瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487.vbs

12   2  /  2  页   跳转

[求助] 无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487.vbs

回复:无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487....

[C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
[PID: 3852 / user][D:\Program Files\Dr.COM宽带认证客户端\ishare_user.exe]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
    [C:\WINDOWS\system32\TcpIpDog0.dll]  [N/A, ]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
[PID: 3952 / user][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.9.2.3]
    [C:\Program Files\Mozilla Firefox\xul.dll]  [Mozilla Foundation, 1.9.2.3]
    [C:\Program Files\Mozilla Firefox\sqlite3.dll]  [sqlite.org, 3.6.16.1]
    [C:\Program Files\Mozilla Firefox\MOZCRT19.dll]  [Mozilla Foundation, 8.00.0000]
    [C:\Program Files\Mozilla Firefox\js3250.dll]  [N/A, ]
    [C:\Program Files\Mozilla Firefox\nspr4.dll]  [Mozilla Foundation, 4.8.3]
    [C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssutil3.dll]  [Mozilla Foundation, 3.12.6.2]
    [C:\Program Files\Mozilla Firefox\plc4.dll]  [Mozilla Foundation, 4.8.3]
    [C:\Program Files\Mozilla Firefox\plds4.dll]  [Mozilla Foundation, 4.8.3]
    [C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.12.6.2 Basic ECC]
    [C:\Program Files\Mozilla Firefox\xpcom.dll]  [Mozilla Foundation, 1.9.2.3]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
    [C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll]  [Mozilla Foundation, 1.9.2.3]
    [C:\WINDOWS\system32\TcpIpDog0.dll]  [N/A, ]
    [C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll]  [Mozilla Foundation, 1.9.2.3]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssdbm3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]
    [C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.12.4.6 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.78]
    [C:\Program Files\360\360safe\safemon\LoadWDUI.dll]  [360.cn, 1, 0, 0, 1018]
    [C:\Program Files\360\360safe\safemon\urlproc.dll]  [360.cn, 1, 2, 1, 1005]
    [C:\Program Files\360\360safe\safemon\urlprocnet.dll]  [360.cn, 1, 2, 1, 1008]
    [C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll]  [, ]
    [C:\Program Files\pipi\JfCheck.dll]  [PIPI Tech., 1, 5, 0, 1]
[PID: 3976 / user][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
    [C:\Program Files\360\360safe\safemon\LoadWDUI.dll]  [360.cn, 1, 0, 0, 1018]
    [C:\Program Files\pipi\JfCheck.dll]  [PIPI Tech., 1, 5, 0, 1]
[PID: 272 / user][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [C:\Program Files\pipi\JfCheck.dll]  [PIPI Tech., 1, 5, 0, 1]
    [C:\WINDOWS\system32\ProcessProtection.dll]  [www.ISRA.org.cn, 1, 3, 10, 26]
    [C:\Program Files\Thunder NetWork\MiniThunder\ToolBarNow.dll]  [深圳市迅雷网络技术有限公司, 3,1,1,58]
    [C:\Program Files\Thunder NetWork\MiniThunder\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [C:\Program Files\Thunder NetWork\MiniThunder\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\Program Files\360\360safe\safemon\urlproc.dll]  [360.cn, 1, 2, 1, 1005]
    [C:\Program Files\360\360safe\safemon\urlprocnet.dll]  [360.cn, 1, 2, 1, 1008]
    [C:\WINDOWS\system32\TcpIpDog0.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash10h.ocx]  [Adobe Systems, Inc., 10,1,53,38]
[PID: 3504 / user][C:\Documents and Settings\user\My Documents\下载\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.2.1321]
[PID: 508 / user][C:\Documents and Settings\user\My Documents\下载\sreng2\SRE2d9b9717.EXE]  [Smallfrogs Studio, 2.8.2.1321]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\360\360safe\safemon\safemon.dll]  [360.cn, 6, 5, 2, 1002]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 5.0.0.3935]
    [C:\Documents and Settings\user\My Documents\下载\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
    [C:\WINDOWS\system32\TcpIpDog0.dll]  [N/A, ]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
RSVP UDP Service Provider
    C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)
RSVP TCP Service Provider
    C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1596, C:\WINDOWS\SYSTEM32\ACS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1432, C:\PROGRAM FILES\ATK HOTKEY\HCONTROL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1492, C:\PROGRAM FILES\ASUS\ATK MEDIA\DMEDIA.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1500, C:\PROGRAM FILES\ATKOSD2\ATKOSD2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1692, C:\PROGRAM FILES\ASUS\POWER4 GEAR\BATTERYLIFE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1716, C:\PROGRAM FILES\ASUS\SPLENDID\ACMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1672, C:\PROGRAM FILES\MOTOROLA\SMSERIAL\SM56HLPR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1772, C:\PROGRAM FILES\ATHEROS\ACU.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2068, C:\WINDOWS\SYSTEM32\ACENGSVR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2160, C:\PROGRAM FILES\CCBCOMPONENTS\HDZB\USBKEYTOOLS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3572, C:\PROGRAM FILES\ATK HOTKEY\ATKOSD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3804, C:\PROGRAM FILES\ATK HOTKEY\WDC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3852, D:\PROGRAM FILES\DR.COM宽带认证客户端\ISHARE_USER.EXE]

==================================
计划任务
[已启用] SogouImeMgr.job
        C:\PROGRA~1\SOGOUI~1\500~1.393\SGTool.exe
[已启用] User_Feed_Synchronization-{D2704296-F6E1-42BD-B747-D5DAD0271C08}.job
        C:\WINDOWS\system32\msfeedssync.exe

==================================
Windows 安全更新检查
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

回复:无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487....

长度太长了,分几次回复的……
请帮帮忙吧~~~谢谢了~~!!!!!!!!!
gototop
 

回复:无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487....

你知道长度长,怎就不知道点吉我这贴右下角的引用,以附件形式发贴呢??

瑞星这破论坛,以及全国所有破论坛都这毛病

正常回帖窗口内没有上传附件的操作。唉

日志看不了
百年以后,你的墓碑旁 刻着的名字不是我
gototop
 

回复:无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487....

在扫日志的SRENG工具》启动项目》注册表》里将<load>项目置空(就是选择“编辑”)这必须关闭杀毒软件的监控,否则改不了可能。
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><"C:\WINDOWS\system32\smss.exe:2075451338.vbs">  [File is missing]

就是将 <load> 的“值”项编辑置空,清空值的所有内容即可
百年以后,你的墓碑旁 刻着的名字不是我
gototop
 

回复:无法加载或运行注册表中指定的"C:\WINDOWS\system32\207423487....

问题解决了。谢谢天月,人太好了~
Thank you so much!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT