瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 无法打开任务管理器,注册表等,请帮忙

12   1  /  2  页   跳转

无法打开任务管理器,注册表等,请帮忙

无法打开任务管理器,注册表等,请帮忙

今天瑞星提示sys.exe要修改注册表,禁止后反应慢,重启后,运行中输入cmd regedit 等界面一闪就没了,任务管理器也无法打开
系统是2003,谢谢大家了
最后编辑2006-04-10 17:23:30
分享到:
gototop
 

【回复“来瞅瞅吧”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载HIJACKTHIS
导出全部日志
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      14:29:07, 日期 2006-4-10
操作系统:  Windows 2003 SP1 (WinNT 5.02.3790)
浏览器:    Internet Explorer v6.00 SP1 (6.00.3790.1830)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\Common Files\System\nhcv32.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\Program Files\Common Files\System\service.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\DlrSendMessage.exe
C:\WINDOWS\system32\DlrReceiveMessage.exe
C:\Program Files\联友科技\E3S-DMS\SendMessage.exe
C:\WINDOWS\system32\ReceiveMessage.exe
C:\WINDOWS\system32\waumguard.exe
C:\WINDOWS\system32\sys.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\深圳联友科技\zyd_ReceiveMessage\eabReceiveMessage.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\Internet Explorer\iexplore.exe
e:\PROGRA~1\wnwb2005\wnwb.exe
C:\Documents and Settings\Administrator\桌面\2535952005811174944\HijackThis1991zww.exe

R3 - URLSearchHook: bho Class - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: update wnwb - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KDTAnywhere] "C:\Program Files\KDT2004\KDTAnywhereS.exe" -servicehelper
O4 - 启动项HKLM\\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - 启动项HKLM\\Run: [DlrSendMessage.exe] C:\WINDOWS\system32\DlrSendMessage.exe
O4 - 启动项HKLM\\Run: [DlrReceiveMessage.exe] C:\WINDOWS\system32\DlrReceiveMessage.exe
O4 - 启动项HKLM\\Run: [SendMessage.exe] C:\Program Files\联友科技\E3S-DMS\SendMessage.exe
O4 - 启动项HKLM\\Run: [ReceiveMessage.exe] C:\WINDOWS\system32\ReceiveMessage.exe
O4 - 启动项HKLM\\Run: [Windows modez Verifier] waumguard.exe
O4 - 启动项HKLM\\RunServices: [Windows modez Verifier] waumguard.exe
O4 - Global Startup: 东风日产二手车数据交互.lnk = ?
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E3A2E45-7009-47C3-9BDD-B2A4A76A2964}: NameServer = 211.97.168.129
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - NT 服务: Distributed Link Tracking Servers (AppToService_Distributed Link Tracking Servers) - Basta Computing  - C:\Program Files\Common Files\System\nhcv32.exe
O23 - NT 服务: KDTAnywhere Server (kdtanywhere) - Unknown owner - C:\Program Files\KDT2004\KDTAnywhereS.exe" -service (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

gototop
 

重启后,C盘根目录下出现一个叫a.bat 的文件,删除重启后又出现
谢谢了!
gototop
 

【回复“来瞅瞅吧”的帖子】
结束如下进程
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\Common Files\System\nhcv32.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\Program Files\Common Files\System\service.exe
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\WINDOWS\system32\DlrSendMessage.exe
C:\WINDOWS\system32\DlrReceiveMessage.exe
C:\WINDOWS\system32\ReceiveMessage.exe
C:\WINDOWS\system32\waumguard.exe
C:\WINDOWS\system32\sys.exe

修复
O4 - 启动项HKLM\\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - 启动项HKLM\\Run: [DlrSendMessage.exe] C:\WINDOWS\system32\DlrSendMessage.exe
O4 - 启动项HKLM\\Run: [DlrReceiveMessage.exe] C:\WINDOWS\system32\DlrReceiveMessage.exe
O4 - 启动项HKLM\\Run: [ReceiveMessage.exe] C:\WINDOWS\system32\ReceiveMessage.exe
O4 - 启动项HKLM\\Run: [Windows modez Verifier] waumguard.exe
O4 - 启动项HKLM\\RunServices: [Windows modez Verifier] waumguard.exe

删除
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\Common Files\System\nhcv32.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\Program Files\Common Files\System\service.exe
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\WINDOWS\system32\DlrSendMessage.exe
C:\WINDOWS\system32\DlrReceiveMessage.exe
C:\WINDOWS\system32\ReceiveMessage.exe
C:\WINDOWS\system32\waumguard.exe
C:\WINDOWS\system32\sys.exe
C:\WINDOWS\system32\serverappliance\
mqrt.dll(在硬盘中搜索)
gototop
 

谢谢不言放弃先生,我等下班进安全模式杀一下,不行的放再找你咨询一下,非常感谢!我QQ:6071570 希望您能加一下,谢谢了
gototop
 

【回复“来瞅瞅吧”的帖子】
不客气

用记事本编辑以下内容:
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system]

"DisableRegistryTools"=dword:00000000

将以上内容存成一个扩展名为reg的文件,双击这个文件,导入注册表!
然后再试试能否打开注册表?

==============

若能打开注册表了
进入注册表
展开:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system下的DisableTaskMgr,将键值改为0

看看能否打开任务管理器?
gototop
 

我晕,还是闪一下就没了
gototop
 

引用:
【来瞅瞅吧的贴子】我晕,还是闪一下就没了

...........................

导入后也不行吗?
gototop
 

运行输入:cmd regedit等,还是一闪就没,本机是服务器,现在不能重启,不能进安全模式弄一下
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT