瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】紧急求助:杀不了的灰鸽子!!高手们帮忙阿

12   2  /  2  页   跳转

【求助】紧急求助:杀不了的灰鸽子!!高手们帮忙阿

用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
gototop
 

非常感谢,下面就是日志,我看不明白,麻烦您帮我看看,谢谢了
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ AtiPTAATI Desktop Control PanelATI Technologies, Inc.c:\winnt\system32\atiptaxx.exe

+ vptrayNorton AntiVirusSymantec Corporationc:\program files\navnt\vptray.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\winnt\system32\hticons.dll

+ LDVP Shell ExtensionsNorton AntiVirusSymantec Corporationc:\program files\common files\symantec shared\ssc\vpshell2.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\System\CurrentControlSet\Services

+ DefWatchVirus Definition DaemonSymantec Corporationc:\program files\navnt\defwatch.exe

+ ibmasrexIBMc:\winnt\system32\ibmasrex.exe

+ IBMHPSIBM Active PCI Alert ServiceIBM Corporationc:\winnt\system32\ibmhpasv.exe

+ ibmsmbusSMBus Upgrade Service for Windows 2000 and aboveInternational Business Machines Corp.c:\winnt\system32\ibmsmbus.exe

+ Norton AntiVirus ServerNorton AntiVirusSymantec Corporationc:\program files\navnt\rtvscan.exe

HKLM\System\CurrentControlSet\Services

+ ati2mpadATI2MPAD Miniport DriverATI Technologies Inc.c:\winnt\system32\drivers\ati2mpad.sys

+ atirage3ATIRAGE3 Miniport DriverATI Technologies Inc.c:\winnt\system32\drivers\atimpab.sys

+ b57w2kBroadcom NetXtreme Gigabit Ethernet NDIS5 Driver.Broadcom Corporationc:\winnt\system32\drivers\b57w2k.sys

+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys

+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys

+ GENERICSMBSMBus Generic Device driver for Windows 9x/2K?International Business Machines Corp.c:\winnt\system32\drivers\smbgen.sys

+ IBMHPAIBM Active PCI Alert DriverIBM Corporationc:\winnt\system32\drivers\ibmhpa.sys

+ IBMHPFIBM Active PCI Filter DriverIBM Corporationc:\winnt\system32\drivers\ibmhpf.sys

+ NAVAPc:\program files\navnt\navap.sys

+ NAVAPELc:\program files\navnt\navapel.sys

+ nfrd960IBM ServeRAID Controller DriverIBM Corporationc:\winnt\system32\drivers\nfrd960.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys

+ safemonSystem Safety Monitor 2.0 extension for Windows security layerSystem Safety Limitedc:\winnt\system32\drivers\safemon.sys

+ SMBusDHSMB Device Hub Controller driver for Windows 9x/2K?International Business Machines Corp.c:\winnt\system32\drivers\smbusdh.sys

+ SMBusHCSMB Host Controller driver for Windows 9x/2K?International Business Machines Corp.c:\winnt\system32\drivers\smbushc.sys

+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ NavLogonc:\winnt\system32\navlogon.dll

+ System Safety MonitorSystem Safety Winlogon NotificationSystem Safety Limitedc:\winnt\system32\ssmwinlogonex.dll

gototop
 

好像看不出与你发的问题得启动项


+ ibmasrexIBMc:\winnt\system32\ibmasrex.exe
确定一下这个是不是IBM得,若不是
删除启动项
重启
删除它

gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT