|
叱咤花甲狮
- 帖子:2464
- 注册:
2007-01-27
- 来自:
|
发表于:
2007-04-12 11:03
|
短消息
资料
| 引用: | 【baohe的贴子】【回复“5870”的帖子】 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <svc><C:\DOCUME~1\new\LOCALS~1\Temp\yqr.exe> [N/A] <1d14brdv0><C:\DOCUME~1\new\LOCALS~1\Temp\c0nime.exe> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <upxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\TIMPLATF0RM.exe> [N/A] <winform><C:\WINDOWS\winform.exe> [] <cmdbcis><C:\WINDOWS\cmdbcis.exe> [] <upxmdnd><C:\DOCUME~1\new\LOCALS~1\Temp\upxmdnd.exe> [N/A] <shalai><C:\WINDOWS\shalai.exe /i> [] <scsmdbcs><C:\WINDOWS\scsmdbcs.exe> [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] <wsttrsg><C:\WINDOWS\wsttrsg.exe> [] 服务 [B302EC43 / B302EC43][Stopped/Auto Start] <C:\WINDOWS\system32\B302EC43.EXE -d><Microsoft Corporation> [error monitor / EmonSrv][Running/Auto Start] <C:\WINDOWS\system32\lfrmewrk.exe><N/A> [Navoct / Navoct][Stopped/Auto Start] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\iesnap\navoct.dll>< >
正在运行的进程 [PID: 808][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 832][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 876][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 888][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 1040][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 1100][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 1040][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 1100][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 1720][C:\WINDOWS\Explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [C:\WINDOWS\system32\winform.dll] [N/A, ] [C:\WINDOWS\system32\scsmdbcs.dll] [N/A, ] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [C:\WINDOWS\system32\winsock32.dll] [N/A, ] [PID: 2016][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\B302EC43.DLL] [Microsoft Corporation, ] [PID: 2540][C:\WINDOWS\system32\MSRundll.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\bofang.dll] [ , 1, 0, 0, 3] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [PID: 2520][C:\WINDOWS\system32\chkfat.exe] [N/A, ] [PID: 2980][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [PID: 3076][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3424] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [C:\WINDOWS\system32\scsmdbcs.dll] [N/A, ] [C:\WINDOWS\system32\winform.dll] [N/A, ] [PID: 3940][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [PID: 972][E:\SREng.EXE] [Smallfrogs Studio, 2.4.12.806] [C:\PROGRA~1\jgmu\wwsh.dll] [, 1, 0, 0, 6] [C:\PROGRA~1\jgmu\byem.dll] [ , 1, 0, 0, 6] [C:\WINDOWS\system32\scsmdbcs.dll] [N/A, ] [C:\WINDOWS\system32\winform.dll] [N/A, ]
以上是日志中的有问题的内容。问题复杂。
楼主如果是MM,就考虑用GHOST备份恢复系统吧(没有鄙视MM的意思。这种情形——MM是搞不掂的)。 如果系统系统还原没关闭且有干净的还原点,也可以尝试系还原。 ……………… |
果然是老猫出手啊.这机器问题太多了.建议重做系统
|