我真着急 - 2006-1-25 9:21:00
我的电脑老是出现到计时关机 说什么 Remote Procedure Call (RPC)以外终止
我用以前人家交的办法不行了 就是开始→运行 shutdown-a 的办法 谁能告诉我怎么回事啊?
阿拉伯伯 - 2006-1-25 9:25:00
可能是中冲击波了吧,发个HijackThis日志上来看看好吗?
BlackStone - 2006-1-25 9:33:00
用
Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)工具的下载、使用参考
http://forum.ikaka.com/topic.asp?board=28&artid=7318038
我真着急 - 2006-1-25 9:41:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ Local Security Authority Servicec:\windows\system32\lssas.exe
+ MS-4011 Memory PatchRavSasserBeijing Rising Tech. Co., Ltd.d:\程序\下载\ravsasser.exe
+ RavMonRavMon MicrosofRising realtime monitor Rising realtime monitor Serviced:\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.d:\rising\rav\ravtimer.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedd:\rising\rfw\rfwmain.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Display Panning CPL ExtensionFile not found: deskpan.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.d:\realplayer\rpshell.dll
+ WinRAR shell extensiond:\winrar\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\tencent\qq\qqiehelper.dll
+ ThunderIEHelper Classxunleibho BHOThunder Networking Technologies,LTDc:\windows\system32\xunleibho_v10.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ @shdoclc.dll,-864c:\windows\web\related.htm
+ 腾讯QQQQTENCENTd:\tencent\qq\qq.exe
HKLM\System\CurrentControlSet\Services
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterrisingd:\rising\rav\ccenter.exe
+ RsRavMonRavMonrisingd:\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys
+ EagleNTFile not found: C:\WINDOWS\System32\drivers\EagleNT.sys
+ ExpScanerExpScan.sysd:\rising\rav\expscan.sys
+ FwDrvnt_fwdrvRisingd:\rising\rfw\fwdrv.sys
+ HOOKAPIHOOKAPI Driver瑞星软件有限公司d:\rising\rav\hookapi.sys
+ HookContTDI HOOK DriverRising tech Co. ltdd:\rising\rav\hookcont.sys
+ HookRegd:\rising\rav\hookreg.sys
+ HookSys瑞星d:\rising\rav\hooksys.sys
+ MEMSCANMemScan Driver瑞星软件有限公司d:\rising\rav\memscan.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\tencent\qq\npkcrypt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 29.58 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\windows\system32\drivers\rtl8139.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ VIAudioVinyl AC'97 Codec Combo WDM DriverVIA Technologies, Inc.c:\windows\system32\drivers\vinyl97.sys
BlackStone - 2006-1-25 9:55:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ Local Security Authority Servicec:\windows\system32\lssas.exe
删除启动项
重启
删除c:\windows\system32\lssas.exe试试
BlackStone - 2006-1-25 10:00:00
注意不是lsass.exe
教我怎么想她 - 2006-1-25 10:04:00
ProcessPIDCPUDescriptionCompany Name
System Idle Process095.45
Interruptsn/aHardware Interrupts
DPCsn/aDeferred Procedure Calls
System4
smss.exe588Windows NT Session ManagerMicrosoft Corporation
csrss.exe648Client Server Runtime ProcessMicrosoft Corporation
winlogon.exe672Windows NT Logon ApplicationMicrosoft Corporation
services.exe7163.03Services and Controller appMicrosoft Corporation
svchost.exe876Generic Host Process for Win32 ServicesMicrosoft Corporation
TIMPlatform.exe2436TIMPlatformtencent
AgentSvr.exe232Microsoft Agent ServerMicrosoft Corporation
svchost.exe956Generic Host Process for Win32 ServicesMicrosoft Corporation
CCenter.exe1076CCenterBeijing Rising Technology Co., Ltd.
svchost.exe1092Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe1144Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe1256Generic Host Process for Win32 ServicesMicrosoft Corporation
RavMonD.exe1296RavMondBeijing Rising Technology Co., Ltd.
RavStub.exe1668Rising RavStubBeijing Rising Technology Co., Ltd.
rfwProxy.exe1360Rising Personal Proxy ServiceBeijing Rising Technology Co., Ltd.
rfwsrv.exe1416Rising Personal FireWall ServiceBeijing Rising Technology Co., Ltd.
rfwmain.exe1800Rising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.
spoolsv.exe1584Spooler SubSystem AppMicrosoft Corporation
wdfmgr.exe1932Windows User Mode Driver ManagerMicrosoft Corporation
alg.exe412Application Layer Gateway ServiceMicrosoft Corporation
svchost.exe1228Generic Host Process for Win32 ServicesMicrosoft Corporation
lsass.exe728LSA Shell (Export Version)Microsoft Corporation
IEXPLORE.EXE1924Internet ExplorerMicrosoft Corporation
Explorer.EXE1184Windows ExplorerMicrosoft Corporation
RavTask.exe1620RavTimerBeijing Rising Technology Co., Ltd.
RavMon.exe1796RavMonBeijing Rising Technology Co., Ltd.
AssistSystray.exe1988全能助手后台服务全能助手工作室
IEXPLORE.EXE3492Internet ExplorerMicrosoft Corporation
flashget.exe1852FlashGetAmaze Soft
Rav.exe1468Rising Antivirus Main exeBeijing Rising Technology Co., Ltd.
RsLogVw.exe2828RsLogVwBeijing Rising Technology Co., Ltd.
WinRAR.exe2484
procexp.exe22441.52Sysinternals Process ExplorerSysinternals
QQ.EXE2336QQTENCENT
ctfmon.exe3036CTF LoaderMicrosoft Corporation
RsAgent.exe340RsAgent ApplicationBeijing Rising Technology Co., Ltd.
procexp.exe220Sysinternals Process ExplorerSysinternals
HijackThis1991zww.exe2264HijackThisSoeperman Enterprises Ltd.
NOTEPAD.EXE3772记事本Microsoft Corporation
Process: Procexp Pid: -2
TypeName
ProcessPIDCPUDescriptionCompany Name
System Idle Process095.45
Interruptsn/aHardware Interrupts
DPCsn/aDeferred Procedure Calls
System4
smss.exe588Windows NT Session ManagerMicrosoft Corporation
csrss.exe648Client Server Runtime ProcessMicrosoft Corporation
winlogon.exe672Windows NT Logon ApplicationMicrosoft Corporation
services.exe7163.03Services and Controller appMicrosoft Corporation
svchost.exe876Generic Host Process for Win32 ServicesMicrosoft Corporation
TIMPlatform.exe2436TIMPlatformtencent
AgentSvr.exe232Microsoft Agent ServerMicrosoft Corporation
svchost.exe956Generic Host Process for Win32 ServicesMicrosoft Corporation
CCenter.exe1076CCenterBeijing Rising Technology Co., Ltd.
svchost.exe1092Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe1144Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe1256Generic Host Process for Win32 ServicesMicrosoft Corporation
RavMonD.exe1296RavMondBeijing Rising Technology Co., Ltd.
RavStub.exe1668Rising RavStubBeijing Rising Technology Co., Ltd.
rfwProxy.exe1360Rising Personal Proxy ServiceBeijing Rising Technology Co., Ltd.
rfwsrv.exe1416Rising Personal FireWall ServiceBeijing Rising Technology Co., Ltd.
rfwmain.exe1800Rising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.
spoolsv.exe1584Spooler SubSystem AppMicrosoft Corporation
wdfmgr.exe1932Windows User Mode Driver ManagerMicrosoft Corporation
alg.exe412Application Layer Gateway ServiceMicrosoft Corporation
svchost.exe1228Generic Host Process for Win32 ServicesMicrosoft Corporation
lsass.exe728LSA Shell (Export Version)Microsoft Corporation
IEXPLORE.EXE1924Internet ExplorerMicrosoft Corporation
Explorer.EXE1184Windows ExplorerMicrosoft Corporation
RavTask.exe1620RavTimerBeijing Rising Technology Co., Ltd.
RavMon.exe1796RavMonBeijing Rising Technology Co., Ltd.
AssistSystray.exe1988全能助手后台服务全能助手工作室
IEXPLORE.EXE3492Internet ExplorerMicrosoft Corporation
flashget.exe1852FlashGetAmaze Soft
Rav.exe1468Rising Antivirus Main exeBeijing Rising Technology Co., Ltd.
RsLogVw.exe2828RsLogVwBeijing Rising Technology Co., Ltd.
WinRAR.exe2484
procexp.exe22441.52Sysinternals Process ExplorerSysinternals
QQ.EXE2336QQTENCENT
ctfmon.exe3036CTF LoaderMicrosoft Corporation
RsAgent.exe340RsAgent ApplicationBeijing Rising Technology Co., Ltd.
procexp.exe220Sysinternals Process ExplorerSysinternals
HijackThis1991zww.exe2264HijackThisSoeperman Enterprises Ltd.
NOTEPAD.EXE3772记事本Microsoft Corporation
Process: Procexp Pid: -2
TypeName
我这有问题吗?
© 2000 - 2026 Rising Corp. Ltd.