结束进程
C:\WINDOWS\Media\updata.exe
C:\WINDOWS\stsystra.exe
修复:
F2 - REG:system.ini: UserInit=C:\WINDOWS\Media\updata.exe,C:\WINDOWS\System32\userinit.exe,
O2 - BHO: (no name) - {08A312BB-5409-49FC-9347-54BB7D069AC6} - (no file)
O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - (no file)
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5115.dll
O2 - BHO: (no name) - {23AB87A9-8D32-4266-AAAD-0EA93DABD7DB} - (no file)
O2 - BHO: XBTP03129 - {6029B367-250A-4696-925C-641709CA7381} - (no file)
O2 - BHO: (no name) - {C61A70F3-505E-4B90-916F-627A8706B4BC} - (no file)
O2 - BHO: (no name) - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - (no file)
O3 - Toolbar: (no name) - {6AE02E1C-8859-4F57-9097-5A55A56A4CAF}? - (no file)
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = faw-vw.in
O17 - HKLM\Software\..\Telephony: DomainName = faw-vw.in
O17 - HKLM\System\CCS\Services\Tcpip\..\{A05E2FDA-7A68-443D-98E7-E012E0901207}: Domain = faw-volkswagen.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = faw-vw.in
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = faw-vw.in
O18 - Protocol: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SapGui\SAPHTMLP.DLL
O18 - Protocol: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SapGui\SAPHTMLP.DLL
O18 - Protocol: vw-wi - {0F3C833F-FB28-40EA-8CB9-6A55B996C3F6} - C:\ElsaWin\bin\wiProt.dll
删除:
C:\WINDOWS\Media\updata.exe
C:\WINDOWS\stsystra.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5115.dll
这个的处理方法参考http://forum.ikaka.com/topic.asp?board=28&artid=8174324
C:\WINDOWS\System32\SVOHOST.exe
这个的详细处理参考http://forum.ikaka.com/topic.asp?board=28&artid=8173208
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
这个的处理:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载lspfix和winsockxpfix
运行lspfix,勾选“I know what I'm doing”并把quartz32.dll从左边窗口移到右边。
重启后如果上不了网,再用winsockxpfix来修复。
注意修复之前请记住你的上网设置,比如本地连接或宽带连接的设置和internet选项中局域网的设置,因为修复可能会把这些设置清空。
另外:
C:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
这又是什么程序?