瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 求助!电脑自动重启;不使用时会死机;冷开机需要多次才行!
xfoooym - 2007-10-4 9:20:00
由于字数受限,我就把未知的进程请大家看一下
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
诊断时间: 2007-10-04  08:57:44
诊断平台: Microsoft Windows XP  Service Pack 2
IE版本: Internet Explorer V7.0.5730.11 Build:75730
计算机物理内存:255.48MB - 当前可用内存:50.75MB

100 - 未知 - Process: RavMonD.exe [RavMond] -
100 - 未知 - Process: rfwsrv.exe [Rising Personal FireWall Service] -
100 - 未知 - Process: RavStub.exe [Rising RavStub] - D:\PROGRAM FILES\RISING\RAV\RavStub.exe
100 - 未知 - Process: rfwmain.exe [Rising Personal FireWall Main Program] - d:\program files\rising\rfw\RfwMain.exe
100 - 未知 - Process: RavTask.exe [RavTimer] -
100 - 未知 - Process: RavMon.exe [RavMon] -
O2 - 未知 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\各种工具\常用工具\下载工具\Thunder\ComDlls\TDAtOnce_Now.dll
O8 - 未知 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - 未知 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - 未知 - Extra context menu item: 使用WEB迅雷下载 - D:\各种工具\常用工具\下载工具\Webthunder\GetUrl.htm
O8 - 未知 - Extra context menu item: 使用WEB迅雷下载全部链接 - D:\各种工具\常用工具\下载工具\Webthunder\GetAllUrl.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载 - D:\各种工具\常用工具\下载工具\Thunder\Program\geturl.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载全部链接 - D:\各种工具\常用工具\下载工具\Thunder\Program\getallurl.htm
O9 - 未知 - Extra button: 启动迅雷5(HKLM) - D:\各种工具\常用工具\下载工具\Thunder\Thunder.exe
O9 - 未知 - Extra button: 番茄花园(HKLM) - http://www.tomatolei.com
O9 - 未知 - Extra button: 信息检索(HKLM) - E:\学习软件\office\OFFICE11\REFIEBAR.DLL
O9 - 未知 - Extra button: 启动WEB迅雷(HKLM) - http://my.xunlei.com
O9 - 未知 - Extra button: 快车(FlashGet)(HKLM) - C:\Program Files\FlashGet\FlashGet.exe
O23 - 未知 - Service: RfwService [Rising Personal Firewall Service] - d:\program files\rising\rfw\rfwsrv.exe - (running)
O23 - 未知 - Service: RsCCenter [Rising Process Communication Center] - "D:\Program Files\Rising\Rav\CCenter.exe" - (running)
O23 - 未知 - Service: RsRavMon [Rising RealTime Monitor] - "D:\PROGRAM FILES\RISING\RAV\Ravmond.exe" - (running)
O30 - 未知 - HKLM\..\Winlogon: [UIHost] [Windows Logon UI] C:\WINDOWS\Resources\Themes\Login\logonui-3.1.exe

=======================================


=======================================

O31 - 未知 - Folder Menu: {F9DB5320-233E-11D1-9F84-707F02C10627} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll - Adobe Systems, Inc. - PDF Shell Extension - 8.0.0.0 - 372736 - a9b3b4a762963be8cac715bef5068232
O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll -  -  -  - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression -  -  -  -  - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 -  -  -  -  - 0 -
O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} -  -  -  -  - 0 -
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} -  -  -  -  - 0 -
O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} -  -  -  -  - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:压缩(zipped)文件夹 -  -  -  -  - 0 -
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - D:\各种工具\常用工具\压缩软件\Winrar\rarext.dll -  -  -  - 128512 - 2b7421a2351fbfa6e29141c46aea6b57
O31 - 未知 - SEApproved: {1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} - C:\WINDOWS\system32\RavExt.dll - Beijing Rising Technology Co., Ltd. - Rising Shell Ext Module - 19.0.0.9 - 106496 - fa20734a7acabcfe9d727fb343da4e8a
O31 - 未知 - Directory Menu: {1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} - C:\WINDOWS\system32\RavExt.dll - Beijing Rising Technology Co., Ltd. - Rising Shell Ext Module - 19.0.0.9 - 106496 - fa20734a7acabcfe9d727fb343da4e8a
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - D:\各种工具\常用工具\压缩软件\Winrar\rarext.dll -  -  -  - 128512 - 2b7421a2351fbfa6e29141c46aea6b57
O31 - 未知 - BootExecute: bsmain -  -  -  - 0 -
O31 - 未知 - LSA: Security Packages - sv1_0.dll -  -  -  - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll -  -  -  - 0 -

=======================================

O40 - Explorer.EXE - Beijing Rising Technology Co., Ltd. - C:\WINDOWS\system32\RavExt.dll - Rising Shell Ext Module - fa20734a7acabcfe9d727fb343da4e8a
O40 - Explorer.EXE - Beijing Rising Technology Co., Ltd. - C:\WINDOWS\system32\shlhook.dll - shlhook Module - 47c020cafb8486eb33061f7ccdf206b6
O40 - Explorer.EXE - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\AntiSpyware\ieprot.dll - IE Protector - c03fc56e7d933a2478f65ddb371353bb
O40 - Explorer.EXE - Adobe Systems, Inc. - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll - PDF Shell Extension - a9b3b4a762963be8cac715bef5068232

=======================================

O41 - BaseTDI - basetdi - C:\WINDOWS\system32\drivers\basetdi.sys - (running) - basetdi - Beijing Rising Technology Co., Ltd. - 0064810c1b03f2c889130b669a4ce937
O41 - ExpScaner - ExpScan.sys - D:\PROGRAM FILES\rising\Rav\ExpScan.sys - (running) - ExpScan.sys -  - 5a690926c7181d5c0b2721016442c9c3
O41 - HookCont - HookCont - D:\PROGRAM FILES\rising\Rav\HookCont.sys - (running) - HookCont - Rising - 3926cb7b005564bc77d6b40235c53817
O41 - HookReg - HookReg - D:\PROGRAM FILES\rising\Rav\HOOKREG.sys - (running) -  -  - 997c395147f8e5b3f714bdd112fe8945
O41 - HookSys - Hooksys - D:\PROGRAM FILES\rising\Rav\HookSys.sys - (running) - Hooksys - Rising - 265b67f85db6226f2439e13e7c1fa8bf
O41 - MEMSCAN - MemScan Driver - D:\PROGRAM FILES\rising\Rav\MemScan.sys - (running) - MemScan Driver - Beijing Rising Technology Co., Ltd. - a909256ef59a987fda249aa3ded01e76
O41 - mProcRs - Rising Personal FireWall  mprocrs.sys - d:\program files\rising\Rfw\mProcRs.sys - (running) - Rising Personal FireWall  mprocrs.sys - Beijing Rising Technology Co., Ltd. - e8423448b41e9498fb0a72562e22711e
O41 - RsAntiSpyware - Anti-RootKit Driver - C:\WINDOWS\system32\drivers\RsBoot.sys - (running) - Anti-RootKit Driver - Beijing Rising Technology Co., Ltd. - f9edc97f228c046832a24b5a76017912
O41 - RsFwDrv - nt_fwdrv - D:\Program Files\rising\Rfw\rsfwdrv.sys - (running) - nt_fwdrv - Beijing Rising Technology Co., Ltd. - cca76ea70f6534837f875290c4c7e91c
O41 - RsNTGDI - RsNTGDI - C:\WINDOWS\system32\drivers\RsNTGdi.sys - (running) - RsNTGDI - Beijing Rising Technology Co., Ltd. - 17214e7b192cb93ff014fca1484b97ad
O41 - RSPPSYS - RSPPSYS.SYS - D:\PROGRAM FILES\rising\Rav\rsppsys.sys - (running) - RSPPSYS.SYS - Rising - f38c10d8c21626a4878ea16717e971fa

=======================================
360Safe.exe=3.6.1.2002
AntiAdwa.dll=3.6.1.1001
AntiEng.dll=3.6.1.1001
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
live.dll=1.0.1.1020

=======================================
操作历史报告:

----------修复IE浏览器操作历史----------

2007-10-03 21:57
R0 - 危险 - IE搜索页 - HKCU\Software\Microsoft\Internet Explorer\Main
R1 - 危险 - IE左侧搜索页 - HKCU\Software\Microsoft\Internet Explorer\Main
R1 - 危险 - 启用备用搜索引擎 - HKCU\Software\Microsoft\Internet Explorer\Main
O28 - 危险 - IE链接的参数 - C:\DOCUME~1\ADMINI~1\「开始~1\程序\附件\系统工具\INTERN~2.LNK


[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
1
查看完整版本: 求助!电脑自动重启;不使用时会死机;冷开机需要多次才行!