瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】SOS!!瑞星,注册表等打不开,摆脱快帮我看看要怎么办?!!

1   1  /  1  页   跳转

【求助】SOS!!瑞星,注册表等打不开,摆脱快帮我看看要怎么办?!!

【求助】SOS!!瑞星,注册表等打不开,摆脱快帮我看看要怎么办?!!

中毒后无法使用瑞星杀毒,无法进入注册表(一闪而过)以及安全模式,用些专杀工具也查不出毒,真是快疯了,各位快来帮帮忙吧!!

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      0:38:36, 日期 2006-3-15
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\SHELLEXT\svchs0t.exe
D:\WINDOWS\System32\systemconfig32.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Network\ipnetwork.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Messenger\msmsgs.exe
D:\WINDOWS\system32\winlogon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe
O1 - Hosts: 8.8.8.8 skypetools.tom.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - D:\WINDOWS\System32\KakaTool.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IMSCMIG40W] D:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
O4 - 启动项HKLM\\Run: [rundll32] D:\WINDOWS\System32\SHELLEXT\svchs0t.exe
O4 - 启动项HKLM\\Run: [Windows Configuration GUI] systemconfig32.exe
O4 - 启动项HKLM\\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [IpNetwork] D:\Program Files\Network\ipnetwork.exe
O4 - 启动项HKLM\\RunServices: [Windows Configuration GUI] systemconfig32.exe
O4 - HKCU\..\Run: [Windows Configuration GUI] systemconfig32.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - 启动项HKCU\\RunServices: [Windows Configuration GUI] systemconfig32.exe
O4 - Startup: 瑞星监控中心.lnk = D:\Program Files\Rising\Rav\RavMon.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O12 - IE插件,支持文件类型.spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (PhotoUploadCtrl Control) - http://imgcache.qq.com/qzone/photo/QzoneMediaTools.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://safe.qq.com/scan/KAllScan.CAB
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{157F138F-3FE5-452C-8343-DCD7DF7CB4D9}: NameServer = 202.96.209.5 202.96.209.133
O17 - HKLM\System\CS2\Services\Tcpip\..\{157F138F-3FE5-452C-8343-DCD7DF7CB4D9}: NameServer = 202.96.209.5 202.96.209.133
O17 - HKLM\System\CS3\Services\Tcpip\..\{157F138F-3FE5-452C-8343-DCD7DF7CB4D9}: NameServer = 202.96.209.5 202.96.209.133
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: KB9148472.LOG
O21 - SSODL: SysTrays - {590498A3-4131-4D8F-BA4B-36791A9803B1} - D:\WINDOWS\System32\DLMain.dll (file missing)
O23 - NT 服务: Windows Firewall/Internet (Connection Sharing (ICS) 服务) - Unknown owner - D:\WINDOWS\Connection.exe
O23 - NT 服务: SetLogon - Unknown owner - D:\WINDOWS\System32\SetLogon.exe (file missing)

最后编辑2006-03-16 02:02:38
分享到:
gototop
 

存在的注册表打不开的问题,用HijackThis修复后可以解决么?
gototop
 

虽然知道瑞星在运行,但想打开主界面却没有反应,“运行”REGEDIT、msconfig、任务管理器也都是这样的情况:(
gototop
 

头痛的很
gototop
 

完全无法进入安全模式!
选“安全模式”后只是重启再回到列表
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT