lethein - 2006-10-31 3:24:00
如题,我是2006版用户
早上在浏览一个游戏攻略网站后,发现进程和启动项多出一堆乱七八糟的东西
瑞星和木马克星被强行关闭
此后再也无法打开,双击Rav.exe无反映
我把我能看到的和能想到的可疑进程和文件都处理了一下
包括自启动的和除正常进程以外的等等
然后用Ewido杀了一下,杀掉了几个,但仍然无法启动瑞星
瑞星个人防火墙和瑞星监控中心都能正常启动,就是杀毒主程序启动不了
用橙色八月专杀安全模式查杀了几个疑似病毒后仍然无法启动瑞星主程序
木马克星无法启动,HijackThis无法启动,SREng无法启动(改扩展名后能)
Ewido可以正常启动使用
完全删除瑞星后下载最新安装文件,可以正常安装
但是装完仍然无法启动瑞星杀毒软件主程序
现在我有瑞星和没瑞星完全没区别,形同虚设
请问除了重新作系统有没有什么解决的办法
比较着急,搞了快20个小时了仍然无果
粗略的看一下就有这么多问题:
C:\Documents and Settings\All Users\「开始」菜单\程序\启动\1DCD34.exe
C:\Documents and Settings\用户\「开始」菜单\程序\启动\1DCD34.exe
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
这两个珊完就自动生成
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
O4 - HKLM\..\Run: [Desktop] ; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
F3 - REG:win.ini: load=; 鹸?粒?粒粒?
????粓? [这个是乱码]
需要我提供什么相关信息麻烦跟帖告知下
谢谢,我会一直顶帖,直到有答案为止
SRE报告我帖在4楼和5楼
HijackThis报告在6楼
mopery - 2006-10-31 3:32:00
http://mopery.hits.io/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
如果SREng.exe 无法运行 改成 SREng.com 运行..
帅的被贼砍 - 2006-10-31 3:35:00
首先要检查的是 服务 在开始下 输入 services.msc 进入服务 找到
附件:
6356212006103132651.BMP
帅的被贼砍 - 2006-10-31 3:37:00
查看是否开启后
在开始下输入 regedit 进入注册表 在分别找到
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RsCCenter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RsRavMon
这两项里面 分别的 start 查看 是否为 "Start"=dword:00000002
lethein - 2006-10-31 3:51:00
0-31,03:38:32
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<themeadp><C:\WINDOWS\system32\themeadp.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<!ewido><; "d:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.]
<Desktop><; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll> [N/A]
<iparmor><; > [N/A]
<IpWins><; > [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
<Load><; 鹸?粒?粒粒?
????粓?> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MoveSearch><; > [N/A]
<msmsgs><; > [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<pucivce><; > [N/A]
<RavTask><; "D:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RavUpes><; > [N/A]
<RfwMain><; "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [N/A]
<rzt><; > [N/A]
<Secure><; Rem d:\Program Files\Secure\Start.exe> [N/A]
<StormCodec_Helper><; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Torjan Program><; > [N/A]
<winla><; > [N/A]
<xy><; > [N/A]
<YLive.exe><; > [N/A]
==================================
启动文件夹
[1DCD34]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\1DCD34.exe --> [N/A]><N>
[1DCD34]
<C:\Documents and Settings\lostseven\「开始」菜单\程序\启动\1DCD34.exe --> [N/A]><N>
==================================
服务
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
<d:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[host Service For Windows / mshosts]
<><N/A>
[Local Connection Manager / SPSCAR]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL,Export 1087><N/A>
==================================
驱动程序
[ESS Allegro Audio Driver (WDM) / allegro]
<system32\drivers\es198x.sys><ESS Technology, Inc.>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
<\??\d:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[ExpScaner / ExpScaner]
<\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[D-Link DFE-530TX PCI Fast Ethernet Adapter Driver / FETNDIS]
<system32\DRIVERS\dlkfet5b.sys><D-Link>
[HookCont / HookCont]
<\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[mapmem / mapmem]
<\??\C:\WINDOWS\system32\Drivers\mapmem.sys><EPoX Inc.>
[MEMSCAN / MEMSCAN]
<\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[paraudio / paraudio]
<\??\C:\WINDOWS\system32\drivers\paraudio.sys><Microsoft Corporation>
[portio / portio]
<\??\C:\WINDOWS\system32\Drivers\portio.sys><Epox Inc.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[SkyProcs / SkyProcs]
<\??\D:\PROGRA~1\SKYNET\FIREWALL\SkyProcs.sys><N/A>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
==================================
lethein - 2006-10-31 3:52:00
浏览器加载项
[酷热影音]
{7D73FF86-05F1-39ed-C850-A423120EC338} <www.kuree.com/index.htm?id=00011001, N/A>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <, N/A>
[]
{69D23154-CA31-43E9-BEEB-F78E6D1642B3} <C:\WINDOWS\system32\3721.6.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 528][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 668][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 896][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 992][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1048][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1624][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\Program Files\Common Files\SYSTEM\E11DD34C.dll] [N/A, N/A]
[PID: 1776][d:\Program Files\ewido anti-spyware 4.0\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172]
[d:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 2032][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 340][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 716][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll] [N/A, N/A]
[C:\Program Files\Common Files\SYSTEM\E11DD34C.dll] [N/A, N/A]
[PID: 1560][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll] [N/A, N/A]
[C:\Program Files\Common Files\SYSTEM\E11DD34C.dll] [N/A, N/A]
[PID: 844][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll] [N/A, N/A]
[D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\Program Files\Common Files\SYSTEM\E11DD34C.dll] [N/A, N/A]
[C:\Documents and Settings\lostseven\桌面\sreng2\SREng\SREng.com] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\Common Files\SYSTEM\E11DD34C.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [notepad.exe %1]
.VBS Error. [wscript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
lethein - 2006-10-31 3:56:00
Logfile of HijackThis v1.99.1
Scan saved at 3:45:11, on 2006-10-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
d:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\lostseven\桌面\hijackthis\HijackThis.com
F3 - REG:win.ini: load=; 鹸?粒?粒粒?
????粓?
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [!ewido] ; "d:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Desktop] ; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [iparmor] ;
O4 - HKLM\..\Run: [IpWins] ;
O4 - HKLM\..\Run: [MoveSearch] ;
O4 - HKLM\..\Run: [msmsgs] ;
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pucivce] ;
O4 - HKLM\..\Run: [RavTask] ; "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavUpes] ;
O4 - HKLM\..\Run: [RfwMain] ; "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [rzt] ;
O4 - HKLM\..\Run: [Secure] ; Rem d:\Program Files\Secure\Start.exe
O4 - HKLM\..\Run: [StormCodec_Helper] ; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Torjan Program] ;
O4 - HKLM\..\Run: [winla] ;
O4 - HKLM\..\Run: [xy] ;
O4 - HKLM\..\Run: [YLive.exe] ;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 酷热影音 - {7D73FF86-05F1-39ed-C850-A423120EC338} - www.kuree.com/index.htm?id=00011001 (file missing)
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C393965F-80DB-4EB2-ACB7-34BBE85D52C9}: NameServer = 202.97.224.69 202.97.224.68
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: themeadp - {64274C93-3CE7-4663-9C8D-CD2DC8A3590B} - C:\WINDOWS\system32\themeadp.dll (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - d:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Local Connection Manager (SPSCAR) - Unknown owner - C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE (file missing)
mopery - 2006-10-31 4:04:00
修复
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
用sreng
删除启动项目=>注册表
<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
<themeadp><C:\WINDOWS\system32\themeadp.dll> [N/A]
<MoveSearch><; > [N/A]
<msmsgs><; > [N/A]
<RavUpes><; > [N/A]
<pucivce><; > [N/A]
<rzt><; > [N/A]
<Torjan Program><; > [N/A]
<winla><; > [N/A]
<xy><; > [N/A]
<YLive.exe><; > [N/A]
删除
C:\Program Files\Common Files\SYSTEM\E11DD34C.dll(安全模式下)
C:\WINDOWS\system32\themeadp.dll
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
参考顶置帖..
http://forum.ikaka.com/topic.asp?board=28&artid=8201339
<Load> 编辑改为 空值
用sreng
删除启动项目=>服务
[host Service For Windows / mshosts]
<><N/A>
[Local Connection Manager / SPSCAR]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL,Export 1087><N/A>
删除文件
C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
<Secure><; Rem d:\Program Files\Secure\Start.exe> [N/A]
自己确认一下是否是正常文件..
重装下瑞星 安全模式下查杀..
lostseven - 2006-10-31 5:08:00
多谢斑竹了
但是
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
这两个修复完了还能查出来
另外<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
这两个珊不掉,其他的都能删掉,就这两个珊完又回来
你说让参考置顶帖,我看了几遍不是很懂
麻烦在说明下好么十分3Q...
另外这个C:\Program Files\Common Files\SYSTEM\E11DD34C.dll
在安全模式下也无法删除
lostseven - 2006-10-31 14:31:00
麻烦斑竹还在么
<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
这两个珊不掉,其他的都能删掉,就这两个珊完又回来
安全模式也珊不掉
© 2000 - 2026 Rising Corp. Ltd.