瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】所有.exe文件都不能用,开机后瑞星监控自动退出,怎么办啊?

1   1  /  1  页   跳转

【求助】所有.exe文件都不能用,开机后瑞星监控自动退出,怎么办啊?

【求助】所有.exe文件都不能用,开机后瑞星监控自动退出,怎么办啊?

请大家帮帮我啦~~~~
最后编辑2007-04-18 22:57:21
分享到:
gototop
 

去下载sreng2,关闭qq,下载软件等一切不必要的程序后扫个日志上来,一次贴不完分段贴,不要修改
http://www.kztechs.com/sreng/sreng2.zip
gototop
 

用威金专杀实施
gototop
 

【回复“水树雨下”的帖子】
下载了,可是怎么扫描日志啊?偶不会啊?
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <xlh33g98ug><C:\WINDOWS\svch0st.exe>  [N/A]
    <iqq3><C:\DOCUME~1\ll\LOCALS~1\Temp\crasos.exe>  []
    <b35ig5ce01et><C:\DOCUME~1\ll\LOCALS~1\Temp\1explore.exe>  []
    <EXPLORER><C:\Program Files\Common Files\System\wab32res.exe>  []
    <2fjz12ujb><C:\DOCUME~1\ll\LOCALS~1\Temp\c0nime.exe>  []
    <0><C:\DOCUME~1\ll\LOCALS~1\Temp\rundl132.exe>  [N/A]
    <9j966izxdmm><C:\DOCUME~1\ll\LOCALS~1\Temp\iexpl0re.exe>  []
    <eMuleAutoStart><; D:\软件程序\电驴\eMule\emule.exe -AutoStart>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <zBrowser Launcher><C:\Program Files\Logitech\iTouch\iTouch.exe>  [Logitech Inc.                    ]
    <EM_EXEC><C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE>  [Logitech Inc.                    ]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <CONFIG><C:\WINDOWS\1.exe>  [N/A]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <NeroFilterCheck><; C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe>  [Nero AG]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><EXPLORER.EXE>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
[QQ游戏启动加速程序]
  <C:\Documents and Settings\ll\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> D:\应用文件\新建文~1\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><N>

==================================
服务
[C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start]
  <C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[Media Player of Remote Control / MPservices][Stopped/Auto Start]
  <C:\WINDOWS\system32\drivers\mpupdate.sys><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
  <C:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>

==================================
驱动程序
[Service for Avance AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CdaC15BA / CdaC15BA][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd>
[Cdsys / Cdsys][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\cdcd.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[usb Card Device 1000 / ft1kEnum][Running/Manual Start]
  <system32\DRIVERS\ic1kenum.sys><OEM Corporation>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[iTouch Keyboard Filter / itchfltr][Stopped/Manual Start]
  <system32\DRIVERS\itchfltr.sys><Logitech Inc.>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[Logitech PS/2 Mouse Filter Driver / l8042pr2][Running/Manual Start]
  <system32\DRIVERS\L8042Pr2.sys><Logitech>
[Logitech USB Filter Driver / LCcfltr][Running/Manual Start]
  <system32\drivers\lccfltr.sys><Logitech>
[Logitech HID/USB Mouse Filter Driver / LHidFlt2][Running/Manual Start]
  <system32\DRIVERS\LHidFlt2.sys><Logitech>
[Logitech USB Receiver device driver / LHidUsb][Running/Manual Start]
  <system32\drivers\lhidusb.sys><Logitech>
[Logitech Keyboard Class Filter Driver / LKbdFlt2][Running/Manual Start]
  <system32\DRIVERS\LKbdFlt2.sys><Logitech>
[Logitech Mouse Class Filter Driver / LMouFlt2][Running/Manual Start]
  <system32\DRIVERS\LMouFlt2.sys><Logitech>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\应用文件\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkcusb / npkcusb][Running/Auto Start]
  <\??\D:\应用文件\npkcusb.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[USB SmartCard Reader Device 1000  / Reader_1000][Running/Manual Start]
  <system32\DRIVERS\usbic1k.sys><OEM>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Sense3 / Sense3][Running/Auto Start]
  <System32\Drivers\sense3.sys><Beijing Senselock>
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[SVKP / SVKP][Running/Auto Start]
  <\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[usb driver for epass1k / token1k][Stopped/Manual Start]
  <system32\DRIVERS\eps1k.sys><OEM>
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT