我的电脑是VISTA系统的,在载了瑞星2008免费下载版杀毒软件之后,发现那个小伞总是在升级后变成黄色,说是邮件监控关闭了,按开启键毫无反应。修复杀毒软件后,中途出现说“通用器错误”和“U盘监控错误”。问题到底出在哪里啊。求救啊。。以下是瑞星听诊器诊断的结果
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程C:\WINDOWS\SYSTEM32\DWM.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.6000.16386_NONE_9EA0AC9EC96E7127\GDIPLUS.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRA~1\WI4EB4~1\WMPBAND.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEUSER.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.6000.16386_NONE_9EA0AC9EC96E7127\GDIPLUS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_5.82.6000.16386_NONE_87E0CB09378714F1\COMCTL32.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.312_NONE_10B2EE7B9BFFC2C7\MSVCR80.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\RPBROWSERRECORDPLUGIN.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\LANG\RPBRP_CN.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
D:\PROGRA~1\ALISOFT\WANGWANG\WANGWANGX4.DLL
C:\WINDOWS\SYSTEM32\IGDUMD32.DLL
C:\WINDOWS\SYSTEM32\SOGOUPY.IME
C:\PROGRAM FILES\SOGOUINPUT\PLUGIN\SGIMEWORD.DLL
C:\WINDOWS\SYSTEM32\ALIEDIT\PTA.DLL
D:\PROGRAM FILES\ALISOFT\WANGWANG\ALI_CHECK.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\WINDOWS\SYSTEM32\TASKENG.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\WINDOWS\SYSTEM32\IGFXTMM.DLL
C:\WINDOWS\SYSTEM32\IGFXDEV.DLL
C:\WINDOWS\SYSTEM32\DLLHOST.EXE
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\WINDOWS\SYSTEM32\IGFXRES.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.6000.16386_NONE_9EA0AC9EC96E7127\GDIPLUS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_5.82.6000.16386_NONE_87E0CB09378714F1\COMCTL32.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.312_NONE_10B2EE7B9BFFC2C7\MSVCR80.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\RPBROWSERRECORDPLUGIN.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\LANG\RPBRP_CN.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\WINDOWS\SYSTEM32\IGDUMD32.DLL
C:\PROGRAM FILES\TENCENT\QQ\TXPLATFORM.EXE
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RECOMP.DLL
C:\PROGRAM FILES\RISING\RAV\REFS.DLL
C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
C:\PROGRAM FILES\RISING\RAV\RELIBLDR.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\MONRULE.DLL
C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RAV\RSXML.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_5.82.6000.16386_NONE_87E0CB09378714F1\COMCTL32.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\TASKMANAGER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\STLPORT_VC646.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ASYN_DNS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\STREAMMEDIALIB.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\AL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\XLDC.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\BD.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\XLNET.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ITARGETAD.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\BHOSTUB.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\DOWNANDPLAY\DOWNANDPLAY.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBED14.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\XLIPC.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\PLAYERHELPER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\XLNET.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\COMMUNITY\XLCOMMUNITY.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\REGISTERDLL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\MSVCIRT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\SECURITY\THUNDERSAFE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ATL71.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\SECURITY\XLSAFEUI.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\SEARCH\XLSEARCH.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\LIVEUPDATE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PLUGINS\XLSAFEHOST\XLSAFEHOST.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PLUGINS\BHOADV\BHO_ADV.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PLUGINS\KANKANTOP\KANKANTOP.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\EXPLORERHELPER\EXPLORERHELPER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\TIPS\TIPSCLIENT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\VPSHELL\VPSHELL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\VPSHELL\VIDEOPICTURE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\USEREXPERIENCE\USEREXPERIENCE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSXLCOM.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\MEDIAWORKER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\TIPS\XLIPC.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\DOWNLOADSTAT\DOWNLOADSTAT.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\IGDUMD32.DLL
C:\USERS\LR\DESKTOP\RSDETECT.EXE
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_5.82.6000.16386_NONE_87E0CB09378714F1\COMCTL32.DLL
C:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.6000.16386_NONE_5D07289E07E1D100\COMCTL32.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
普通自启动项HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSC /AUTO
HotKeysCmds = C:\WINDOWS\SYSTEM32\HKCMD.EXE
Thunder = "C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\THUNDER.EXE" /S
Adobe Reader Speed Launcher = "C:\PROGRAM FILES\ADOBE\READER 8.0\READER\READER_SL.EXE"
WangWang = "D:\PROGRAM FILES\ALISOFT\WANGWANG\WANGWANG.EXE"
360Safetray = C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE /START
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Launcher = %WINDIR%\SMINST\LAUNCHER.EXE
AppInit_DLLsHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WPS.Doc.6 = "C:\Program Files\Kingsoft\WPS Office Personal\office6\wps.exe" "%1"
其它启动项WIN.INI
无信息
SYSTEM.INI
SHELL = explorer.exe
SCRNSAVE.EXE = C:\Windows\system32\logon.scr
Winlogon 启动项HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
igfxcui = IGFXDEV.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHOHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233} = C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = NULL
{3049C3E9-B461-4BC5-8870-4C09146192CA} = C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
{7E853D72-626A-48EC-A868-BA8D5E23E045} = NULL
{889D2FEB-5411-4565-8998-1DD2C5261283} = C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} = C:\Program Files\360safe\safemon\safemon.dll
Winsock SPIRising Net Filter over [MSAFD Tcpip [TCP/IP]] = C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
Rising Net Filter over [RSVP TCP = C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
MSAFD Tcpip [TCP/IP] = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [TCP/IPv6] = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IPv6] = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IPv6] = C:\Windows\SYSTEM32\MSWSOCK.DLL
RSVP TCPv6 = C:\Windows\SYSTEM32\MSWSOCK.DLL
RSVP TCP = C:\Windows\SYSTEM32\MSWSOCK.DLL
RSVP UDPv6 = C:\Windows\SYSTEM32\MSWSOCK.DLL
RSVP UDP = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{3510FC19-EF06-47E1-9DD0-54538A33D543}] SEQPACKET 0 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{3510FC19-EF06-47E1-9DD0-54538A33D543}] DATAGRAM 0 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E1B5A56F-2471-44E9-816C-E452709A9D6E}] SEQPACKET 2 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E1B5A56F-2471-44E9-816C-E452709A9D6E}] DATAGRAM 2 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3510FC19-EF06-47E1-9DD0-54538A33D543}] SEQPACKET 1 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3510FC19-EF06-47E1-9DD0-54538A33D543}] DATAGRAM 1 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E1B5A56F-2471-44E9-816C-E452709A9D6E}] SEQPACKET 3 = C:\Windows\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E1B5A56F-2471-44E9-816C-E452709A9D6E}] DATAGRAM 3 = C:\Windows\SYSTEM32\MSWSOCK.DLL
Rising Net Filter = C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL
系统服务项文件驱动系统驱动项用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WPS; KuGooSoft; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.04506)