瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助,"xpa.sys"导致的蓝屏死机问题,无法解决

1   1  /  1  页   跳转

求助,"xpa.sys"导致的蓝屏死机问题,无法解决

求助,"xpa.sys"导致的蓝屏死机问题,无法解决

朋友的电脑,系统是windows2000,进入桌面,即将启动完毕之后,会出现蓝屏,然后是如下信息,每次都如此。

--------------
STOP:0X000000D1(0X77E60B00,0X000000FF,0X000001,0XF75D8639)
DRIVER_IRQL_NOT_LESS_OR_EQUAL
Address F75D8639 base at F75d8000,
Datestamp 45652489 -xpa.sys

--------------
能进入windows的安全模式。在安全模式中,发现winnt/temp目录下有xpa.sys文件,3点多k大小;在注册表中,发现有"xpa.sys"的键值。

删除有关的文件和注册表键值,重启,进入普通模式,依然是在启动差不多完成(可以看到桌面背景和图标)的时候出现蓝屏,出现同样的错误提示信息。

再进入安全模式,发现原先已经删除的xpa.sys文件和注册表项依然存在。

怀疑是流氓软件所为,在普通模式下企图加载某些东西而导致系统的崩溃。但无法删除,而且瑞星无法查杀。

不知道这个究竟是什么东西,该如何处理,希望大家能帮帮我。
最后编辑2007-01-28 19:47:36
分享到:
gototop
 

扫描一个日志  SRE的  http://www4.skycn.com/soft/23312.html
gototop
 

在那边就跟你说了,让你扫描个日志发上来。用sreng扫描保存日志,粘贴上来。
gototop
 

http://www.kztechs.com/sreng/index.html
这里是sreng的官方下载地址。
gototop
 

扫描结果如下,请帮忙看看。

[CODE]

2007-01-20,08:52:15

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat><internat.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <TrackPointSrv><tp4mon.exe>  [IBM]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <IMSCMIG40W><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll>  [Microsoft Corporation]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Corporation]
    <SysTray><stobject.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nwprovau]
    <WinlogonNotify: nwprovau><nwprovau.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    <WinlogonNotify: wzcnotif><wzcdlg.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[ThinkPad Modem Copyright]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\ThinkPad Modem Copyright.lnk --> C:\WINNT\MWW32\manager\mwcpyrt.exe [IBM Corporation]><N>

==================================
服务
[Security Machine Manager / BRGNS][Stopped/Auto Start]
  <C:\WINNT\SYSTEM32\RUNDLL32.EXE C:\WINNT\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
[Indexing Service / cisvc][Stopped/Manual Start]
  <C:\WINNT\System32\cisvc.exe><Microsoft Corporation>
[Remote Registry Protect / ClipArt][Stopped/Auto Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\uzelo.dll><Microsoft Corporation>
[ClipBook / ClipSrv][Stopped/Manual Start]
  <C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[Comeputer Browser / Comeputer Browser][Stopped/Auto Start]
  <C:\WINNT\G_Server2006.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[EventLog  / EventLog ][Stopped/Auto Start]
  <C:\Program Files\1.txt><N/A>
[GrayPigeonServer / GrayPigeonServer][Stopped/Auto Start]
  <C:\WINNT\G_Server2006.exe><N/A>
[Gray_Pigeon_Server2.03 / GrayPigeonServer2.03][Stopped/Auto Start]
  <C:\WINNT\G_Server2.03.exe><N/A>
[IEXPLORE.dat / IEXPLORE.dat][Stopped/Auto Start]
  <C:\WINNT\IEXPLORE.dat><N/A>
[Infrared Monitor / Irmon][Stopped/Auto Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\irmon.dll><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
  <C:\WINNT\System32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC][Stopped/Manual Start]
  <C:\WINNT\System32\msdtc.exe><Microsoft Corporation>
[Removable Storage / NtmsSvc][Stopped/Auto Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\NtmsSvc.dll><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><Microsoft Corporation>
[Rayion / Rayion][Stopped/Auto Start]
  <C:\WINNT\Edhtb.exe><N/A>
[Remote Droceduae Call (RDC) / RdcSca Droceduae Call (RDC)][Stopped/Auto Start]
  <C:\WINNT\G_Server1.23.exe><N/A>
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><Microsoft Corporation>
[Remote Registry Service / RemoteRegistry][Stopped/Auto Start]
  <C:\WINNT\system32\regsvc.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
  <C:\WINNT\System32\locator.exe><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Stopped/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[QoS RSVP / RSVP][Stopped/Manual Start]
  <C:\WINNT\System32\rsvp.exe -s><Microsoft Corporation>
[Smart Card Helper / SCardDrv][Stopped/Manual Start]
  <C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Manual Start]
  <C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[System Event Notification / SENS][Stopped/Auto Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><Microsoft Corporation>
[Still Image Service / StiSvc][Stopped/Auto Start]
  <C:\WINNT\system32\stisvc.exe><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
  <C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS][Stopped/Manual Start]
  <C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan][Stopped/Manual Start]
  <C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[Windows Adnin / Windows Adnin][Stopped/Auto Start]
  <C:\Program Files\HgzServer\G_Server2006.exe><N/A>
[Windows Management Instrumentation / WinMgmt][Running/Auto Start]
  <C:\WINNT\System32\WBEM\WinMgmt.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
[Automatic Updates / wuauserv][Stopped/Auto Start]
  <C:\WINNT\system32\svchost.exe -k wugroup-->C:\WINNT\system32\wuauserv.dll><Microsoft Corporation>
[Wireless Configuration / WZCSVC][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wzcsvc.dll><Microsoft Corporation>
[Backgryound Inteiigent Transfe / 提供软件安装服务,诸如分派,发][Stopped/Auto Start]
  <C:\WINNT\G_Server2006.exe><N/A>
gototop
 

==================================
驱动程序
[696413 / 696413][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\696413.sys><N/A>
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ACPI.sys><Microsoft Corporation>
[Microsoft Embedded Controller Driver / ACPIEC][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ACPIEC.sys><Microsoft Corporation>
[ADProt / ADProt][Stopped/System Start]
  <system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Intel AGP Bus Filter / agp440][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\agp440.sys><Microsoft Corporation>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
  <System32\DRIVERS\asyncmac.sys><Microsoft Corporation>
[Standard IDE/ESDI Hard Disk Controller / atapi][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\atapi.sys><Microsoft Corporation>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
  <System32\DRIVERS\atmarpc.sys><Microsoft Corporation>
[atssse / atssse][Stopped/Manual Start]
  <\??\C:\WINNT\system32\sosdrp.sys><N/A>
[Audio Stub Driver / audstub][Stopped/Manual Start]
  <System32\DRIVERS\audstub.sys><Microsoft Corporation>
[Rising TDI Base Driver / BaseTDI][Stopped/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[HelloNet PPPoE 虚拟网卡 / BRPPPOE][Stopped/Manual Start]
  <system32\DRIVERS\brpppoe.sys><N/A>
[Closed Caption Decoder / ccdecode][Stopped/Manual Start]
  <system32\drivers\ccdecode.sys><Microsoft Corporation>
[CD-ROM Driver / Cdrom][Running/System Start]
  <System32\DRIVERS\cdrom.sys><Microsoft Corporation>
[Xircom Ethernet + Modem 56 Network Driver / cem56][Stopped/Manual Start]
  <System32\DRIVERS\cem56n5.sys><N/A>
[Microsoft ACPI Control Method Battery Driver / CmBatt][Stopped/Manual Start]
  <System32\DRIVERS\CmBatt.sys><Microsoft Corporation>
[Microsoft Composite Battery Driver / Compbatt][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\compbatt.sys><Microsoft Corporation>
[Crystal WDM MPU-401 UART Driver / cwbmidi_device][Stopped/Manual Start]
  <system32\drivers\cwbmidi.sys><Microsoft Corporation>
[Crystal WDM Audio Codec Driver / cwbwdm_device][Stopped/Manual Start]
  <system32\drivers\cwbwdm.sys><Microsoft Corporation>
[Disk Driver / Disk][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\disk.sys><Microsoft Corporation>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Stopped/Disabled]
  <System32\drivers\dmload.sys><VERITAS Software Corp.>
[Microsoft DirectMusic SW Synth (WDM) / DMusic][Stopped/Manual Start]
  <system32\drivers\DMusic.sys><Microsoft Corporation>
[edigtbs / edigtbs][Running/Boot Start]
  <\SystemRoot\system32\drivers\edigtbs.sys><>
[ExpScaner / ExpScaner][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[Floppy Disk Controller Driver / Fdc][Running/Manual Start]
  <System32\DRIVERS\fdc.sys><Microsoft Corporation>
[Floppy Disk Driver / Flpydisk][Running/Manual Start]
  <System32\DRIVERS\flpydisk.sys><Microsoft Corporation>
[FsVga / FsVga][Stopped/System Start]
  <System32\DRIVERS\fsvga.sys><N/A>
[Game Port Enumerator / gameenum][Stopped/Manual Start]
  <System32\DRIVERS\gameenum.sys><Microsoft Corporation>
[WAN Miniport Driver For PPPoE Protocol / GNetPPPoE][Stopped/Manual Start]
  <system32\DRIVERS\PPPoE.SYS><Guangdong Gnet Application R & D Center>
[Generic Packet Classifier / Gpc][Stopped/Manual Start]
  <System32\DRIVERS\msgpc.sys><Microsoft Corporation>
[Microsoft HID Class Driver / HidUsb][Stopped/Auto Start]
  <System32\DRIVERS\hidusb.sys><Microsoft Corporation>
[HookCont / HookCont][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[i8042 Keyboard and PS/2 Mouse Port Driver / i8042prt][Running/System Start]
  <System32\DRIVERS\i8042prt.sys><Microsoft Corporation>
[icddrv / icddrv][Stopped/Manual Start]
  <\??\C:\WINNT\system32\drivers\icddrv.sys><N/A>
[IntelIde / IntelIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\intelide.sys><Microsoft Corporation>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
  <System32\DRIVERS\ipfltdrv.sys><Microsoft Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <System32\DRIVERS\ipinip.sys><Microsoft Corporation>
[IrDA Protocol / irda][Stopped/Auto Start]
  <System32\DRIVERS\irda.sys><Microsoft Corporation>
[IR Enumerator Service / IRENUM][Stopped/Manual Start]
  <System32\DRIVERS\irenum.sys><Microsoft Corporation>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Keyboard Class Driver / Kbdclass][Running/System Start]
  <System32\DRIVERS\kbdclass.sys><Microsoft Corporation>
[Microsoft Kernel Wave Audio Mixer / kmixer][Stopped/Manual Start]
  <system32\drivers\kmixer.sys><Microsoft Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINNT\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mf / mf][Stopped/Manual Start]
  <System32\DRIVERS\mf.sys><Microsoft Corporation>
[Unimodem Streaming Filter Device / MODEMCSA][Stopped/Manual Start]
  <system32\drivers\MODEMCSA.sys><Microsoft Corporation>
[Mouse Class Driver / Mouclass][Running/System Start]
  <System32\DRIVERS\mouclass.sys><Microsoft Corporation>
[Mouse HID Driver / mouhid][Stopped/Manual Start]
  <System32\DRIVERS\mouhid.sys><Microsoft Corporation>
[Microsoft Streaming Service Proxy / MSKSSRV][Stopped/Manual Start]
  <system32\drivers\MSKSSRV.sys><Microsoft Corporation>
[Microsoft Streaming Clock Proxy / MSPCLOCK][Stopped/Manual Start]
  <system32\drivers\MSPCLOCK.sys><Microsoft Corporation>
[Microsoft Streaming Quality Manager Proxy / MSPQM][Stopped/Manual Start]
  <system32\drivers\MSPQM.sys><Microsoft Corporation>
[Microsoft Streaming Tee/Sink-to-Sink Converter / MSTEE][Stopped/Manual Start]
  <system32\drivers\MSTEE.sys><Microsoft Corporation>
[Remote Access NDIS TAPI Driver / NdisTapi][Stopped/Manual Start]
  <System32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NDIS 用户模式 I/O 协议 / Ndisuio][Stopped/Manual Start]
  <System32\DRIVERS\ndisuio.sys><Microsoft Corporation>
[Remote Access NDIS WAN Driver / NdisWan][Stopped/Manual Start]
  <System32\DRIVERS\ndiswan.sys><Microsoft Corporation>
[neo20xx / neo20xx][Stopped/Manual Start]
  <System32\DRIVERS\neo20xx.sys><NeoMagic Corporation>
[NetBIOS Interface / NetBIOS][Stopped/System Start]
  <System32\DRIVERS\netbios.sys><Microsoft Corporation>
[NetDetect / NetDetect][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\netdtect.sys><Microsoft Corporation>
[New0 / New0][Stopped/Auto Start]
  <\??\C:\WINNT\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\C:\Program Files\Tencent\qq\npkcrypt.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA][Stopped/Manual Start]
  <System32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
  <System32\DRIVERS\nwlnkflt.sys><Microsoft Corporation>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
  <System32\DRIVERS\nwlnkfwd.sys><Microsoft Corporation>
[paasweq / paasweq][Stopped/Manual Start]
  <\??\C:\WINNT\system32\sosdrp.sys><N/A>
[Parallel class driver / Parallel][Running/Manual Start]
  <System32\DRIVERS\parallel.sys><Microsoft Corporation>
[Parallel port driver / Parport][Stopped/System Start]
  <System32\DRIVERS\parport.sys><Microsoft Corporation>
[PCI Bus Driver / PCI][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\pci.sys><Microsoft Corporation>
[Pcmcia / Pcmcia][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\pcmcia.sys><Microsoft Corporation>
[WAN Miniport (PPTP) / PptpMiniport][Stopped/Manual Start]
  <System32\DRIVERS\raspptp.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink][Stopped/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Remote Access Auto Connection Driver / RasAcd][Stopped/System Start]
  <System32\DRIVERS\rasacd.sys><Microsoft Corporation>
[WAN Miniport (IrDA Modem) / Rasirda][Stopped/Manual Start]
  <System32\DRIVERS\rasirda.sys><Microsoft Corporation>
[WAN Miniport (L2TP) / Rasl2tp][Stopped/Manual Start]
  <System32\DRIVERS\rasl2tp.sys><Microsoft Corporation>
[Direct Parallel / Raspti][Stopped/Manual Start]
  <System32\DRIVERS\raspti.sys><Microsoft Corporation>
[Microsoft Streaming Network Raw Channel Access / RCA][Stopped/Manual Start]
  <system32\drivers\RCA.sys><Microsoft Corporation>
[Digital CD Audio Playback Filter Driver / redbook][Stopped/System Start]
  <System32\DRIVERS\redbook.sys><Microsoft Corporation>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
gototop
 

[Serenum Filter Driver / serenum][Stopped/Manual Start]
  <System32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Stopped/System Start]
  <System32\DRIVERS\serial.sys><Microsoft Corporation>
[SVKP / SVKP][Stopped/Auto Start]
  <\??\C:\WINNT\system32\SVKP.sys><AntiCracking>
[Software Bus Driver / swenum][Running/Manual Start]
  <System32\DRIVERS\swenum.sys><Microsoft Corporation>
[Microsoft Kernel GS Wavetable Synthesizer / swmidi][Stopped/Manual Start]
  <system32\drivers\swmidi.sys><Microsoft Corporation>
[Microsoft System Audio Device / sysaudio][Stopped/Manual Start]
  <system32\drivers\sysaudio.sys><Microsoft Corporation>
[ThinkPad DSP Driver Service / ThinkPadDSP][Stopped/Manual Start]
  <System32\DRIVERS\mwwdm.sys><IBM Corporation>
[IBM PS/2 TrackPoint Filter Driver / TwoTrack][Running/Manual Start]
  <System32\DRIVERS\TwoTrack.sys><Microsoft Corporation>
[Microsoft USB Universal Host Controller Driver / uhcd][Running/Manual Start]
  <System32\DRIVERS\uhcd.sys><Microsoft Corporation>
[Microcode Update Driver / Update][Running/Manual Start]
  <System32\DRIVERS\update.sys><Microsoft Corporation>
[Microsoft USB Standard Hub Driver / usbhub][Running/Manual Start]
  <System32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB Scanner Driver / usbscan][Stopped/Manual Start]
  <System32\DRIVERS\usbscan.sys><Microsoft Corporation>
[USB Mass Storage Driver / USBSTOR][Running/Manual Start]
  <System32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[vbppdryu / vbppdryu][Stopped/Manual Start]
  <\??\C:\WINNT\system32\sosdrp.sys><N/A>
[VgaSave / VgaSave][Running/System Start]
  <\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Stopped/Manual Start]
  <System32\DRIVERS\wanarp.sys><Microsoft Corporation>
[Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Stopped/Manual Start]
  <system32\drivers\wdmaud.sys><Microsoft Corporation>
[Windows 套接字 2 .0 Non-IFS 服务提供程序支持环境 / WS2IFSL][Stopped/Auto Start]
  <\SystemRoot\System32\drivers\ws2ifsl.sys><Microsoft Corporation>
[VIMICRO USB PC Camera 301x / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
  {53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINNT\system32\ssup.dll, TENCENT>
[Schedule Class]
  {8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\WINNT\system32\sscli.dll, >
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[PGEdit Class]
  {2BFAA61B-5C83-4865-8281-D8BDBF863061} <C:\WINNT\Downloaded Program Files\PG_ATL_Edit.dll, 中国银联广州分公司>
[WebActivater Control]
  {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINNT\system32\WEBACT~1.OCX, QQ>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Ravonline]
  {DA984A6D-508E-11D6-AA49-0050FF3C628D} <C:\WINNT\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <C:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 108][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 136][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 156][\??\C:\WINNT\SYSTEM32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6997]
    [C:\WINNT\SYSTEM32\APIHookDll.dll]  [N/A, N/A]
    [C:\WINNT\SYSTEM32\tssoft32.acm]  [DSP GROUP, INC., 1.01]
    [C:\WINNT\SYSTEM32\tsd32.dll]  [N/A, N/A]
    [C:\WINNT\SYSTEM32\iac25_32.ax]  [Ligos Corporation, 2.05.54]
    [C:\WINNT\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINNT\SYSTEM32\sl_anet.acm]  [Sipro Lab Telecom Inc., 3.02]
    [C:\WINNT\SYSTEM32\vct3216.acm]  [Voxware, Inc., 1.6.0.17]
    [C:\WINNT\SYSTEM32\vct3216.dll]  [Voxware, Inc., 1.6.0.12]
    [C:\WINNT\system32\msms001.vwp]  [Voxware, Inc., 2.0.2.61]
    [C:\WINNT\system32\mvoice.vwp]  [Voxware, Inc., 2.0.0.12.01]
    [C:\WINNT\SYSTEM32\vorbis.acm]  [HMS http://hp.vector.co.jp/authors/VA012897/, 0, 0, 3, 6]
[PID: 184][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.7035]
    [C:\WINNT\system32\APIHookDll.dll]  [N/A, N/A]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
[PID: 196][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.7011]
    [C:\WINNT\system32\APIHookDll.dll]  [N/A, N/A]
[PID: 344][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\APIHookDll.dll]  [N/A, N/A]
[PID: 384][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
    [C:\WINNT\SYSTEM32\APIHookDll.dll]  [N/A, N/A]
[PID: 224][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\APIHookDll.dll]  [N/A, N/A]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\WINNT\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 496][C:\软件\Sreng\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINNT\system32\APIHookDll.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP UDP Service Provider
    C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
RSVP TCP Service Provider
    C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] SEQPACKET 3
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] DATAGRAM 3
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] SEQPACKET 0
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] DATAGRAM 0
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] SEQPACKET 1
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] DATAGRAM 1
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] SEQPACKET 2
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] DATAGRAM 2
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

该用户帖子内容已被屏蔽
gototop
 

有没有人能看懂?帮帮忙。
gototop
 

我电脑现在也经常蓝屏啊!!!我是菜尿郁闷啊 ````有时候一些程序都打不开来!!!老是出错!!!!!老是要调试``怎么办啊~~~~~~~~懂的+我QQ452956830A  谢谢````
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT