft Office HTML Icon Handler
        [A ] 68. d:\microsoft office\office11\msohev.dll


      RISING
        [AM] 69. c:\windows\system32\ravext.dll


      Portable Media Devices
        [A ] 70. c:\windows\system32\audiodev.dll


      Portable Media Devices Menu
        [A ] 70. c:\windows\system32\audiodev.dll


      IE Microsoft BrowserBand
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Fade Task
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Menu Desk Bar
        [AM] 51. c:\windows\system32\ieframe.dll


      IE AutoComplete
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Search Band
        [AM] 51. c:\windows\system32\ieframe.dll


      Microsoft Url History Service
        [AM] 51. c:\windows\system32\ieframe.dll


      The Internet
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Navigation Bar
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Menu Site
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Menu Band
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Microsoft History AutoComplete List
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Tracking Shell Menu
        [AM] 51. c:\windows\system32\ieframe.dll


      IE IShellFolderBand
        [AM] 51. c:\windows\system32\ieframe.dll


      IE BandProxy
        [AM] 51. c:\windows\system32\ieframe.dll


      Temporary Internet Files
        [AM] 51. c:\windows\system32\ieframe.dll


      Temporary Internet Files
        [AM] 51. c:\windows\system32\ieframe.dll


      Internet Name Space
        [AM] 51. c:\windows\system32\ieframe.dll


      IE MRU AutoComplete List
        [AM] 51. c:\windows\system32\ieframe.dll


      IE RSS Feeder Folder
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Microsoft Shell Folder AutoComplete List
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Microsoft Multiple AutoComplete List Container
        [AM] 51. c:\windows\system32\ieframe.dll


      Microsoft Browser Architecture
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Shell Rebar BandSite
        [AM] 51. c:\windows\system32\ieframe.dll


      Microsoft Url Search Hook
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Shell Band Site Menu
        [AM] 51. c:\windows\system32\ieframe.dll


     




pzbhallow - 2007-12-22 22:09:00
Shell DocObject Viewer
        [AM] 51. c:\windows\system32\ieframe.dll


      &Links
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Registry Tree Options Utility
        [AM] 51. c:\windows\system32\ieframe.dll


      IE User Assist
        [AM] 51. c:\windows\system32\ieframe.dll


      InternetShortcut
        [AM] 51. c:\windows\system32\ieframe.dll


      IE Custom MRU AutoCompleted List
        [AM] 51. c:\windows\system32\ieframe.dll


      History
        [AM] 51. c:\windows\system32\ieframe.dll



    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
      {32CD708B-60A7-4C00-9377-D73EAA495F0F}
        [AM] 69. c:\windows\system32\ravext.dll




  + 用户登陆自运行项目
    + HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      RTHDCPL
        [A ] 71. c:\windows\rthdcpl.exe


      Alcmtr
        [A ] 72. c:\windows\alcmtr.exe


      AlcWzrd
        [A ] 73. c:\windows\alcwzrd.exe


      High Definition Audio Property Page Shortcut
        [A ] 74. c:\windows\system32\hdashcut.exe


      HotKeysCmds
        [A ] 75. c:\windows\system32\hkcmd.exe


      IgfxTray
        [A ] 76. c:\windows\system32\igfxtray.exe


      SoundMan
        [A ] 77. c:\windows\soundman.exe


      TkBellExe
        [AM] 78. c:\program files\common files\real\update_ob\realsched.exe


      runeip
        [AM] 79. c:\program files\rising\antispyware\runiep.exe


      RavTask
        [AM] 80. c:\program files\rising\rav\ravtask.exe


      RfwMain
        [A ] 81. c:\program files\rising\rfw\rfwmain.exe


      Adobe Reader Speed Launcher
        [A ] 82. d:\program files\adobe\reader 8.0\reader\reader_sl.exe


      DHTray
        [AM] 83. c:\windows\system32\dhtray.exe


      A0380mon
        [A ] 84. c:\windows\system32\a0380mon.exe




  + 开机执行
    + HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
      BootExecute
        [A ] 85. c:\windows\system32\bsmain.exe




  + 映像劫持
    + HKCR\.html
      htmlfile\Edit\Command
        [A ] 86. d:\microsoft office\office11\msohtmed.exe


      htmlfile\Maxthon\Command
        [AM] 87. d:\maxthon\maxthon.exe


      htmlfile\Print\Command
        [A ] 86. d:\microsoft office\office11\msohtmed.exe



    + HKCR\.htm
      htmlfile\Edit\Command
        [A ] 86. d:\microsoft office\office11\msohtmed.exe


      htmlfile\Maxthon\Command
        [AM] 87. d:\maxthon\maxthon.exe


      htmlfile\Print\Command
        [A ] 86. d:\microsoft office\office11\msohtmed.exe




  + 打印机监控
    + HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
      Microsoft Document Imaging Writer Monitor
        [AM] 88. c:\windows\system32\mdimon.dll





+ 其他自启动项目
  + C:\Documents and Settings\new\「开始」菜单\程序\启动
    腾讯QQ.lnk
      [AM] 89. d:\program files\tencent\qq\qq.exe




+ 正在运行的进程
  + 00000124(292) realsched.exe
    00400000[0002F000]
      [AM] 78. c:\program files\common files\real\update_ob\realsched.exe


    10000000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll



  + 0000012c(300) runiep.exe
    00400000[00016000]
      [AM] 79. c:\program files\rising\antispyware\runiep.exe


    00C60000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll



  + 0000016c(364) RavTask.exe
    00400000[00034000]
      [AM] 80. c:\program files\rising\rav\ravtask.exe


    10000000[0001F000]
      [ M] 92. c:\program files\rising\rav\proccom.dll


    00A30000[00024000]
      [ M] 93. c:\program files\rising\rav\rscommx2.dll


    23700000[00028000]
      [ M] 94. c:\program files\rising\rav\rscommon.dll


    00C90000[0000E000]
      [ M] 95. c:\program files\rising\rav\rsappmgr.dll


    08CB0000[00030000]
      [ M] 96. c:\program files\rising\rav\cfgdll.dll


    08F90000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll



  + 0000018c(396) Ravmon.exe
    00400000[00057000]
      [ M] 97. c:\program files\rising\rav\ravmon.exe


    7C140000[00103000]
      [ M] 98. c:\windows\system32\mfc71.dll


    7C340000[00056000]
      [ M] 99. c:\windows\system32\msvcr71.dll


    7C3A0000[0007B000]
      [ M] 100. c:\windows\system32\msvcp71.dll


    10000000[0001F000]
      [ M] 92. c:\program files\rising\rav\proccom.dll


    00B10000[00024000]
      [ M] 93. c:\program files\rising\rav\rscommx2.dll


    23700000[00028000]
      [ M] 94. c:\program files\rising\rav\rscommon.dll


    00D60000[00028000]
      [ M] 101. c:\program files\rising\rav\recomp.dll


    00DA0000[00030000]
      [ M] 102. c:\program files\rising\rav\refs.dll


    00DE0000[0002C000]
      [ M] 103. c:\program files\rising\rav\viruslib.dll


    00F20000[00027000]
      [ M] 104. c:\program files\rising\rav\relibldr.dll


    00FA0000[0000E000]
      [ M] 95. c:\program files\rising\rav\rsappmgr.dll


    00FC0000[00030000]
      [ M] 96. c:\program files\rising\rav\cfgdll.dll


    01120000[00075000]
      [ M] 105. c:\program files\rising\rav\monrule.dll


    23900000[00040000]
      [ M] 106. c:\program files\rising\rav\pngdll.dll


    26600000[000B5000]
      [ M] 107. c:\program files\rising\rav\rsguilib.dll


    23800000[00018000]
      [ M] 108. c:\program files\rising\rav\rsxml.dll


    02B10000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll



  + 000001cc(460) DHTray.exe
    00400000[00050000]
      [AM] 83. c:\windows\system32\dhtray.exe


    10000000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll

  + 00000268(616) smss.exe

  + 000002a8(680) csrss.exe

  + 000002c0(704) winlogon.exe
    72C80000[00008000]
      [ M] 109. c:\windows\system32\msacm32.drv



  + 000002f0(752) services.exe
    47260000[0000F000]
      [ M] 110. c:\windows\apppatch\acadproc.dll



  + 000002fc(764) lsass.exe

  + 00000370(880) QQ.exe
    00400000[001C3000]
      [AM] 89. d:\program files\tencent\qq\qq.exe


    10000000[00288000]
      [ M] 111. d:\program files\tencent\qq\qqbaseclassindll.dll


    005D0000[000C2000]
      [ M] 112. d:\program files\tencent\qq\qqhelperdll.dll


pzbhallow - 2007-12-22 22:10:00
600A0000[0006B000]
      [ M] 113. d:\program files\tencent\qq\basicctrldll.dll


    60A80000[000F2000]
      [ M] 114. d:\program files\tencent\qq\mfc42.dll


    00380000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll


    62410000[00005000]
      [ M] 116. d:\program files\tencent\qq\riched32.dll


    623A0000[00068000]
      [ M] 117. d:\program files\tencent\qq\riched20.dll


    61350000[0003A000]
      [ M] 118. d:\program files\tencent\qq\qqapi.dll


    62560000[00007000]
      [ M] 119. d:\program files\tencent\qq\timproxy.dll


    015D0000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    60890000[0003D000]
      [ M] 120. d:\program files\tencent\qq\loginctrl.dll


    608D0000[0009A000]
      [ M] 121. d:\program files\tencent\qq\loginctrlres.dll


    61C00000[0058D000]
      [ M] 122. d:\program files\tencent\qq\qqres.dll


    62A40000[0003D000]
      [ M] 123. d:\program files\tencent\qq\wizardctrl.dll


    618C0000[000A0000]
      [ M] 124. d:\program files\tencent\qq\qqmainframe.dll


    60400000[001A3000]
      [ M] 125. d:\program files\tencent\qq\gdiplus.dll


    62590000[00020000]
      [ M] 126. d:\program files\tencent\qq\unreadmsgmgr.dll


    03390000[00142000]
      [ M] 127. d:\program files\tencent\qq\cqqapplication.dll


    603C0000[0003F000]
      [ M] 128. d:\program files\tencent\qq\flashavatardll.dll


    60C20000[0005F000]
      [ M] 129. d:\program files\tencent\qq\newskin.dll


    60A40000[00032000]
      [ M] 130. d:\program files\tencent\qq\mailsummary.dll


    62250000[00026000]
      [ M] 131. d:\program files\tencent\qq\qqspace.dll


    625D0000[00071000]
      [ M] 132. d:\program files\tencent\qq\vbscript.dll


    61870000[00018000]
      [ M] 133. d:\program files\tencent\qq\qqknowledgesearch.dll


    61720000[00071000]
      [ M] 134. d:\program files\tencent\qq\qqgroupmng.dll


    61110000[00237000]
      [ M] 135. d:\program files\tencent\qq\qqallinone.dll


    62440000[0002B000]
      [ M] 136. d:\program files\tencent\qq\sccore.dll


    60130000[00034000]
      [ M] 137. d:\program files\tencent\qq\cameradll.dll


    625B0000[00017000]
      [ M] 138. d:\program files\tencent\qq\userdefinedhead.dll


    61A90000[00122000]
      [ M] 139. d:\program files\tencent\qq\qqplugin.dll


    61660000[0000E000]
      [ M] 140. d:\program files\tencent\qq\qqconfigplugin.dll


    61390000[0003D000]
      [ M] 141. d:\program files\tencent\qq\qqavatar.dll


    422B0000[005CD000]
      [AM] 51. c:\windows\system32\ieframe.dll


    61670000[00055000]
      [ M] 142. d:\program files\tencent\qq\qqcustomface.dll


    62380000[00016000]
      [ M] 143. d:\program files\tencent\qq\qringmng.dll


    60970000[000A8000]
      [ M] 144. d:\program files\tencent\qq\longconnection.dll


    60D20000[00026000]
      [ M] 145. d:\program files\tencent\qq\phoneapi.dll


    60370000[0000D000]
      [ M] 146. d:\program files\tencent\qq\dialerallinone.dll


    72C80000[00008000]
      [ M] 109. c:\windows\system32\msacm32.drv


    61A60000[0002B000]
      [ M] 147. d:\program files\tencent\qq\qqpet.dll


    01820000[0003E000]
      [ M] 148. d:\program files\tencent\qq\qqsysmsgmng.dll


    60110000[0001F000]
      [ M] 149. d:\program files\tencent\qq\bqqapplication.dll


    72C60000[00007000]
      [ M] 150. c:\windows\system32\msadp32.acm


    60770000[0001A000]
      [ M] 151. d:\program files\tencent\qq\imageole.dll


    61890000[00015000]
      [ M] 152. d:\program files\tencent\qq\qqliveqmng.dll


    018B0000[00028000]
      [ M] 153. c:\program files\rising\rav\ravscrch.dll


    60170000[0004F000]
      [ M] 154. d:\program files\tencent\qq\commercesmng.dll


    60CA0000[0000F000]
      [ M] 155. d:\program files\tencent\qq\personaldesktop.dll


    04EB0000[00286000]
      [ M] 156. d:\program files\tencent\qq\qqaddr.dll


    62190000[0002D000]
      [ M] 157. d:\program files\tencent\qq\qqscenemng.dll


    011C0000[0002C000]
      [ M] 158. d:\program files\tencent\qq\addrsearch.dll


    606C0000[00024000]
      [ M] 159. d:\program files\tencent\qq\groupconnection.dll


    629E0000[0002A000]
      [ M] 160. d:\program files\tencent\qq\vqqmodule.dll


    62960000[0007B000]
      [ M] 161. d:\program files\tencent\qq\vqqallinone.dll


    607A0000[000DD000]
      [ M] 162. d:\program files\tencent\qq\inplus.dll


    62530000[00012000]
      [ M] 163. d:\program files\tencent\qq\tencent-proto1.dll


    62500000[00024000]
      [ M] 164. d:\program files\tencent\qq\tencent-comlib.dll


    62550000[0000D000]
      [ M] 165. d:\program files\tencent\qq\tencent-proto2.dll


    06340000[004FD000]
      [ M] 166. c:\windows\system32\unispim6.ime


    30000000[002EF000]
      [ M] 167. c:\windows\system32\macromed\flash\flash9d.ocx


    618B0000[0000E000]
      [ M] 168. d:\program files\tencent\qq\qqmagicface.dll


    616E0000[0002B000]
      [ M] 169. d:\program files\tencent\qq\qqfiletransfer.dll



  + 00000394(916) svchost.exe

  + 000003e0(992) svchost.exe

  + 00000410(1040) TIMPlatform.exe
    00400000[00013000]
      [ M] 170. d:\program files\tencent\qq\timplatform.exe


    10000000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    62560000[00007000]
      [ M] 119. d:\program files\tencent\qq\timproxy.dll



  + 00000430(1072) Ras.exe
    00400000[00170000]
      [ M] 171. c:\program files\rising\antispyware\ras.exe


    00370000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll


    780C0000[00061000]
      [ M] 172. c:\program files\rising\antispyware\msvcp60.dll


    10000000[00013000]
      [ M] 173. c:\program files\rising\antispyware\topsoft.dll


    7C140000[00103000]
      [ M] 174. c:\program files\rising\antispyware\mfc71.dll


    7C340000[00056000]
      [ M] 175. c:\program files\rising\antispyware\msvcr71.dll


    7C3A0000[0007B000]
      [ M] 176. c:\program files\rising\antispyware\msvcp71.dll


    00E60000[0001F000]
      [ M] 92. c:\program files\rising\rav\proccom.dll


    00FF0000[00024000]
      [ M] 93. c:\program files\rising\rav\rscommx2.dll


    01130000[000BD000]
      [ M] 177. c:\program files\rising\antispyware\rasgui.dll


    01100000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    422B0000[005CD000]
      [AM] 51. c:\windows\system32\ieframe.dll


    02F40000[0001C000]
      [AM] 69. c:\windows\system32\ravext.dll


    029B0000[00028000]
      [ M] 153. c:\program files\rising\rav\ravscrch.dll



  + 00000440(1088) CCenter.exe
    00400000[00029000]
      [AM] 4. c:\program files\rising\rav\ccenter.exe



  + 00000450(1104) svchost.exe
    00D70000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll



  + 000004b4(1204) svchost.exe

  + 000004f4(1268) svchost.exe
    00800000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll



  + 00000510(1296) Ravmond.exe
    00400000[0006C000]
      [AM] 5. c:\program files\rising\rav\ravmond.exe


    10000000[00042000]
      [ M] 178. c:\program files\rising\rav\bwlist.dll


    7C140000[00103000]
      [ M] 98. c:\windows\system32\mfc71.dll


    7C340000[00056000]
      [ M] 99. c:\windows\system32\msvcr71.dll


    7C3A0000[0007B000]
      [ M] 100. c:\windows\system32\msvcp71.dll


    00B20000[0000E000]
      [ M] 95. c:\program files\rising\rav\rsappmgr.dll


    00B40000[00030000]
      [ M] 96. c:\program files\rising\rav\cfgdll.dll


    00EE0000[00066000]
      [ M] 179. c:\program files\rising\rav\rslog.dll


    00B80000[0001F000]
      [ M] 92. c:\program files\rising\rav\proccom.dll


    00F50000[00024000]
      [ M] 93. c:\program files\rising\rav\rscommx2.dll


    00F90000[00075000]
      [ M] 105. c:\program files\rising\rav\monrule.dll


    01020000[00013000]
      [ M] 180. c:\program files\rising\rav\hooksys.dll


    01180000[00013000]
      [ M] 181. c:\program files\rising\rav\hookreg.dll


    011E0000[00013000]
      [ M] 182. c:\program files\rising\rav\hookntos.dll


    01240000[0001C000]
      [ M] 183. c:\program files\rising\rav\rswalmon.dll


    02070000[00028000]
      [ M] 101. c:\program files\rising\rav\recomp.dll


    020B0000[00030000]
      [ M] 102. c:\program files\rising\rav\refs.dll


    020F0000[0001A000]
      [ M] 184. c:\program files\rising\rav\ffr.dll


pzbhallow - 2007-12-22 22:10:00
02320000[00020000]
      [ M] 185. c:\program files\rising\rav\rsstore.dll


    02550000[00013000]
      [ M] 186. c:\program files\rising\rav\hookcont.dll


    02580000[00027000]
      [ M] 187. c:\program files\rising\rav\fakescan.dll


    025C0000[00021000]
      [ M] 188. c:\program files\rising\rav\scanner.dll


    025F0000[0002C000]
      [ M] 103. c:\program files\rising\rav\viruslib.dll


    02730000[00027000]
      [ M] 104. c:\program files\rising\rav\relibldr.dll


    02BC0000[0000D000]
      [ M] 189. c:\program files\rising\rav\hookweb.dll


    03A20000[000D9000]
      [ M] 190. c:\program files\rising\rav\extfile.dll


    03B00000[00027000]
      [ M] 191. c:\program files\rising\rav\pearc.dll


    03B90000[00020000]
      [ M] 192. c:\program files\rising\rav\nvfile.dll


    13AB0000[00044000]
      [ M] 193. c:\program files\rising\rav\scanexec.dll


    05040000[002DC000]
      [ M] 194. c:\program files\rising\rav\unexe.dll


    05330000[0004A000]
      [ M] 195. c:\program files\rising\rav\scanex.dll


    03B50000[00035000]
      [ M] 196. c:\program files\rising\rav\scanpack.dll


    04390000[000B4000]
      [ M] 197. c:\program files\rising\rav\revm.dll


    04680000[00017000]
      [ M] 198. c:\program files\rising\rav\urutils.dll


    046B0000[00011000]
      [ M] 199. c:\program files\rising\rav\ur000.dat


    04B60000[00022000]
      [ M] 200. c:\program files\rising\rav\scansct.dll


    03770000[00036000]
      [ M] 201. c:\program files\rising\rav\scriptci.dll


    03910000[000FB000]
      [ M] 202. c:\program files\rising\rav\uroutine.dll



  + 00000624(1572) RavStub.exe
    00400000[00021000]
      [ M] 203. c:\program files\rising\rav\ravstub.exe


    10000000[0001F000]
      [ M] 92. c:\program files\rising\rav\proccom.dll


    00620000[00024000]
      [ M] 93. c:\program files\rising\rav\rscommx2.dll


    23700000[00028000]
      [ M] 94. c:\program files\rising\rav\rscommon.dll



  + 000006c0(1728) spoolsv.exe
    00AF0000[00008000]
      [AM] 88. c:\windows\system32\mdimon.dll


    00B00000[00008000]
      [ M] 204. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll


    00B10000[00005000]
      [ M] 205. c:\windows\system32\spool\prtprocs\w32x86\vprproc.dll



  + 0000077c(1916) svchost.exe

  + 00000790(1936) wdfmgr.exe
    01000000[0000C000]
      [AM] 6. c:\windows\system32\wdfmgr.exe



  + 000007c4(1988) Explorer.EXE
    00400000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll


    422B0000[005CD000]
      [AM] 51. c:\windows\system32\ieframe.dll


    01320000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    72C80000[00008000]
      [ M] 109. c:\windows\system32\msacm32.drv


    01B60000[0005B000]
      [AM] 61. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll


    02890000[0004C000]
      [ M] 206. c:\program files\common files\adobe\acrobat\activex\pdfshell.chs


    23700000[00028000]
      [ M] 94. c:\program files\rising\rav\rscommon.dll


    10000000[0001C000]
      [AM] 69. c:\windows\system32\ravext.dll



  + 00000814(2068) uphclean.exe
    00400000[00030000]
      [AM] 7. c:\program files\uphclean\uphclean.exe



  + 00000980(2432) conime.exe
    10000000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll



  + 00000a6c(2668) alg.exe

  + 00000cb0(3248) Maxthon.exe
    00400000[00228000]
      [AM] 87. d:\maxthon\maxthon.exe


    00380000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll


    10000000[00015000]
      [ M] 207. d:\maxthon\maxzlib.dll


    01920000[0000C000]
      [AM] 52. c:\windows\system32\xunleibho_v8.dll


    422B0000[005CD000]
      [AM] 51. c:\windows\system32\ieframe.dll


    03030000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    03250000[00028000]
      [ M] 153. c:\program files\rising\rav\ravscrch.dll


    04150000[0000B000]
      [ M] 208. d:\maxthon\services\realtime\real_time.dll


    30000000[002EF000]
      [ M] 167. c:\windows\system32\macromed\flash\flash9d.ocx


    72C80000[00008000]
      [ M] 109. c:\windows\system32\msacm32.drv


    06560000[004FD000]
      [ M] 166. c:\windows\system32\unispim6.ime


    08360000[001D0000]
      [ M] 209. c:\windows\system32\unispim5.ime


    3B030000[000A9000]
      [ M] 210. c:\windows\system32\imsc40a.ime



  + 00000cd0(3280) VnetClient.exe
    00400000[0004C000]
      [ M] 211. c:\program files\chinanet\vnetclient.exe


    10000000[0000D000]
      [ M] 212. c:\program files\chinanet\communicate.dll


    00380000[00077000]
      [ M] 213. c:\program files\chinanet\dialmodule.dll


    6BC40000[000F2000]
      [ M] 214. c:\program files\chinanet\mfc42.dll


    011E0000[0002D000]
      [ M] 215. c:\program files\chinanet\clientapi.dll


    01210000[00009000]
      [ M] 115. c:\windows\system32\normaliz.dll


    41D50000[00045000]
      [ M] 91. c:\windows\system32\iertutil.dll


    019F0000[00024000]
      [ M] 216. c:\program files\chinanet\plugincontainer.ocx


    01B90000[0000E000]
      [ M] 217. c:\program files\chinanet\sign.dll


    010D0000[00017000]
      [ M] 218. c:\program files\chinanet\advertise.ocx


    01100000[0005D000]
      [ M] 219. c:\program files\chinanet\vnetbs.ocx


    01160000[0000F000]
      [ M] 220. c:\program files\chinanet\bdsearch.ocx


    01170000[00012000]
      [ M] 221. c:\program files\chinanet\pagefram.ocx


    422B0000[005CD000]
      [AM] 51. c:\windows\system32\ieframe.dll


    02A50000[0001D000]
      [ M] 222. c:\program files\chinanet\accountpage.ocx


    02A70000[00027000]
      [ M] 223. c:\program files\chinanet\accountmgr.dll


    02AA0000[0004C000]
      [ M] 224. c:\program files\chinanet\vpndial.dll


    02C90000[000D3000]
      [ M] 225. c:\program files\chinanet\plugins\plugin002\smsmodule.ocx


    01EC0000[0002D000]
      [ M] 226. c:\program files\chinanet\plugins\plugin002\smscom.dll


    02F70000[00044000]
      [ M] 227. c:\program files\chinanet\plugins\plugin002\smsctrls.dll


    01F50000[00010000]
      [ M] 228. c:\program files\chinanet\icosbar.ocx


    030C0000[0004B000]
      [ M] 229. c:\program files\chinanet\vnetskin.ocx


    03110000[00085000]
      [ M] 230. c:\program files\chinanet\dialogstyle.dll


    033C0000[00028000]
      [ M] 231. c:\program files\chinanet\timer.ocx


    033F0000[00083000]
      [ M] 232. c:\program files\chinanet\pluginman.ocx


    034D0000[0005A000]
      [ M] 233. c:\program files\chinanet\newmessage.dll


    03490000[00011000]
      [ M] 234. c:\program files\chinanet\passctrl.dll


    03530000[0003B000]
      [ M] 235. c:\windows\system32\wpcap.dll


    034B0000[0000D000]
      [ M] 236. c:\windows\system32\pthreadvc.dll


    03570000[0000F000]
      [ M] 237. c:\windows\system32\packet.dll


    035B0000[00012000]
      [ M] 238. c:\program files\chinanet\plugpush.dll


    035E0000[0001A000]
      [ M] 239. c:\program files\chinanet\allinterface.dll


    03710000[00015000]
      [ M] 240. c:\program files\chinanet\vnetlogin.ocx


    03730000[00012000]
      [ M] 241. c:\program files\chinanet\statnum.dll


    03620000[00021000]
      [ M] 242. c:\program files\chinanet\vnetonlineupdate.ocx


    03650000[00063000]
      [ M] 243. c:\program files\chinanet\allfunctions.dll


    036C0000[00022000]
      [ M] 244. c:\program files\chinanet\vnetoptlog.dll


    03850000[0004A000]
      [ M] 245. c:\program files\chinanet\vnetsettings.ocx


    03700000[00009000]
      [ M] 246. c:\program files\chinanet\clientdll.dll


    038A0000[00010000]
      [ M] 247. c:\program files\chinanet\weather.ocx


    038B0000[0001B000]
      [ M] 90. c:\program files\rising\antispyware\ieprot.dll


    30000000[002EF000]
      [ M] 167. c:\windows\system32\macromed\flash\flash9d.ocx


    72C80000[00008000]
      [ M] 109. c:\windows\system32\msacm32.drv


    057B0000[00032000]
      [ M] 248. c:\program files\chinanet\base64.dll


    01360000[00028000]
      [ M] 153. c:\program files\rising\rav\ravscrch.dll


pzbhallow - 2007-12-23 9:39:00
顶一个
pzbhallow - 2007-12-23 9:39:00
顶一个
pzbhallow - 2007-12-23 9:39:00
顶一个
天月来了 - 2007-12-23 9:52:00
你有时间顶

没时间在这多看看贴??????

没见到除了SRENG日志以外,其他的日志都没人看吗???

扫SRENG日志发来
http://download.kztechs.com/files/sreng2.zip
下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把报告保存后以附件的形式发上来,把日志文件的扩展名“.log”改成“.txt”就可以发来了。
  或者直接将日志内容彻底复制到一个空记事本里,然后再保存,就可以发来了。
pzbhallow - 2007-12-23 9:55:00
终于有大虾回复了,呵呵
pzbhallow - 2007-12-23 10:06:00
下面是SREng扫描的日志
[CODE]

2007-12-23,09:45:17

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RTHDCPL><; RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <Alcmtr><; ALCMTR.EXE>  [(Verified)Microsoft Windows Publisher]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <AlcWzrd><; ALCWZRD.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <High Definition Audio Property Page Shortcut><; HDAShCut.exe>  [(Verified)Microsoft Windows Publisher]
    <HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IgfxTray><; C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <SoundMan><; SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
    <ISUSPM><"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler>  [N/A]
    <Adobe Reader Speed Launcher><"D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <DHTray><C:\WINDOWS\system32\DHTray.exe>  []
    <A0380mon><C:\WINDOWS\system32\A0380mon.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Anti Trojan Elite><; D:\Program Files\Anti Trojan Elite\TJEnder.exe>  [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><; internat.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <TrojanScanner><; D:\Program Files\Trojan Remover\Trjscan.exe>  [N/A]
    <yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [N/A]
    <YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [N/A]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\new\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\Tencent\qq\QQ.exe [TENCENT]><N>

天月来了 - 2007-12-23 10:19:00
以附件形式发来

否则不想看,也没工夫复制。
pzbhallow - 2007-12-23 10:25:00
好的,在主题中,复制都粘贴不上来,折腾了半天,还是放到主题贴里面去了,拜托
baohe - 2007-12-23 10:36:00
【回复“pzbhallow”的帖子】
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<DHTray><C:\WINDOWS\system32\DHTray.exe> []
<A0380mon><C:\WINDOWS\system32\A0380mon.exe> []

用IceSword强制删除上述两个加载项指向的程序。用SRENG删除这两个加载项。

清理一下“浏览器加载项”(没必要保留那么多)。
天月来了 - 2007-12-23 10:41:00
————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里面找下面项目删除:
启动项目
注册表
    <DHTray><C:\WINDOWS\system32\DHTray.exe>  []
    <A0380mon><C:\WINDOWS\system32\A0380mon.exe>  []
————————————————————————————
在扫日志的SRENG工具》启动项目》服务》Win32服务应用程序》里面找下面各项,将启动类型改为“Disabled”
==================================
服务
[Clipboard / License][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\spted.dll><N/A>
下面这个不认识,你自己看看吧。
[MATLAB Server / matlabserver][Stopped/Auto Start]
  <D:\MATLAB6p5\webserver\bin\win32\matlabserver.exe><N/A>
————————————————————————————————————
在扫日志的SRENG工具》启动项目》服务》驱动程序》里面找下面各项,将启动类型改为“Disabled”
==================================
驱动程序
[New0 / New0][Stopped/Auto Start]
  <\??\C:\WINDOWS\system32\new.sys><N/A>
[Netgroup Packet Filter / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>

————————————————————————————————————
再重启电脑,升级杀毒软件至最新版本全盘杀毒。

既然那么喜欢浏览器里留东西,那我改了吧。
pzbhallow - 2007-12-23 11:39:00
谢谢,处理中
gwlucker - 2007-12-23 12:21:00
引用:
【天月来了的贴子】————————————————————————————————————
  ==================================
下面这个不认识,你自己看看吧。
[MATLAB Server / matlabserver][Stopped/Auto Start]
  <D:\MATLAB6p5\webserver\bin\win32\matlabserver.exe><N/A>
————————————————————————————————————
==================================
驱动程序
—————————————————————————————
浏览器加载项
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[]
  {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
………………


matlab是做数据处理了,楼主要是自己的机器应该知道吧。

浏览器里的KUGOO都不放过...够狠- -#~跟我有的拼~
pzbhallow - 2007-12-23 12:24:00
matlab当然是没问题了,我就是靠这个混饭吃,不过kugoo3我还真有点不放心,从第一次使用的时候机子就出问题,不知道是巧合还是?反正现在音乐播放器也多,
gwlucker - 2007-12-23 12:27:00
其实那个就是浏览器加载的插件,实现一些辅助功能,可有可无,一般我都删除,就留个下载工具插件,让IE干净点~
pzbhallow - 2007-12-23 21:04:00
已经把kugoo的这个插件搞定了,小菜鸟谢谢各位大虾们的帮助。结束了那两个不明进程,瑞星防火墙也重新安装修复了,只是还是不能在线观看电影,郁闷中
1
查看完整版本: 【求助】瑞星防火墙文件被损坏,自动关机,不明进程A0380mon.exe,有日志