1   1  /  1  页   跳转

[求助] woderizhi

woderizhi

瑞星卡卡电脑诊断日志 v1.30 (2008-11-17 13:24:43)  北京瑞星信息技术有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
  + 系统服务
    + HKLM\System\CurrentControlSet\Services
      eB2003
        [A ] 1. d:\eb2003\eb2003.exe

      MSSQLSERVER
        [AM] 2. c:\program files\microsoft sql server\mssql\binn\sqlservr.exe

      MSSQLServerADHelper
        [A ] 3. c:\program files\microsoft sql server\80\tools\binn\sqladhlp.exe

      ose
        [A ] 4. c:\program files\common files\microsoft shared\source engine\ose.exe

      RsCCenter
        [AM] 5. c:\program files\rising\rav\ccenter.exe

      RsRavMon
        [AM] 6. c:\program files\rising\rav\ravmond.exe

      SQLSERVERAGENT
        [A ] 7. c:\program files\microsoft sql server\mssql\binn\sqlagent.exe

      UMWdf
        [AM] 8. c:\windows\system32\wdfmgr.exe

      usnjsvc
        [A ] 9. c:\program files\windows live\messenger\usnsvc.exe

      WLSetupSvc
        [A ] 10. c:\program files\windows live\installer\wlsetupsvc.exe


  + 内核驱动
    + HKLM\System\CurrentControlSet\Services
      aaatimeo
        [A ] 11. c:\windows\system32\drivers\aaatimeo.sys

      AFAMgt
        [A ] 12. c:\windows\system32\drivers\afamgt.sys

      ahcix86
        [A ] 13. c:\windows\system32\drivers\ahcix86.sys

      ALCXWDM
        [A ] 14. c:\windows\system32\drivers\alcxwdm.sys

      amdbusdr
        [A ] 15. c:\windows\system32\drivers\amdbusdr.sys

      amdeide
        [A ] 16. c:\windows\system32\drivers\amdeide.sys

      AmdK8
        [A ] 17. c:\windows\system32\drivers\amdk8.sys

      ASH1205
        [A ] 18. c:\windows\system32\drivers\ash1205.sys

      ata1200a
        [A ] 19. c:\windows\system32\drivers\ata1200a.sys

      atiide
        [A ] 20. c:\windows\system32\drivers\atiide.sys

      bb-run
        [A ] 21. c:\windows\system32\drivers\bb-run.sys

      cercsr6
        [A ] 22. c:\windows\system32\drivers\cercsr6.sys

      Cpq32fs2
        [A ] 23. c:\windows\system32\drivers\cpq32fs2.sys

      DelEx
        [A ] 24. c:\windows\system32\drivers\filecrusher.sys

      DgiVecp
        [A ] 25. c:\windows\system32\drivers\dgivecp.sys

      dontgo
        [A ] 26. c:\windows\system32\drivers\dontgo.sys

      FET5X86V
        [A ] 27. c:\windows\system32\drivers\fetnd5bv.sys

      fttxr52P
        [A ] 28. c:\windows\system32\drivers\fttxr52p.sys

      HookCont
        [A ] 29. c:\windows\system32\drivers\hookcont.sys

      HookNtos
        [A ] 30. c:\windows\system32\drivers\hookntos.sys

      HookReg
        [A ] 31. c:\windows\system32\drivers\hookreg.sys

      HookSys
        [A ] 32. c:\windows\system32\drivers\hooksys.sys

      HpCISSm2
        [A ] 33. c:\windows\system32\drivers\hpcissm2.sys

      hptmv6
        [A ] 34. c:\windows\system32\drivers\hptmv6.sys

      iaStor55
        [A ] 35. c:\windows\system32\drivers\iastor55.sys

      iaStor70
        [A ] 36. c:\windows\system32\drivers\iastor70.sys

      mv61xx
        [A ] 37. c:\windows\system32\drivers\mv61xx.sys

      mvSata
        [A ] 38. c:\windows\system32\drivers\mvsata.sys

      nvgts
        [A ] 39. c:\windows\system32\drivers\nvgts.sys

      nvrd32
        [A ] 40. c:\windows\system32\drivers\nvrd32.sys

      ql2100
        [A ] 41. c:\windows\system32\drivers\ql2100.sys

      ql2200
        [A ] 42. c:\windows\system32\drivers\ql2200.sys

      qttiatv
        [A ] 43. c:\windows\system32\drivers\qttiatv.sys

      rr172x
        [A ] 44. c:\windows\system32\drivers\rr172x.sys

      rr174x
        [A ] 45. c:\windows\system32\drivers\rr174x.sys

      rr2340
        [A ] 46. c:\windows\system32\drivers\rr2340.sys

      RsNTGDI
        [A ] 47. c:\windows\system32\drivers\rsntgdi.sys

      Secdrv
        [A ] 48. c:\windows\system32\drivers\secdrv.sys

      SiRemFil
        [A ] 49. c:\windows\system32\drivers\siremfil.sys

      sisraidx
        [A ] 50. c:\windows\system32\drivers\sisraidx.sys

      ViBus
        [A ] 51. c:\windows\system32\drivers\vibus.sys

      videX32
        [A ] 52. c:\windows\system32\drivers\videx32.sys

      ViPrt
        [A ] 53. c:\windows\system32\drivers\viprt.sys

      xfilt
        [A ] 54. c:\windows\system32\drivers\xfilt.sys


  + IE浏览器加载模块
    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
      {9030D464-4C02-4ABF-8ECC-5164760863C6}
        [A ] 55. c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll

      {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
        [A ] 56. c:\windows\system32\urlfilter.dll


  + 资源管理器加载模块
    + HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
      text/xml
        [A ] 57. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll

    + HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
      livecall
        [A ] 58. c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll

      msnim
        [A ] 58. c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
      HyperTerminal Icon Ext
        [A ] 59. c:\windows\system32\hticons.dll

      WinRAR shell extension
        [AM] 60. c:\program files\winrar\rarext.dll

      Microsoft Office HTML Icon Handler
        [A ] 61. c:\program files\microsoft office\office11\msohev.dll

      Web Folders
        [A ] 62. c:\program files\common files\microsoft shared\web folders\msonsext.dll

      Portable Media Devices
        [A ] 63. c:\windows\system32\audiodev.dll

      Portable Media Devices Menu
        [A ] 63. c:\windows\system32\audiodev.dll

      RISING
        [AM] 64. c:\windows\system32\ravext.dll

      Messenger Sharing Folders
        [A ] 65. c:\program files\windows live\messenger\fsshext.8.5.1302.1018.dll

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
      {32CD708B-60A7-4C00-9377-D73EAA495F0F}
        [AM] 64. c:\windows\system32\ravext.dll


  + 用户登陆自运行项目
    + HKCU\Software\Microsoft\Windows\CurrentVersion\Run
      MsnMsgr
        [A ] 66. c:\program files\windows live\messenger\msnmsgr.exe

    + HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      runeip
        [AM] 67. d:\软件\瑞星\卡卡\rstray.exe

      Samsung PanelMgr
        [AM] 68. c:\windows\samsung\panelmgr\ssmmgr.exe

      RavTask
        [AM] 69. c:\program files\rising\rav\ravtask.exe

      infsykum
        [A ] 70. c:\windows\inf\smssu.exe

      !!QQKav
        [AM] 71. c:\documents and settings\administrator\桌面\qqkav_newhua.exe

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
      KKDelay
        [A ] 72. d:\软件\瑞星\卡卡\runonce.exe


  + 开机执行
    + HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
      BootExecute
        [A ] 73. c:\windows\system32\kknative.exe


  + 映像劫持
    + HKCR\.html
      htmlfile\Edit\Command
        [A ] 74. c:\program files\microsoft office\office11\msohtmed.exe

      htmlfile\Print\Command
        [A ] 74. c:\program files\microsoft office\office11\msohtmed.exe

    + HKCR\.htm
      htmlfile\Edit\Command
        [A ] 74. c:\program files\microsoft office\office11\msohtmed.exe

      htmlfile\Print\Command
        [A ] 74. c:\program files\microsoft office\office11\msohtmed.exe


  + 程序初始化和已知动态连接库
    + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
      AppInit_DLLs
        [AM] 75. c:\windows\system32\kmon.dll

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
分享到:
gototop
 

回复:woderizhi

+ 打印机监控
    + HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
      SUGG1 Langmon
        [AM] 76. c:\windows\system32\sugg1lmk.dll


+ 其他自启动项目
  + C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
    腾讯QQ.lnk
      [A ] 77. d:\软件\qq\qq.exe

  + C:\Documents and Settings\All Users\「开始」菜单\程序\启动
    服务管理器.lnk
      [AM] 78. c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe


+ 正在运行的进程
  + 000000b8(184) ssmmgr.exe
    00400000[00084000]
      [AM] 68. c:\windows\samsung\panelmgr\ssmmgr.exe

  + 000001ac(428) RavTask.exe
    00400000[00034000]
      [AM] 69. c:\program files\rising\rav\ravtask.exe

    10000000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00A30000[00024000]
      [ M] 80. c:\program files\rising\rav\rscommx2.dll

    23700000[00028000]
      [ M] 81. c:\program files\rising\rav\rscommon.dll

    00C90000[0000E000]
      [ M] 82. c:\program files\rising\rav\rsappmgr.dll

    08CB0000[00030000]
      [ M] 83. c:\program files\rising\rav\cfgdll.dll

  + 000001c4(452) Ravmon.exe
    00400000[00067000]
      [ M] 84. c:\program files\rising\rav\ravmon.exe

    7C140000[00103000]
      [ M] 85. c:\windows\system32\mfc71.dll

    7C340000[00056000]
      [ M] 86. c:\windows\system32\msvcr71.dll

    7C3A0000[0007B000]
      [ M] 87. c:\windows\system32\msvcp71.dll

    10000000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00B20000[00024000]
      [ M] 80. c:\program files\rising\rav\rscommx2.dll

    23700000[00028000]
      [ M] 81. c:\program files\rising\rav\rscommon.dll

    00D70000[00035000]
      [ M] 88. c:\program files\rising\rav\recomp.dll

    00DC0000[00036000]
      [ M] 89. c:\program files\rising\rav\refs.dll

    01020000[0002F000]
      [ M] 90. c:\program files\rising\rav\viruslib.dll

    01160000[00028000]
      [ M] 91. c:\program files\rising\rav\relibldr.dll

    011E0000[0000E000]
      [ M] 82. c:\program files\rising\rav\rsappmgr.dll

    01200000[00030000]
      [ M] 83. c:\program files\rising\rav\cfgdll.dll

    01360000[00075000]
      [ M] 92. c:\program files\rising\rav\monrule.dll

    23900000[00040000]
      [ M] 93. c:\program files\rising\rav\pngdll.dll

    26600000[000A8000]
      [ M] 94. c:\program files\rising\rav\rsguilib.dll

    23800000[00022000]
      [ M] 95. c:\program files\rising\rav\rsxml.dll

  + 000001dc(476) wdfmgr.exe
    01000000[0000C000]
      [AM] 8. c:\windows\system32\wdfmgr.exe

  + 00000224(548) smss.exe
  + 00000274(628) csrss.exe
  + 0000028c(652) winlogon.exe
    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

  + 000002b8(696) services.exe
  + 000002c4(708) lsass.exe
  + 00000354(852) svchost.exe
    76230000[00063000]
      [ M] 97. c:\windows\system32\spcss.dll

  + 000003b4(948) svchost.exe
    76230000[00063000]
      [ M] 97. c:\windows\system32\spcss.dll

  + 0000042c(1068) CCenter.exe
    00400000[0002A000]
      [AM] 5. c:\program files\rising\rav\ccenter.exe

  + 0000043c(1084) svchost.exe
  + 00000488(1160) svchost.exe
  + 000004e4(1252) rstray.exe
    00400000[00023000]
      [AM] 67. d:\软件\瑞星\卡卡\rstray.exe

    10000000[0003C000]
      [ M] 98. d:\软件\瑞星\卡卡\rsmginfo.dll

    23800000[00022000]
      [ M] 99. d:\软件\瑞星\卡卡\rsxml.dll

    7C3A0000[0007B000]
      [ M] 100. d:\软件\瑞星\卡卡\msvcp71.dll

    7C340000[00056000]
      [ M] 101. d:\软件\瑞星\卡卡\msvcr71.dll

    00BC0000[00024000]
      [ M] 102. d:\软件\瑞星\卡卡\comserv.dll

    00A90000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll

    23700000[00026000]
      [ M] 104. d:\软件\瑞星\卡卡\rscommon.dll

    00C10000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    23900000[00040000]
      [ M] 106. d:\软件\瑞星\卡卡\pngdll.dll

    01020000[00060000]
      [ M] 107. d:\软件\瑞星\卡卡\runiep.dll

    01080000[0002F000]
      [ M] 108. d:\软件\瑞星\卡卡\ncomm.dll

    010D0000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    010F0000[00024000]
      [ M] 109. d:\软件\瑞星\卡卡\rscommx2.dll

    02330000[0001C000]
      [AM] 64. c:\windows\system32\ravext.dll

  + 00000504(1284) svchost.exe
  + 00000528(1320) svchost.exe
  + 00000570(1392) ravmond.exe
    00400000[00069000]
      [AM] 6. c:\program files\rising\rav\ravmond.exe

    10000000[00042000]
      [ M] 110. c:\program files\rising\rav\bwlist.dll

    7C140000[00103000]
      [ M] 85. c:\windows\system32\mfc71.dll

    7C340000[00056000]
      [ M] 86. c:\windows\system32\msvcr71.dll

    7C3A0000[0007B000]
      [ M] 87. c:\windows\system32\msvcp71.dll

    00B20000[0000E000]
      [ M] 82. c:\program files\rising\rav\rsappmgr.dll

    00B40000[00030000]
      [ M] 83. c:\program files\rising\rav\cfgdll.dll

    00DE0000[00067000]
      [ M] 111. c:\program files\rising\rav\rslog.dll

    00B80000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00E50000[00024000]
      [ M] 80. c:\program files\rising\rav\rscommx2.dll

    00E90000[00075000]
      [ M] 92. c:\program files\rising\rav\monrule.dll

    00F20000[00013000]
      [ M] 112. c:\program files\rising\rav\hooksys.dll

    01080000[00013000]
      [ M] 113. c:\program files\rising\rav\hookreg.dll

    010E0000[00013000]
      [ M] 114. c:\program files\rising\rav\hookntos.dll

    01140000[0001D000]
      [ M] 115. c:\program files\rising\rav\rswalmon.dll

    01F70000[00035000]
      [ M] 88. c:\program files\rising\rav\recomp.dll

    01FC0000[00036000]
      [ M] 89. c:\program files\rising\rav\refs.dll

    02010000[00022000]
      [ M] 116. c:\program files\rising\rav\ffr.dll

    02050000[00020000]
      [ M] 117. c:\program files\rising\rav\rsstore.dll

    02080000[00013000]
      [ M] 118. c:\program files\rising\rav\hookcont.dll

    020B0000[00028000]
      [ M] 119. c:\program files\rising\rav\fakescan.dll

    020F0000[00022000]
      [ M] 120. c:\program files\rising\rav\scanner.dll

    02730000[0002F000]
      [ M] 90. c:\program files\rising\rav\viruslib.dll

    02870000[00028000]
      [ M] 91. c:\program files\rising\rav\relibldr.dll

    02E60000[00012000]
      [ M] 121. c:\program files\rising\rav\hookweb.dll

    03F20000[000DC000]
      [ M] 122. c:\program files\rising\rav\extfile.dll

    04120000[00027000]
      [ M] 123. c:\program files\rising\rav\pearc.dll

    04150000[00021000]
      [ M] 124. c:\program files\rising\rav\nvfile.dll

    13AB0000[0004A000]
      [ M] 125. c:\program files\rising\rav\scanexec.dll

    05A40000[002DC000]
      [ M] 126. c:\program files\rising\rav\unexe.dll

    05D30000[000D4000]
      [ M] 127. c:\program files\rising\rav\scanex.dll

    062B0000[00036000]
      [ M] 128. c:\program files\rising\rav\scanpack.dll

    06300000[000B7000]
      [ M] 129. c:\program files\rising\rav\revm.dll

    064F0000[00020000]
      [ M] 130. c:\program files\rising\rav\urutils.dll

    07410000[00038000]
      [ M] 131. c:\program files\rising\rav\scriptci.dll

    07450000[000F3000]
      [ M] 132. c:\program files\rising\rav\uroutine.dll

    085E0000[00046000]
      [ M] 133. c:\program files\rising\rav\posttrt.dll

    04A20000[00023000]
      [ M] 134. c:\program files\rising\rav\scansct.dll

    03C40000[00018000]
      [ M] 135. c:\program files\rising\rav\ur000.dat

    03C70000[0001D000]
      [ M] 136. c:\program files\rising\rav\ur001.dat

    03CA0000[00017000]
      [ M] 137. c:\program files\rising\rav\ur023.dat

    05200000[00045000]
      [ M] 138. c:\program files\rising\rav\extole.dll

    14210000[00038000]
      [ M] 139. c:\program files\rising\rav\extmail.dll

  + 00000584(1412) ras.exe
    00400000[0000B000]
      [ M] 140. d:\软件\瑞星\卡卡\ras.exe

    7C140000[00103000]
      [ M] 141. d:\软件\瑞星\卡卡\mfc71.dll

    7C340000[00056000]
      [ M] 101. d:\软件\瑞星\卡卡\msvcr71.dll

    10000000[00047000]
      [ M] 142. d:\软件\瑞星\卡卡\kakamgr.dll

    7C3A0000[0007B000]
      [ M] 100. d:\软件\瑞星\卡卡\msvcp71.dll

    00B00000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll

    00B30000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00B50000[00024000]
      [ M] 109. d:\软件\瑞星\卡卡\rscommx2.dll

    00CA0000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    00F10000[00058000]
      [ M] 143. d:\软件\瑞星\卡卡\dbmgr.dll

    23800000[00022000]
      [ M] 99. d:\软件\瑞星\卡卡\rsxml.dll

    01070000[0002D000]
      [ M] 144. d:\软件\瑞星\卡卡\pweb.dll

    010A0000[000C3000]
      [ M] 145. d:\软件\瑞星\卡卡\pscan.dll

    01170000[0002F000]
      [ M] 108. d:\软件\瑞星\卡卡\ncomm.dll

    011C0000[00070000]
      [ M] 146. d:\软件\瑞星\卡卡\pset.dll

    01250000[0002A000]
      [ M] 147. d:\软件\瑞星\卡卡\pdefend.dll

    01280000[000B6000]
      [ M] 148. d:\软件\瑞星\卡卡\ptools.dll

    01440000[0008C000]
      [ M] 149. d:\软件\瑞星\卡卡\psysinfo.dll

    014F0000[0001C000]
      [AM] 64. c:\windows\system32\ravext.dll

    23900000[00040000]
      [ M] 106. d:\软件\瑞星\卡卡\pngdll.dll

    02C50000[00028000]
      [ M] 150. c:\program files\rising\rav\ravscrch.dll

    30000000[003AE000]
      [ M] 151. c:\windows\system32\macromed\flash\flash9e.ocx

    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

  + 000005ac(1452) spoolsv.exe
    00AE0000[0000A000]
      [AM] 76. c:\windows\system32\sugg1lmk.dll

    6A900000[00030000]
      [ M] 152. c:\windows\system32\spool\drivers\w32x86\3\sugg1ui.dll

  + 00000694(1684) RavStub.exe
    00400000[00021000]
      [ M] 153. c:\program files\rising\rav\ravstub.exe

    10000000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00620000[00024000]
      [ M] 80. c:\program files\rising\rav\rscommx2.dll

    23700000[00028000]
      [ M] 81. c:\program files\rising\rav\rscommon.dll

  + 000006cc(1740) RavQQMsender.exe
    00400000[00051000]
      [ M] 154. c:\documents and settings\administrator\桌面\ravqqmsender.exe

    60000000[00074000]
      [AM] 75. c:\windows\system32\kmon.dll

    10000000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    00A60000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll

  + 00000754(1876) qqkav_newhua.exe
    00400000[00223000]
      [AM] 71. c:\documents and settings\administrator\桌面\qqkav_newhua.exe

    10000000[00028000]
      [ M] 150. c:\program files\rising\rav\ravscrch.dll

    30000000[003AE000]
      [ M] 151. c:\windows\system32\macromed\flash\flash9e.ocx

    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

  + 00000770(1904) Explorer.EXE
    10000000[0001C000]
      [AM] 64. c:\windows\system32\ravext.dll

    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

    00F80000[0002E000]
      [AM] 60. c:\program files\winrar\rarext.dll

    23700000[00028000]
      [ M] 81. c:\program files\rising\rav\rscommon.dll

  + 00000874(2164) conime.exe
  + 000008a8(2216) sqlmangr.exe
    00400000[00012000]
      [AM] 78. c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe

    41140000[0000C000]
      [ M] 155. c:\program files\microsoft sql server\80\tools\binn\w95scm.dll

    42C40000[00017000]
      [ M] 156. c:\program files\microsoft sql server\80\tools\binn\sqlsvc.dll

    4B4F0000[00006000]
      [ M] 157. c:\windows\system32\odbcbcp.dll

    42AC0000[00007000]
      [ M] 158. c:\program files\microsoft sql server\80\tools\binn\sqlresld.dll

    43970000[00006000]
      [ M] 159. c:\program files\microsoft sql server\80\tools\binn\resources\2052\sqlsvc.rll

    43790000[00018000]
      [ M] 160. c:\program files\microsoft sql server\80\tools\binn\resources\2052\sqlmangr.rll

  + 000009fc(2556) Rav.exe
    00400000[000A8000]
      [ M] 161. c:\program files\rising\rav\rav.exe

    10000000[0001F000]
      [ M] 79. c:\program files\rising\rav\proccom.dll

    00B00000[00024000]
      [ M] 80. c:\program files\rising\rav\rscommx2.dll

    26600000[000A8000]
      [ M] 94. c:\program files\rising\rav\rsguilib.dll

    7C140000[00103000]
      [ M] 85. c:\windows\system32\mfc71.dll

    7C340000[00056000]
      [ M] 86. c:\windows\system32\msvcr71.dll

    7C3A0000[0007B000]
      [ M] 87. c:\windows\system32\msvcp71.dll

    23800000[00022000]
      [ M] 95. c:\program files\rising\rav\rsxml.dll

    23900000[00040000]
      [ M] 93. c:\program files\rising\rav\pngdll.dll

    23700000[00028000]
      [ M] 81. c:\program files\rising\rav\rscommon.dll

    27000000[000DD000]
      [ M] 162. c:\program files\rising\rav\ravpagem.dll

    01750000[00032000]
      [ M] 163. c:\program files\rising\rav\htmllib.dll

    27100000[00050000]
      [ M] 164. c:\program files\rising\rav\ravpagew.dll

    01B70000[0000E000]
      [ M] 82. c:\program files\rising\rav\rsappmgr.dll

    01E90000[00030000]
      [ M] 83. c:\program files\rising\rav\cfgdll.dll

    03340000[00028000]
      [ M] 119. c:\program files\rising\rav\fakescan.dll

    03370000[00022000]
      [ M] 120. c:\program files\rising\rav\scanner.dll

    033A0000[00042000]
      [ M] 110. c:\program files\rising\rav\bwlist.dll

    03440000[00035000]
      [ M] 88. c:\program files\rising\rav\recomp.dll

    03490000[00036000]
      [ M] 89. c:\program files\rising\rav\refs.dll

    03770000[0002F000]
      [ M] 90. c:\program files\rising\rav\viruslib.dll

    038A0000[00028000]
      [ M] 91. c:\program files\rising\rav\relibldr.dll

    03960000[00030000]
      [ M] 165. c:\program files\rising\rav\mvengine.dll

    039A0000[00046000]
      [ M] 133. c:\program files\rising\rav\posttrt.dll

    01BE0000[0000C000]
      [ M] 166. c:\program files\rising\rav\sysmail.dll

    04490000[00022000]
      [ M] 116. c:\program files\rising\rav\ffr.dll

    044D0000[00021000]
      [ M] 124. c:\program files\rising\rav\nvfile.dll

    13AB0000[0004A000]
      [ M] 125. c:\program files\rising\rav\scanexec.dll

    05DC0000[002DC000]
      [ M] 126. c:\program files\rising\rav\unexe.dll

    060B0000[000D4000]
      [ M] 127. c:\program files\rising\rav\scanex.dll

    06520000[00027000]
      [ M] 123. c:\program files\rising\rav\pearc.dll

    06660000[000DC000]
      [ M] 122. c:\program files\rising\rav\extfile.dll

    03040000[00036000]
      [ M] 128. c:\program files\rising\rav\scanpack.dll

    03240000[000B7000]
      [ M] 129. c:\program files\rising\rav\revm.dll

    030C0000[00020000]
      [ M] 130. c:\program files\rising\rav\urutils.dll

    030F0000[00018000]
      [ M] 135. c:\program files\rising\rav\ur000.dat

    03300000[00038000]
      [ M] 131. c:\program files\rising\rav\scriptci.dll

    04FD0000[0001D000]
      [ M] 136. c:\program files\rising\rav\ur001.dat

    05020000[00017000]
      [ M] 137. c:\program files\rising\rav\ur023.dat

    05050000[000F3000]
      [ M] 132. c:\program files\rising\rav\uroutine.dll

    051D0000[00020000]
      [ M] 117. c:\program files\rising\rav\rsstore.dll

    05CD0000[00067000]
      [ M] 111. c:\program files\rising\rav\rslog.dll

    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

    05A90000[00045000]
      [ M] 138. c:\program files\rising\rav\extole.dll

    05B10000[00023000]
      [ M] 134. c:\program files\rising\rav\scansct.dll

    14210000[00038000]
      [ M] 139. c:\program files\rising\rav\extmail.dll

    0BD00000[00023000]
      [ M] 167. c:\program files\rising\rav\scanmac.dll

    0BE50000[0001F000]
      [ M] 168. c:\program files\rising\rav\ur004.dat

    0BED0000[0001C000]
      [AM] 64. c:\windows\system32\ravext.dll

  + 00000a34(2612) sqlservr.exe
    00400000[0071A000]
      [AM] 2. c:\program files\microsoft sql server\mssql\binn\sqlservr.exe

    41060000[00006000]
      [ M] 169. c:\program files\microsoft sql server\mssql\binn\opends60.dll

    41070000[0000D000]
      [ M] 170. c:\program files\microsoft sql server\mssql\binn\ums.dll

    42AE0000[00090000]
      [ M] 171. c:\program files\microsoft sql server\mssql\binn\sqlsort.dll

    60000000[00074000]
      [AM] 75. c:\windows\system32\kmon.dll

    10000000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    00F00000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll

    41080000[00007000]
      [ M] 172. c:\program files\microsoft sql server\mssql\binn\resources\2052\sqlevn70.rll

    42CF0000[00016000]
      [ M] 173. c:\program files\microsoft sql server\mssql\binn\ssnetlib.dll

    410D0000[00006000]
      [ M] 174. c:\program files\microsoft sql server\mssql\binn\ssnmpn70.dll

    42CD0000[00007000]
      [ M] 175. c:\program files\microsoft sql server\mssql\binn\ssmslpcn.dll

  + 00000c00(3072) qqkav_newhua.exe
    00400000[00223000]
      [AM] 71. c:\documents and settings\administrator\桌面\qqkav_newhua.exe

    60000000[00074000]
      [AM] 75. c:\windows\system32\kmon.dll

    10000000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    00F30000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll

    02F60000[00028000]
      [ M] 150. c:\program files\rising\rav\ravscrch.dll

    30000000[003AE000]
      [ M] 151. c:\windows\system32\macromed\flash\flash9e.ocx

    72C80000[00008000]
      [ M] 96. c:\windows\system32\msacm32.drv

  + 00000d78(3448) knownsvr.exe
    00400000[00072000]
      [ M] 176. d:\软件\瑞星\卡卡\knownsvr.exe

    10000000[0002F000]
      [ M] 108. d:\软件\瑞星\卡卡\ncomm.dll

    60000000[00074000]
      [AM] 75. c:\windows\system32\kmon.dll

    00A90000[0002E000]
      [ M] 105. d:\软件\瑞星\卡卡\comx3.dll

    00AC0000[00019000]
      [ M] 103. d:\软件\瑞星\卡卡\syslay.dll
gototop
 

回复:woderizhi

使用System Repair Engineer扫描日志,将日志作为附件上传上来。
下载页面:http://www.kztechs.com/sreng/download.html
操作方法:
1、下载后解压缩,运行SREngPS.EXE;
2、如果无法打开尝试把SREngPS.EXE改名为123.com,并复制到c:\windows目录下运行;
3、依次点击【智能扫描】-【扫描】,耐心等待,扫描结束后点击【保存报告】;
4、选择保存路径,文件名保持默认,直接点击【保存】;
5、打开保存的日志文件SREngLOG.log,完整复制全部内容,新建一个文本文档,将日志中的全部内容粘贴到“新建文本文档.txt”中;
6、将“新建文本文档.txt”作为附件上传,同时务必详细描述问题现象,如果有查杀不净的病毒务必提供病毒名和路径。
注意:扫描前请尽量关闭QQ、游戏、下载工具、媒体播放器等应用程序
gototop
 

回复: woderizhi

bu hao yi si,wo de "yu yan lan" bu zhi zen mo bu neng yong le.QQ mei deng lu dan lao chu xiao xi shuo " QQ shi nian zhong jiang "

附件附件:

文件名:ri zhi.txt
下载次数:152
文件类型:text/plain
文件大小:
上传时间:2008-11-17 13:53:08
描述:txt

gototop
 

回复:woderizhi

1.建议使用XDelBox删除以下文件:(XDelBox1.8下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。


c:\windows\inf\smssu.exe
c:\windows\system32\drivers\qttiatv.sys


2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[{9F684DE8-3E87-4174-9033-E02A3DFD8B61}]    <9F684DE8.dll>
[{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}]    <755D0ED0.dll>
[{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}]    <4FBFD5A4.dll>
[{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}]    <16AF66EB.dll>
[{66AFCB56-FAA9-42D2-8C72-2767A46C7FA8}]    <66AFCB56.dll>
[{C8FFD223-C0FB-40C5-94A0-FD7891AC18E9}]    <C8FFD223.dll>
[{E0D39066-96D7-4891-8527-488ADAFCD60F}]    <E0D39066.dll>
[{70B0129E-726E-4789-A7C0-5DDC33241E94}]    <70B0129E.dll>
[infsykum]    <C:\WINDOWS\inf\smssu.exe>

    启动项目 -- 服务-- 驱动程序之如下项删除:
[qttiatv / qttiatv]    <\??\C:\WINDOWS\system32\drivers\qttiatv.sys>
[de8296f / de8296f]    <>
[de8296f / de8296f]    <>

    系统修复-- HOSTS文件--重置

**************以上分析报告由SREngLog分析助手提供******************
分析:草莽书生
时间:2008-11-17
SREngLog分析助手 1.3 (20070808 更新 BY 草莽书生)


qq文件夹粉碎重新安装。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT