瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:刚格完机器重装xp系统,无法安装瑞星

1   1  /  1  页   跳转

求助:刚格完机器重装xp系统,无法安装瑞星

求助:刚格完机器重装xp系统,无法安装瑞星

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      8:21:52, 日期 2006-12-05
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\win32app\nsr\bin\nsrexecd.exe
c:\orant\bin\oracle80.exe
C:\orant\BIN\TNSLSNR80.EXE
C:\orant\bin\OWASTsvr.exe
C:\win32app\nsr\bin\portmap.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\cw\LOCALS~1\Temp\Rar$EX00.313\HijackThis1991zww.exe

O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll (file missing)
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - 启动项HKLM\\Run: [tecosx] C:\WINDOWS\system32\amiame.exe
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1487044E-3B96-4CF5-A8FB-93B92FCC942C}: NameServer = 10.8.101.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{1487044E-3B96-4CF5-A8FB-93B92FCC942C}: NameServer = 10.8.101.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{1487044E-3B96-4CF5-A8FB-93B92FCC942C}: NameServer = 10.8.101.241
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - 列举现有的协议: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - 列举现有的协议: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - NT 服务: NetWorker Backup and Recover Server (nsrd) - Unknown owner - C:\win32app\nsr\bin\nsrd (file missing)
O23 - NT 服务: NetWorker Remote Exec Service (nsrexecd) - Unknown owner - C:\win32app\nsr\bin\nsrexecd (file missing)
O23 - NT 服务: OracleAgent80 - oracle - C:\orant\agentbin\DBSNMP.EXE
O23 - NT 服务: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - NT 服务: OracleDataGatherer - Unknown owner - C:\orant\bin\vppdc.exe
O23 - NT 服务: OracleExtprocAgent - Unknown owner - C:\orant\BIN\EXTPROCT.EXE
O23 - NT 服务: OracleNamesService80 - Unknown owner - C:\orant\BIN\NAMES80.EXE
O23 - NT 服务: OracleServiceORCL - Oracle Corporation - c:\orant\bin\oracle80.exe
O23 - NT 服务: OracleStartORCL - Unknown owner - C:\orant\BIN\strtdb80.exe
O23 - NT 服务: OracleTNSListener80 - Unknown owner - C:\orant\BIN\TNSLSNR80.EXE
O23 - NT 服务: OracleWebAssistant - Oracle Corporation - C:\orant\bin\OWASTsvr.exe
O23 - NT 服务: Storage Management Portmapper (portmap) - Unknown owner - C:\win32app\nsr\bin\portmap (file missing)

最后编辑2006-12-05 14:07:12
分享到:
gototop
 

2006-12-05,08:21:12

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <OrderReminder><C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe>  [Hewlett-Packard]
    <tecosx><C:\WINDOWS\system32\amiame.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
gototop
 

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NetWorker Backup and Recover Server / nsrd]
  <C:\win32app\nsr\bin\nsrd><N/A>
[NetWorker Remote Exec Service / nsrexecd]
  <C:\win32app\nsr\bin\nsrexecd><N/A>
[OracleAgent80 / OracleAgent80]
  <C:\orant\agentbin\DBSNMP.EXE><oracle>
[OracleClientCache80 / OracleClientCache80]
  <C:\orant\BIN\ONRSD80.EXE><N/A>
[OracleDataGatherer / OracleDataGatherer]
  <C:\orant\bin\vppdc.exe><N/A>
[OracleExtprocAgent / OracleExtprocAgent]
  <C:\orant\BIN\EXTPROCT.EXE extproc><N/A>
[OracleNamesService80 / OracleNamesService80]
  <C:\orant\BIN\NAMES80.EXE><N/A>
[OracleServiceORCL / OracleServiceORCL]
  <c:\orant\bin\oracle80.exe ORCL><Oracle Corporation>
[OracleStartORCL / OracleStartORCL]
  <C:\orant\BIN\strtdb80.exe><N/A>
[OracleTNSListener80 / OracleTNSListener80]
  <C:\orant\BIN\TNSLSNR80.EXE><N/A>
[OracleWebAssistant / OracleWebAssistant]
  <C:\orant\bin\OWASTsvr.exe><Oracle Corporation>
[Storage Management Portmapper / portmap]
  <C:\win32app\nsr\bin\portmap><N/A>

==================================
驱动程序
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
gototop
 

==================================
浏览器加载项
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, N/A>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, N/A>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
gototop
 

==================================
正在运行的进程
[PID: 464][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 520][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 544][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 588][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 816][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\orant\bin\oci.dll]  [Oracle Corporation, 8.0.5.0.1]
    [C:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [C:\orant\bin\SQLLib80.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\xa80.dll]  [Oracle Corporation, 8.0.5.0.0]
[PID: 968][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1000][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ZLhp1020.DLL]  [Zenographics, Inc., 5, 53, 3723, 0]
    [C:\WINDOWS\system32\ZLM.dll]  [Zenographics, Inc., 5, 50, 1416, 0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL]  [Zenographics, Inc., 5, 54, 330, 0]
    [C:\WINDOWS\system32\Imf32.dll]  [Zenographics, Inc., 5, 60, 1204, 0]
    [C:\WINDOWS\system32\ZTAG32.dll]  [Zenographics, Inc., 5, 60, 1210, 0]
    [C:\WINDOWS\system32\ZSPOOL.dll]  [Zenographics, Inc., 5, 51, 709, 0]
[PID: 1392][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\amiame.dll]  [N/A, N/A]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
[PID: 1476][C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe]  [Hewlett-Packard, 2, 0, 1, 26]
[PID: 1708][C:\win32app\nsr\bin\nsrexecd.exe]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\liblocal.dll]  [N/A, N/A]
[PID: 1736][c:\orant\bin\oracle80.exe]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [c:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [c:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [c:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [c:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [c:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [c:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [c:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [c:\orant\bin\O80VSNOP.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\orasbt.dll]  [N/A, N/A]
    [C:\orant\bin\ntp80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
[PID: 1836][C:\orant\BIN\TNSLSNR80.EXE]  [N/A, N/A]
    [C:\orant\BIN\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\BIN\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\BIN\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\BIN\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\BIN\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\BIN\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\BIN\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\BIN\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\BIN\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntus80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntn80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntt80.DLL]  [Oracle Corporation, 8.0.4.0.2 Production]
[PID: 1852][C:\orant\bin\OWASTsvr.exe]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\OCI.dll]  [Oracle Corporation, 8.0.5.0.1]
    [C:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [C:\orant\bin\owasmus.dll]  [N/A, N/A]
[PID: 1880][C:\win32app\nsr\bin\portmap.exe]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\liblocal.dll]  [N/A, N/A]
[PID: 428][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1956][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\WINDOWS\system32\amiame.dll]  [N/A, N/A]
[PID: 2040][C:\DOCUME~1\cw\LOCALS~1\Temp\Rar$EX00.781\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\system32\amiame.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
[E:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
[F:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8220076
下专杀
gototop
 

C:\WINDOWS\system32\amiame.exe
这是个什么东西?没见过
gototop
 

下载一个叫“EXE关联修复”的小东西修复一下试看。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT