12   1  /  2  页   跳转

[求助] 紧急!升级后rsfwdrv.sys导致Vista蓝屏

紧急!升级后rsfwdrv.sys导致Vista蓝屏

首先说明,蓝屏仅仅出现在试图上传附件的时候,所以我现在不能上传任何附件,请不要让我按照那个帖子的方法去做。我手上有minidump的文件,但是不能上传。

问题就是这样,只要我上传附件,不管是邮件还是论坛,点“浏览”那个按钮,一点立刻就蓝屏,然后看到是rsfwdrv.sys引起的。

一个异常情况是,最近每次开机都会有一个DNS变色龙被瑞星监控发现,杀了以后没用的。下次开机,只要我打开IE,这个东西就又会出来,瑞星最近一次的监控日志:

Trojan.Win32.DNSChanger.fye                                    删除染毒文件成功                                                2009-02-14 21:49:44                                            文件监控                                                        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE                C:\WINDOWS\SYSTEM32\GAOPDXXSWDWBXQ.DLL 

我查了启动项,都认得的东西,没有异常。全盘杀毒也试过了,没有杀到。

但我觉的两者没有关系,因为昨天没有升级的时候,我还可以正常使用邮件的附件功能。这个病毒已经存在很久了。

操作系统: windows vista business (Thankpad T61 原配)

请瑞星工程师尽快帮我解决。我每天工作依赖于电子邮件,现在不能上传附件,简直就和瘫痪了没区别。
我在线等!

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.04506; .NET CLR 1.1.4322)
最后编辑巴别塔下的熊 最后编辑于 2009-02-15 14:09:11
分享到:
gototop
 

回复: 紧急!升级后rsfwdrv.sys导致Vista蓝屏



引用:
原帖由 帅哥阿福 于 2009-2-15 14:10:00 发表
扫SRENG日志发这论坛来
下载SRENG2.6版工具:http://www.kztechs.com/sreng/download.html
SRENG工具的扫描日志操作,看这贴2楼:http://bbs.ikaka.com/showtopic-8442813.aspx

另外,楼主如果确认是rsfwdrv.sys引起的蓝屏,可将防火墙目录下的该文件版


1、sreng的日志,我马上去弄,稍侯发来
2、我确认是rsfwdrv.sys引起的,刚才又蓝屏,我又看了,是它。
3、rsfwdrv.sys的版本信息我看不到,因为刚才蓝屏,就是因为我去看这个文件的版本信息,一点就蓝屏,和上传附件蓝屏一样,这文件像个炸弹一样碰不得。
4、瑞星防火墙和杀毒都是最新版本。刚在线升级检查了。
最后编辑巴别塔下的熊 最后编辑于 2009-02-15 14:21:23
gototop
 

回复: 紧急!升级后rsfwdrv.sys导致Vista蓝屏

扫到SERNG日志了,但是我不能上附件。只能直接贴。系统限制,分几次贴。
[CODE]
2009-02-15,14:27:57
System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)
Windows Vista Business Edition Service Pack 1 (Build 6001) - Administrative User - Completed Functions Allowed
Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process

Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
    <Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun>  [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <TPHOTKEY><C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <PWMTRV><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor>  [(Verified)Lenovo(Japan)Ltd.]
    <BLOG><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog>  [(Verified)Lenovo (Japan) Ltd.]
    <runeip><"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <TpShocks><TpShocks.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <BigDog305><C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)>  [File is missing]
    <RavTray><"C:\Program Files\Rising\Rav\RsTray.exe" -system>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RFWTray><"C:\Program Files\Rising\Rfw\RsTray.exe" -system>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><explorer.exe>  [(Verified)Microsoft Windows]
    <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><kmon.dll>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WebCheck><C:\Windows\system32\webcheck.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    <WinlogonNotify: igfxcui><igfxdev.dll>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\Windows\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><C:\Windows\system32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    <Browser Customizations><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer><C:\Windows\system32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Adobe Reader Speed Launcher><; "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <AMSG><; C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup>  [(Verified)Lenovo (Japan) Ltd.]
    <AwaySch><; C:\Program Files\Lenovo\AwayTask\AwaySch.EXE>  [(Verified)Lenovo (Japan) Ltd]
    <BigDog305><; C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)>  [File is missing]
    <cssauth><; "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent>  [File is missing]
    <DiskeeperSystray><; "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe">  [File is missing]
    <EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>  [(Verified)Lenovo (Japan) Ltd.]
    <Grid Service><; "C:\Program Files\GridService\peer.exe" -n Grid>  [FS2YOU]
    <HotKeysCmds><; C:\Windows\system32\hkcmd.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IgfxTray><; C:\Windows\system32\igfxtray.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <LenovoOobeOffers><; c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt">  [File is missing]
    <LPManager><; C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe>  [(Verified)Lenovo (Japan) Ltd.]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Nokia.PCSync><; "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog>  [Time Information Services Ltd.]
    <PC Suite Tray><; "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray>  [Nokia]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Persistence><; C:\Windows\system32\igfxpers.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RoxioDragToDisc><; "C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe">  [(Verified)Sonic Solutions]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Sidebar><; C:\Program Files\windows sidebar\sidebar.exe /autoRun>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <SoundMAXPnP><; C:\Program Files\Analog Devices\Core\smax4pnp.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <SunJavaUpdateSched><; "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
    <SynTPEnh><; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <TPFNF7><; C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r>  [(Verified)Lenovo (Japan) Ltd.]
    <TpShocks><; TpShocks.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <TVT Scheduler Proxy><; C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe>  [Lenovo Group Limited]
    <Windows Defender><; %ProgramFiles%\Windows Defender\MSASCui.exe -hide>  [File is missing]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <WindowsWelcomeCenter><; rundll32.exe oobefldr.dll,ShowWelcomeCenter>  [(Verified)Microsoft Windows]
    <WMPNSCFG><; C:\Program Files\Windows Media Player\WMPNSCFG.exe>  [(Verified)Microsoft Windows]
==================================
Startup Folders
[OUTLOOK]
  <C:\Users\adminNUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OUTLOOK.lnk --> C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE [Microsoft Corporation]><N>
[OUTLOOK]
  <C:\Users\adminNUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OUTLOOK.lnk --> C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE [Microsoft Corporation]><N>
==================================
Services
[Andrea ADI Filters Service / AEADIFilters][Running/Auto Start]
  <C:\Windows\system32\AEADISRV.EXE><Andrea Electronics Corporation>
[Bluetooth Service / btwdins][Stopped/Disabled]
  <C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation.>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <C:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[Diskeeper / Diskeeper][Running/Auto Start]
  <C:\Program Files\Diskeeper\DkService.exe><Diskeeper Corporation>
[Juniper Network Connect Service / dsNcService][Running/Auto Start]
  <C:\Program Files\Juniper Networks\Common Files\dsNcService.exe><Juniper Networks>
[Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[ThinkPad PM Service / IBMPMSVC][Running/Auto Start]
  <C:\Windows\system32\ibmpmsvc.exe><Lenovo>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[IPS Core Service / IPSSVC][Running/Auto Start]
  <C:\Windows\system32\IPSSVC.EXE><Lenovo Group Limited>
[IviRegMgr / IviRegMgr][Stopped/Disabled]
  <C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe><InterVideo>
[Power Manager DBC Service / Power Manager DBC Service][Running/Auto Start]
  <"C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE"><Lenovo>
[Rav Process Communication Center / RavCCenter][Stopped/Auto Start]
  <C:\Program Files\Rising\Rav\CCENTER.EXE><Beijing Rising Information Technology Co., Ltd.>
[Rising RavTask Manager / RavTask][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavTask.exe" RavTask><Beijing Rising Information Technology Co., Ltd.>
[Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Rfw Process Communication Center / RfwCCenter][Stopped/Auto Start]
  <C:\Program Files\Rising\Rfw\CCENTER.EXE><Beijing Rising Information Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Stopped/Auto Start]
  <C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Information Technology Co., Ltd.>
[Rising RfwTask Manager / RfwTask][Running/Auto Start]
  <"C:\Program Files\Rising\Rfw\RavTask.exe" RfwTask><Beijing Rising Information Technology Co., Ltd.>
[Roxio UPnP Renderer 9 / Roxio UPnP Renderer 9][Stopped/Disabled]
  <"C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe"><Sonic Solutions>
[Roxio Upnp Server 9 / Roxio Upnp Server 9][Stopped/Disabled]
  <"C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe"><Sonic Solutions>
[RoxMediaDB9 / RoxMediaDB9][Stopped/Disabled]
  <"C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe"><Sonic Solutions>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
  <C:\Program Files\Rising\Rav\RavMonD.exe><Beijing Rising Information Technology Co., Ltd.>
[Rising Scan Service / RsScanSrv][Stopped/Auto Start]
  <C:\Program Files\Rising\Rav\ScanFrm.exe><Beijing Rising Information Technology Co., Ltd.>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
  <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia.>
[Shell Hardware Detection / ShellHWDetection][Running/Auto Start]
  <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation>
[stllssvr / stllssvr][Stopped/Manual Start]
  <"C:\Program Files\Common Files\SureThing Shared\stllssvr.exe"><MicroVision Development, Inc.>
[System Update / SUService][Running/Auto Start]
  <c:\program files\lenovo\system update\suservice.exe><Lenovo Group Limited>
[Themes / Themes][Running/Auto Start]
  <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\shsvcs.dll><Microsoft Corporation>
[ThinkVantage Registry Monitor Service / ThinkVantage Registry Monitor Service][Running/Auto Start]
  <"C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe"><Lenovo Group Limited>
[ThinkPad HDD APS Logging Service / TPHDEXLGSVC][Running/Auto Start]
  <System32\TPHDEXLG.exe><(File is missing)>
[On Screen Display / TPHKSVC][Running/Auto Start]
  <C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe><Lenovo Group Limited>
[TSS Core Service / TSSCoreService][Stopped/Disabled]
  <"C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe"><IBM>
[TVT Scheduler / TVT Scheduler][Running/Auto Start]
  <"C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe"><Lenovo Group Limited>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
  <"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><Microsoft Corporation>
[XAudioService / XAudioService][Stopped/Disabled]
  <C:\Windows\system32\DRIVERS\xaudio.exe><Conexant Systems, Inc.>
==================================
Drivers
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
  <system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[adp94xx / adp94xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu160m.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
[aliide / aliide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
[arc / arc][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
[Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Stopped/Manual Start]
  <system32\DRIVERS\b57nd60x.sys><Broadcom Corporation>
[blbdrive / blbdrive][Stopped/Disabled]
  <\SystemRoot\system32\drivers\blbdrive.sys><N/A>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltlo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltup.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserwdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brusbmdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brusbser.sys><Brother Industries Ltd.>
[Bluetooth Audio Device Service / btwaudio][Stopped/Manual Start]
  <system32\drivers\btwaudio.sys><Broadcom Corporation.>
[Bluetooth AVDT / btwavdt][Stopped/Manual Start]
  <system32\drivers\btwavdt.sys><Broadcom Corporation.>
[btwrchid / btwrchid][Stopped/Manual Start]
  <system32\DRIVERS\btwrchid.sys><Broadcom Corporation.>
[cmdide / cmdide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
[DLABMFSM / DLABMFSM][Running/Auto Start]
  <System32\DLA\DLABMFSM.SYS><Roxio>
[DLABOIOM / DLABOIOM][Running/Auto Start]
  <System32\DLA\DLABOIOM.SYS><Roxio>
[DLACDBHM / DLACDBHM][Running/System Start]
  <System32\Drivers\DLACDBHM.SYS><Roxio>
[DLADResM / DLADResM][Running/Auto Start]
  <System32\DLA\DLADResM.SYS><Roxio>
[DLAIFS_M / DLAIFS_M][Running/Auto Start]
  <System32\DLA\DLAIFS_M.SYS><Roxio>
[DLAOPIOM / DLAOPIOM][Running/Auto Start]
  <System32\DLA\DLAOPIOM.SYS><Roxio>
[DLAPoolM / DLAPoolM][Running/Auto Start]
  <System32\DLA\DLAPoolM.SYS><Roxio>
[DLARTL_M / DLARTL_M][Running/System Start]
  <System32\Drivers\DLARTL_M.SYS><Roxio>
[DLAUDFAM / DLAUDFAM][Running/Auto Start]
  <System32\DLA\DLAUDFAM.SYS><Roxio>
[DLAUDF_M / DLAUDF_M][Running/Auto Start]
  <System32\DLA\DLAUDF_M.SYS><Roxio>
[DRVMCDB / DRVMCDB][Running/Boot Start]
  <\SystemRoot\System32\Drivers\DRVMCDB.SYS><Sonic Solutions>
[DRVNDDM / DRVNDDM][Running/Auto Start]
  <System32\Drivers\DRVNDDM.SYS><Roxio>
[Juniper Network Connect Adapter / dsNcAdpt][Running/Manual Start]
  <system32\DRIVERS\dsNcAdpt.sys><Juniper Networks>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Stopped/Manual Start]
  <system32\DRIVERS\e1e6032.sys><Intel Corporation>
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
  <system32\DRIVERS\E1G60I32.sys><Intel Corporation>
[elxstor / elxstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[Virtual Audio Cable (WDM) / EuMusDesignVirtualAudioCableWdm][Running/Manual Start]
  <system32\DRIVERS\vrtaucbl.sys><Eugene V. Muzychenko>
[hookcont / hookcont][Running/System Start]
  <system32\drivers\HookCont.sys><Beijing Rising Information Technology Co., Ltd.>
[hooksys / hooksys][Running/System Start]
  <system32\drivers\HookSys.sys><Beijing Rising Information Technology Co., Ltd.>
[HpCISSs / HpCISSs][Stopped/Disabled]
  <\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[HSFHWAZL / HSFHWAZL][Stopped/Manual Start]
  <system32\DRIVERS\VSTAZL3.SYS><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSX_DPV.sys><Conexant Systems, Inc.>
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSXHWAZL.sys><Conexant Systems, Inc.>
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

[ialm / ialm][Stopped/Manual Start]
  <system32\DRIVERS\igdkmd32.sys><Intel Corporation>
[Intel AHCI Controller / iaStor][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iastorv.sys><Intel Corporation>
[IBMPMDRV / IBMPMDRV][Running/Manual Start]
  <system32\DRIVERS\ibmpmdrv.sys><Lenovo.>
[igfx / igfx][Running/Manual Start]
  <system32\DRIVERS\igdkmd32.sys><Intel Corporation>
[iirsp / iirsp][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><N/A>
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteatapi.sys><Integrated Technology Express, Inc.>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteraid.sys><Integrated Technology Express, Inc.>
[Lenovo System Interface Driver / lenovo.smi][Running/System Start]
  <system32\DRIVERS\smiif32.sys><Lenovo Group Limited>
[LSI_FC / LSI_FC][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Logic>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[megasas / megasas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[Mraid35x / Mraid35x][Stopped/Disabled]
  <\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit / NETw3v32][Stopped/Manual Start]
  <system32\DRIVERS\NETw3v32.sys><Intel? Corporation>
[Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit / NETw4v32][Running/Manual Start]
  <system32\DRIVERS\NETw4v32.sys><Intel Corporation>
[nfrd960 / nfrd960][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[Nokia USB Phone Parent / nmwcd][Stopped/Manual Start]
  <system32\drivers\ccdcmb.sys><Nokia>
[Nokia USB Generic / nmwcdc][Stopped/Manual Start]
  <system32\drivers\ccdcmbo.sys><Nokia>
[Nokia USB Flashing Phone Parent / nmwcdnsu][Stopped/Manual Start]
  <system32\drivers\nmwcdnsu.sys><Nokia>
[Nokia USB Flashing Generic / nmwcdnsuc][Stopped/Manual Start]
  <system32\drivers\nmwcdnsuc.sys><Nokia>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ntrigdigi.sys><N-trig Innovative Technologies>
[nvraid / nvraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkflt.sys><N/A>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkfwd.sys><N/A>
[PCCS Mode Change Filter Driver / pccsmcfd][Stopped/Manual Start]
  <system32\DRIVERS\pccsmcfd.sys><Nokia>
[IPS Helper Driver / PROCDD][Running/Auto Start]
  <system32\DRIVERS\PROCDD.SYS><Lenovo Group Limited>
[Lenovo Parties Service Access Device Driver / psadd][Running/Manual Start]
  <system32\DRIVERS\psadd.sys><Lenovo (United States) Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
[rfsafe / rfsafe][Running/Boot Start]
  <\SystemRoot\system32\drivers\rfsafe.sys><sina>
[Rising RfwBase Driver / RfwBase9][Running/System Start]
  <system32\DRIVERS\rfwbase.sys><Beijing Rising Information Technology Co., Ltd.>
[rfwtdi / rfwtdi][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\rfwtdi.sys><Beijing Rising Information Technology Co., Ltd.>
[rsfwdrv / rsfwdrv][Running/System Start]
  <\??\C:\Program Files\Rising\Rfw\rsfwdrv.sys><Beijing Rising Information Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Information Technology Co., Ltd.>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 2.x) / sfsync02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfsync02.sys><Protection Technology>
[Shockprf / Shockprf][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\Apsx86.sys><Lenovo.>
[SiSRaid2 / SiSRaid2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Player Recovery Device Control Driver / StMp3Rec][Stopped/Manual Start]
  <System32\Drivers\StMp3Rec.sys><Generic>
[SVKP / SVKP][Running/Auto Start]
  <\??\C:\Windows\system32\SVKP.sys><AntiCracking>
[Symc8xx / Symc8xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\symc8xx.sys><LSI Logic>
[Sym_hi / Sym_hi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_hi.sys><LSI Logic>
[Sym_u3 / Sym_u3][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TPDIGIMN / TPDIGIMN][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ApsHM86.sys><Lenovo.>
[TPPWRIF / TPPWRIF][Running/System Start]
  <System32\drivers\Tppwr32v.sys><N/A>
[Lenovo SM bus driver / TVTI2C][Running/Manual Start]
  <system32\DRIVERS\Tvti2c.sys><Lenovo (United States) Inc.>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[uliahci / uliahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\uliahci.sys><ULi Electronics Inc.>
[UlSata / UlSata][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata.sys><Promise Technology, Inc.>
[ulsata2 / ulsata2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata2.sys><Promise Technology, Inc.>
[upperdev / upperdev][Stopped/Manual Start]
  <system32\DRIVERS\usbser_lowerflt.sys><Windows (R) Codename Longhorn DDK provider>
[UsbserFilt / UsbserFilt][Stopped/Manual Start]
  <system32\DRIVERS\usbser_lowerfltj.sys><Windows (R) Codename Longhorn DDK provider>
[viaide / viaide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
[vvftav / vvftav][Stopped/Manual Start]
  <system32\drivers\vvftav.sys><Vimicro Corporation>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSX_CNXT.sys><Conexant Systems, Inc.>
[XAudio / XAudio][Running/Auto Start]
  <system32\DRIVERS\xaudio.sys><Conexant Systems, Inc.>
[A4 TECH PC Camera V / ZSMC0305][Stopped/Manual Start]
  <System32\Drivers\usbVM305.sys><Vimicro Corporation>

==================================
Browser Add-ons
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
[IDDTInitObj Class]
  {15DDE989-CD45-4561-BF99-D22C0D5C2B74} <C:\PROGRA~1\Sina\ddt\DDTInit.dll, 北京新浪信息技术有限公司>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll, (Signed) BitComet>
[KillObj Class]
  {66C28884-4E5D-494B-80C9-CAA27528FD6D} <C:\PROGRA~1\Sina\ddt\ddtkillw.ocx, 北京新浪信息技术有限公司>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Windows Live 登录帮助程序]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\Windows\system32\UrlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.>
[FlashGetBHO]
  {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} <C:\ProgramData\FlashGetBHO\FlashGetBHO.dll, (Signed) FlashGet>
[CPwmIEBrowserHelper Object]
  {F040E541-A427-4CF7-85D8-75E3E0F476C5} <C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll, (Signed) Lenovo Group Limited>
[CPwmIEToolsMenuItem Object]
  {0045D4BC-5189-4b67-969C-83BB1906C421} <C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll, (Signed) Lenovo Group Limited>
[Java Plug-in 1.6.0_02]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[很快视频搜索]
  {998A88A0-A355-809B-831C-B83A80000991} <http://www.henkuai.com/?from=iebannel, N/A>
[启动UUSee 网络电视]
  {998A88A0-A355-809B-831C-B83A80000992} <C:\Program Files\uusee\UUSeePlayer.exe, (Signed) >
[@btrez.dll,-4015]
  {CCA281CA-C863-46ef-9331-5C8D4460577F} <, >
[BitComet]
  {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} <, >
[新浪点点通]
  {F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[]
  {974AD624-EA50-4831-A6C0-3040F6665396} <C:\PROGRA~1\Sina\ddt\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通阅读器]
  {F0646DC8-58CD-4C64-8F6B-525043914685} <C:\PROGRA~1\Sina\ddt\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通]
  {F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\Windows\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {0045D4BC-5189-4B67-969C-83BB1906C421} <, >
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {022C4009-5283-4365-97BF-144054B40E2E} <, >
[Yahoo! Toolbar Helper]
  {02478D38-C3F9-4EFB-9B51-7695ECA05670} <, >
[Outlook Today's Data-binding control]
  {0468C085-CA5B-11D0-AF08-00609797F0E0} <C:\PROGRA~1\MICROS~3\Office12\OUTLCTL.DLL, (Signed) >
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
[ULiveCtrl Control]
  {070CA17A-4BD2-4612-83B4-32B1B9159B48} <C:\PROGRA~1\Sina\SINAWE~1\302~1.9BE\UCLIVE~1.OCX, (Signed) 北京新浪信息技术有限公司>
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[PeerDraw Class]
  {10072CEC-8CC1-11D1-986E-00A0C955B42E} <%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll, (Signed) N/A>
[IFlashGetNetscapeEx Class]
  {116BA71C-8187-4F15-9A1F-C9D6289155D1} <C:\ProgramData\FlashGetBHO\FlashGetBHO.dll, (Signed) FlashGet>
[Player Class]
  {11F2A418-94B2-4E16-9B0C-B00C0435F903} <C:\Program Files\Tencent\QQ\QQLive\LiveMedia.dll, (Signed) Tencent>
[VistaWUWebControl Class]
  {12A66224-5E8A-4679-8941-0B9B960BF5EA} <%SystemRoot%\system32\wuwebv.dll, (Signed) N/A>
[IDDTInitObj Class]
  {15DDE989-CD45-4561-BF99-D22C0D5C2B74} <C:\PROGRA~1\Sina\ddt\DDTInit.dll, 北京新浪信息技术有限公司>
[Fade]
  {16B280C5-EE70-11D1-9066-00C04FD9189D} <C:\Windows\system32\Dxtmsft.dll, (Signed) Microsoft Corporation>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\Windows\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
[EWA Control]
  {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~2.OCX, (Signed) Synacast>
[InformationCardSigninHelper Class]
  {19916E01-B44E-4E31-94A4-4696DF46157B} <C:\Windows\system32\icardie.dll, (Signed) Microsoft Corporation>
[InstallHelper Class]
  {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <C:\Program Files\Tencent\QQ\QQLive\QQLiveInstaller.dll, (Signed) >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\Windows\System32\wmpdxm.dll, (Signed) Microsoft Corporation>
[]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <, >
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\Windows\system32\mshtml.dll, (Signed) Microsoft Corporation>
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XSL Template]
  {2933BF94-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[JetCarNetscape Class]
  {2974C985-8151-4DE5-B23C-B875F0A8522F} <C:\ProgramData\FlashGetBHO\FlashGetBHO.dll, (Signed) FlashGet>
[UUUpgrade Control]
  {2CACD7BB-1C59-4BBB-8E81-6E83F82C813B} <C:\PROGRA~1\COMMON~1\uusee\UUUPGR~1.OCX, (Signed) UUSSE>
[]
  {2DAD3559-2923-4935-AD49-B673D2539944} <, >
[HtmlDlgSafeHelper Class]
  {3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\Windows\system32\mshtmled.dll, (Signed) Microsoft Corporation>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\Windows\system32\tdc.ocx, (Signed) Microsoft Corporation>
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, (Signed) Microsoft Corporation>
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll, (Signed) BitComet>
[]
  {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} <, >
[]
  {44990301-3C9D-426D-81DF-AAB636FA4345} <, >
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[TVAnts ActiveX Control]
  {4C833081-D026-4FF8-968F-7EAB660D2FBA} <C:\PROGRA~1\TVAnts\TvantsX.ocx, Zhejiang University>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <%SystemRoot%\System32\hhctrl.ocx, (Signed) N/A>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\Windows\system32\ieframe.dll, (Signed) Microsoft Corporation>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\PROGRA~1\PPStream\110~1.261\POWERP~1.DLL, (Signed) PPStream Inc.>
[QHLivePlayer]
  {616DACC1-C5E6-4646-B36A-3FA4FC726BAD} <C:\PROGRA~1\QHLiveII\QHLive.ocx, 球皇体育 (http://www.qhball.com)>
[XMP Class]
  {6483F145-A768-4C41-AACC-52D4D7845851} <C:\ProgramData\Thunder Network\KanKan\xplayer.dll_1_work, Xunlei Networking Technologies,LTD>
[KillObj Class]
  {66C28884-4E5D-494B-80C9-CAA27528FD6D} <C:\PROGRA~1\Sina\ddt\ddtkillw.ocx, 北京新浪信息技术有限公司>
[XDRM]
  {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\ProgramData\Thunder Network\KanKan\xdrm.dll_1_work, >
[StormPlayer Object]
  {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} <C:\Program Files\StormII\mps.dll, 北京暴风网际科技有限公司>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[]
  {7260569F-1D40-4E7F-B95B-2E68D35668B9} <, >
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin18.dll, (Signed) Thunder Networking Technologies,LTD>
[UUPlayerOCX Control]
  {77910CD3-5447-4CCB-92DE-35BA8198BE81} <C:\PROGRA~1\COMMON~1\uusee\UUPlayer.ocx, (Signed) >
[]
  {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} <, >
[]
  {7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
[Peer Adapter]
  {80E18282-3716-48CA-B50C-F7B7F6A32791} <, >
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[XML DOM Document 4.0]
  {88D969C0-F192-11D4-A65F-0040963251E5} <c:\Windows\system32\msxml4.dll, (Signed) Microsoft Corporation>
[XML HTTP 4.0]
  {88D969C5-F192-11D4-A65F-0040963251E5} <c:\Windows\system32\msxml4.dll, (Signed) Microsoft Corporation>
[XML DOM Document 5.0]
  {88D969E5-F192-11D4-A65F-0040963251E5} <C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.dll, (Signed) Microsoft Corporation>
[XML HTTP 5.0]
  {88D969EA-F192-11D4-A65F-0040963251E5} <C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.dll, (Signed) Microsoft Corporation>
[XML DOM Document 6.0]
  {88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[XML HTTP 6.0]
  {88D96A0A-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[Uploader Class]
  {8B054DFE-79A3-4A6A-9F46-CD2A2F601129} <C:\Windows\system32\TXGYMailActiveX.dll, (Signed) Tencent Inc.>
[SopCore Control]
  {8FEFF364-6A5F-4966-A917-A3AC28411659} <C:\PROGRA~1\SopCast\sopocx.ocx, SopCast.com>
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[Windows Live 登录帮助程序]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
  {974AD624-EA50-4831-A6C0-3040F6665396} <C:\PROGRA~1\Sina\ddt\rssband.dll, 北京新浪信息技术有限公司>
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\Windows\system32\UrlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.>
[]
  {998A88A0-A355-809B-831C-B83A80000991} <, >
[]
  {998A88A0-A355-809B-831C-B83A80000992} <, >
[UploadFilePartition Class]
  {A877BA28-1F7E-4876-B299-50B3199A1A5D} <C:\Windows\system32\TXGYMailActiveX.dll, (Signed) Tencent Inc.>
[]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <, >
[]
  {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} <, >
[DapCtrl Class]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.1.5805.77.(663).dll, ShenZhen Thunder Networking Technologies Ltd.>
[]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <, >
[FlashGetBHO]
  {B070D3E3-FEC0-47D9-8E8A-99D4EEB3D3B0} <C:\ProgramData\FlashGetBHO\FlashGetBHO.dll, (Signed) FlashGet>
[]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <, >
[]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <, >
[]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <, >
[SharePoint Spreadsheet Launcher]
  {BDEADE9E-C265-11D0-BCED-00A0C90AB50F} <C:\PROGRA~1\MICROS~3\Office12\OWSCLT.DLL, (Signed) Microsoft Corporation>
[ScreenCapture Class]
  {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} <C:\Windows\system32\TXGYMailActiveX.dll, (Signed) Tencent Inc.>
[KooPlayer Control]
  {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\Users\adminNUS\AppData\Roaming\CCTV\tv\CCTVPL~1.OCX, CCTV.COM>
[BitComet Agent]
  {C8FF2A06-638A-4913-8403-50294CFF6608} <C:\Program Files\BitComet\tools\BitCometAgent_1.2.1.30.dll, (Signed) BitComet>
[Microsoft Office 12 Authorization Control]
  {C9712B19-838B-45A5-ABF2-9A315DDDED50} <C:\PROGRA~1\MICROS~3\Office12\AUTHZAX.DLL, (Signed) Microsoft Corporation>
[]
  {CCA281CA-C863-46EF-9331-5C8D4460577F} <, >
[QQPlayerCtrl Class]
  {CD108273-D434-43E6-AA90-1469F97EB398} <C:\Program Files\Tencent\QQMusic\QzoneMusic.dll, (Signed) 深圳腾讯科技>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\Program Files\StormII\Codec\rmoc3260.dll, (Signed) RealNetworks, Inc.>
[]
  {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, >
[Windows Live 登录控制]
  {D2517915-48CE-4286-970F-921E881B8C5C} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10a.ocx, (Signed) Adobe Systems, Inc.>
[]
  {DC7094C6-8F61-42ED-AECE-63F5EEF647C5} <, >
[Microsoft Silverlight]
  {DFEAF541-F3E1-4C24-ACAC-99C30715084A} <c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll, (Signed)  Microsoft Corporation>
[PlayerCtrl Class]
  {E05BC2A3-9A46-4A32-80C9-023A473F5B23} <C:\Program Files\Tencent\QQMusic\QzoneMusic.dll, (Signed) 深圳腾讯科技>
[]
  {E1771B7F-98BE-407F-BA67-AA16ADA5D0C5} <C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGSC8~1.DLL, (Signed) Microsoft Corporation>
[NameCtrl Class]
  {E18FEC31-2EA1-49A2-A7A6-902DC0D1FF05} <C:\Program Files\Microsoft Office\Office12\NAME.DLL, (Signed) Microsoft Corporation>
[RevealTrans]
  {E31E87C4-86EA-4940-9B8A-5BD5D179A737} <C:\Windows\system32\Dxtmsft.dll, (Signed) Microsoft Corporation>
[UPlayer Control]
  {EAB7A1CC-C77B-45E5-9AC2-AD037D047BCC} <C:\PROGRA~1\COMMON~1\uusee\SEEPLA~1.OCX, (Signed) UUSEE>
[TimwpDll.TimwpCheck]
  {ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} <C:\PROGRA~1\Tencent\QQ\Timwp.dll, (Signed) TENCENT>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Thunder DapPlayer]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.5712.71.520.dll, ShenZhen Thunder Networking Technologies Ltd.>
[Yahoo! ㄣ]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} <, >
[CPwmIEBrowserHelper Object]
  {F040E541-A427-4CF7-85D8-75E3E0F476C5} <C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll, (Signed) Lenovo Group Limited>
[新浪点点通阅读器]
  {F0646DC8-58CD-4C64-8F6B-525043914685} <C:\PROGRA~1\Sina\ddt\rssband.dll, 北京新浪信息技术有限公司>
[]
  {F27237D7-93C8-44C2-AC6E-D6057B9A918F} <, >
[XPPlayer Class]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.1.5853.212.(663).dll, Xunlei Networking Technologies,LTD>
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Free Threaded XML DOM Document 3.0]
  {F5078F33-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP 3.0]
  {F5078F35-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XSL Template 3.0]
  {F5078F36-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[新浪点点通]
  {F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[XML DOM Document]
  {F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Free Threaded XML DOM Document]
  {F6D90F12-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {FB5DA724-162B-11D3-8B9B-AA70B4B0B525} <, >
[]
  {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} <, >
[&使用BitComet下载]
  <res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
  <res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
  <res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000, N/A>
[使用UUSee下载]
  <C:\Program Files\uusee\geturltodown.htm, N/A>
[使用UUSee加速播放]
  <C:\Program Files\uusee\geturltoplay.htm, N/A>
[使用彩信超级自写发送到手机]
  <http://mms.sina.com.cn/mmsnews.html, N/A>
[使用快车(Flas&hGet)下载]
  <C:\FlashGet Network\Flashget\GetUrl.htm, N/A>
[使用快车(Flash&Get)下载全部链接]
  <C:\FlashGet Network\Flashget\GetAllUrl.htm, N/A>
[使用快车(FlashGet)下载该网页FLV]
  <C:\FlashGet Network\Flashget\FlvDetector.htm, N/A>
[使用新浪下载助手下载]
  <C:\PROGRA~1\Sina\ddt\sinadl.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[发送图片到手机(&M)]
  <http://sms.sina.com.cn/diy/send.html?from=467, N/A>
[收藏此页到新浪ViVi]
  <http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A>
[新浪搜索]
  <http://cha.sina.com.cn/ddt.html, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>

==================================
Running Processes
[PID: 452 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 552 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 596 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 604 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 644 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 668 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\system32\SHSVCS.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 720 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 728 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 860 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 936 / SYSTEM][C:\Windows\system32\ibmpmsvc.exe]  [Lenovo, 1.44]
[PID: 1000 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1112 / SYSTEM][C:\Program Files\Rising\Rav\CCENTER.EXE]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rav\cnt09.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37]
    [C:\Program Files\Rising\Rav\cnt08.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7]
[PID: 1136 / SYSTEM][C:\Program Files\Rising\Rfw\CCENTER.EXE]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rfw\cnt09.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37]
[PID: 1160 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1208 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [c:\windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1228 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [c:\windows\system32\shsvcs.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1360 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1376 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1468 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

[PID: 1636 / SYSTEM][C:\Program Files\Rising\Rfw\rfwsrv.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rfw\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rfw\MonBase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5]
    [C:\Program Files\Rising\Rfw\MonComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rfw\rfwlog.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9]
    [C:\Program Files\Rising\Rfw\rfwrule.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.25]
    [C:\Program Files\Rising\Rfw\rfwsrv.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.78]
    [C:\Program Files\Rising\Rfw\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rfw\mPorts.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.0]
    [C:\Program Files\Rising\Rfw\rfwdrvc.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.3]
    [C:\Program Files\Rising\Rfw\Rfwdrv.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.5]
    [C:\Program Files\Rising\Rfw\urlrule.dll]  [Beijing Rising Information Technology Co., Ltd., 1.0.0.18]
    [C:\Program Files\Rising\Rfw\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\rsnetsvr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13]
    [C:\Program Files\Rising\Rfw\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rfw\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rfw\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rfw\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\rfwproxy.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.25]
    [C:\Program Files\Rising\Rfw\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rfw\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rfw\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
[PID: 1664 / SYSTEM][C:\Program Files\Rising\Rav\RavMonD.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1]
    [C:\Program Files\Rising\Rav\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\moncomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rav\MonBase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5]
    [C:\Program Files\Rising\Rav\Rslog.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.32]
    [C:\Program Files\Rising\Rav\mondrv.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7]
    [C:\Program Files\Rising\Rav\defmon.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 29]
    [C:\Program Files\Rising\Rav\moncom08.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1]
    [C:\Program Files\Rising\Rav\MonRule.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9]
    [C:\Program Files\Rising\Rav\FileMon.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 21]
    [C:\Program Files\Rising\Rav\MailMon.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rav\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rav\Hooksys.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 18]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HookCont.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11]
    [C:\Program Files\Rising\Rav\rsnetsvr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13]
    [C:\Program Files\Rising\Rav\BACore.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 19]
    [C:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSStore.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9]
    [C:\Program Files\Rising\Rav\ScanAdd.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.14]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.33]
    [C:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\ffr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\nvfile.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\scanexec.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\unexe.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1]
    [C:\Program Files\Rising\Rav\scanex.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 18]
    [C:\Program Files\Rising\Rav\extfile.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rav\pearc.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\scanpe.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7]
    [C:\Program Files\Rising\Rav\ur000.dat]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5]
    [C:\Program Files\Rising\Rav\revm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\urutils.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\scansct.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\posttrt.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\ur001.dat]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\ur025.dat]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1]
    [C:\Program Files\Rising\Rav\scriptci.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1]
    [C:\Program Files\Rising\Rav\uroutine.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\extmail.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
[PID: 1876 / SYSTEM][C:\Program Files\Rising\Rav\rsnetsvr.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13]
    [C:\Program Files\Rising\Rav\NComm.dll]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.9]
    [C:\Program Files\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rav\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
[PID: 1932 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1972 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 348 / SYSTEM][C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe]  [Lenovo Group Limited, 1.03]
[PID: 376 / SYSTEM][C:\Windows\system32\IPSSVC.EXE]  [Lenovo Group Limited, 3, 0, 3, 0]
    [C:\Windows\system32\PROCHLP.DLL]  [Lenovo Group Limited, 3, 0, 0, 0]
    [C:\Program Files\Lenovo\AwayTask\AwayDB.DLL]  [Lenovo Group Limited, 3, 0, 3, 0]
[PID: 396 / SYSTEM][C:\Windows\system32\AEADISRV.EXE]  [Andrea Electronics Corporation, 1.0.32.3]
[PID: 484 / SYSTEM][C:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 8, 12, 12]
    [C:\Program Files\StormII\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\StormII\bfoptdll.dll]  [北京暴风网际科技有限公司, 3, 8, 7, 16]
    [C:\Program Files\StormII\box\BoxLog.dll]  [北京暴风网际科技有限公司, 3, 8, 12, 12]
[PID: 792 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1108 / SYSTEM][C:\Program Files\Diskeeper\DkService.exe]  [Diskeeper Corporation, 12.0.759.0]
    [C:\Program Files\Diskeeper\PrFacade.dll]  [Diskeeper Corporation, 12.0.759.0]
    [C:\Program Files\Diskeeper\DKLib.dll]  [Diskeeper Corporation, 12.0.759.0]
    [C:\Program Files\Diskeeper\Tab.dll]  [Diskeeper Corporation, 3.0.38.0]
    [C:\Program Files\Diskeeper\2052\DkRes.dll]  [Diskeeper Corporation, 12.0.759.0]
    [C:\Program Files\Diskeeper\DkTabProvider.dll]  [Diskeeper Corporation, 12.0.759.0]
    [C:\Program Files\Diskeeper\NsIfaastMeas.dll]  [Diskeeper Corporation, 12.0.759.0]
[PID: 808 / SYSTEM][C:\Program Files\Juniper Networks\Common Files\dsNcService.exe]  [Juniper Networks, 6, 0, 0, 12507]
[PID: 1548 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 11. 5. 0. 2]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 11. 5. 0. 2]
[PID: 2068 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2088 / SYSTEM][C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE]  [Lenovo, 1.0.0.1]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
[PID: 2116 / SYSTEM][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23]
    [C:\Program Files\Rising\Rav\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rav\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\rsstub.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rav\rstask.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 36]
[PID: 2136 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  [Intel Corporation, 11. 5. 0. 2]
[PID: 2148 / SYSTEM][C:\Program Files\Rising\Rav\RsStub.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rav\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
[PID: 2180 / SYSTEM][C:\Program Files\Rising\Rfw\RavTask.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23]
    [C:\Program Files\Rising\Rfw\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rfw\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rfw\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rfw\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rfw\rsstub.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rfw\rstask.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 36]
[PID: 2236 / SYSTEM][C:\Program Files\Rising\Rav\ScanFrm.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.11]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rav\moncomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\Program Files\Rising\Rav\scansrvp.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.11]
    [C:\Program Files\Rising\Rav\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Program Files\Rising\Rav\ScanSrv.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.9]
    [C:\Program Files\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rav\ScanSimT.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\Rav\ScanBT.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.38]
    [C:\Program Files\Rising\Rav\ScanStub.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.8]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.32]
    [C:\Program Files\Rising\Rav\ScanAdd.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.14]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.33]
    [C:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
[PID: 2264 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2352 / SYSTEM][C:\Program Files\Rising\Rfw\RsStub.exe]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rfw\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
[PID: 2368 / SYSTEM][C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe]  [Lenovo Group Limited, 1.20.0301.00]
[PID: 2452 / SYSTEM][C:\Windows\System32\TPHDEXLG.exe]  [Lenovo., 1.60.0.6]
[PID: 2468 / SYSTEM][C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe]  [Lenovo Group Limited, 4,0,504,0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\MFC71ENU.DLL]  [Microsoft Corporation, 7.10.6030.0]
[PID: 2572 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2696 / SYSTEM][c:\program files\lenovo\system update\suservice.exe]  [Lenovo Group Limited, 3.0.23.0]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7fc75a5efc16a58b759ead620b895fb9\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\7f5a60668cfdc7daf3ed2daf2db01064\System.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\49765af758b875cde367e974066cac62\System.ServiceProcess.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [c:\program files\lenovo\system update\TvsuServiceCommon.dll]  [ , 0.0.0.0]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\0b83502a54c9b86a4f38298b66357ba3\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

[PID: 3296 / adminNUS][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\igdumd32.dll]  [Intel Corporation, 7.14.10.1437]
[PID: 3332 / adminNUS][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\btncopy.dll]  [Broadcom Corporation., 6.0.1.4900]
    [C:\Program Files\Nokia\Nokia PC Suite 7\phonebrowser.dll]  [Nokia, 7, 0, 103, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.DLL]  [Nokia, 7, 0, 140, 6]
    [C:\Program Files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 7, 0, 64, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 7, 0, 20, 0]
    [C:\Program Files\Lenovo\Drag-to-Disc\Shellex.dll]  [Roxio, 9.0.5.27]
    [C:\Windows\system32\DLAAPI_W.DLL]  [N/A, ]
    [C:\Program Files\Lenovo\Drag-to-Disc\ShellRes.dll]  [Roxio, 9.0.5.27]
[PID: 3516 / adminNUS][C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe]  [Lenovo Group Limited, 1.04]
    [C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.dll]  [Lenovo Group Limited, 1.00]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
    [C:\Program Files\Lenovo\HOTKEY\tplhmm.dll]  [Lenovo Group Limited, 1.01]
[PID: 3524 / adminNUS][C:\Windows\System32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL]  [Lenovo Group Limited, 1, 0, 0, 0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\System32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\US\PWMRT32V.DLL]  [N/A, ]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIF32V.DLL]  [Lenovo Group Limited, 1, 0, 0, 0]
    [C:\Windows\System32\Sensor.dll]  [Lenovo., 1.60.0.6]
    [C:\Windows\System32\OEMDSPIF.DLL]  [Intel Corporation, 7.14.10.1437]
    [C:\Windows\system32\igfxdev.dll]  [Intel Corporation, 7.14.10.1437]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\ATM.DLL]  [Lenovo Japan, 1, 3, 1, 0]
[PID: 3540 / adminNUS][C:\Program Files\Rising\AntiSpyware\RSTray.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.16]
    [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\AntiSpyware\RsXML.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
    [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Rising\AntiSpyware\ComServ.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.31]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\AntiSpyware\rscommon.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.1.1]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\AntiSpyware\pngdll.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\runiep.dll]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.42]
    [C:\Program Files\Rising\AntiSpyware\NComm.dll]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.11]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\AntiSpyware\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 3548 / adminNUS][C:\Windows\System32\TpShocks.exe]  [Lenovo., 1.61.0.1]
    [C:\Program Files\ThinkPad\TpShocks\MUI\0409\TpShocks.dll]  [Lenovo., 1.61.0.1]
    [C:\Windows\System32\Sensor.dll]  [Lenovo., 1.60.0.6]
    [C:\Windows\System32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3560 / adminNUS][C:\Windows\vm305_sti.exe]  [VM305SNAP, 3, 6, 818, 7]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3572 / adminNUS][C:\Program Files\Rising\Rav\RsTray.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.22]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rav\ComServ.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.49]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\rslang.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 27]
    [C:\Program Files\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rav\rsxml.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rav\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Program Files\Rising\Rav\MonState.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7]
    [C:\Program Files\Rising\Rav\ScanEvnt.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.12]
    [C:\Program Files\Rising\Rav\rsguilib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 70]
    [C:\Windows\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\MFC71ENU.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rav\rspalvd.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.21]
    [C:\Program Files\Rising\Rav\ravbintl.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 25]
    [C:\Program Files\Rising\Rav\mruleui.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 10]
    [C:\Program Files\Rising\Rav\MonTray.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.90]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RavITray.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 19]
    [C:\Program Files\Rising\Rav\ScanPrxy.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.14]
    [C:\Program Files\Rising\Rav\rsmginfo.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
[PID: 3580 / adminNUS][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 9.1.3.6 21Nov07]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\SynCOM.dll]  [Synaptics, Inc., 9.1.3.6 21Nov07]
    [C:\Windows\system32\SynTPAPI.dll]  [Synaptics, Inc., 9.1.3.6 21Nov07]
[PID: 3592 / adminNUS][C:\Program Files\Rising\Rfw\RsTray.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.22]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rfw\ComServ.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.49]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rfw\rslang.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 27]
    [C:\Program Files\Rising\Rfw\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rfw\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rfw\rsxml.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Program Files\Rising\Rfw\MonState.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7]
    [C:\Program Files\Rising\Rfw\rfwrule.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.25]
    [C:\Program Files\Rising\Rfw\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [C:\Program Files\Rising\Rfw\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rfw\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rfw\rspalvd.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.21]
    [C:\Program Files\Rising\Rfw\rsguilib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 70]
    [C:\Windows\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\MFC71ENU.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rfw\ravbintl.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 25]
    [C:\Program Files\Rising\Rfw\rsnetsvr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13]
    [C:\Program Files\Rising\Rfw\rsmginfo.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rfw\rfwtray.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 1, 5]
    [C:\Program Files\Rising\Rfw\PngDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [C:\Program Files\Rising\Rfw\rfwlog.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9]
[PID: 3604 / adminNUS][C:\Program Files\Windows Live\Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.5.1302.1018]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3612 / adminNUS][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.60]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\igdumd32.dll]  [Intel Corporation, 7.14.10.1437]
[PID: 3620 / adminNUS][C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe]  [Lenovo Group Limited, 5.01]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3644 / adminNUS][C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE]  [Microsoft Corporation, 12.0.6316.5000]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
    [C:\PROGRA~1\MICROS~3\Office12\ADDINS\COLLEA~1.DLL]  [, ]
    [C:\Program Files\Rising\Rav\RsOLScan.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.10]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Rising\Rav\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [C:\Program Files\Rising\Rav\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanPrxy.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.14]
    [C:\Program Files\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [C:\Program Files\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\Program Files\Rising\Rav\rslang.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 27]
    [C:\PROGRA~1\MICROS~3\Office12\ADDINS\UMOUTL~1.DLL]  [, ]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL]  [, ]
    [C:\Program Files\Rising\Rav\RsPlugIn.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.15]
[PID: 3736 / adminNUS][C:\Program Files\Lenovo\Zoom\TpScrex.exe]  [Lenovo Group Limited, 2.02]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 4020 / adminNUS][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\igfxTMM.dll]  [Intel Corporation, 7.14.10.1437]
    [C:\Windows\system32\igfxdev.dll]  [Intel Corporation, 7.14.10.1437]
[PID: 4084 / adminNUS][C:\Windows\System32\mobsync.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\System32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2060 / SYSTEM][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1280 / adminNUS][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 9.1.3.6 21Nov07]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\SynCOM.dll]  [Synaptics, Inc., 9.1.3.6 21Nov07]
[PID: 1084 / adminNUS][C:\Windows\system32\wbem\unsecapp.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2404 / SYSTEM][C:\Windows\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 2672 / adminNUS][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL]  [北京新浪信息技术有限公司, 1, 2, 1, 5]
    [C:\PROGRA~1\Sina\ddt\DDTInit.dll]  [北京新浪信息技术有限公司, 1, 2, 1, 7]
    [C:\PROGRA~1\Sina\ddt\DDTUpdate.dll]  [北京新浪信息技术有限公司, 1, 2, 1, 1]
    [C:\PROGRA~1\Sina\ddt\ddtwea.ocx]  [北京新浪信息技术有限公司, 1, 1, 0, 7]
    [C:\PROGRA~1\Sina\ddt\DDTcomm.dll]  [北京新浪信息技术有限公司, 1, 1, 0, 3]
    [C:\PROGRA~1\Sina\ddt\ddtnews.ocx]  [北京新浪信息技术有限公司, 1, 1, 1, 5]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
    [C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll]  [BitComet, 20080626]
    [C:\PROGRA~1\Sina\ddt\ddtkillw.ocx]  [北京新浪信息技术有限公司, 1, 1, 0, 5]
    [C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll]  [Sun Microsystems, Inc., 6.0.20.5]
    [C:\Program Files\Java\jre1.6.0_02\bin\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\Windows\system32\UrlFilter.dll]  [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15]
    [C:\Program Files\Rising\AntiSpyware\UrlRule.dll]  [Beijing Rising Information Technology Co., Ltd., 1.0.0.15]
    [C:\ProgramData\FlashGetBHO\FlashGetBHO.dll]  [FlashGet, 2, 1, 0, 1024]
    [C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll]  [Lenovo Group Limited, 2.1.0]
    [C:\Program Files\Lenovo\Client Security Solution\tvt_passwordmanager.dll]  [Lenovo Group Limited, 2.1.0]
    [C:\Program Files\Lenovo\Client Security Solution\css_banner.dll]  [Lenovo Group Limited, 8.00.0121.00]
    [C:\Program Files\Lenovo\Client Security Solution\csswait.dll]  [Lenovo Group Limited, 8.00.0121.00]
    [C:\Windows\system32\cssuserdatadispatcher.dll]  [Lenovo Group Limited, 8.00.0121.00]
    [C:\Program Files\Lenovo\Client Security Solution\css_dlgcustompolicy.dll]  [Lenovo Group Limited, 8.00.0121.00]
    [C:\Windows\system32\tvttsp.dll]  [Lenovo, 1,1,3,107]
    [C:\Windows\system32\tcsrpc.dll]  [Lenovo, 1,1,3,107]
    [C:\Program Files\Common Files\Lenovo\tvt_think_res.dll]  [Lenovo Group Limited, 1.20.0300.00]
    [C:\Program Files\Lenovo\Client Security Solution\css_think_res.dll]  [Lenovo Group Limited, 8.00.0121.00]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.60]
    [C:\Windows\system32\igdumd32.dll]  [Intel Corporation, 7.14.10.1437]
    [C:\Windows\system32\Macromed\Flash\Flash10a.ocx]  [Adobe Systems, Inc., 10,0,12,36]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
    [C:\Windows\system32\UNISPIM6.IME]  [北京紫光华宇软件股份有限公司, 6.1.0.6223]
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

[PID: 3192 / adminNUS][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.60]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Windows\system32\igdumd32.dll]  [Intel Corporation, 7.14.10.1437]
[PID: 2720 / adminNUS][C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe]  [Microsoft Corporation, 4.200.520.1]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 4340 / adminNUS][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Nokia\Nokia PC Suite 7\phonebrowser.dll]  [Nokia, 7, 0, 103, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.DLL]  [Nokia, 7, 0, 140, 6]
    [C:\Program Files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 7, 0, 64, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 7, 0, 20, 0]
[PID: 2668 / adminNUS][C:\Users\adminNUS\AppData\Local\Temp\Rar$EX00.091\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 4060 / adminNUS][C:\Users\adminNUS\AppData\Local\Temp\Rar$EX00.091\SREc9d76888.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\Windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Users\adminNUS\AppData\Local\Temp\Rar$EX00.091\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  Error. [C:\Windows\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["%SystemRoot%\hh.exe" %1]
.HLP  OK. [%SystemRoot%\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1      localhost
::1            localhost

==================================
Process Privileges Scan
N/A

==================================
Scheduled Tasks
[Enabled] \\PMTask
        C:\PROGRA~1\ThinkPad\UTILIT~1\PwmIdTsv.exe
[Enabled] \\RunAsStdUser Task23607
        C:\PROGRAM FILES\RISING\RAV\RavStore.exe
[Enabled] \\{4C4128ED-CD1F-4A90-9B06-929C55CABA1D}
        C:\Windows\system32\pcalua.exe -a "C:\Program Files\Rising\Rfw\Update\Setup.exe" -c /UNINSTALL
[Enabled] \\{B9AB94C1-8876-4EAF-ABFD-8BA2D40F9E3C}
        C:\Windows\system32\pcalua.exe -a "C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_2_0_30\Temp{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}.exe" -c /X
[Disabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
        N/A
[Enabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
        N/A
[Enabled] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
        BthUdTask.exe $(Arg0)
[Enabled] \Microsoft\Windows\CertificateServicesClient\SystemTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
        N/A
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
        %SystemRoot%\System32\wsqmcons.exe
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
        %SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[Enabled] \Microsoft\Windows\Defrag\ManualDefrag
        %windir%\system32\defrag.exe -c
[Enabled] \Microsoft\Windows\Defrag\ScheduledDefrag
        %windir%\system32\defrag.exe -c -i
[Enabled] \Microsoft\Windows\MobilePC\HotStart
        N/A
[Enabled] \Microsoft\Windows\MobilePC\TMM
        N/A
[Enabled] \Microsoft\Windows\MUI\LPRemove
        %windir%\system32\lpremove.exe
[Enabled] \Microsoft\Windows\MUI\Mcbuilder
        C:\Windows\System32\mcbuilder.exe
[Enabled] \Microsoft\Windows\Multimedia\SystemSoundsService
        N/A
[Enabled] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
        N/A
[Enabled] \Microsoft\Windows\Shell\CrawlStartPages
        N/A
[Disabled] \Microsoft\Windows\SideShow\AutoWake
        N/A
[Enabled] \Microsoft\Windows\SideShow\GadgetManager
        N/A
[Disabled] \Microsoft\Windows\SideShow\SessionAgent
        N/A
[Disabled] \Microsoft\Windows\SideShow\SystemDataProviders
        N/A
[Disabled] \Microsoft\Windows\SystemRestore\SR
        %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict1
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict2
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[Enabled] \Microsoft\Windows\UPnP\UPnPHostConfig
        sc.exe config upnphost start= auto
[Enabled] \Microsoft\Windows\Windows Error Reporting\QueueReporting
        %windir%\system32\wermgr.exe -queuereporting
[Enabled] \Microsoft\Windows\Wired\GatherWiredInfo
        %windir%\system32\gatherWiredInfo.vbs
[Enabled] \Microsoft\Windows\Wireless\GatherWirelessInfo
        %windir%\system32\gatherWirelessInfo.vbs

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


[/CODE]
gototop
 

回复:紧急!升级后rsfwdrv.sys导致Vista蓝屏

如果可以,请同时帮我看一下那个dnschanger的病毒是怎么回事(我在顶楼说的)。杀不掉。

症状:
1、不能登录瑞星网站,怀疑被病毒屏蔽
2、不能升级瑞星,提示错误12007
3、不能升级windows update,提示错误代码82007F8F。微软对这个代码的解释是本机时间日期错误,或者根证书没有更新。我确定本机时间是正确,因为和time.windows.com同步的。根证书那些的也按照微软的解决方案做了,没用。

问题1和2已经解决,但是我的办法是关闭windows的DNS client服务,这个服务已经被我禁用了,因为只要它打开,就不能升级瑞星,不知道是不是病毒在里面做了手脚。

问题3到现在没法解决,不能用windows update很麻烦。
请高手们帮忙。
最后编辑巴别塔下的熊 最后编辑于 2009-02-15 14:36:33
gototop
 

回复: 紧急!升级后rsfwdrv.sys导致Vista蓝屏



引用:
原帖由 嗷嗷不高兴 于 2009-2-15 14:45:00 发表
重启计算机到带网络链接的安全模式,该模式下瑞星软件并不自行启动。然后将dump文件与日志一同打包发上来。

附件附件:

下载次数:258
文件类型:application/octet-stream
文件大小:
上传时间:2009-2-15 14:53:48
描述:Dump文件和Sreng扫描结果

最后编辑巴别塔下的熊 最后编辑于 2009-02-15 15:05:48
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT