飞侠119 - 2006-6-8 11:22:00
按你的方法我弄了,还是去不掉!!最新的扫描。你从头再给我说一下!!
2006-06-08,11:11:34
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<pyjj><C:\Program Files\jj4\jjsvr4.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<KavPFW><"C:\KAV2005\KPFW32.EXE">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Super Rabbit SRRestore><C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[microsoft office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\microsoft office.lnk><N>
[Active Messenger]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Active Messenger.lnk><N>
[快捷方式 到 KAV32]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\快捷方式 到 KAV32.lnk><N>
==================================
服务
[pcAnywhere Host Service / awhost32]
<C:\Program Files\Symantec\pcAnywhere\awhost32.exe><Symantec Corporation>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\System32\drivers\CDAC11BA.EXE><Macrovision>
[User Authentication Manager / DpHost]
<C:\Program Files\DigitalPersona\UareUPro\DpHost.exe><Digital Persona, Inc.>
[Kingsoft Personal Firewall Service / KPfwSvc]
<"C:\KAV2005\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc]
<C:\KAV2005\KWatch.EXE><Kingsoft Corporation>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[ServiceLayer / ServiceLayer]
<"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"><Nokia.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
==================================
飞侠119 - 2006-6-8 11:14:00
浏览器加载项
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A>
==================================
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 592][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 604][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 772][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 820][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 960][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 988][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\KAV2005\KWatch.EXE] <Kingsoft Corporation><2005, 9, 27, 51>
[C:\KAV2005\KAVIPC2.DLL] <Kingsoft Corporation><2004, 12, 28, 20>
[C:\KAV2005\KAEPlat.DLL] <Kingsoft Corp.><2005, 12, 29, 56>
[C:\KAV2005\KAEMem.DAT] <Kingsoft><2006, 4, 12, 13>
[C:\KAV2005\KAEUnpack.DAT] <Kingsoft Corp.><2006, 3, 21, 17>
[PID: 1120][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[C:\WINDOWS\System32\AdobePDF.dll] <Adobe Systems Incorporated.><7.0.0.00>
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] <N/A><N/A>
[C:\WINDOWS\system32\awmon.dll] <Symantec Corporation><9.2.1>
[PID: 1404][C:\WINDOWS\System32\drivers\CDAC11BA.EXE] <Macrovision><4.20.020>
[PID: 1424][C:\Program Files\DigitalPersona\UareUPro\DpHost.exe] <Digital Persona, Inc.><1.1.0.0>
[C:\Program Files\DigitalPersona\UareUPro\DPPS.dll] <Digital Persona, Inc.><1.1.0.0>
[C:\Program Files\DigitalPersona\UareUPro\DpCmpMgt.dll] <Digital Persona, Inc.><1.1.0.0>
[C:\Program Files\DigitalPersona\UareUPro\DpDtObjs.dll] <Digital Persona, Inc.><1.1.0.0>
[C:\Program Files\DigitalPersona\UareUPro\DPDevAgt.dll] <Digital Persona, Inc.><1.1.0.0>
[C:\WINDOWS\System32\dpDevCtl.dll] <DigitalPersona, Inc.><2.1.1.499>
[PID: 1480][C:\WINDOWS\System32\inetsrv\inetinfo.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1504][C:\KAV2005\KPfwSvc.EXE] <Kingsoft Corporation><2005, 9, 5, 28>
[PID: 1520][C:\WINDOWS\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.5672>
[PID: 1592][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1632][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\hpwx3770.dll] <Hewlett-Packard><3.2.2.674>
[C:\WINDOWS\System32\hpgt3770.dll] <Hewlett-Packard><1.0.2.682>
[PID: 1660][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1812][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><16.0.0.86>
[C:\PROGRA~1\COMMON~1\system\msdc32.dll] <C1NETHELPER><1, 0, 0, 1>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] <Adobe Systems, Inc.><7.0.0.0>
[C:\WINDOWS\System32\nvcpl.dll] <NVIDIA Corporation><6.14.10.5672>
[C:\WINDOWS\System32\nvshell.dll] <NVIDIA Corporation><6.14.10.5672>
[C:\WINDOWS\System32\NVWRSZHC.DLL] <NVIDIA Corporation><6.14.10.5672>
[C:\PROGRA~1\COMMON~1\system\mod\ca.dll] <N/A><N/A>
[C:\PROGRA~1\COMMON~1\system\mod\ca32.dll] <N/A><N/A>
[PID: 1956][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1964][C:\Program Files\MSN Messenger\msnmsgr.exe] <Microsoft Corporation><7.5.0324>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\KAV2005\KAScript.DLL] <Kingsoft Corporation><2006, 2, 10, 60>
[C:\KAV2005\KAEPlat.DLL] <Kingsoft Corp.><2005, 12, 29, 56>
[C:\KAV2005\KAEMem.DAT] <Kingsoft><2006, 4, 12, 13>
[C:\KAV2005\KAEUnpack.DAT] <Kingsoft Corp.><2006, 3, 21, 17>
[C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1984][C:\Program Files\jj4\jjsvr4.exe] <加加开发组><4.0.0.20>
[PID: 168][C:\KAV2005\KPFW32.EXE] <Kingsoft Corporation><2006, 1, 17, 609>
[C:\KAV2005\KAVIPC2.DLL] <Kingsoft Corporation><2004, 12, 28, 20>
[C:\KAV2005\KAConfig.DLL] <Kingsoft Corporation><2005, 3, 23, 30>
[C:\KAV2005\FiltList.dll] <N/A><N/A>
[C:\KAV2005\KAVPassp.DLL] <Kingsoft Corporation><2006, 5, 26, 246>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\KAV2005\KAEPlat.DLL] <Kingsoft Corp.><2005, 12, 29, 56>
[C:\KAV2005\KAEMem.DAT] <Kingsoft><2006, 4, 12, 13>
[C:\KAV2005\KAEUnpack.DAT] <Kingsoft Corp.><2006, 3, 21, 17>
[C:\KAV2005\KAScript.DLL] <Kingsoft Corporation><2006, 2, 10, 60>
[PID: 396][C:\Program Files\Activesoft\Active Messenger\Msger.exe] <Activesoft><3, 0, 6, 1>
[PID: 1844][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\QQ\CoralAssist.DLL] <Coral Team><4.5.0 build 20060515>
[C:\Program Files\Tencent\QQ\CoralQQ.DLL] <Coral Team><4.5 Build 20060515>
[C:\Program Files\Tencent\QQ\ipsearcher.dll] <N/A><1.0.0.4>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[C:\Program Files\Tencent\QQ\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
飞侠119 - 2006-6-8 11:14:00
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\GroupLive.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQPet.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll] <tencent><0, 2, 2, 3>
[C:\Program Files\Tencent\QQ\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[C:\Program Files\Tencent\QQ\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\Tencent\QQ\GroupConnection.dll] <Tencent><5, 0, 202, 170>
[C:\Program Files\Tencent\QQ\QQFileTransfer.dll] <Tencent><5, 0, 202, 180>
[C:\WINDOWS\System32\HOOKLFp.dll] <N/A><N/A>
[C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll] <Nokia><6, 80, 37, 4>
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] <Nokia><6, 80, 66, 0>
[C:\WINDOWS\System32\ConnAPI.DLL] <Nokia.><6, 80, 55, 5>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] <Nokia><6, 80, 26, 0>
[C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] <Nokia><6, 80, 8, 0>
[PID: 1872][C:\Program Files\Tencent\QQ\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 3660][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\WINDOWS\System32\KakaTool.dll] <Beijing Rising Technology Co., Ltd.><2, 0, 0, 8>
[C:\KAV2005\KAScript.DLL] <Kingsoft Corporation><2006, 2, 10, 60>
[C:\KAV2005\KAEPlat.DLL] <Kingsoft Corp.><2005, 12, 29, 56>
[C:\KAV2005\KAEMem.DAT] <Kingsoft><2006, 4, 12, 13>
[C:\KAV2005\KAEUnpack.DAT] <Kingsoft Corp.><2006, 3, 21, 17>
[C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] <Adobe Systems, Inc.><7.0.0.0>
[PID: 4024][D:\foxmail\Foxmail.exe] <Boda Network Technology Inc.><5.0>
[D:\foxmail\FoxAntiSpam.dll] <N/A><N/A>
[D:\foxmail\3rdParty\punylib.dll] <CNNIC><1, 0, 0, 3>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[PID: 1688][E:\game\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-6-8 13:19:00
一眼望过,似乎就这一项没有解决了
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
请问版主,你用兔子的专业卸载不能解决这个问题吗?
这似乎难以相信,因为我有过这个经历的。
建议你再打开兔子,卸载所有提示的垃圾软件。
如果还是不行
可以这样
请到www.27814939.ys168.com下载诺顿进程管理器终止所有RUNDLL32.EXE 的进程
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
最后删除C:\PROGRA~1\COMMON~1\system\msdc32.dll
所出现的提示窗口可以不做理会
飞侠119 - 2006-6-8 13:36:00
每次启动后都会多处这项。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
但是我在我的硬盘根本找不到C:\PROGRA~1\这个目录啊!
我无邪 - 2006-6-8 13:41:00
目录是这样的
C:\Program Files\Common Files\system\msdc32.dll
请问楼主,你的兔子是否是最新的,你可以在线更新它
还有,在兔子的专业卸载里,所有的垃圾软件都删除了吗?因为,这个垃圾软件很早就有了。
飞侠119 - 2006-6-8 13:47:00
已经手动删除了。感谢我无邪 老大,不厌其烦的解答!!谢谢。
© 2000 - 2026 Rising Corp. Ltd.