瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 病毒弄得瑞星都打不开了(附SRE日志)

1   1  /  1  页   跳转

[已解决] 病毒弄得瑞星都打不开了(附SRE日志)

病毒弄得瑞星都打不开了(附SRE日志)

瑞星完全瘫痪了,电脑还会蓝屏,请高手帮忙看看该删些杀,杀些啥
[table=50%][tr][td][code]2008-06-07,13:58:04
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><D:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <ATIPTA><D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IMJPMIG8.1><"D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Component Publisher]
    <RfwMain><"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
    <RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><D:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><H:\beatmania 5\desk\LOGON\logonui\green glass diy.exe>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><D:\WINDOWS\system32\RavExt.dll>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
    <WinlogonNotify: MCPClient><D:\Program Files\Common Files\Stardock\mcpstub.dll>  [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
    <WinlogonNotify: WBSrv><D:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll>  [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><D:\WINDOWS\system32\Rundll32.exe D:\WINDOWS\system32\mscories.dll,Install>  [Microsoft Corporation]
==================================
启动文件夹
[Stardock ObjectDock]
  <D:\Documents and Settings\gao\「开始」菜单\程序\启动\Stardock ObjectDock.lnk --> C:\PROGRA~1\OBJECT~1\OBJECT~1.EXE [Stardock]><N>
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Antiy live update / Alive Auto-Update Service][Stopped/Disabled]
  <><N/A>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <D:\WINDOWS\system32\Ati2evxx.exe><>
[ATI Smart / ATI Smart][Stopped/Manual Start]
  <D:\WINDOWS\system32\ati2sgag.exe><>
[##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## / Bonjour Service][Stopped/Auto Start]
  <><N/A>
[Crypkey License / Crypkey License][Stopped/Disabled]
  <crypserv.exe><Kenonic Controls Ltd.>
[FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
  <"D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <D:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"><Microsoft Corporation>
[Chinese Paladin 4 CN Drivers Auto Removal (pr2ach4f) / pr2ach4f][Stopped/Auto Start]
  <D:\WINDOWS\system32\pr2ach4f.exe svc><SOFTSTAR>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
  <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><N/A>
[SolidPDFConverterReadSpool / ScReadSpool][Stopped/Disabled]
  <><N/A>
==================================
驱动程序
[a347bus / a347bus][Stopped/Boot Start]
  <\SystemRoot\system32\DRIVERS\a347bus.sys><N/A>
[a347scsi / a347scsi][Stopped/Boot Start]
  <\SystemRoot\System32\Drivers\a347scsi.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[BM Win32 Network Adapter / bmnadapter][Running/Manual Start]
  <system32\DRIVERS\bmnet.sys><The OpenVPN Project>
[dbhhbgbh / dbhhbgbh][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\dbhhbgbh.sys><N/A>
[ExpScaner / ExpScaner][Stopped/Auto Start]
  <\??\D:\Program Files\Rising\Rav\ExpScan.sys><N/A>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
  <\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><N/A>
[HookCont / HookCont][Running/System Start]
  <\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Technology Co., Ltd>
[HookNtos / HookNtos][Running/System Start]
  <\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Technology Co., Ltd>
[HookReg / HookReg][Running/System Start]
  <\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Technology Co., Ltd>
[HookSys / HookSys][Running/System Start]
  <\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Technology Co., Ltd>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\D:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120 / libusb0][Stopped/Manual Start]
  <system32\DRIVERS\libusb0.sys><http://libusb-win32.sourceforge.net>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
  <\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><N/A>
[mProcRs / mProcRs][Stopped/Auto Start]
  <\??\d:\program files\rising\rfw\mProcRs.sys><N/A>
[Chinese Paladin 4 CN Environment Driver (pe3ach4f) / pe3ach4f][Running/Boot Start]
  <\SystemRoot\system32\drivers\pe3ach4f.sys><SOFTSTAR>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[Chinese Paladin 4 CN Synchronization Driver (ps6ach4f) / ps6ach4f][Running/Boot Start]
  <\SystemRoot\system32\drivers\ps6ach4f.sys><SOFTSTAR>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[rfwbase / rfwbase][Running/Auto Start]
  <\SystemRoot\System32\Drivers\rfwbase.SYS><Beijing Rising Technology Co., Ltd.>
[RsFwDrv / RsFwDrv][Running/System Start]
  <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
  <\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[StarForce Protection Environment Driver (version 1.x.a) / sfdrv01a][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfdrv01a.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology (StarForce)>
[StarForce Protection VFS Driver (version 2.x) / sfvfs02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfvfs02.sys><Protection Technology (StarForce)>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
  <\??\D:\WINDOWS\system32\SVKP.sys><AntiCracking>
[ycsud / ycsud][Stopped/Manual Start]
  <\??\D:\WINDOWS\system32\drivers\ycsud.sys><N/A>
[NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter / yukonwxp][Running/Manual Start]
  <system32\DRIVERS\yukonwxp.sys><Marvell Semiconductor Inc.>
==================================
浏览器加载项
[Thunder Browser Helper]
  {1F364305-AA45-47B5-9F9D-39A8B94E7EF1} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[FG2CatchUrl]
  {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <G:\Program Files\FlashGet\ComDlls\bhoCATCH.dll, FlashGet>
[Loader Class]
  {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} <C:\Program Files\FindeXer\FindeXer.dll, A Part of the LessCliX Suite by Alianyn>
[StylerToolBar]
  {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <D:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[Dldrv2 Control]
  {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} <D:\WINDOWS\DOWNLO~1\Dldrv.ocx, GIGA>
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <D:\WINDOWS\system32\aliedit\aliedit.dll, >
[ICBC Security Ctrl]
  {5AB9367B-DD7F-411D-A030-DF7DE5E17AAE} <D:\WINDOWS\DOWNLO~1\NETBAN~1.OCX, Industrial and Commercial Bank of China>
[ImageShack Toolbar]
  {6932D140-ABC4-4073-A44C-D4A541665E35} <D:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll, ImageShack Corp.>
[Java Plug-in]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
  {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} <D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_07]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <D:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[ファイルバンクランチャー]
  {E0BE586C-7C66-4909-94D6-D18BBBDD6373} <D:\WINDOWS\DOWNLO~1\fbx2.ocx, Gretech Japan>
[Thunder Browser Helper]
  {00000000-12C2-4305-82F9-43058F20E8D2} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[]
  {105E4D0C-5E21-41ED-90F9-013EEF271BD6} <D:\WINDOWS\system32\widgetdownload.dll, 鱼鱼桌面秀widget插件下载工具>
[Thunder Browser Helper]
  {1F364305-AA45-47B5-9F9D-39A8B94E7EF1} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[FG2CatchUrl]
  {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <G:\Program Files\FlashGet\ComDlls\bhoCATCH.dll, FlashGet>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <D:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <H:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Microsoft 外壳 UI 帮助程序]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[ImageShack Toolbar]
  {6932D140-ABC4-4073-A44C-D4A541665E35} <D:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll, ImageShack Corp.>
[WangWangObj Class]
  {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <E:\Program Files\淘宝旺旺\WangWangX6.dll, 阿里巴巴软件(上海)有限公司>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[StylerToolBar]
  {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <D:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[Loader Class]
  {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} <C:\Program Files\FindeXer\FindeXer.dll, A Part of the LessCliX Suite by Alianyn>
[使用迅雷下载]
  <H:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <H:\Program Files\Thunder\Program\getallurl.htm, N/A>
==================================

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; WPS; InfoPath.1; MAXTHON 2.0)
最后编辑hemis 最后编辑于 2008-06-07 20:16:16
分享到:
gototop
 

回复:病毒弄得瑞星都打不开了(附SRE日志)

正在运行的进程
[PID: 812 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 332 / SYSTEM][\??\D:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 600 / SYSTEM][\??\D:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\WINDOWS\system32\Ati2evxx.dll]  [, ]
    [D:\Program Files\Common Files\Stardock\mcpstub.dll]  [Stardock, 0, 0, 5, 2]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll]  [Stardock, 5, 0, 0, 1]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 736 / SYSTEM][D:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 792 / SYSTEM][D:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1052 / SYSTEM][D:\WINDOWS\system32\Ati2evxx.exe]  [, ]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 1096 / SYSTEM][D:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1216 / NETWORK SERVICE][D:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1320 / SYSTEM][D:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.28]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 1344 / SYSTEM][D:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 1472 / NETWORK SERVICE][D:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1592 / SYSTEM][d:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 7.0.0.68]
    [D:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rfw\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [d:\program files\rising\rfw\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.13]
    [d:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.12]
    [d:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.41]
    [d:\program files\rising\rfw\ijt_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.0]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [d:\program files\rising\rfw\unvdet.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.5]
    [d:\program files\rising\rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.3]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 224 / SYSTEM][d:\program files\rising\rfw\rfwstub.exe]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [D:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 508 / LOCAL SERVICE][D:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 556 / SYSTEM][D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.10.3077]
    [D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll]  [Microsoft Corporation, 7.10.3077]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 688 / LOCAL SERVICE][D:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1812 / gao][D:\Program Files\Common Files\Stardock\SDMCP.exe]  [Stardock, 0, 0, 5, 11]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 288 / gao][D:\WINDOWS\system32\Ati2evxx.exe]  [, ]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
[PID: 628 / gao][D:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll]  [N/A, ]
    [D:\PROGRA~1\COMMON~1\Stardock\MCPCore.dll]  [Stardock, 0, 0, 5, 4]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
    [D:\Program Files\Styler\TB\StylerTB.dll]  [StyleFantasist, 1, 1, 8, 0]
    [D:\WINDOWS\system32\icm32.dll]  [Microsoft Corporation, 5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)]
    [H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 18]
    [H:\Program Files\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 11]
    [H:\Program Files\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 12]
    [C:\Program Files\FindeXer\FindeXer.dll]  [A Part of the LessCliX Suite by Alianyn, 1.1.0.3]
    [D:\PROGRA~1\Wopti\WOPTIC~1.DLL]  [Wopti, 1.0.7.126]
    [D:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[PID: 760 / gao][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 7.0.1.65]
    [D:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
    [D:\WINDOWS\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rfw\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [d:\program files\rising\rfw\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [d:\program files\rising\rfw\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [d:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.7]
    [d:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
    [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.13]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
[PID: 1604 / gao][D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5103]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [D:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5103]
    [D:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5103]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5103]
[PID: 1952 / gao][D:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.39]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 500 / gao][D:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.23]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
[PID: 1016 / gao][D:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1456 / gao][C:\Program Files\ObjectDock\ObjectDock.exe]  [Stardock, v1.30.526u]
    [C:\Program Files\ObjectDock\CrashRpt.dll]  [, 3.0.2.2]
    [C:\Program Files\ObjectDock\zlib.dll]  [, 1.1.3]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [D:\Program Files\Common Files\Stardock\ODImg.dll]  [N/A, ]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
    [C:\Program Files\ObjectDock\Docklets\KKMenu\KkMenu.dll]  [N/A, ]
    [D:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[PID: 560 / gao][D:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 20.0.01.19]
    [D:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\WINDOWS\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 38]
    [D:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
    [D:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
    [D:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [D:\Program Files\Rising\Rav\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.29]
    [D:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
    [D:\Program Files\Rising\Rav\Rsguilib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89]
    [D:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 4072 / gao][H:\Program Files\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [d:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.10]
    [d:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.6]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock.Net, Inc, 5.0]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\Program Files\ObjectDock\DockShellHook.dll]  [N/A, ]
    [H:\Program Files\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["D:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
==================================
gototop
 

回复:病毒弄得瑞星都打不开了(附SRE日志)

Winsock 提供者
MSAFD Tcpip [TCP/IP]
    D:\WINDOWS\system32\ESPI11.dll(, N/A)
MSAFD Tcpip [UDP/IP]
    D:\WINDOWS\system32\ESPI11.dll(, N/A)
MSAFD Tcpip [RAW/IP]
    D:\WINDOWS\system32\ESPI11.dll(, N/A)
RSVP UDP Service Provider
    D:\WINDOWS\system32\ESPI11.dll(, N/A)
RSVP TCP Service Provider
    D:\WINDOWS\system32\ESPI11.dll(, N/A)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1      localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1812, D:\PROGRAM FILES\COMMON FILES\STARDOCK\SDMCP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1604, D:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1604, D:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1456, C:\PROGRAM FILES\OBJECTDOCK\OBJECTDOCK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1456, C:\PROGRAM FILES\OBJECTDOCK\OBJECTDOCK.EXE]
==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x00EC1FFD)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x00EC20E5)
==================================
隐藏进程
N/A
==================================[/code][/td][/tr][/table]
gototop
 

回复: 病毒弄得瑞星都打不开了(附SRE日志)

红字的几个都不敢删,其他都删了

附件附件:

文件名:SREngLOG.rar
下载次数:145
文件类型:application/octet-stream
文件大小:
上传时间:2008-6-7 17:11:25
描述:rar

gototop
 

回复:病毒弄得瑞星都打不开了(附SRE日志)

谢谢楼上了,把瑞星卸了重装的确能用了,但是邮件监控无法打开,现在从小红伞变成小黄伞状态了
最后编辑hemis 最后编辑于 2008-06-07 17:46:26
gototop
 

回复: 病毒弄得瑞星都打不开了(附SRE日志)

刚用了Windows XP Fix修复HIJACK的一个问题后重启小绿伞竟然好了?!Dr.Web CureIt扫了一遍说没毒,清理助手也扫了一遍,补丁也打好了,现在就剩下还剩下两个问题没解决,大大给看看吧,谢谢
1.进不了安全模式(一按F8就刷出一屏幕的文件地址,然后提示按ESC停止SPTD.SYS,不管按了没按,光标就停着不动了
2. 下面两个怎么也修复不了
gototop
 

回复:病毒弄得瑞星都打不开了(附SRE日志)

谢谢天月大了,都解决了^_^
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT