瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 广告程序软件无法删除
yujiqi - 2009-7-24 19:50:00
请教高手我电脑中了orzhz恶意广告程序无法删除,删除以后重启电脑就有了,而且老是修改的ie首页,现在我ie首页已经被他修改成别的首页,我自己在ie浏览器设置首页确不起作用,请问高手如何解决你

用户系统信息:Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.9.0.12) Gecko/2009070611 Firefox/3.0.12
aaccbbdd - 2009-7-24 19:52:00
Sreng官方下载
SREng/智能扫描(记得勾选“检查进程的数字签名)
等扫描完成,保存日志(LOG格式)
PS:如主程序SREng**.exe无法运行,导致无法扫描日志
将主程序改名为我爱小狮子.bat
或我爱小狮子.scr
日志放入附件
(点击我这贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。)
yujiqi - 2009-7-24 20:08:00
各位高手:

非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!

该诊断报告由360安全卫士提供 http://www.360.cn

诊断时间: 2009-04-02 23:36:34

诊断平台: Microsoft Windows XP Service Pack 2

IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180

计算机物理内存:191.18MB - 当前可用内存:60.06MB

100 - 未知 - Process: egui.exe [Eset GUI] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

100 - 未知 - Process: xms.exe [] - C:\WINDOWS\system32\xms.exe

R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/

O2 - 未知 - BHO: (pnflz.rtp) - [无效的CLSID:{E53450DE-6FD0-46ED-BE25-D56CF8C41446}] - {E53450DE-6FD0-46ED-BE25-D56CF8C41446} -

O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}] - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} -

O8 - 未知 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm

O8 - 未知 - Extra context menu item: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM

O9 - 未知 - Extra button: 豪杰超级解霸V8(HKLM) - C:\Herosoft\HeroV8\STHSDVD.EXE

O9 - 未知 - Extra button: 微软(HKLM) - http://www.microsoft.com/china/index.htm

O16 - 未知 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O23 - 未知 - Service: Remote [Network Connections] - C:\WINDOWS\system32\xms.exe - (running)

O23 - 未知 - Service: W32Time [维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。

] - C:\WINDOWS\System32\fywd.dll - (not running)

=======================================

100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe

100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base

100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe

100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe

100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService

100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE

100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe

100 - 安全 - Process: Alert.exe [starsoftcomm软通科技相关产品。] - C:\Program Files\Starsoftcomm\StarCenter\alert.exe

100 - 安全 - Process: StarCenter.exe [starsoftcomm软通科技相关软件。] - C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe

100 - 安全 - Process: UpdTray.exe [starsoftcomm软通科技相关产品。] - C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe

100 - 安全 - Process: safeboxTray.exe [360安全卫士保险箱相关程序。] - C:\Program Files\360\360safebox\safeboxTray.exe

100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe

100 - 安全 - Process: Thunder5.exe [迅雷5,支持多资源超线程技术的下载工具] - C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe

100 - 安全 - Process: ekrn.exe [NOD32相关文件。] - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k imgsvc

100 - 安全 - Process: wdfmgr.exe [windows media player播放器相关程序。] - C:\WINDOWS\system32\wdfmgr.exe

100 - 安全 - Process: wmiapsrv.exe [wmiapsrv(wmi性能适配器服务),从wmi hiperf提供程序性能库信息。] - C:\WINDOWS\system32\wbem\wmiapsrv.exe

100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe

100 - 安全 - Process: wuauclt.exe [windows操作系统后台程序,用于系统升级。] - C:\WINDOWS\system32\wuauclt.exe

100 - 安全 - Process: 360Safe.exe [360安全卫士] - C:\Program Files\360\360Safe\360Safe.exe

100 - 安全 - Process: 360tray.exe [360安全卫士实时保护模块] - C:\Program Files\360\360Safe\safemon\360Tray.exe

100 - 安全 - Process: SoftManager.exe [360软件管理] - C:\Program Files\360\360Safe\SoftMgr\SoftManager.exe

100 - 安全 - Process: 360SE.exe [360安全浏览器] - C:\Program Files\360safe\360se\360SE.exe

R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm

R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm

O2 - 安全 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块。] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll

O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll

O2 - 安全 - BHO: (NTIECatcher Class) - [影音(网络)传送带相关插件。] - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll

O4 - 安全 - HKLM\..\Run: [Alert] [starsoftcomm软通科技相关产品。] C:\Program Files\Starsoftcomm\StarCenter\alert.exe

O4 - 安全 - HKLM\..\Run: [StarCenter] [starsoftcomm软通科技相关产品。] C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe

O4 - 安全 - HKLM\..\Run: [AutoUpd] [starsoftcomm软通科技相关产品。] C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe

O4 - 安全 - HKLM\..\Run: [Thunder] [迅雷下载器软件相关程序。] "C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s

O4 - 安全 - HKLM\..\Run: [360Safebox] [360安全卫士保险箱相关程序。] "C:\Program Files\360\360safebox\safeboxTray.exe" /r

O4 - 安全 - HKLM\..\Run: [egui] [NOD32杀毒软件相关程序。] "C:\Program Files\ESET\ESET NOD32 Antivirus\EsetACT\egui.exe" /hide /waitservice

O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe

O4 - 安全 - Startup folder: [壁纸自动换.lnk] [一款自动换壁纸软件相关程序。] C:\Documents and Settings\All Users\「开始」菜单\程序\启动\壁纸自动换.lnk

O4 - 安全 - Startup folder: [腾讯QQ.lnk] [qq:即时通讯软件] C:\Documents and Settings\new\「开始」菜单\程序\启动\腾讯QQ.lnk

O4 - 安全 - Startup folder: [QQ游戏启动加速程序.lnk] [qq游戏启动加速相关程序。] C:\Documents and Settings\new\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk

O8 - 安全 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html

O8 - 安全 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html

O8 - 安全 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm

O8 - 安全 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm

O8 - 安全 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - 安全 - Extra button: 启动迅雷5(HKLM)(HKLM) - C:\Program Files\Thunder Network\Thunder\Thunder.exe

O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

O21 - 安全 - Protocol Icons: HKCR\http\shell\open\command - "C:\Program Files\360safe\360se\360SE.exe" "%1"

O21 - 安全 - Protocol Icons: HKCR\https\shell\open\command - "C:\Program Files\360safe\360se\360SE.exe" "%1"

O21 - 安全 - Protocol Icons: HKCR\htmlfile\shell\open\command - "C:\Program Files\360safe\360se\360SE.exe" "%1"

O23 - 安全 - Service: EhttpSrv [NOD32杀毒软件相关服务。] - "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" - (not running)

O23 - 安全 - Service: ekrn [NOD32杀毒软件相关服务。] - "C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe" - (running)

=======================================

O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -

O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -

O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -

O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
yujiqi - 2009-7-24 20:09:00
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -

O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 -

O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 124416 - 1b089bd70767a1ca5419a24b581cc753

O31 - 未知 - SEApproved: {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - C:\Program Files\Real\RealPlayer\rpshell.dll - RealNetworks, Inc. - RealPlayer Shell Extensions - 1.0.1.2156 - 49198 - 9ac5a66c293fef3858f442589e4b33eb

O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 124416 - 1b089bd70767a1ca5419a24b581cc753

O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -

O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -

=======================================


=======================================

O41 - SSCFLTXP - File System Filter Driver - C:\WINDOWS\system32\drivers\SSCFLTXP.sys - (running) - File System Filter Driver - Windows (R) 2000 DDK provider - 449b08c87207576efd4b0edb335c6fcf

O41 - viamraid - VIA RAID DRIVER FOR WIN 2000/XP/2003IA32 - C:\WINDOWS\system32\drivers\viamraid.sys - (running) - VIA RAID DRIVER FOR WIN 2000/XP/2003IA32 - VIA Technologies inc,.ltd - f199939205dccc7836ae5ab8b5dd5e83

O41 - a320raid - Adaptec HostRAID for Ultra320 SCSI - C:\WINDOWS\system32\drivers\a320raid.sys - (not running) - Adaptec HostRAID for Ultra320 SCSI - Adaptec, Inc. - 0532434d53314ee8858b7bfdbe761837

O41 - AAC - Adaptec RAID Miniport Driver - C:\WINDOWS\system32\drivers\aac.sys - (not running) - Adaptec RAID Miniport Driver - Adaptec, Inc. - f9ee3c7a185d121b145164cb10c057a7

O41 - aar1210 - Adaptec HostRAID for Serial ATA - C:\WINDOWS\system32\drivers\aar1210.sys - (not running) - Adaptec HostRAID for Serial ATA - Adaptec, Inc. - 316945ebc9398f222a6fff3d04d41fcb

O41 - aec6210 - aec6210 - C:\WINDOWS\system32\drivers\AEC6210.sys - (not running) - - ACARD Technology Corp. - 38e6c035e89fb8b079301e71b2523f3d

O41 - aec6260 - ID=0006, 0007 - C:\WINDOWS\system32\drivers\AEC6260.sys - (not running) - ID=0006, 0007 - ACARD Technology Corp. - db227bd0ba1f29bb38950f8fd97caa35

O41 - aec6280 - AEC6280 Miniport Driver - C:\WINDOWS\system32\drivers\AEC6280.SYS - (not running) - AEC6280 Miniport Driver - ACARD Technology Corp. - 71c3ab81b22c151a2e2ba97ec53430ca

O41 - AEC6290 - AEC6280 Miniport Driver - C:\WINDOWS\system32\drivers\AEC6290.SYS - (not running) - AEC6280 Miniport Driver - ACARD Technology Corp. - 71c3ab81b22c151a2e2ba97ec53430ca

O41 - AEC67160 - AEC67160 PCI Ultra3 LVD/SE Adapter Driver - C:\WINDOWS\system32\drivers\AEC67160.SYS - (not running) - AEC67160 PCI Ultra3 LVD/SE Adapter Driver - ACARD Technology Corp. - f2b276e8f4057dd1ba2bd40ecaf1ac57

O41 - AEC671X - AEC671X PCI Ultra/W SCSI3 Adapter Driver - C:\WINDOWS\system32\drivers\AEC671X.SYS - (not running) - AEC671X PCI Ultra/W SCSI3 Adapter Driver - ACARD Technology Corp. - 9493824293585203212d0157cb2430a7

O41 - AEC6880 - AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver - C:\WINDOWS\system32\drivers\AEC6880.SYS - (not running) - AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver - ACARD Technology Corp. - 415f252cee34bbf839acbcadb2bc85ce

O41 - AEC6890 - AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver - C:\WINDOWS\system32\drivers\AEC6890.SYS - (not running) - AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver - ACARD Technology Corp. - 415f252cee34bbf839acbcadb2bc85ce

O41 - aec68x5 - AEC6885/95/96 PCI ATA133 4 Channel RAID Adapter Driver - C:\WINDOWS\system32\drivers\aec68X5.sys - (not running) - AEC6885/95/96 PCI ATA133 4 Channel RAID Adapter Driver - ACARD Technology Corp. - 6275261ebb499358ff5c5cf901f7ad6c

O41 - FASTSX - Promise FastTRAK SX4/SX4000 Driver for WindowsXP - C:\WINDOWS\system32\drivers\fastsx.sys - (not running) - Promise FastTRAK SX4/SX4000 Driver for WindowsXP - Promise Technology, Inc. - 21ab10bc1c78a68cdf0cbd304dbfb7fa

O41 - fasttrak - Promise FastTrak Series Driver for WinXP - C:\WINDOWS\system32\drivers\fasttrak.sys - (not running) - Promise FastTrak Series Driver for WinXP - Promise Technology, Inc. - eb1c078d99cc081c1d2ae3a19e2284cc

O41 - fasttx2k - Promise Driver for Windows XP - C:\WINDOWS\system32\drivers\fasttx2k.sys - (not running) - Promise Driver for Windows XP - Promise Technology, Inc. - 5d95724d3c3923449c02be1106657bcd

O41 - fasttx2k2 - Promise FastTrak Series Driver for WindowsXP - C:\WINDOWS\system32\drivers\fasttx2k2.sys - (not running) - Promise FastTrak Series Driver for WindowsXP - Promise Technology, Inc. - c127946de07bbb00f69f78923577dae4

O41 - Hpt366 - ATAPI IDE Miniport Driver - C:\WINDOWS\system32\drivers\hpt366.sys - (not running) - ATAPI IDE Miniport Driver - Microsoft Corporation - 4e4c5dde3eb4e9392c9659818790ed6c

O41 - HPT371 - HPT3xx Miniport Driver - C:\WINDOWS\system32\drivers\hpt371.sys - (not running) - HPT3xx Miniport Driver - HighPoint Technologies, Inc. - cac96d5be76a3d20c41759b12167c09b

O41 - hpt374 - HPT374 Miniport Driver - C:\WINDOWS\system32\drivers\hpt374.sys - (not running) - HPT374 Miniport Driver - HighPoint Technologies, Inc. - ccee236589335d118e22d0fe400233a6

O41 - hpt3xx - HPT3xx Miniport Driver - C:\WINDOWS\system32\drivers\hpt3xx.sys - (not running) - HPT3xx Miniport Driver - HighPoint Technologies, Inc. - 9f2dfe54317b1cd38143686935a278d9

O41 - hptmv - hptmv Miniport Driver - C:\WINDOWS\system32\drivers\hptmv.sys - (not running) - hptmv Miniport Driver - HighPoint Technologies, Inc. - 4f92f14095d52ca870039b192a3319b0

O41 - hptpro - Hptpro - C:\WINDOWS\system32\drivers\hptpro.sys - (not running) - Hptpro - HighPoint Technologies, Inc. - 977716f8a6edda986fdb41de52bdb689

O41 - iaStor - Intel Application Accelerator driver - C:\WINDOWS\system32\drivers\iastor.sys - (not running) - Intel Application Accelerator driver - Intel Corporation - bdce6b54e1d7d8399175a83a02274b7a

O41 - m5228 - M5228 ATA RAID Controller Driver - C:\WINDOWS\system32\drivers\m5228.sys - (not running) - M5228 ATA RAID Controller Driver - ALi Corporation. - 4bc8aa133cdb516392ac76d9948138bc

O41 - m5281 - M5281 SATA RAID Controller Driver - C:\WINDOWS\system32\drivers\m5281.sys - (not running) - M5281 SATA RAID Controller Driver - ALi Corporation - 3bb7e4f0d880c57b75ab2197f6e21897

O41 - mraid2k - MEGARAID SCSI Controller Driver for Windows 2000 PAE - C:\WINDOWS\system32\drivers\MRAID2K.SYS - (not running) - MEGARAID SCSI Controller Driver for Windows 2000 PAE - American Megatrends, Inc. - a7bb113a38b04c0296bfa76b41d92f95

O41 - npkcrypt - npkcrypt - C:\Program Files\QQ2005\npkcrypt.sys - (not running) - - -

O41 - NTSIM - Network Device Monitor Utility - C:\WINDOWS\system32\ntsim.sys - (not running) - Network Device Monitor Utility - VIA Networking Technologies, Inc. - a568b9a9ffe2d9387222a5c90f86d731

O41 - NvAtaBus - NVIDIA? nForce(TM) IDE Performance Driver - C:\WINDOWS\system32\drivers\NvAtaBus.sys - (not running) - NVIDIA? nForce(TM) IDE Performance Driver - NVIDIA Corporation - a1f88223528aadbb6374132becbbdcc1

O41 - PNP649R - IDE RAID miniport driver - C:\WINDOWS\system32\drivers\PnP649r.sys - (not running) - IDE RAID miniport driver - CMD Technology, Inc. - 5a5a6a1003eecd15df2f383972e86188

O41 - Pnp680 - DMA capable ATA miniport driver - C:\WINDOWS\system32\drivers\Pnp680.sys - (not running) - DMA capable ATA miniport driver - Silicon Image, Inc. - 023657a82e76ad98f3fafbd1ec425a71

O41 - Pnp680r - DMA capable ATA RAID miniport driver - C:\WINDOWS\system32\drivers\PnP680r.sys - (not running) - DMA capable ATA RAID miniport driver - Silicon Image, Inc - a1d7a9214b71ebbb6f31cb84aac15525

O41 - RAIDSRC - Intel(r)/ICP Miniport Driver - C:\WINDOWS\system32\drivers\raidsrc.sys - (not running) - Intel(r)/ICP Miniport Driver - Intel/ICP - 4ba4a4ac184ed0cf15faa62e2375883f

O41 - S150SX8 - Promise SATAII150 SX8 Driver for WindowsXP - C:\WINDOWS\system32\drivers\S150sx8.sys - (not running) - Promise SATAII150 SX8 Driver for WindowsXP - Promise Technology, Inc. - 13d1e68b006ae72276079f5fcbe5a471

O41 - SCBACK - File System Filter Driver - C:\WINDOWS\system32\drivers\SCBACK.sys - (not running) - File System Filter Driver - StarSoftComm - a5071a7072b2293be27439dde7031e93

O41 - SI3112 - Serial ATA miniport driver - C:\WINDOWS\system32\drivers\Si3112.sys - (not running) - Serial ATA miniport driver - Silicon Image, Inc. - 77f5cf403657f5086df7f4ed1f497cbb

O41 - SI3112r - Serial ATA RAID Miniport Driver - C:\WINDOWS\system32\drivers\Si3112r.sys - (not running) - Serial ATA RAID Miniport Driver - Silicon Image, Inc - d89dde61753a3b5d64e15a1a925588cc

O41 - SI3114 - Serial ATA miniport driver - C:\WINDOWS\system32\drivers\Si3114.sys - (not running) - Serial ATA miniport driver - Silicon Image, Inc. - 9c67403714df81c8bdf177ce440c9d84

O41 - SI3114r - SATARAID Miniport Driver - C:\WINDOWS\system32\drivers\Si3114r.sys - (not running) - SATARAID Miniport Driver - Silicon Image, Inc - 53ee85fa0b48eb64031a190adf23c8d8

O41 - SI3124 - Serial ATA miniport driver - C:\WINDOWS\system32\drivers\Si3124.sys - (not running) - Serial ATA miniport driver - Silicon Image, Inc. - da09038c6d12cf69031b515741250f7b

O41 - SI3124r - SATARAID miniport driver (PRE-RELEASE) - C:\WINDOWS\system32\drivers\Si3124r.sys - (not running) - SATARAID miniport driver (PRE-RELEASE) - Silicon Image, Inc - 0c71855057883e63ca2c19736cbab018

O41 - SiFilter - Windows Accelerator Driver - C:\WINDOWS\system32\drivers\SiWinAcc.sys - (not running) - Windows Accelerator Driver - Silicon Image, Inc. - 1582e88c6f340627247b1ecd00fa84fe

O41 - SISIDE - SiS PCI Mini IDE Driver - C:\WINDOWS\system32\drivers\siside.sys - (not running) - SiS PCI Mini IDE Driver - Silicon Integrated Systems Corp. - b4485881bd8aed9b157a2e6cf43c2d51

O41 - SiSRaid - SiS RAID Miniport Driver - C:\WINDOWS\system32\drivers\sisraid.sys - (not running) - SiS RAID Miniport Driver - Silicon Integrated Systems - 4c597e4de6edf6453990059ba0eac7d0

O41 - SiSRaid1 - SiS RAID Miniport Driver - C:\WINDOWS\system32\drivers\sisraid1.sys - (not running) - SiS RAID Miniport Driver - Silicon Integrated Systems - 52192d1a30ae56a203c047213b0f596b

O41 - SISRAIDS - SiS RAID Miniport Driver - C:\WINDOWS\system32\drivers\SISRAIDS.SYS - (not running) - SiS RAID Miniport Driver - Silicon Integrated Systems Corp - 46cecd8f57e63bdb9d6c9f130be2d97c

O41 - sptrak - Promise SuperTrak Family Driver for WindowsNT - C:\WINDOWS\system32\drivers\Sptrak.sys - (not running) - Promise SuperTrak Family Driver for WindowsNT - Promise Technology, Inc. - b04bdc24f80ecb319f64189194399989

O41 - SYMMPI - LSI Logic Fusion-MPT MiniPort Driver (ScsiPort) - C:\WINDOWS\system32\drivers\symmpi.sys - (not running) - LSI Logic Fusion-MPT MiniPort Driver (ScsiPort) - LSI Logic - 3adffb39782474652f4ea2cf1345b340

O41 - ULSATAS - Promise SATAII150 Series Driver for Win2003 - C:\WINDOWS\system32\drivers\ulsatas.sys - (not running) - Promise SATAII150 Series Driver for Win2003 - Promise Technology, Inc. - 0c5583d3bb02e78e639eac234e97d515

O41 - viapdsk - VIA VT4149 PATA Driver - C:\WINDOWS\system32\drivers\viapdsk.sys - (not running) - VIA VT4149 PATA Driver - VIA Technologies, Inc. - f314359357b6960eb727620470ffc9cf

O41 - viaraid - VT6410 RAID DRIVER FOR WINXP - C:\WINDOWS\system32\drivers\viaraid.sys - (not running) - VT6410 RAID DRIVER FOR WINXP - VIA Technologies inc,.ltd - 29d02cee410d4ed80014bbf0fc98bd2d

O41 - viasraid - VIA SATA RAID DRIVER FOR WINXP - C:\WINDOWS\system32\drivers\viasraid.sys - (not running) - VIA SATA RAID DRIVER FOR WINXP - VIA Technologies inc,.ltd - ebe101c01d80a42868f57b327be1b564

O41 - vmscsi - VMware SCSI Controller - C:\WINDOWS\system32\drivers\vmscsi.sys - (not running) - VMware SCSI Controller - VMware, Inc. - cd8a1f04836111dc0e6c0cd904b3c660

=======================================

360Safe.exe=5.0.0.1011

AntiAdwa.dll=4.2.0.1002

AntiEng.dll=4.4.0.1001

AntiActi.dll=2.0.0.3000

CleanHis.dll=4.2.0.1002

live.dll=1.0.1.1029
aaccbbdd - 2009-7-24 20:20:00
sreng日志呢
dipahole - 2009-7-24 20:29:00
删除文件 C:\WINDOWS\system32\xms.exe

为了更好地解决你的问题,请上传SRENG日志.

下载SRENG2.6版工具:http://www.kztechs.com/sreng/download.html
yujiqi - 2009-7-24 21:03:00

附件: SREngLOG.log (2009-7-24 21:03:29, 59.27 K)
该附件被下载次数 178

yujiqi - 2009-7-24 21:15:00


引用:
原帖由 dipahole 于 2009-7-24 20:29:00 发表
删除文件 C:\WINDOWS\system32\xms.exe

为了更好地解决你的问题,请上传SRENG日志.

下载SRENG2.6版工具:http://www.kztechs.com/sreng/download.html

到c盘那里找不到xms.exe这个文件呀
merrk_chuan - 2009-7-24 22:06:00
c:\windows\System32\drivers\xbpublic.sys
将这个文件发到www.virscan.org 检测下看看

其中有些流氓软件的文件,就请用下面的windows清理助手清理下吧

关闭IE用下面的工具全选,清理系统临时文件和IE临时文件夹     
http://www.atribune.org/public-beta/ATF-Cleaner.exe

下载windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.rar(升级后使用)
working_man - 2009-7-25 0:35:00
使用360安全卫士高级选项中的IE修复更能,然后在查杀流氓软件,清理之后,用优化大师之类的软件清理垃圾文件和注册表,重启。
yujiqi - 2009-7-25 19:29:00
:kaka2: :kaka2:
圣壶儿 - 2009-7-28 23:18:00
1.注消或重启电脑,然后再试着删除。

2.进入“安全模式删除”。

3.在纯DOS命令行下使用DEL、DELTREE和RD命令将其删除。

4.如果是文件夹中有比较多的子目录或文件而导致无法删除,可先删除该文件夹中的子目录和文件,再删除文件夹。

5.如果是在“添加或删除程序”选项卸载一个软件后,发现软件的安装目录仍旧存在,里边残留着几个文件,直接删除时,系统却提示文件正在使用无法删除。

此时可首先打开“命令提示符”窗口,按“Ctrl+Alt+Del”组合键打开任务管理器,在进程中将“explorer.exe”进程关闭掉(在这之前最好将所有程序关闭掉,如图1),切换到命令提示符窗口,使用DOS命令进入无法删除的文件夹,输入“Del 文件夹名”就可以将该文件夹删除了。删除完成后,在任务管理器中选择“文件→新任务”,输入“explorer.exe”重新建立系统的外壳。
xyz002 - 2009-7-29 16:09:00
windows清理助手 专门针对这些流氓软件
1
查看完整版本: 广告程序软件无法删除