12   2  /  2  页   跳转

杀毒软件开不了了,帮忙看看.

<D:\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <D:\BitSpirit\bsurl.htm, N/A>

==================================
正在运行的进程
[PID: 768][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 840][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 864][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\WINDOWS\system32\Ati2evxx.dll]  <ATI Technologies Inc.><6.14.10.4113>
    [C:\WINDOWS\system32\klogon.dll]  <Kaspersky Lab><6.0.0.299>
[PID: 916][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 928][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\DOCUME~1\whlx\LOCALS~1\Temp\dt2uzqi5.dll]  <WinRAR archiver><3, 4, 2, 0>
[PID: 1104][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4113>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2496>
[PID: 1124][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 1200][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 1348][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\DOCUME~1\whlx\LOCALS~1\Temp\dt2uzqi5.dll]  <WinRAR archiver><3, 4, 2, 0>
[PID: 1408][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 1508][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 1880][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 2024][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4113>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2496>
[PID: 248][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\DOCUME~1\whlx\LOCALS~1\Temp\dt2uzqi5.dll]  <WinRAR archiver><3, 4, 2, 0>
    [d:\WinRAR\rarext.dll]  <N/A><N/A>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll]  <Kaspersky Lab><5.0.388.1>
[PID: 380][C:\WINDOWS\system32\msime.exe]  <Microsoft Corporation><5.1.2600.2180>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [C:\DOCUME~1\whlx\LOCALS~1\Temp\dt2uzqi5.dll]  <WinRAR archiver><3, 4, 2, 0>
[PID: 488][C:\WINDOWS\system32\internet.exe]  <N/A><N/A>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 504][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 684][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 796][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [c:\program files\gaov\mysee2\runtime.dll]  <北京高维视讯科技有限公司><1, 0, 0, 3>
    [C:\WINDOWS\system32\MycAce551vc71.dll]  <N/A><5.5.1>
[PID: 996][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
[PID: 2540][D:\Maxthon\Max.exe]  <Maxthon International Ltd.><1, 5, 3, 18>
    [D:\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>
    [D:\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]  <Kaspersky Lab><5.0.388.1>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.388.0>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]  <Kaspersky Lab><5.0.388.0>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]  <Kaspersky Lab><5.0.388.1>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]  <Kaspersky Lab><5.0.388.0>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]  <Kaspersky Lab><5.0.388.1>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]  <Kaspersky Lab><5.0.388.2>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]  <Kaspersky Lab><5.0.388.1>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]  <Kaspersky Lab><5.0.388.0>
    [d:\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]  <Kaspersky Lab><5.0.388.0>
    [d:\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]  <Kaspersky Lab><5.0.388.0>
    [d:\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]  <Kaspersky Lab><5.0.388.0>
    [d:\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]  <Kaspersky Lab><5.0.388.0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3756][D:\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\KB525181M.LOG]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

修复
O1 - Hosts: 219.153.18.212 www.2345sf.com
O20 - AppInit_DLLs: KB525181M.LOG
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
删除
C:\WINDOWS\system32\klogon.dll
C:\WINDOWS\KB525181M.LOG

O23 - NT 服务: Windows XP Vista - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索Windows XP Vista删除...
删除
C:\WINDOWS\Hacker.com.cn.ini
gototop
 

打开SRE 启动项目 注册表 删除
<CheckFaultKernel><C:\WINDOWS\system32\mswdm.exe> []
删除
C:\WINDOWS\system32\mswdm.exe
gototop
 

谢谢老兄
gototop
 

怎么开注册表啊??
gototop
 

开始-运行-regedit
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT