本人在用电脑时突然关机自动重启,然后瑞星就不见了,显示文件被损坏用什么chkdsk来修复,并且在桌面上也找不到瑞星杀毒软件了,但是瑞星防火墙能正常运行及升级。我就准备重新安装,但是在安装途中也被显示损坏文件(附图),我在瑞星的安装目录里面找到一个文件夹,发现那个文件里面有36G的文件(附图),但我C盘总共才20G。我想用系统还原也不行了,想在安全模式下运行安装也不行。我也用了SREngPS.EXE扫描和瑞星听诊器,现将这些文件发给你们,你们帮我想下办法,谢谢!!
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\NVAPI.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\TASKMGR.EXE
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
RSHIDE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_CTRL.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RFW\UNVDET.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\PROGRAM FILES\RISING\RFW\RFWPROXY.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RFW\MONMID.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\PROGRAM FILES\RISING\RFW\RFWSTUB.EXE
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\PDFSHELL.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\PDFSHELL.CHS
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\NVAPI.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\HPBMMON.DLL
C:\WINDOWS\SYSTEM32\HPPAMON0.DLL
C:\WINDOWS\SYSTEM32\HPDOMON.DLL
C:\WINDOWS\SYSTEM32\HPBHEALR.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\IMFPRINT.DLL
C:\WINDOWS\SYSTEM32\IMF32.DLL
C:\WINDOWS\SYSTEM32\ZTAG32.DLL
C:\WINDOWS\SYSTEM32\ZSPOOL.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
RSHIDE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\DOCUME~1\JIMMY\LOCALS~1\TEMP\RSV1A.TMP
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.2)附件:
646434200841212040.jpg