查看: 2482|回复: 4
收起左侧

[其他相关] 各位快进来帮帮我啊,实在没办法了,在线等

[复制链接]
运指如飞
发表于 2007-2-27 20:51:46 | 显示全部楼层 |阅读模式
我的小红伞自从昨天安装过那个什么Spyware Terminator 就不能监控了。
每次启动后都是小伞合上的那样,监控无法开启,选了Start AntiVir也不行。
我就怀疑是Spyware Terminator 引起的。
就把Spyware Terminator 删除了,删除的应该很干净。(用Uruninstaller卸载工具删除的,然后又在注册表扫描关于Spyware Terminator 的项目,都删除了,也用HijackThis把找到的相关项目删除了)

可是还是不行,我用的COMODO的防火墙,关于红伞的程序我都允许了。有图

我用SReng和HijackThis分别扫下日志,麻烦各位帮我看看,小弟实在没办法啊
下午没的用,还上KAV6.0,用的真是不舒服,太拖系统速度了,实在是放不下红伞

我也试过完全卸载重新安装,(用了红伞专门的卸载工具的),也试过用安装文件修复,都不行!
会不会是COMODO有问题?


SReng日志:

  1. 2007-02-27,20:46:01
  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600)
  5. - 管理权限用户 - 完整功能
  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE>  [(Verified)Microsoft Corporation]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <COMODO Firewall Pro><"C:\Program Files\Comodo\Firewall\CPF.exe" /background>  [(Verified)COMODO]
  22.     <avgnt><"C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" /min>  [Avira GmbH]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.     <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
  25.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <AppInit_DLLs><>  [N/A]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
  30. ==================================
  31. 启动文件夹
  32. N/A
  33. ==================================
  34. 服务
  35. [AntiVir PersonalEdition Premium MailGuard / AntiVirMailService][Stopped/Auto Start]
  36.   <C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe><Avira GmbH>
  37. [AntiVir PersonalEdition Premium Scheduler / AntiVirScheduler][Running/Auto Start]
  38.   <C:\Program Files\AntiVir PersonalEdition Premium\sched.exe><Avira GmbH>
  39. [AntiVir PersonalEdition Premium Guard / AntiVirService][Running/Auto Start]
  40.   <C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe><AVIRA GmbH>
  41. [Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  42.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  43. [ATI Smart / ATI Smart][Stopped/Disabled]
  44.   <C:\WINDOWS\system32\ati2sgag.exe><>
  45. [AntiVir PersonalEdition Premium MailGuard helper service / AVEService][Others/Auto Start]
  46.   <C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe><Avira GmbH>
  47. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Disabled]
  48.   <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
  49. [Comodo Application Agent / CmdAgent][Running/Auto Start]
  50.   <C:\Program Files\Comodo\Firewall\cmdagent.exe><COMODO>
  51. [Human Interface Device Access / HidServ][Stopped/Disabled]
  52.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  53. [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
  54.   <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
  55. [Spyware Terminator Realtime Shield Service / sp_rssrv][Stopped/Disabled]
  56.   <F:\TDdownload\SpywareTerminator\Spyware Terminator\sp_rsser.exe><N/A>
  57. ==================================
  58. 驱动程序
  59. [aeaudio / aeaudio][Running/Manual Start]
  60.   <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
  61. [ati2mtag / ati2mtag][Running/Manual Start]
  62.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  63. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  64.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  65. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  66.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  67. [avgio / avgio][Running/System Start]
  68.   <\??\C:\Program Files\AntiVir PersonalEdition Premium\avgio.sys><AVIRA GmbH>
  69. [avgntflt / avgntflt][Running/Manual Start]
  70.   <\??\C:\Program Files\AntiVir PersonalEdition Premium\avgntflt.sys><AVIRA GmbH>
  71. [Comodo Application Engine / CmdMon][Running/System Start]
  72.   <System32\DRIVERS\cmdmon.sys><Comodo Research Lab., Inc.>
  73. [Comodo Network Engine / Inspect][Running/Boot Start]
  74.   <\SystemRoot\System32\DRIVERS\inspect.sys><COMODO>
  75. [MidiSyn / MidiSyn][Stopped/Manual Start]
  76.   <system32\drivers\MidiSyn.sys><Analog Devices Inc>
  77. [npkcrypt / npkcrypt][Running/Auto Start]
  78.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  79. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  80.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  81. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  82.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  83. [Secdrv / Secdrv][Stopped/Manual Start]
  84.   <system32\DRIVERS\secdrv.sys><N/A>
  85. [smwdm / smwdm][Running/Manual Start]
  86.   <system32\drivers\smwdm.sys><Analog Devices, Inc.>
  87. [Spyware Terminator Driver 2 / sp_rsdrv2][Running/System Start]
  88.   <\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys><N/A>
  89. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  90.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  91. [viaraid / viaraid][Running/Boot Start]
  92.   <\SystemRoot\system32\DRIVERS\viaraid.sys><VIA Technologies inc,.ltd>
  93. ==================================
  94. 浏览器加载项
  95. [Thunder Browser Helper]
  96.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  97. [IEHlpObj Class]
  98.   {EFBCA345-14DC-4640-994E-4AF1DFDEB4FD} <C:\Program Files\Riptide\Plugin\Plugin.dll, >
  99. [信息检索(&R)]
  100.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  101. [发现音视频地址]
  102.   {CFB84BBD-959B-4fcb-9A03-22ACE091043C} <C:\Program Files\Riptide\Monitor.exe, Colormedia Corporation>
  103. [Dr.eye WebPage Translation]
  104.   {92B255FE-94E2-4BCA-958D-3926CE38913F} <C:\Program Files\Inventec\Dreye\DreyeMT\DreyeIEBar.dll, >
  105. [Thunder Browser Helper]
  106.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  107. [IEHlpObj Class]
  108.   {EFBCA345-14DC-4640-994E-4AF1DFDEB4FD} <C:\Program Files\Riptide\Plugin\Plugin.dll, >
  109. [&_找本网页音视频链接_]
  110.   <C:\Program Files\Riptide\Plugin\Monitor.htm, N/A>
  111. [&使用迅雷下载]
  112.   <C:\Program Files\Thunder\Program\geturl.htm, N/A>
  113. [&使用迅雷下载全部链接]
  114.   <C:\Program Files\Thunder\Program\getallurl.htm, N/A>
  115. [导出到 Microsoft Office Excel(&X)]
  116.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  117. [用比特精灵下载(&B)]
  118.   <C:\Program Files\BitSpirit\bsurl.htm, N/A>
  119. ==================================
  120. 正在运行的进程
  121. [PID: 488][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  122. [PID: 540][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  123. [PID: 568][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  124.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4121]
  125. [PID: 612][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  126. [PID: 624][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  127. [PID: 772][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  128. [PID: 832][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  129.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  130.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  131. [PID: 896][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  132.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  133.     [C:\WINDOWS\System32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  134. [PID: 932][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  135. [PID: 1252][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  136.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  137.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  138.     [C:\Program Files\Thunder\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
  139. [PID: 1316][C:\Program Files\AntiVir PersonalEdition Premium\sched.exe]  [Avira GmbH, 7.00.00.34]
  140.     [C:\Program Files\AntiVir PersonalEdition Premium\schedr.dll]  [ Avira GmbH, 7.00.18.00]
  141.     [C:\Program Files\AntiVir PersonalEdition Premium\avevtlog.dll]  [Avira GmbH, 7.00.00.12]
  142.     [C:\Program Files\AntiVir PersonalEdition Premium\sqlite3.dll]  [N/A, 3, 3, 6, 0]
  143. [PID: 1384][C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe]  [AVIRA GmbH, 7.00.00.45]
  144.     [C:\Program Files\AntiVir PersonalEdition Premium\GUARDMSG.DLL]  [Avira GmbH, 7.00.05.00]
  145.     [C:\Program Files\AntiVir PersonalEdition Premium\avevtlog.dll]  [Avira GmbH, 7.00.00.12]
  146.     [C:\Program Files\AntiVir PersonalEdition Premium\sqlite3.dll]  [N/A, 3, 3, 6, 0]
  147.     [C:\Program Files\AntiVir PersonalEdition Premium\AVPREF.DLL]  [Avira GmbH, 7.00.02.00]
  148.     [C:\Program Files\AntiVir PersonalEdition Premium\SMTPLIB.DLL]  [Avira GmbH, 1.02.00.09]
  149.     [C:\Program Files\AntiVir PersonalEdition Premium\AVEWIN32.DLL]  [Avira GmbH, 7.3.1.38]
  150.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  151.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  152. [PID: 1396][C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe]  [Avira GmbH, 7.00.00.24]
  153.     [C:\Program Files\AntiVir PersonalEdition Premium\AVESVCR.DLL]  [Avira GmbH, 07.00.07.00]
  154.     [C:\Program Files\AntiVir PersonalEdition Premium\avpack32.dll]  [Avira GmbH, 7.02.00.05]
  155.     [C:\Program Files\AntiVir PersonalEdition Premium\unacev2.dll]  [N/A, N/A]
  156.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  157.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  158. [PID: 1496][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  [Analog Devices, Inc., 3, 2, 6, 0]
  159. [PID: 1528][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  160.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  161.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  162. [PID: 1948][C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe]  [Avira GmbH, 7.00.02.01]
  163.     [C:\Program Files\AntiVir PersonalEdition Premium\avgcmxp.dll]  [Avira GmbH, 7.00.02.00]
  164.     [C:\Program Files\AntiVir PersonalEdition Premium\AVWINLL.DLL]  [Avira GmbH, 1.00.00.06]
  165.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  166.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  167. [PID: 1976][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  168. [PID: 260][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
  169.     [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
  170.     [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
  171.     [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
  172.     [C:\Program Files\Tencent\QQ\PYKer.dll]  [飘云 http://www.pyqq.cn, 飘云]
  173.     [C:\Program Files\Tencent\QQ\ipsearcher.dll]  [, 1.0.0.3]
  174.     [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
  175.     [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
  176.     [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
  177.     [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
  178.     [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
  179.     [C:\Program Files\Tencent\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
  180.     [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
  181.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  182.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  183.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  184.     [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
  185.     [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
  186.     [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
  187.     [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
  188.     [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
  189.     [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
  190.     [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
  191.     [C:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, N/A]
  192.     [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
  193.     [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
  194.     [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
  195.     [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
  196.     [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
  197.     [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
  198.     [C:\Program Files\Tencent\QQ\VPortal.dll]  [, 1, 0, 0, 4]
  199.     [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
  200.     [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
  201.     [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
  202.     [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
  203.     [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
  204.     [C:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
  205.     [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
  206.     [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
  207.     [C:\WINDOWS\system32\FOURI_M3.IME]  [北京紫光华宇软件股份有限公司, 4.0.0.5027]
  208.     [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
  209.     [C:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
  210.     [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
  211.     [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
  212.     [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
  213.     [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 5, 50]
  214.     [C:\WINDOWS\system32\DREYESC.IME]  [IES, 1, 0, 0, 1]
  215.     [C:\Program Files\Inventec\Dreye\DreyeMIM\exchange.dll]  [, 1, 0, 0, 1]
  216. [PID: 1476][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  217. [PID: 480][C:\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 80]
  218.     [C:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
  219.     [C:\Program Files\Thunder\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
  220.     [C:\Program Files\Riptide\Plugin\Plugin.dll]  [, 1, 0, 0, 1]
  221.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  222.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  223.     [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
  224.     [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
  225.     [C:\WINDOWS\system32\FOURI_M3.IME]  [北京紫光华宇软件股份有限公司, 4.0.0.5027]
  226. [PID: 596][D:\反病毒文件夹\HijackThis1991\HijackThis.exe]  [Soeperman Enterprises Ltd., 1.99.0001]
  227. [PID: 1336][D:\反病毒文件夹\SREng\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  228.     [C:\WINDOWS\system32\GameLink.dll]  [N/A, N/A]
  229.     [C:\WINDOWS\system32\avsda.dll]  [Avira GmbH, 07.00.00.01]
  230. ==================================
  231. 文件关联
  232. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  233. .EXE  OK. ["%1" %*]
  234. .COM  OK. ["%1" %*]
  235. .PIF  OK. ["%1" %*]
  236. .REG  OK. [regedit.exe "%1"]
  237. .BAT  OK. ["%1" %*]
  238. .SCR  OK. ["%1" /S]
  239. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  240. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  241. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  242. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  243. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  244. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  245. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  246. ==================================
  247. Winsock 提供者
  248. Easy2Game-TCPChain
  249.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  250. Easy2Game-UDPChain
  251.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  252. Easy2Game-UDPChain
  253.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  254. Easy2Game-TCPChain
  255.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  256. AVSDA over [MSAFD Tcpip [TCP/IP]]
  257.     avsda.dll(Avira GmbH, AntiVir layered service provider)
  258. AVSDA over [MSAFD Tcpip [UDP/IP]]
  259.     avsda.dll(Avira GmbH, AntiVir layered service provider)
  260. Easy2Game-TCPFilter
  261.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  262. Easy2Game-UDPFilter
  263.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  264. Easy2Game-UDPFilter
  265.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  266. Easy2Game-TCPFilter
  267.     C:\WINDOWS\system32\GameLink.dll(N/A, N/A)
  268. AVSDA
  269.     avsda.dll(Avira GmbH, AntiVir layered service provider)
  270. ==================================
  271. Autorun.inf
  272. N/A
  273. ==================================
  274. HOSTS 文件
  275. 127.0.0.1       localhost
  276. ==================================
  277. API HOOK
  278. N/A
  279. ==================================
复制代码

[ 本帖最后由 运指如飞 于 2007-2-27 20:56 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
运指如飞
 楼主| 发表于 2007-2-27 20:53:32 | 显示全部楼层
HijackThis日志:




  1. Logfile of HijackThis v1.99.1
  2. Scan saved at 20:45:16, on 2007-2-27
  3. Platform: Windows XP SP2 (WinNT 5.01.2600)
  4. MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

  5. Running processes:
  6. C:\WINDOWS\System32\smss.exe
  7. C:\WINDOWS\system32\winlogon.exe
  8. C:\WINDOWS\system32\services.exe
  9. C:\WINDOWS\system32\lsass.exe
  10. C:\WINDOWS\system32\svchost.exe
  11. C:\WINDOWS\System32\svchost.exe
  12. C:\WINDOWS\Explorer.EXE
  13. C:\Program Files\AntiVir PersonalEdition Premium\sched.exe
  14. C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe
  15. C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe
  16. C:\Program Files\Comodo\Firewall\cmdagent.exe
  17. C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
  18. C:\Program Files\Comodo\Firewall\CPF.exe
  19. C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe
  20. C:\WINDOWS\system32\ctfmon.exe
  21. C:\Program Files\Tencent\QQ\QQ.exe
  22. C:\WINDOWS\System32\svchost.exe
  23. C:\Program Files\Maxthon\Maxthon.exe
  24. D:\反病毒文件夹\HijackThis1991\HijackThis.exe

  25. O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder\ComDlls\XunLeiBHO_007.dll
  26. O2 - BHO: Riptide BHO - {EFBCA345-14DC-4640-994E-4AF1DFDEB4FD} - C:\Program Files\Riptide\Plugin\Plugin.dll
  27. O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - C:\Program Files\Inventec\Dreye\DreyeMT\DreyeIEBar.dll
  28. O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
  29. O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" /min
  30. O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
  31. O8 - Extra context menu item: &_找本网页音视频链接_ - C:\Program Files\Riptide\Plugin\Monitor.htm
  32. O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder\Program\geturl.htm
  33. O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder\Program\getallurl.htm
  34. O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
  35. O8 - Extra context menu item: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
  36. O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
  37. O9 - Extra button: 发现音视频地址 - {CFB84BBD-959B-4fcb-9A03-22ACE091043C} - C:\Program Files\Riptide\Monitor.exe
  38. O9 - Extra 'Tools' menuitem: 发现音视频地址 - {CFB84BBD-959B-4fcb-9A03-22ACE091043C} - C:\Program Files\Riptide\Monitor.exe
  39. O10 - Unknown file in Winsock LSP: c:\windows\system32\gamelink.dll
  40. O10 - Unknown file in Winsock LSP: c:\windows\system32\gamelink.dll
  41. O10 - Unknown file in Winsock LSP: c:\windows\system32\gamelink.dll
  42. O10 - Unknown file in Winsock LSP: c:\windows\system32\gamelink.dll
  43. O10 - Broken Internet access because of LSP provider 'avsda.dll' missing
  44. O17 - HKLM\System\CCS\Services\Tcpip\..\{F2F0554C-3C75-469C-840B-6062604D08DD}: NameServer = 202.103.24.68
  45. O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
  46. O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
  47. O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
  48. O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  49. O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  50. O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  51. O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  52. O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  53. O18 - Protocol: ipp - (no CLSID) - (no file)
  54. O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
  55. O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
  56. O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  57. O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
  58. O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
  59. O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
  60. O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
  61. O18 - Protocol: msdaipp - (no CLSID) - (no file)
  62. O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
  63. O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
  64. O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
  65. O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
  66. O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
  67. O23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe
  68. O23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\sched.exe
  69. O23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe
  70. O23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe
  71. O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
  72. O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

复制代码
运指如飞
 楼主| 发表于 2007-2-27 22:31:38 | 显示全部楼层
问题解决了,真的是Spyware Terminator 的问题
服务项目和驱动项目都有残留
用SReng删除掉它的服务和驱动项目就好了

这里要特别感谢曲中求的大力支持,谢谢大家~
lood
发表于 2007-2-28 00:11:47 | 显示全部楼层
解决了就好
morningssun
发表于 2007-2-28 00:15:15 | 显示全部楼层
我也装了Spyware Terminator,但没有楼主的情况啊~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-9-20 00:06 , Processed in 0.137043 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表