瑞星卡卡安全论坛
wbxhs - 2007-7-27 10:46:00
你试着找一台有问题的机,扫份日志上来看看!
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 关掉所有手动打开的东西
4 智能扫描=》扫描=》保存报告
5 把日志中的报告完整拷贝贴上来,不要修改,(一次贴不完分多次贴)!
飞天揽月 - 2007-7-27 10:49:00
把你的C盘格式后再重新安装系统。利用你的局域网在别的电脑上下载安装端共享安装试试看!!!
老GG - 2007-7-27 11:00:00
1、2楼的朋友
非常感谢你们的及时回应,我已是激动得感激流涕了!谢谢!谢谢!
2楼,c盘是格式了重装的,在局网上共享安装这个,能否再请吧具体步骤列细一点,知道,咱菜鸟啊,这也是没办法的事,恳请了!
1楼,您这是什么呀,怎么整啊,能否再详细一点,多谢了!
又:我已下载了此软件,正在学习怎么用,学好了就按你说的吧日志传上来哈,费心了!
wbxhs - 2007-7-27 11:09:00
你就下载那个软件扫描份日志(在有问题的机上)分次贴上来!
飞天揽月 - 2007-7-27 13:32:00
| 引用: |
【老GG的贴子】1、2楼的朋友 非常感谢你们的及时回应,我已是激动得感激流涕了!谢谢!谢谢! 2楼,c盘是格式了重装的,在局网上共享安装这个,能否再请吧具体步骤列细一点,知道,咱菜鸟啊,这也是没办法的事,恳请了! 1楼,您这是什么呀,怎么整啊,能否再详细一点,多谢了! 又:我已下载了此软件,正在学习怎么用,学好了就按你说的吧日志传上来哈,费心了! ……………… |
1、格式后重新安装,我就不多说了!
2、局域网共享安装:例如你公司里面有多台电脑,那么你选择一个性能比较好的并且没有出现问题的电脑用其下在一个瑞星安装端“www.rising.com.cn”里产品升级里有,然后将下载下的安装端放在一个文件夹中共享之,OK你在去你那台有问题的电脑利用局域网找到上述共享的文件夹,安装瑞星试试!
老GG - 2007-7-27 15:46:00
谢谢2楼的朋友了!这个方法很好,有机会我一定试一下。只是现在他们让电脑公司的人来装了卡巴斯基了,没办法,作为一种选择吧,以后有机会再试吧,再次感谢了!
这贴子我也复制保存了!
老GG - 2007-7-27 15:56:00
========Content========
========Content========
【回复“wbxhs”的帖子】
1楼的老兄:
很遗憾,他们等不急,就让电脑公司来装了卡巴斯基了。不过,我还是想了解问题到底出在哪儿,以后遇到类似问题,也好处理,所以还是吧日志他传上来,请您指教!
还有就是,问题可不可能出在下载上,我在我的机器上下载了也不能用,主要是“安装包 19.16Rav2007”不能打开,显示的就是我最先传上来的图片。这个应该不过期啊,同样的板子,我的其他机器都还用得尚好。也能升级,要是就这样过期了,我们才冤,当时考虑到以后要购机器,所以多买了几十套,这下还没用就过期了,才可惜些钱哟,呵呵!
[CODE]
2007-07-27,15:09:17
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
<360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start> [奇虎网]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\Userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
老GG - 2007-7-27 15:58:00
启动文件夹
N/A
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基反病毒6.0个人版 / AVP][Running/Auto Start]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[EPSON Printer Status Agent2 / EPSONStatusAgent2][Running/Auto Start]
<C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe><SEIKO EPSON CORPORATION>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
==================================
驱动程序
[AliIde / AliIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme 57xx Gigabit Controller / b57w2k][Running/Manual Start]
<system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[senfilt / senfilt][Running/Manual Start]
<system32\drivers\senfilt.sys><Creative Technology Ltd.>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
==================================
浏览器加载项
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
[Web反病毒统计]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[JUJU猫]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.jujumao.net, N/A>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[使用网际快车下载]
<C:\PROGRA~1\FLASHGET\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\PROGRA~1\FLASHGET\jc_all.htm, N/A>
[使用迅雷下载]
<C:\Program Files\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
老GG - 2007-7-27 16:00:00
正在运行的进程
[PID: 428 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 792 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 968 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4116]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 996 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1076 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1164 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1252 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1324 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1540 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\EBPMON2.DLL] [SEIKO EPSON CORPORATION, 2, 39, 0, 0]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU15CE.DLL] [SEIKO EPSON Corporation, 0.3.0.3]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DMAI13.DLL] [SEIKO EPSON Corporation, 0. 3. 0. 16]
[PID: 1772 / user][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU15CE.DLL] [SEIKO EPSON Corporation, 0.3.0.3]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[C:\WINDOWS\system32\UNISPIM.IME] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[PID: 1824 / user][C:\Program Files\Analog Devices\Core\smax4pnp.exe] [Analog Devices, Inc., 5, 2, 0, 5]
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] [Analog Devices, Inc., 5, 2, 3, 000]
[C:\WINDOWS\system32\EDCrypt.DLL] [Analog Devices Incorporated, 1.0.0.8]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[PID: 1928 / user][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 3, 5, 2, 1001]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 5, 0, 1001]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 5, 1, 1001]
[PID: 1940 / user][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 192 / SYSTEM][C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe] [SEIKO EPSON CORPORATION, 2, 3, 0, 0]
[C:\WINDOWS\system32\EBAPI2.DLL] [SEIKO EPSON CORPORATION, 1, 4, 0, 0]
[C:\Program Files\Common Files\EPSON\EBAPI\EBPLPT.DLL] [SEIKO EPSON CORPORATION, 2, 26, 0, 0]
[PID: 528 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2644 / user][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3510]
老GG - 2007-7-27 16:02:00
========Content========
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[PID: 2868 / user][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\PROGRA~1\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\basegui.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\thpimpl.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\FSSync.dll] [Kaspersky Lab, 6.0.5.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\winreg.ppl] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Thunder\ComDlls\ThunderAgent_003.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[PID: 204 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932 / user][C:\Program Files\Tencent\qq\QQ.exe] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQHelperDll.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\Program Files\Tencent\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\Tencent\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[C:\Program Files\Tencent\qq\QQAPI.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\qq\LoginCtrl.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\LoginCtrlRes.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQRes.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQMainFrame.dll] [N/A, ]
[C:\Program Files\Tencent\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\qq\CQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\Tencent\qq\NewSkin.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\HostingMgr.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\CameraDll.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\MailSummary.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQKnowledgeSearch.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQAllInOne.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\QQSpace.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\Tencent\qq\QQGroupMng.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQPlugin.dll] [N/A, ]
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQAvatar.dll] [N/A, ]
[C:\Program Files\Tencent\qq\QQCustomFace.dll] [N/A, ]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Tencent\qq\QRingMng.dll] [N/A, ]
[C:\Program Files\Tencent\qq\LongConnection.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\PhoneAPI.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Tencent\qq\QQPet.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQFileTransfer.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\OEMApplication.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
老GG - 2007-7-27 16:03:00
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.2.621]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Tencent\qq\BQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\qq\CommercesMng.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\Tencent\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
[C:\Program Files\Tencent\qq\QQSceneMng.dll] [N/A, ]
[C:\Program Files\Tencent\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\qq\ImageOle.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQLiveQMng.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQMagicFace.dll] [TENCENT, 7,0,365,1701]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,60,120]
[C:\Program Files\Tencent\QQGame\GamePublic.dll] [N/A, ]
[C:\Program Files\Tencent\QQGame\Common\Utility.dll] [N/A, ]
[C:\Program Files\Tencent\QQGame\Factory.dll] [N/A, ]
[C:\Program Files\Tencent\QQGame\Logic\UIStyle.dll] [N/A, ]
[C:\Program Files\Tencent\QQGame\ProtHand\QQProt.dll] [N/A, ]
[C:\Program Files\Tencent\QQGame\Socket\NetMod.dll] [N/A, ]
[C:\Program Files\Tencent\qq\GroupConnection.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\QQZip.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\VqqModule.dll] [TENCENT, 7,0,365,1701]
[C:\Program Files\Tencent\qq\VqqAllInOne.dll] [Tencent, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\InPlus.dll] [Tencent, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\tencent-proto1.dll] [tencent, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\tencent-comlib.dll] [tencent, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\tencent-proto2.dll] [tencent, 1, 6, 0, 2]
[PID: 2892 / user][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [TENCENT, 7,0,365,1701]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 1028 / user][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.6359]
[C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.6360]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.99.2009]
[C:\PROGRA~1\MICROS~2\OFFICE11\ADDINS\SYMINPUT.DLL] [Microsoft Corporation, 1.02]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL] [Microsoft Corporation, 1.1.6215]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL] [Microsoft Corporation, 3.1.2303]
[C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU15CE.DLL] [SEIKO EPSON Corporation, 0.3.0.3]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DMAI13.DLL] [SEIKO EPSON Corporation, 0. 3. 0. 16]
[PID: 2312 / user][D:\我的文档\sreng2微机诊断软件_rar~\sreng2微机诊断软件\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[D:\我的文档\sreng2微机诊断软件_rar~\sreng2微机诊断软件\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
老GG - 2007-7-27 16:03:00
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1928, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2644, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================
[/CODE]
开始的距离 - 2007-7-27 21:09:00
表装咔吧,现在咔吧很烂,常误杀啊!
wbxhs - 2007-7-27 22:41:00
【回复“老GG”的帖子】
日志像是没问题!
修复一下文件关联(用扫描的那个软件!)
老GG - 2007-7-30 10:26:00
wbxhs老兄:
谢谢你这样耐心、敬业!向您学习!致敬!
我也想能象你这样为大家服务,怎耐学业不精,只好待以后有点学有所长再说了。
我也知道,“表装咔吧,现在咔吧很烂,常误杀啊!”,但咱学业不精,遇到问题不能及时给人家解决,人家9图个方便、快捷。呵呵,所以啊,技术保障4最根本的,感谢各位高手援手相助!有问题我一定再向各位请教啊!
wbxhs老兄,还有一问题向您请教,94我用该软件在我的机器上一打开9有一个对话框出来,警告我“发现一个隐藏进程”并让我“请使用智能扫描功能扫描你的系统并仔细分析扫描日志”,我该怎么做?扫描日志我知道,但扫出来后怎么用,怎么才知道有问题?有了问题怎么办?
这4扫描出来的:
“隐藏进程
[756] C:\Program Files\hxupdate\hxgame-update.exe”
这个对机器有影响没有?
呵呵,4不4太菜鸟了!没办法!只好请老兄费心了!拜托了!
上面说的那台机器,我感觉装不上好象4下载文件的问题,但不知道问题出在哪儿,只好再下几次试试,没办法,呵呵!
1
© 2000 - 2026 Rising Corp. Ltd.