1   1  /  1  页   跳转

【求助】开机自动弹出安装

【求助】开机自动弹出安装

开机自动弹出安装“酷猴”2。0。0。7
最后编辑2005-09-18 19:37:35
分享到:
gototop
 


建议您下载并使用HijackThis1.99.1

HijackThis下载地址请参考:
【必读】本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
gototop
 

请诊断,谢谢


Logfile of HijackThis v1.99.1
Scan saved at 18:49:37, on 2005-9-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\crypserv.exe
D:\happyhome\幸福飞梭\lxswitch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NewRemoteControl\NewRmtService.exe
C:\Program Files\Rising\Rav\RavTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\QuickTime\qttask.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\Program Files\Common Files\DeviceManager\lxdevclient.exe
C:\WINDOWS\svchost_ts015.exe
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\联想(北京)有限公司\Common\Bin\WinCinemaMgr.exe
C:\Program Files\联想(北京)有限公司\幸福电视\RecordAgent.exe
D:\happyhome\幸福飞梭\FlyShuttle.exe
C:\Program Files\LEGEND\联想标准功能键盘驱动程序安装\skdaemon.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\Program Files\Common Files\Legend\Happyhome\bin\AssistantApp.exe
C:\WINDOWS\enrtins.exe
C:\WINDOWS\TEMP\_K10.tmp
C:\WINDOWS\TEMP\KBS6.tmp
C:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\user\My Documents\12.最新下载\浏览器相关软件\hijackthis_0911\HijackThis.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FlashGet\jccatch.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NewRmtService ] C:\Program Files\NewRemoteControl\NewRmtService.exe
O4 - HKLM\..\Run: [RavTimer] C:\Program Files\Rising\Rav\RavTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RavTray] C:\Program Files\Rising\Rav\RavTray.exe
O4 - HKLM\..\Run: [RavMon] C:\Program Files\Rising\Rav\RavMon.exe -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [lxdevclient] C:\Program Files\Common Files\DeviceManager\lxdevclient.exe
O4 - HKLM\..\Run: [SVCHOST] C:\WINDOWS\svchost_ts015.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: 幸福电视代理.lnk = ?
O4 - Global Startup: 幸福飞梭.lnk = ?SystemRoot%\Installer\{448A3A90-4C81-4007-BFE5-81B599CE9D62}\NewShortcut2_1.exe
O4 - Global Startup: 联想键盘驱动程序.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ECFA783-8538-4A9E-9A66-9DA7235CD242}: NameServer = 202.97.150.138,202.97.150.139
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: lxswitch - Unknown owner - D:\happyhome\幸福飞梭\lxswitch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

【回复“上夸克”的帖子】
重新启动至安全模式,关闭所有窗口,使用HijackThis扫描后修复(在需要修复的项目前面打对勾,然后按“Fix checked”或“修复”,修复前会询问您是否需要备份,请选择“Yes”或“是”):
显示隐藏文件和系统文件,删除(如果存在的话):
O4 - HKLM\..\Run: [SVCHOST] C:\WINDOWS\svchost_ts015.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
删除:
C:\WINDOWS\svchost_ts015.exe
以上建议仅供参考,如果您认识其中的一些设置抑或是您的手动设置,就不必执行。
gototop
 

打开任务管理器终止svchost_ts015.exe进程.

修复:
O4 - HKLM\..\Run: [SVCHOST] C:\WINDOWS\svchost_ts015.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)

删除:
C:\WINDOWS\svchost_ts015.exe



gototop
 

问题解决了,谢谢!!
在这中秋之夜,托当空的皓月带去对你们的祝福,愿二位好运多多,月圆人圆事事圆!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT