瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 严重的电脑问题,请求帮忙!
315480588 - 2009-8-23 12:46:00
我的电脑很奇怪,一开机的时候 不管有没有操作 过了几分钟 鼠标和键盘 就像失灵了一样,不动了。电脑就陷入了死机状态,然后只能强行重启。 重启之后 电脑似乎又能恢复正常。同时,不时还会出现蓝屏的情况。
    请问这是什么问题?是软件冲突?还是硬件有损坏?该如何解决呢? 请高手指点!谢谢!

  扫描报告在4楼 请各位高手鼎力相助!
315480588 - 2009-8-23 12:47:00
扫描报告在四楼...请大家帮帮忙啊
Ass_Frog - 2009-8-23 12:56:00
楼主重装下系统看看,若还有上述问题出现,下载最新版本的SRENG工具:http://www.kztechs.com/sreng/download.html
      操作方可以看这贴2楼:http://bbs.ikaka.com/showtopic-8442813.aspx
    1 下载的是压缩包,必须解压缩后再运行。
    2 运行SREng***.EXE
    3 选择主界面左边的:智能扫描=》扫描=》保存报告
    4 把报告保存后,将日志文件发这论坛来。
315480588 - 2009-8-23 13:20:00
System Repair Engineer 2.7.1.1261
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <Lskbdrv><C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe>  []
    <LenSoft><C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe>  []
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <runeip><"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [File is missing]
    <360Safetray><F:\360safe\safemon\360Tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <360Antiarp><F:\360safe\antiarp\antiarp.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\System32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><kmon.dll>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><%SystemRoot%\System32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><C:\WINDOWS\System32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
N/A

==================================
服务
[ARP防火墙加载程序 / AntiARPClientLoader][Running/Auto Start]
  <D:\ARP防火墙单机版\AntiARPClientLoader.exe><N/A>
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"><Apple Inc.>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Bonjour 服务 / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe"><Apple Inc.>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <F:\暴风影音3.6\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod 服务 / iPod Service][Stopped/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Inc.>
[LexBce Server / LexBceS][Running/Auto Start]
  <C:\WINDOWS\system32\LEXBCES.EXE><Lexmark International, Inc.>
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"><Nero AG>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Procedure Call System(RPCS) / rocedu][Stopped/Disabled]
  <><(File is missing)>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><CACE Technologies>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
  <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia.>
[Ulead Burning Helper / UleadBurningHelper][Running/Auto Start]
  <C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>
315480588 - 2009-8-23 13:20:00
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
[99f2ce2453fe7cdd / 99f2ce2453fe7cdd][Stopped/Manual Start]
  <\??\C:\99f2ce2453fe7cdd.dat><N/A>
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AntiARP NDIS Protocol Driver / AntiArpNdisProt][Running/Auto Start]
  <system32\DRIVERS\AntiArpNdisProt.sys><Windows (R) 2000 DDK provider>
[dump_wmimmc / dump_wmimmc][Stopped/Manual Start]
  <\??\F:\泡泡堂机械帝国\GameGuard\dump_wmimmc.sys><N/A>
[EagleNT / EagleNT][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  <System32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start]
  <System32\Drivers\GEARAspiWDM.sys><GEAR Software Inc.>
[InCDPass / InCDPass][Running/System Start]
  <System32\DRIVERS\InCDPass.sys><Ahead Software>
[lnsfw1 / lnsfw1][Running/System Start]
  <system32\drivers\lnsfw1.sys><>
[MSJDrvr / MSJDrvr][Running/System Start]
  <System32\DRIVERS\MSJDrvr.sys><N/A>
[Nokia USB Phone Parent / nmwcd][Stopped/Manual Start]
  <system32\drivers\nmwcd.sys><Nokia>
[Nokia USB Generic / nmwcdc][Stopped/Manual Start]
  <system32\drivers\nmwcdc.sys><Nokia>
[Nokia USB Port / nmwcdcj][Stopped/Manual Start]
  <system32\drivers\nmwcdcj.sys><Nokia>
[Nokia USB Modem / nmwcdcm][Stopped/Manual Start]
  <system32\drivers\nmwcdcm.sys><Nokia>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[NPPTNT2 / NPPTNT2][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npptNT2.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[DDK PACKET Protocol / Packet][Running/Manual Start]
  <system32\DRIVERS\ProtoDrv.sys><360安全中心>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
  <\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
  <\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology>
[Look 'n' Stop Driver / SFilter][Running/Manual Start]
  <system32\DRIVERS\lnsfw.sys><>
[StarForce Protection Synchronization Driver (version 2.x) / sfsync02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfsync02.sys><Protection Technology>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TAP VPN Adapter / tapvpn][Running/Manual Start]
  <system32\DRIVERS\tapvpn.sys><The OpenVPN Project>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <System32\DRIVERS\tcpip.sys><Microsoft Corporation>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[xAntiArpSpoof Service / xAntiArp][Running/Manual Start]
  <system32\DRIVERS\xAntiArp.sys><Windows (R) 2000 DDK provider>

==================================
浏览器加载项
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\urlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\360safe\safemon\safemon.dll, (Signed) 360.CN>
[]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[联想]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.legend.com, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
[DLoader Class]
  {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} <C:\WINDOWS\Downloaded Program Files\downloader.dll, (Signed) Sina Com>
[163Uploader Control]
  {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\system32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx, (Signed) Adobe Systems, Inc.>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {01DFB4B4-0E07-4E3F-8B7A-98FD6BFF153F} <, >
[Microsoft Office Template and Media Control]
  {02BCC737-B171-4746-94C9-0D8A0B2C0089} <C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL, (Signed) >
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, (Signed) Microsoft Corporation>
[]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <, >
[ULiveCtrl Control]
  {070CA17A-4BD2-4612-83B4-32B1B9159B48} <C:\PROGRA~1\sina\SINAWE~1\305~1.0\UCLIVE~1.OCX, (Signed) 北京新浪信息技术有限公司>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\System32\msjava.dll, Microsoft Corporation>
[BDA 调节型号 MPEG2 微调请求]
  {0955AC62-BF2E-4CBA-A2B9-A63F772D46CF} <C:\WINDOWS\system32\msvidctl.dll, (Signed) Microsoft Corporation>
[Player Class]
  {11F2A418-94B2-4e16-9B0C-B00C0435F903} <D:\QQlive\LiveMedia.dll, (Signed) Tencent>
[]
  {1345F3CB-7C40-41C2-9AC2-87CF8B68E34E} <, >
[EWA Control]
  {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, (Signed) Synacast>
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[]
  {19EFFC12-25FB-479A-A0F2-1569AE1B3365} <, >
[InstallHelper Class]
  {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <D:\QQlive\QQLiveInstaller.dll, (Signed) >
[]
  {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <, >
[]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, (Signed) Microsoft Corporation>
[PhotoDraw Class]
  {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\Program Files\Tencent\Qzone\QQPhotoDraw.dll, (Signed) TENCENT>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\System32\mshtml.dll, (Signed) N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation>
[]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <, >
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, (Signed) Microsoft Corporation>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <F:\BitComet\BitComet_0.89\tools\BitCometBHO_1.1.5.19.dll, N/A>
[WZClient Control]
  {4038B28D-D30A-4DA6-ADA0-BC081D6D4F97} <C:\WINDOWS\system32\WZClient.ocx, g>
[QuickTime Object]
  {4063BE15-3B08-470D-A0D5-B37161CFFD69} <F:\StormII\Codec\QTPlugin.ocx, (Signed) Apple Inc.>
[Microsoft Office Control]
  {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~2\OFFICE11\AUTHZAX.DLL, (Signed) Microsoft Corporation>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Megaupload Toolbar]
  {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} <C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL, (Signed) MEGAUPLOAD                                  >
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, (Signed) Microsoft Corporation>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\System32\shdocvw.dll, (Signed) N/A>
[]
  {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} <, >
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.328\METEOR~1\POWERP~1.DLL, N/A>
[]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[]
  {635A7AFA-FB22-4A4E-8AB8-C85CFAB14626} <, >
[XMP Class]
  {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
  {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[QQLiveFile Class]
  {6B232760-90F1-41c3-9902-C8552C1D8A72} <D:\QQlive\FileVersion.dll, (Signed) Tencent>
[StormPlayer Object]
  {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} <F:\暴风影音3.6\StormII\mps.dll, 北京暴风网际科技有限公司>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A>
[DLoader Class]
  {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} <C:\WINDOWS\Downloaded Program Files\downloader.dll, (Signed) Sina Com>
[]
  {79B0CAAA-35B4-4DB8-ADAE-19693F1A4DFB} <, >
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <F:\360safe\live.dll, (Signed) 360.cn>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, (Signed) Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\urlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.>
[]
  {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} <, >
[DapCtrl Class]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.1.5804.62.(446).dll, ShenZhen Thunder Networking Technologies Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, (Signed) N/A>
[Messenger Object]
  {B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, (Signed) Microsoft Corporation>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\360safe\safemon\safemon.dll, (Signed) 360.CN>
[WebPlayer Class]
  {B965124A-7C58-45f8-91BF-28A981CE7594} <D:\QQlive\WebLiveMedia.dll, (Signed) Tencent>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\system\msadc\msadco.dll, (Signed) Microsoft Corporation>
[KooPlayer Control]
  {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.328\METEOR~1\Kernel\CCTV\CCTVPL~1.OCX, N/A>
[]
  {C95FE080-8F5D-11D2-A20B-00AA003C157A} <, >
[Adobe PDF Reader]
  {CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll, (Signed) Adobe Systems, Inc.>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <D:\暴风影音3\Codec\rmoc3260.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx, (Signed) Adobe Systems, Inc.>
[iTunesDetector Class]
  {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} <F:\iTunes\ITDetector.ocx, (Signed) Apple Inc.>
[QQLive Class]
  {D9EBCF5D-3F8F-4b6a-89BA-70577BE73C62} <D:\QQlive\LiveAPI.dll, (Signed) Tencent>
[瑞星卡卡工具条(&R)]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, (Signed) Beijing Rising Information Technology Co., Ltd.>
[PlayerCtrl Class]
  {E05BC2A3-9A46-4A32-80C9-023A473F5B23} <, >
[]
  {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <, >
[]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <, >
[UPlayer Control]
  {EAB7A1CC-C77B-45E5-9AC2-AD037D047BCC} <C:\PROGRA~1\COMMON~1\uusee\SEEPLA~1.OCX, (Signed) UUSEE>
[Thunder DapPlayer]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <D:\Thunder\Components\DownAndPlay\DapPlayer3.0.5712.71.445.dll, ShenZhen Thunder Networking Technologies Ltd.>
[]
  {EF0D1A14-1033-41A2-A589-240C01EDC078} <, >
[XPPlayer Class]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.0.5835.191.(446).dll, Xunlei Networking Technologies,LTD>
[]
  {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} <, >
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[Messenger Application]
  {FB7199AB-79BF-11D2-8D94-0000F875C541} <C:\Program Files\Messenger\msgsc.dll, (Signed) Microsoft Corporation>
[使用快车(Flas&hGet)下载]
  <199AB-79BF-11D2-8D94-0000F875C541}, N/A>
[使用快车(Flash&Get)下载全部链接]
  <, >
[使用迅雷下载]
  <D:\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <D:\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[通过网易邮箱发送]
  <F:\网易闪电邮\闪电邮\getcontent.htm, N/A>
315480588 - 2009-8-23 13:21:00
API HOOK
入口点错误:NtCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003C571D)
入口点错误:NtCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003C58BD)
入口点错误:NtLoadDriver (危险等级: 高,  被下面模块所HOOK: 0x003C600D)
入口点错误:NtSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003C598D)
入口点错误:NtWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003C57ED)
入口点错误:ZwCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003C571D)
入口点错误:ZwCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003C58BD)
入口点错误:ZwSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003C598D)
入口点错误:ZwWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003C57ED)
入口点错误:CreateServiceA (危险等级: 高,  被下面模块所HOOK: 0x003C5CCD)
入口点错误:CreateServiceW (危险等级: 高,  被下面模块所HOOK: 0x003C5D9D)
入口点错误:LoadLibraryA (危险等级: 高,  被下面模块所HOOK: 0x003C69CD)
入口点错误:LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: 0x003C55B5)
入口点错误:CreateFileW (危险等级: 高,  被下面模块所HOOK: 0x003C64ED)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x003C68FD)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x003C675D)
Ass_Frog - 2009-8-23 13:54:00
使用sreng删除以下注册表项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
删除以下服务:
[Remote Procedure Call System(RPCS) / rocedu][Stopped/Disabled]
  <><(File is missing)>
删除以下驱动条目:
[99f2ce2453fe7cdd / 99f2ce2453fe7cdd][Stopped/Manual Start]
  <\??\C:\99f2ce2453fe7cdd.dat><N/A>【并查看C盘有无此文件再生】
删除以下IE加载项:
[]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {01DFB4B4-0E07-4E3F-8B7A-98FD6BFF153F} <, >
[]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <, >
[]
  {1345F3CB-7C40-41C2-9AC2-87CF8B68E34E} <, >
[]
  {19EFFC12-25FB-479A-A0F2-1569AE1B3365} <, >
[]
  {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <, >
[]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, >
[]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <, >
[]
  {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} <, >
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.328\METEOR~1\POWERP~1.DLL, N/A>
[]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[]
  {635A7AFA-FB22-4A4E-8AB8-C85CFAB14626} <, >
[]
  {79B0CAAA-35B4-4DB8-ADAE-19693F1A4DFB} <, >
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
  {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} <, >
[KooPlayer Control]
  {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.328\METEOR~1\Kernel\CCTV\CCTVPL~1.OCX, N/A>
[]
  {C95FE080-8F5D-11D2-A20B-00AA003C157A} <, >
[PlayerCtrl Class]
  {E05BC2A3-9A46-4A32-80C9-023A473F5B23} <, >
[]
  {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <, >
[]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <, >
[]
  {EF0D1A14-1033-41A2-A589-240C01EDC078} <, >
[]
  {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} <, >
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[使用快车(Flash&Get)下载全部链接]
  <, >
修复以下API:(需重启,修复方法:sreng系统修复--高级修复--APIHOOK检查)
API HOOK
入口点错误:NtCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003C571D)
入口点错误:NtCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003C58BD)
入口点错误:NtLoadDriver (危险等级: 高,  被下面模块所HOOK: 0x003C600D)
入口点错误:NtSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003C598D)
入口点错误:NtWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003C57ED)
入口点错误:ZwCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003C571D)
入口点错误:ZwCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003C58BD)
入口点错误:ZwSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003C598D)
入口点错误:ZwWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003C57ED)
入口点错误:CreateServiceA (危险等级: 高,  被下面模块所HOOK: 0x003C5CCD)
入口点错误:CreateServiceW (危险等级: 高,  被下面模块所HOOK: 0x003C5D9D)
入口点错误:LoadLibraryA (危险等级: 高,  被下面模块所HOOK: 0x003C69CD)
入口点错误:LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: 0x003C55B5)
入口点错误:CreateFileW (危险等级: 高,  被下面模块所HOOK: 0x003C64ED)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x003C68FD)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x003C675D)
重启后不要打开其他分区,全盘杀毒并扫描流氓软件,windows清理助手扫描流氓软件并清理:http://www.arswp.com/download/arswp3/x86/arswp3_x86.zip(升级后使用)
若还是蓝屏,请用笔记下蓝屏字符,然后发上来。
1
查看完整版本: 严重的电脑问题,请求帮忙!