C盘能双击打开,而DEF盘都只能用右键打开,有AUTO选项.
我想问下,那些病毒会造成这种状况(朋友的机子,我看了看日志没明显异常,汗)
还有如果在系统还原的时候出现错误,会不会造成这种状况.
附日志
Logfile of HijackThis v1.99.1
Scan saved at 20:13:54, on 2006-11-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\工具\卡巴斯基\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\工具\卡巴斯基\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\802.1X认证客户端\Dot1XClient.exe
D:\网络游戏\Tencent\QQ\QQ.exe
D:\网络游戏\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\system32\conime.exe
F:\Downloads\AntiArpSniffer.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\网络游戏\征途\data\zhengtu.dat
F:\Downloads\HijackThis.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [kis] "D:\工具\卡巴斯基\avp.exe"
O4 - HKLM\..\Run: [AntiArpSniffer] F:\Downloads\AntiArpSniffer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 添加到QQ表情 - D:\网络游戏\Tencent\QQ\AddEmotion.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\工具\浩方对战平台\GameClient.exe
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\工具\卡巴斯基\scieplugin.dll
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://tomatolei.com (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C2990A2-EE1F-43B0-962F-5F2F71425D22}: NameServer = 202.115.176.200
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: 卡巴斯基互联网安全套装 6.0 (AVP) - Kaspersky Lab - D:\工具\卡巴斯基\avp.exe
O23 - Service: GhostStartService - Symantec Corporation - D:\NORTON~1\GHOSTS~2.EXE