瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 瑞星监控变红伞了启动不了~~麻烦帮我看下日志

12   1  /  2  页   跳转

瑞星监控变红伞了启动不了~~麻烦帮我看下日志

瑞星监控变红伞了启动不了~~麻烦帮我看下日志

2006-09-29,17:13:59

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <Super Rabbit IEPro><; C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  []
    <Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe>  []
    <stonedrv><>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <rx><C:\WINDOWS\System32\explore.exe>  []
    <zz><C:\WINDOWS\System32\intenet.exe>  []
    <wow><C:\WINDOWS\System32\Launcher.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><; nwiz.exe /install>  []
    <kpcdst><; G:\豪杰超级解霸\金山影霸2003\安装\cdsprite.exe>  [金山软件股份有限公司]
    <WinampAgent><; C:\Program Files\Winamp\winampa.exe>  []
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe>  []
    <RichMedia><C:\WINDOWS\System32\Rundll32.exe  "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows>  [Shanghai Henbang Technology Co., Ltd]
    <stonedrv><>  []
    <SoundMam><C:\WINDOWS\System32\SVOHOST.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><E:\GAMES\疯狂赛车\data\GUI\mov\kartss.scr>  []

==================================
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[AntiVir PersonalEdition Premium MailGuard / AntiVirMailService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe><N/A>
[AntiVir PersonalEdition Premium Scheduler / AntiVirScheduler]
  <C:\Program Files\AntiVir PersonalEdition Premium\sched.exe><Avira GmbH>
[AntiVir PersonalEdition Premium Guard / AntiVirService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe><AVIRA GmbH>
[AntiVir PersonalEdition Premium MailGuard helper service / AVEService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe><Avira GmbH>
[BlueSoleil Hid Service / BlueSoleil Hid Service]
  <C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
  <C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe><SEIKO EPSON CORPORATION>
[GrayPigeon / GrayPigeon]
  <C:\WINDOWS\H><N/A>
[KSD2Service / KSD2Service]
  <C:\WINDOWS\System32\SVCH0ST.exe><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Ulead Burning Helper / UleadBurningHelper]
  <C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>

==================================
浏览器加载项
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[XBTP03129 Class]
  {6029B367-250A-4696-925C-641709CA7381} <C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL, IE Toolbar>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, N/A>
[XBTP03129 Class]
  {B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3} <C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL, IE Toolbar>
[isObject Class]
  {BE0B5843-553A-48C2-9A42-258A1D791AFC} <C:\PROGRA~1\pcast\hbcast.dll, Shanghai Henbang Technology Co., Ltd>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[MSN]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <G:\FLASHGET\fgiebar.dll, Amaze Soft>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, N/A>
[SearchCar]
  {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\SearchCar\SearchCar.dll, IE Toolbar>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\WINDOWS\DOWNLO~1\POWERP~1.DLL, PPStream Inc.>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <G:\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <G:\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 800][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 856][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 880][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 924][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 936][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1096][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1160][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1284][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1312][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1368][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 33>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 2016][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\Rsvtub.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\myztr.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\sfc_os.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\mywow.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\myrx.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.8198>
    [C:\WINDOWS\System32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.8198>
    [C:\WINDOWS\System32\nvshell.dll]  <N/A><N/A>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Sony Ericsson\Mobile\File Manager\fmgrguil.dll]  <Sony Ericsson Mobile Communications AB><1, 1, 1, 1>
[PID: 188][C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe]  <N/A><N/A>
[PID: 224][C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe]  <SEIKO EPSON CORPORATION><2, 3, 0, 0>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\WINDOWS\System32\EBAPI2.DLL]  <SEIKO EPSON CORPORATION><1, 4, 0, 0>
    [C:\Program Files\Common Files\EPSON\EBAPI\EBPLPT.DLL]  <SEIKO EPSON CORPORATION><2, 26, 0, 0>
[PID: 432][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
最后编辑2006-09-30 15:54:11
分享到:
gototop
 

[PID: 448][C:\WINDOWS\System32\SVCH0ST.exe]  <N/A><N/A>
[PID: 468][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8198>
[PID: 564][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe]  <Ulead Systems, Inc.><1, 0, 0, 4>
[PID: 712][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
[PID: 720][C:\WINDOWS\System32\Realplayer.exe]  <N/A><N/A>
[PID: 736][C:\WINDOWS\System32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\PROGRA~1\pcast\hbcast.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 8>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 744][C:\WINDOWS\System32\SVOHOST.exe]  <N/A><N/A>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 288][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
[PID: 1140][C:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
[PID: 1464][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 52>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
[PID: 1588][C:\Program Files\rising\Rav\RavMon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
[PID: 1816][C:\Program Files\Tencent\qq\QQ.exe]  <TENCENT><14, 27, 0, 082>
    [C:\Program Files\Tencent\qq\CoralAssist.DLL]  <N/A><4.0.0 Build 20051112>
    [C:\Program Files\Tencent\qq\CoralQQ.DLL]  <Coral Team><4.0.0 Build 20051112>
    [C:\Program Files\Tencent\qq\IPSearcher.dll]  <><1.0.0.3>
    [C:\Program Files\Tencent\qq\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QQHelperDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\BasicCtrlDll.dll]  <Tencent><0, 3, 3, 6>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\LoginCtrl.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QQAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [C:\Program Files\Tencent\qq\npkcntc.dll]  <INCA Internet Co., Ltd.><2005, 9, 1, 1>
    [C:\Program Files\Tencent\qq\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [C:\Program Files\Tencent\qq\QQRes.dll]  <tencent><1, 0, 0, 1>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\Program Files\Tencent\qq\QQMainFrame.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\CQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\NewSkin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\HostingMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\MailSummary.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\QQSysMsgMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QRingMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\PhoneAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [C:\Program Files\Tencent\qq\QQAvatar.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [C:\Program Files\Tencent\qq\LongConnection.dll]  <tencent><0, 3, 3, 8>
    [C:\Program Files\Tencent\qq\QQPet.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\Program Files\Tencent\qq\QQPlugin.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\Program Files\Tencent\qq\QQGroupMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QQAllInOne.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\CameraDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\SCCore.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\QQCustomFace.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\BQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [C:\Program Files\Tencent\qq\CommercesMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\qq\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [C:\Program Files\Tencent\qq\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
    [C:\Program Files\Tencent\qq\QQSceneMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
    [C:\WINDOWS\System32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [C:\Program Files\Tencent\qq\GroupConnection.dll]  <Tencent><0, 3, 3, 5>
[PID: 144][C:\Program Files\Tencent\qq\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 828][C:\Program Files\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 42>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
[PID: 3388][G:\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

有没有人帮我看看
感谢
gototop
 

C:\WINDOWS\System32\explore.exe>  毒
gototop
 

我删了还是没用 重扫了份 麻烦再帮我看看 谢谢


2006-09-29,20:51:46

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <Super Rabbit IEPro><; C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  []
    <Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe>  []
    <stonedrv><>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <rx><C:\WINDOWS\System32\explore.exe>  []
    <zz><C:\WINDOWS\System32\intenet.exe>  []
    <wow><C:\WINDOWS\System32\Launcher.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><; nwiz.exe /install>  []
    <kpcdst><; G:\豪杰超级解霸\金山影霸2003\安装\cdsprite.exe>  [金山软件股份有限公司]
    <WinampAgent><; C:\Program Files\Winamp\winampa.exe>  []
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe>  []
    <RichMedia><C:\WINDOWS\System32\Rundll32.exe  "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows>  [Shanghai Henbang Technology Co., Ltd]
    <stonedrv><>  []
    <SoundMam><C:\WINDOWS\System32\SVOHOST.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><E:\GAMES\疯狂赛车\data\GUI\mov\kartss.scr>  []

==================================
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[AntiVir PersonalEdition Premium MailGuard / AntiVirMailService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe><N/A>
[AntiVir PersonalEdition Premium Scheduler / AntiVirScheduler]
  <C:\Program Files\AntiVir PersonalEdition Premium\sched.exe><Avira GmbH>
[AntiVir PersonalEdition Premium Guard / AntiVirService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe><AVIRA GmbH>
[AntiVir PersonalEdition Premium MailGuard helper service / AVEService]
  <C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe><Avira GmbH>
[BlueSoleil Hid Service / BlueSoleil Hid Service]
  <C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
  <C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe><SEIKO EPSON CORPORATION>
[GrayPigeon / GrayPigeon]
  <C:\WINDOWS\H><N/A>
[KSD2Service / KSD2Service]
  <C:\WINDOWS\System32\SVCH0ST.exe><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Ulead Burning Helper / UleadBurningHelper]
  <C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>

==================================
浏览器加载项
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[XBTP03129 Class]
  {6029B367-250A-4696-925C-641709CA7381} <C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL, IE Toolbar>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, N/A>
[XBTP03129 Class]
  {B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3} <C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL, IE Toolbar>
[isObject Class]
  {BE0B5843-553A-48C2-9A42-258A1D791AFC} <C:\PROGRA~1\pcast\hbcast.dll, Shanghai Henbang Technology Co., Ltd>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[MSN]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <G:\FLASHGET\fgiebar.dll, Amaze Soft>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, N/A>
[SearchCar]
  {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\SearchCar\SearchCar.dll, IE Toolbar>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\WINDOWS\DOWNLO~1\POWERP~1.DLL, PPStream Inc.>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <G:\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <G:\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 800][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 856][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 880][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 924][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 936][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1096][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1160][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1288][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 1312][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1352][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 33>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 180][C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe]  <N/A><N/A>
[PID: 172][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\Rsvtub.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\myrx.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\sfc_os.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\mywow.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.8198>
    [C:\WINDOWS\System32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.8198>
    [C:\WINDOWS\System32\nvshell.dll]  <N/A><N/A>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Sony Ericsson\Mobile\File Manager\fmgrguil.dll]  <Sony Ericsson Mobile Communications AB><1, 1, 1, 1>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Herosoft\Hero Video Convert\VCvtShell.dll]  <N/A><N/A>
    [C:\Herosoft\Hero Video Convert\VCvtS936.dll]  <N/A><N/A>
[PID: 248][C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe]  <SEIKO EPSON CORPORATION><2, 3, 0, 0>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\WINDOWS\System32\EBAPI2.DLL]  <SEIKO EPSON CORPORATION><1, 4, 0, 0>
    [C:\Program Files\Common Files\EPSON\EBAPI\EBPLPT.DLL]  <SEIKO EPSON CORPORATION><2, 26, 0, 0>
[PID: 448][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
[PID: 472][C:\WINDOWS\System32\SVCH0ST.exe]  <N/A><N/A>
[PID: 496][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8198>
[PID: 612][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe]  <Ulead Systems, Inc.><1, 0, 0, 4>
[PID: 412][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 784][C:\WINDOWS\System32\Realplayer.exe]  <N/A><N/A>
[PID: 792][C:\WINDOWS\System32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\PROGRA~1\pcast\hbcast.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 8>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 808][C:\WINDOWS\System32\SVOHOST.exe]  <N/A><N/A>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 988][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1192][C:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1568][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 52>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1604][C:\Program Files\rising\Rav\RavMon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1348][C:\Program Files\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 42>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 528][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1140][G:\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
    [C:\WINDOWS\System32\winscok.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\avsda.dll]  <H+BEDV Datentechnik GmbH><06.30.00.02>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

<Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe> []
参考置顶,下载专杀

打开SREng 启动项目 注册表,删除
<rx><C:\WINDOWS\System32\explore.exe> []
<zz><C:\WINDOWS\System32\intenet.exe> []
<wow><C:\WINDOWS\System32\Launcher.exe> []
<RichMedia><C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows> [Shanghai Henbang Technology Co., Ltd]
<stonedrv><> []
<SoundMam><C:\WINDOWS\System32\SVOHOST.exe> []


<Userinit><userinit.exe,>编辑成<Userinit><C:\WINDOWS\System32\userinit.exe,>

启动项目 服务WIN32  删除
[GrayPigeon / GrayPigeon]
<C:\WINDOWS\H><N/A>
[KSD2Service / KSD2Service]
<C:\WINDOWS\System32\SVCH0ST.exe><N/A>

重启 安全模式下,删除
C:\WINDOWS\System32\explore.exe
C:\WINDOWS\System32\intenet.exe
C:\WINDOWS\System32\Launcher.exe
C:\WINDOWS\System32\SVOHOST.exe
C:\WINDOWS\H
C:\WINDOWS\System32\SVCH0ST.exe


控制面版把RichMedia卸掉
gototop
 

可怜的孩子的机器被摧残了..
gototop
 

非常感谢
<Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe> []

请问这个要下哪一个专杀啊
gototop
 

置顶,7939那个帖子
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT