应朋友之约,看此日志:
第一份日志处理意见:
删除启动项:
<KSVSvc><rem C:\WINDOWS\KSVSvc.exe /i> [N/A]
<{131AB311-16F1-F13B-1E43-11A24B51AFD1}><C:\WINDOWS\system32\gdipri.dll> [N/A]
<{31F612A3-3223-3313-3123-31161A31A125}><C:\WINDOWS\system32\godpri.dll> [N/A]
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> [N/A]
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> [N/A]
<{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}><C:\Program Files\Internet Explorer\IEXPLORE.win> [N/A]
<{7D4E0710-61E3-4ED0-82BE-EAA1AF0F2270}><C:\Program Files\Common Files\Microsoft Shared\MSInfo\mydll.dll> [N/A]
<{42A612A4-4334-4424-4234-42261A31A236}><C:\WINDOWS\system32\pdkpri.dll> []
<{242BC422-2712-124C-2F54-22B35C62B1E2}><C:\WINDOWS\system32\exppri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfys]
<WinlogonNotify: sclgntfys><C:\WINDOWS\sclgntfys.dll> []
删除服务:
[4559FDA2 / 4559FDA2][Stopped/Auto Start]
<C:\WINDOWS\system32\D97A73FB.EXE -g><Microsoft Corporation>
[Windows User Mode Driver / UMWdfmgr][Stopped/Auto Start]
<rundll32.exe C:\WINDOWS\winamps.dll _start@16><N/A>
[Windows Accounts Driver / WindowsConnections][Stopped/Auto Start]
<C:\WINDOWS\system32\zj[1].exe><N/A>
[WinWLServiceNow / WinWLServiceNow][Stopped/Auto Start]
<C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RAVWL.EXE><N/A>
[Wserver / Wserver][Stopped/Auto Start]
<C:\WINDOWS\system32\Wservers.exe><N/A>
删除驱动:
[agiccgbi / agiccgbi][Stopped/Boot Start]
<\SystemRoot\system32\drivers\agiccgbi.sys><N/A>
[dckmkb9 / dckmkb94][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\dckmkb94.sys><N/A>
[mmcj / mmcjr][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\mmcjr.sys><N/A>
[uvdy / uvdys][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\uvdys.sys><N/A>
删除文件:
[C:\WINDOWS\system32\pdkpri.dll] [N/A, ]
[C:\WINDOWS\system32\exppri.dll] [N/A, ]
[C:\WINDOWS\system32\yhqzd.dll] [N/A, ]
[C:\WINDOWS\system32\A8530156.DLL] [Microsoft Corporation, ]