同事一台机,她自己装了一个软件重起后,就一直开不了机,系统自动重起.进入安全模式用自动还原不行,装的软件删不了.
R0 - 未知 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://seek.yahoo.com.cn/srchasst.htm
O2 - 未知 - BHO: (浏览器辅助对象(BHO)) - [无效的CLSID:{7E853D72-626A-48EC-A868-BA8D5E23E045}] - {7E853D72-626A-48EC-A868-BA8D5E23E045} -
O4 - 未知 - HKLM\..\Run: [BDMCon] [BitDefender Management Console] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - 未知 - HKLM\..\Run: [BDAgent] [BDSwitch Application] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - 未知 - HKCU\..\Run: [acdseemc.exe] [] C:\Program Files\Common Files\ACD Systems\ACDSeeMC.EXE
O8 - 未知 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - 未知 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - 未知 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - 未知 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O18 - 未知 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\PROGRA~1\KuGoo3\InExtend\KUGOO3~1.OCX
O18 - 未知 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 未知 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - 未知 - AppInit DLLs: sockspy.dll
O23 - 未知 - Service: AVP [保护计算机远离病毒和间谍软件的威胁。] - "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r - (not running)
O23 - 未知 - Service: bdss [Scans media for viruses and other security threats] - "C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service - (not running)
O23 - 未知 - Service: LIVESRV [Downloads BitDefender updates and new malware signatures from the Internet] - "C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service - (not running)
O23 - 未知 - Service: TrkNetsSvcs [在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。] - C:\WINDOWS\svchost.exe -netsvcs - (not running)
O23 - 未知 - Service: usnjsvc [Messenger 上安装的启用共享情况的服务] - "C:\Program Files\MSN Messenger\usnsvc.exe" - (not running)
O23 - 未知 - Service: VSSERV [Scans media for viruses and other security threats] - "C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service - (not running)
O23 - 未知 - Service: XCOMM [Ensures proper communication between BitDefender components] - "C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service - (not running)
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k netsvcs
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: wmiprvse.exe [wmi 提供程序 (wmi provider) 在 wmi 和操作系统、应用程序以及其他系统的组件之间充当中介.此进程为合法的系统进程。] - C:\WINDOWS\system32\wbem\wmiprvse.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士] - D:\Program Files\360safe\360Safe.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O4 - 安全 - HKLM\..\Run: [IMJPMIG8.1] [微软Microsoft输入法编辑器程序。] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 安全 - HKLM\..\Run: [PHIME2002A] [输入法软件相关程序。] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 安全 - HKLM\..\Run: [IgfxTray] [是Intel显卡配置和诊断程序,会同Intel 810芯片组的集成显卡安装。] C:\WINDOWS\system32\igfxtray.exe
O4 - 安全 - HKLM\..\Run: [HotKeysCmds] [是Intel显示卡相关程序,用于配置和诊断相关设备。] C:\WINDOWS\system32\hkcmd.exe
O4 - 安全 - HKLM\..\Run: [Easy-PrintToolBox] [佳能出品的相关软件。] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - 安全 - HKLM\..\Run: [BigDogPath] [网眼摄像头驱动] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - 安全 - HKLM\..\Run: [kav] [卡巴斯基杀毒软件相关程序。] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - 安全 - HKLM\..\Run: [miniqqlive] [QQLive视频播放软件相关程序。] "C:\Program Files\Tencent\QQLive\MiniQQLive.exe"
O4 - 安全 - HKCU\..\Run: [MsnMsgr] [微软msn即时通讯工具] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - Startup folder: [QQ游戏启动加速程序.lnk] [qq游戏启动加速相关程序。] C:\Documents and Settings\new\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk
O4 - 安全 - Startup folder: [腾讯QQ.lnk] [qq:即时通讯软件] C:\Documents and Settings\new\「开始」菜单\程序\启动\腾讯QQ.lnk
O9 - 安全 - Extra button: 卡巴斯基Web反病毒保护插件(HKLM) - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - 安全 - Service: C-DillaCdaC11BA [是MacroVision safeCast反复制保护软件。该进程是一些软件为了保护其产品不被盗版而安装的。] - C:\WINDOWS\system32\drivers\CDAC11BA.EXE - (not running)
O23 - 安全 - Service: SoundMAX Agent Service (default) [是Analog SoundMAX声卡产品相关程序。] - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe - (not running)
=======================================
O40 - winlogon.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - winlogon.exe - Kaspersky Lab - C:\WINDOWS\system32\klogon.dll - Logon Visualizer - 7072750eb5c0f0cd54b48f972855ca61
O40 - services.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - lsass.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - svchost.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - svchost.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - svchost.exe - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - Explorer.EXE - - C:\WINDOWS\system32\sockspy.dll - - 6382040502f8e7271e65a523b70f2b0a
O40 - Explorer.EXE - - C:\Program Files\Softwin\BitDefender10\bdshelxt.dll - BDShellExt Module - f0db5b73f531f02a7f6873ab8f8a3794
O40 - Explorer.EXE - Microsoft Corporation - C:\WINDOWS\system32\MSVCR71.dll - Microsoft? C Runtime Library - 86f1895ae8c5e8b17d99ece768a70732
O40 - Explorer.EXE - - d:\Program Files\WinRAR\rarext.dll - - 0bf971b9a6af0c5ad358fea8330b663d
O40 - Explorer.EXE - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll - Windows Shell Extension - 62281a8da78c81f4f4695c3de52ba680
=======================================
O41 - pfc - Padus(R) ASPI Shell - C:\WINDOWS\system32\drivers\pfc.sys - (running) - Padus(R) ASPI Shell - Padus, Inc. - ed2e7f396b4098608c95bc3806bdf6fc
O41 - bdfdll - bdfdll - C:\Program Files\Softwin\BitDefender10\bdfdll.sys - (not running) - - - ed2179e5cd86eabfdc227601c3094c64
O41 - BDFSDRV - BDFSDRV - C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys - (not running) - - - 09144a34a6bc8c1228db81995bacc0f8
O41 - BDRSDRV - BDRSDRV - C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys - (not running) - - - 6f85116c3a51c2c07efbe957b69f1199
O41 - CdaC15BA - CdaC15BA - C:\WINDOWS\system32\drivers\CDAC15BA.SYS - (not running) - - - 82c4c6a2343b592c4fd590f625a724a9
O41 - kl1 - Kaspersky Unified Driver - C:\WINDOWS\system32\drivers\kl1.sys - (not running) - Kaspersky Unified Driver - Kaspersky Lab - 5445b03cd42dedf5f85b9daf712fdd09
O41 - klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (not running) - spuper-ptor - Kaspersky Lab - 92210989cc1d06f997b9628d8e4b1819
O41 - npkcrypt - nProtect KeyCrypt Driver - C:\QQ\npkcrypt.sys - (not running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - ZSMC301b - Video streaming and Capture Device Driver - C:\WINDOWS\system32\drivers\usbVM31b.sys - (not running) - Video streaming and Capture Device Driver - VM - f34e79ae663bfb36284cf2b4fa20b6f3
=======================================
360Safe.exe=3.2.1.1002
AntiAdwa.dll=3.2.0.1001
AntiEng.dll=3.0.2.2000
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
safelive.exe=1.0.0.2007
live.dll=1.0.0.1011