瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 越来越不河蟹了啊!开不了机!新问题详见15、16楼!跪谢!【求助】

123   2  /  3  页   跳转

越来越不河蟹了啊!开不了机!新问题详见15、16楼!跪谢!【求助】

[&使用超级旋风下载]
  <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
  <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[Alexa Web Search]
  <http://client.alexa.com/holiday/script/actions/search.htm, N/A>
[Get Alexa Data]
  <http://client.alexa.com/holiday/script/actions/sitedata.htm, N/A>
[Mail to a Friend...]
  <http://client.alexa.com/holiday/script/actions/mailto.htm, N/A>
[See Related Links]
  <http://client.alexa.com/holiday/script/actions/related.htm, N/A>
[Write a Review...]
  <http://client.alexa.com/holiday/script/actions/review.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>

==================================
正在运行的进程
[PID: 432 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WgaLogon.dll]  [Microsoft Corporation, 1.7.0018.5]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 732 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 788 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 844 / SYSTEM][D:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 27]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 860 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 960 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 1000 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 1016 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.59]
    [D:\PROGRAM FILES\RISING\RAV\BWList.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.4]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\PROGRAM FILES\RISING\RAV\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.27]
    [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.24]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
    [D:\PROGRAM FILES\RISING\RAV\Hooksys.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 7]
    [D:\PROGRAM FILES\RISING\RAV\HookReg.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\HookNtos.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\rswalmon.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 20]
    [D:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.8]
    [D:\Program Files\Rising\Rav\fakescan.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.13]
    [D:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.33]
    [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.2]
    [D:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 7]
    [D:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
    [D:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
    [D:\Program Files\Rising\Rav\ffr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Rising\Rav\nvfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Rising\Rav\scanexec.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
    [D:\Program Files\Rising\Rav\unexe.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Rising\Rav\scanex.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
    [D:\Program Files\Rising\Rav\pearc.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Rising\Rav\scanpack.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Rising\Rav\revm.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 7]
    [D:\Program Files\Rising\Rav\uroutine.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18]
    [D:\Program Files\Rising\Rav\scriptci.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 2]
    [D:\Program Files\Rising\Rav\scansct.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6]
[PID: 1100 / SYSTEM][d:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 7.0.0.47]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rfw\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [d:\program files\rising\rfw\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.13]
    [d:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.12]
    [d:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.39]
    [d:\program files\rising\rfw\psapi.dll]  [Microsoft Corporation, 4.00]
    [d:\program files\rising\rfw\ijt_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 7, 0, 0, 0]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
    [d:\program files\rising\rfw\unvdet.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.5]
    [d:\program files\rising\rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 1348 / SYSTEM][d:\program files\rising\rfw\rfwstub.exe]  [Beijing Rising Technology Co., Ltd., 7.0.0.9]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[PID: 1560 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.9]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
    [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[PID: 1652 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.8]
gototop
 

[d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
[PID: 228 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1520 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\sqmapi32.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll]  [N/A, ]
    [C:\Program Files\Media Player Classic\Codecs\mkunicode.dll]  [N/A, ]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [C:\WINDOWS\system32\xunleibho_v14.dll]  [Thunder Networking Technologies,LTD, 4, 6, 0, 62]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 12]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 13]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll]  [Sony Ericsson Mobile Communications AB, 1, 3, 11, 0]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrguil.dll]  [Sony Ericsson Mobile Communications AB, 1, 3, 4, 0]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.16]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
    [C:\Program Files\TENCENT\SSPlus\SAddr.dll]  [Tencent, 5, 0, 1, 18]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 44]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 2076 / Administrator][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 7.0.1.32]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 79]
    [D:\Program Files\Rising\Rfw\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [d:\program files\rising\rfw\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [d:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.7]
    [d:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
    [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.13]
[PID: 2520 / Administrator][C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe]  [Sony Ericsson Mobile Communications AB, 1.1.1.3]
    [C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll]  [Teleca/Popwire AB, 1, 0, 2, 3]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll]  [N/A, ]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application LauncherLg.dll]  [Sony Ericsson Mobile Communications AB, 1.0.4.1]
    [C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application LauncherBmp.dll]  [Sony Ericsson Mobile Communications AB, 1.0.3.7]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll]  [Teleca Software Solutions, 1, 0, 1, 1]
[PID: 2592 / Administrator][D:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.20]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[PID: 2612 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
[PID: 2692 / Administrator][D:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.98]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 7]
    [D:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
    [D:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
    [D:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\Program Files\Rising\Rav\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.24]
    [D:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Rising\Rav\Rsguilib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 79]
    [D:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 3008 / Administrator][C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe]  [Teleca Software Solutions AB, 0.0.1.48]
    [C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll]  [Teleca/Popwire AB, 1, 0, 2, 3]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll]  [N/A, ]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9848.0]
gototop
 

[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 3976 / Administrator][C:\Program Files\Common Files\Teleca Shared\Generic.exe]  [Teleca Software Solutions, 1, 0, 3, 2]
    [C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll]  [Teleca/Popwire AB, 1, 0, 2, 3]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll]  [N/A, ]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9848.0]
    [C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll]  [Teleca Software Solutions, 1, 0, 1, 1]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\Program Files\Sony Ericsson\Mobile2\Device Manager\SpecificMPM.dll]  [SonyEricsson, 1, 0, 2, 1]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll]  [N/A, ]
    [C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll]  [Popwire AB, 1, 2, 1, 1]
    [C:\Program Files\Common Files\Teleca Shared\tlib_log.dll]  [Popwire AB, 1, 0, 3, 3]
    [C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll]  [N/A, ]
[PID: 208 / Administrator][C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe]  [Sony Ericsson Mobile Communications AB, 1, 2, 0,1183]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,115]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll]  [N/A, ]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cellphone_object.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,1187]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsmoddata.dll]  [Sony Ericsson Mobile Communications AB, 1, 2, 0,302]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_object.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,938]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_object.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,983]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_object.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,995]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9848.0]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,1219]
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\xpbtsock_2_object.dll]  [Sony Ericsson Mobile Communications AB, 1, 0, 0,131]
[PID: 2072 / Administrator][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
[PID: 3592 / Administrator][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3080 / Administrator][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE]  [Microsoft Corporation, 11.0.6359]
    [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll]  [Microsoft Corporation, 11.0.6360]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll]  [Microsoft Corporation, 5.50.99.2009]
    [D:\Program Files\Rising\Rav\RsPlugIn.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.17]
    [C:\PROGRA~1\MICROS~2\OFFICE11\ADDINS\SYMINPUT.DLL]  [Microsoft Corporation, 1.02]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9690]
    [C:\WINDOWS\system32\VB6CHS.DLL]  [Microsoft Corporation, 6.00.8169]
    [C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL]  [Microsoft Corporation, 1.1.6215]
    [C:\Program Files\Common Files\Microsoft Shared\PROOF\mslid.dll]  [Microsoft Corporation, 1.0.2305]
    [C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL]  [Microsoft Corporation, 3.1.2303]
    [C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 3116 / Administrator][D:\Program Files\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\jratl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dthxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\dh3atl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qqhxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wdatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\gjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zxatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wmatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\tlatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\qjatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\myatl.dll]  [N/A, ]
    [C:\WINDOWS\system32\zhtuatl.dll]  [N/A, ]
    [D:\Program Files\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAPI Tcpip [TCP/IP]
    C:\WINDOWS\system32\sqmapi32.dll(, N/A)
MSAPI Tcpip [TCP/IP]
    C:\WINDOWS\system32\sqmapi32.dll(, N/A)
MSAPI Tcpip [UDP/IP]
    C:\WINDOWS\system32\sqmapi32.dll(, N/A)

==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[D:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[E:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[F:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe

==================================
HOSTS 文件
N/A

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2520, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\APPLICATION LAUNCHER\APPLICATION LAUNCHER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3008, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\CAPABILITYMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3976, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\GENERIC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 208, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\MOBILE PHONE MONITOR\EPMWORKER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3592, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

好长啊```呼呼 

谢谢
gototop
 

C:\SVCHOST.exe请把这文件发到我邮箱,(szzlblm@qq.com)

用XDelBox删除以下文件:
(http://www.dodudou.com/down/download.php?fname=./01.原创软件/XDelBox1.6.rar)使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\daso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fyso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jtso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wgso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wmso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wdso.exe
[C:\WINDOWS\system32\jratl.dll
[C:\WINDOWS\system32\dthxatl.dll
[C:\WINDOWS\system32\dh3atl.dll
[C:\WINDOWS\system32\qqhxatl.dll
[C:\WINDOWS\system32\wdatl.dll
[C:\WINDOWS\system32\gjatl.dll
[C:\WINDOWS\system32\wlatl.dll
[C:\WINDOWS\system32\zxatl.dll
[C:\WINDOWS\system32\wmatl.dll
[C:\WINDOWS\system32\tlatl.dll
[C:\WINDOWS\system32\qjatl.dll
[C:\WINDOWS\system32\myatl.dll
[C:\WINDOWS\system32\zhtuatl.dll
C:\windows\system32\com\comrepl32.exe
C:\WINDOWS\system32\nwizzhuxians.exe
C:\WINDOWS\system32\rarjapi.dll
C:\WINDOWS\system32\sqmapi32.dll
C:\SVCHOST.exe
D:\SVCHOST.exe
E:\SVCHOST.exe
F:\SVCHOST.exe
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf

打开SREng->启动项目->注册表->删除以下启动项目
<tlsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\daso.exe> [N/A]
<ztsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso.exe> [N/A]
<mhsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso.exe> [N/A]
<wosa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso.exe> [N/A]
<fysa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wdso.exe> [N/A]
<comrepl32><C:\windows\system32\com\comrepl32.exe> []
<N/A><C:\WINDOWS\system32\nwizzhuxians.exe> [N/A]

编辑<AppInit_DLLs><rarjapi.dll>
为<AppInit_DLLs><>

SRE->系统修复->winsock供应者->重置
gototop
 


谢谢 但是下载的XDelBox解不了压 以上的步骤用文本形式复制过去也打不开
winword.exe应用程序出错,
应用程序正常初始化(0XC0000005)失败

越来越不河蟹了啊啊啊~~~~
gototop
 

今天准备在安全模式下杀个毒的,但是连机都开不了了啊!!!
正常开机也开不了啊 啊啊
显示器蓝屏,说的是:
C0000135 Unknown Hard Error
到底该怎么办啊```各位帮帮我吧 OTZ!!!!!!
gototop
 

重装吧
gototop
 

重装新系统至少必须格了C盘(如果不想全格的话)。

切记!

在新系统进入的第一次,绝对不能打开任何磁盘。绝对不能使用原机任何文件。

只能连网,去下载WinRAR安装后,用WinRAR打开各盘,删除根目录下的两个文件:
Autorun.inf
SVCHOST.exe

然后重启电脑,再去网络上下载瑞星或江民的2008版的免费杀毒软件,安装后立即升级至最新版本,全盘杀毒。

还是那句话,不全格磁盘,就绝不能在全盘杀毒前使用原机任何文件和打开任何磁盘。


gototop
 

没有其他办法了吗?到底是怎么回事啊?
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT