1   1  /  1  页   跳转

........瑞星,你是什么?

........瑞星,你是什么?

瑞星,我是正版单机用户,这2天电脑不正常,瑞星不能随开机启动,而鼠标漏斗也永远是在读取状态,进程也显示cpu使用100%,桌面状态也经常弹跳弹窗。升级最新版本杀了N遍,问题解决不了,故2005年8月22日9点30几分来电话给你82678800客服求助,客服声音一来懒洋洋,以生厌恶,告诉对方问题后,建议下载瑞星听诊器,我多问了句,为什么有病毒瑞星杀不了?如果听诊器处理完还是解决不了,怎么办,对方说,你明白不明白,这是插件,我答,我就是不明白啊,对方答,你明白不明白,这是插件,我们不负责,态度恶劣,莫名其妙,我做错了什么,这么大声教训我?我电话:13641124132 黄东海
最后编辑2005-08-23 13:45:04
分享到:
gototop
 

bbbbbbbbbbbbbb
gototop
 

汗...客服的确可怕.

请您用hijackthis1.99.1版把日志贴上来.此工具在本版置顶贴中提供下载.
gototop
 

瑞星的客副是捣糨糊,害得我被客户骂,靠,明明才40。43解决不了问题,给我说已经出41了,让我去下,神经
gototop
 

那些客服一天到晚像别人欠他们钱一样
支持楼主

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-8-22 13:00:41
描述:



gototop
 

请花先生帮我也分析一下我的日志“
Logfile of HijackThis v1.99.1
Scan saved at 8:32:37, on 2005-8-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bgswitch.exe
C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\QQexternal.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\HSRT_KT\桌面\少用程序快捷方式\系统日志扫描\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\YiSou\yisou.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [桌面图标文字自动透明] C:\Program Files\Wom\WinMem.exe XP
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe"
O4 - HKLM\..\Run: [CApp] C:\WINDOWS\system32\capp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [MSCalsClocks] C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Kugoo] I:\Program Files\KuGoo2\KuGoo.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: !搜一搜(&S) - res://C:\Program Files\YiSou\yisou.dll/232
O8 - Extra context menu item: 使用Kugoo下载 - I:\Program Files\KuGoo2\KugooDownX.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\HF\浩方对战平台\GameClient.exe
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://tomatolei.com (file missing)
O9 - Extra button: 网际飞音 - {8E4E4123-AAC7-42CA-AF1B-68CE70B8D385} - C:\Program Files\Donor\donor.exe
O9 - Extra 'Tools' menuitem: 网际飞音(&D) - {8E4E4123-AAC7-42CA-AF1B-68CE70B8D385} - C:\Program Files\Donor\donor.exe
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\Sw2005_SP0_licenses\SolidWorks SolidNetWork License Manager\lmgrd.exe

gototop
 

自启动项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Currentversion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
SysExplr = C:\Herosoft\HeroV8\SYSEXPLR.EXE
SoundMax = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
dl_accel = C:\Program Files\3721\Dlaccel\YDownloader.exe
RfwMain = "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
thunder_mini = C:\Program Files\Sandai\ThunderMini\ThunderMini.exe
helper.dll = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
YDTMain.exe = C:\PROGRA~1\ydt\YDTMain.exe
advapi32 = RUNDLL32 C:\WINDOWS\Downlo~1\_IS_0518\_IS_ISC.DLL,isc

HKEY_CURRENT_USER Software\Microsoft\Windows\Currentversion\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Currentversion\RunOnce
RavStub = "C:\PROGRAM FILES\RISING\RAV\ravstub.exe" /RUNONCE

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shell32.dll =
shell32.dll =

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WebCheck = %SystemRoot%\system32\webcheck.dll
SysTray = C:\WINDOWS\system32\stobject.dll
PostBootReminder = %SystemRoot%\system32\SHELL32.dll
CDBurn = %SystemRoot%\system32\SHELL32.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
%SystemRoot%\system32\browseui.dll= Browseui 预加载程序
%SystemRoot%\system32\browseui.dll= 组件类别缓存程序


SYSTEM.INI BOOT SHELL Explorer.exe


其他相关项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon DefaultUserName ----> 0
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon AltDefaultUserName ----> 0
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit ----> C:\WINDOWS\system32\userinit.exe,
HKEY_LOCAL_MACHINE SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs ----> C:\WINDOWS\system32\userinit.exe,


WININIT.INI
[RENAME]
NUL=
NUL=

Hosts
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost



进程列表

[System Process]
System
C:\WINDOWS\system32\LEXBCES.EXE (Made by Lexmark International, Inc.)
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Sandai\ThunderMini\ThunderMini.exe (Made by 深圳市三代科技开发有限公司)

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Herosoft\HeroV8\SYSEXPLR.EXE
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\3721\Dlaccel\YDownloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\rising\rav\RavMon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
F:\RavDetect.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe

进程详细信息


C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\xunleibho_v6.dll

8A|F9~
tkVWSS
addallurl
sendurl
--------------------------------------------------
--------------------------
---------------------------
Cookie
---------------------------
------------------------------
CCatchRightClick Create
thunder://
Software\Sandai Technologies Inc.\Thunder\Paramete
ThunderOemArray
Software\Sandai Technologies Inc.\ThunderOem
IsMiniVer
[yufeng]-------------------
----------------
-----------------
----------------
IsInvalid
UseDlaccel
Software\Sandai Technologies Inc.\ThunderOem\
Software\3721
yahoo_mini
mmst://
mms://
https://
http://
ftp://
Config_Monitor
IESuffixs
.asf;.avi;.exe;.iso;.mp3;.mpeg;.mpga;.ra;.rar;.rm;
thunder.ini
MonitoringIE
#32770
CallThunder
#*05#*
#*04#*
#*03#*
#*02#*
#*01#*
bho exit
ThunderCatchRight Class
ThunderIEHelper Class
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Xunleibho.CatchRightClick.1
CLSID\%s
Xunleibho.CatchRightClick.1\CLSID
\ProgID
CLSID\
Apartment
ThreadingModel
CLSID\%s\InprocServer32
.?AV_com_error@@
.?AVtype_info@@


C:\WINDOWS\Downlo~1\_IS_0518\_IS_WEBH.dll

t(SSSj
t!WWWh
9l$ t*
SSSShd
90u29p
uRFGHt
"WWSh0
HHtpHHtl
Y95`;|
YYF;5`;|
btHHt.
YYF;5`;|
_9=\'|
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t.;t$$t(
VC20XC00U
_9=`;|
G;=`;|
QQSUVWj
_^][YY
VWuBh@
PPPPPPPP
PPPPPPPP
Encode
SearchKey
SiteName
MonitorSite
Local\51a5e4aa-c30e-4c42-b4f4-3c2389c1d1d5
Local\a5ae79c6-1e05-4c9f-a078-b36e0da61878
Local\3c463f16-c1c7-444e-b9ce-cf6f295b943c
Local\d11d1070-7e68-437d-8e44-3b7420c6dc12
Local\745ba167-eb90-41ff-acdd-a93fb6e96f1f
Local\ec6a11e3-e817-4738-8724-2bb76d64ab44
Local\90d1ed62-8636-4135-b666-07b178599b72
Local\72fbb74c-e96d-4f13-8c1b-20c6d87555f4
Local\fbda5e40-1294-4dee-bd61-8ca14be346b1
{448332E8-BC90-4f80-AA00-6FC89A2854BF}
_IS_Site.ini
CONFIG
ADRePlay
WebADURL
WebAD_Index
WebAD_URL
URL_Index
KW_Index
KeyWord
_IS_KWRD.ini
{1CC08B2F-AFF1-11D9-9651-0003FF7E92CE}
_IS_BESYS_MAINDLG
http://
MenuBar
ReBarWindow32
Afx:400000:0:10011:110005c:0
BaseBar
MyIE2AD
MySiteBar
ADFlag
AfxADControlBar
MessageBoxA
ExitThread
DeleteFileA
CopyFileA
Global\{B8E454EF-A74C-41ec-8471-2C3538C561BC}
Global\_IS_SHAREDMEM
user32.dll
kernel32.dll
gb2312
ttraveler.exe
iexplore.exe
maxthon.exe
explorer.exe
_IS_UPD.DLL
http://liveupdate.myim.cn/liveupdate/myimlite
%s.imd
MYIM_DOWNLOAD
proc_for_ie
_IS_LOIE.dll
InprocServer32
CLSID\{1272F701-349D-4DB3-BBCD-10CBDCD049FE}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
regsvr32.exe
UnInstall
FNo configration so far
Thanks
C:\WINDOWS\Downlo~1\_IS_0518
_IS_WEBH.dll
C:\Program Files\Internet Explorer\IEXPLORE.EXE
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
((((((((((((((((((((((((((
http://
rfile://%s/%s
_IS_InAD
Main(%d,"%s")
javascript
afterBegin

AD
gototop
 

如此态度,投诉他。
gototop
 

无话可说
gototop
 

特别气愤
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT