| 引用: |
| 【豪斯登堡新郎的贴子】 楼上好快的速度…… ……………… |
| 引用: |
| 【微笑abc的贴子】[CODE] 2008-02-11,18:16:07 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <switch><c:\windows\system32\壁纸自动换.exe> [] <SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Publisher] <VTTimer><VTTimer.exe> [S3 Graphics, Inc.] <VTTrayp><VTtrayp.exe> [S3 Graphics Co., Ltd.] <TPPOLL><C:\Program Files\Topro\tppoll.exe> [] <SHAProc><C:\WINDOWS\SHAProc.exe> [] <WinForm><C:\WINDOWS\WinForm.exE> [] <SSLDyn><C:\WINDOWS\SSLDyn.exE> [] <Kvsc3><C:\WINDOWS\Kvsc3.exE> [] <AVPSrv><C:\WINDOWS\AVPSrv.exE> [] <mppds><C:\WINDOWS\mppds.exe> [] <MsPrint32D><C:\WINDOWS\MsPrint32D.exe> [] <NAVMon32><C:\WINDOWS\NAVMon32.exE> [] <LotusHlp><C:\WINDOWS\LotusHlp.exe> [] <WinSysM><C:\WINDOWS\919331M.exe> [N/A] <msccrt><C:\WINDOWS\msccrt.exe> [] <MsIMMs32><C:\WINDOWS\MsIMMs32.exE> [] <WinSysW><C:\WINDOWS\919331L.exe> [N/A] <PTSShell><C:\WINDOWS\PTSShell.exe> [] <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] <wiasoisao><wiasoisao.exe> [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher] <Userinit><userinit.exe,> [(Verified)Microsoft Windows Publisher] <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceDelayLoad] <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 启动文件夹 [QQ游戏启动加速程序] <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><N> ================================== 服务 [286EE121 / 286EE121][Stopped/Auto Start] <C:\WINDOWS\system32\792405C6.EXE -k><> [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [Rising Process Communication Center / RsCCenter][Stopped/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.> ……………… |
| 引用: |
| 【微笑abc的贴子】用解压缩工具WinRAR打开C,D,E,F盘,删除根目录下的Autorun.inf文件,重启电脑 ???????????????????????什么意思? ……………… |
| 引用: |
| 【豪斯登堡新郎的贴子 不知道你是怎么操作的 没有处理任何东西 你没感觉这个日志和之前的日志一样的吗?? 按照上面的方法 断网再做一次 做完后进行全盘杀毒 然后再扫描份日志传上来 ……………… |
| 引用: |
| 【侠者秋水的贴子】看样子是 加QQ24064682 我帮你远程弄了看看 今天闲 ……………… |
| 引用: |
| 【天月来了的贴子】 你没看日志上的时间啊 他刚发的还是原来的那个日志而已 ……………… |
| 引用: |
| 【微笑abc的贴子】刚扫的! ……………… |