瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 ->>瑞星/HijackThis/SREng无法启动,请工作人员来看一下<<-

1   1  /  1  页   跳转

->>瑞星/HijackThis/SREng无法启动,请工作人员来看一下<<-

->>瑞星/HijackThis/SREng无法启动,请工作人员来看一下<<-

如题,我是2006版用户

早上在浏览一个游戏攻略网站后,发现进程和启动项多出一堆乱七八糟的东西

瑞星和木马克星被强行关闭

此后再也无法打开,双击Rav.exe无反映

我把我能看到的和能想到的可疑进程和文件都处理了一下

包括自启动的和除正常进程以外的等等

然后用Ewido杀了一下,杀掉了几个,但仍然无法启动瑞星

瑞星个人防火墙和瑞星监控中心都能正常启动,就是杀毒主程序启动不了

用橙色八月专杀安全模式查杀了几个疑似病毒后仍然无法启动瑞星主程序

木马克星无法启动,HijackThis无法启动,SREng无法启动(改扩展名后能)

Ewido可以正常启动使用

完全删除瑞星后下载最新安装文件,可以正常安装

但是装完仍然无法启动瑞星杀毒软件主程序

现在我有瑞星和没瑞星完全没区别,形同虚设

请问除了重新作系统有没有什么解决的办法

比较着急,搞了快20个小时了仍然无果
粗略的看一下就有这么多问题:

C:\Documents and Settings\All Users\「开始」菜单\程序\启动\1DCD34.exe
C:\Documents and Settings\用户\「开始」菜单\程序\启动\1DCD34.exe
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
这两个珊完就自动生成
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
O4 - HKLM\..\Run: [Desktop] ; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
F3 - REG:win.ini: load=; 鹸?粒?粒粒?
????粓? [这个是乱码]

需要我提供什么相关信息麻烦跟帖告知下

谢谢,我会一直顶帖,直到有答案为止

SRE报告我帖在4楼和5楼

HijackThis报告在6楼

最后编辑2006-10-31 14:22:55
分享到:
gototop
 

http://mopery.hits.io/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改

如果SREng.exe 无法运行 改成 SREng.com 运行..
gototop
 

首先要检查的是 服务  在开始下 输入 services.msc  进入服务 找到

附件附件:

下载次数:166
文件类型:application/octet-stream
文件大小:
上传时间:2006-10-31 3:35:19
描述:



gototop
 

查看是否开启后

在开始下输入 regedit 进入注册表  在分别找到

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RsCCenter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RsRavMon


这两项里面 分别的 start 查看 是否为 "Start"=dword:00000002
gototop
 

0-31,03:38:32

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll>  [N/A]
    <{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll>  [N/A]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <themeadp><C:\WINDOWS\system32\themeadp.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <!ewido><; "d:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized>  [Anti-Malware Development a.s.]
    <Desktop><; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>  [N/A]
    <iparmor><; >  [N/A]
    <IpWins><; >  [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    <Load><; 鹸?粒?粒粒?
????粓?>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MoveSearch><; >  [N/A]
    <msmsgs><; >  [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <pucivce><; >  [N/A]
    <RavTask><; "D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RavUpes><; >  [N/A]
    <RfwMain><; "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [N/A]
    <rzt><; >  [N/A]
    <Secure><; Rem d:\Program Files\Secure\Start.exe>  [N/A]
    <StormCodec_Helper><; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <Torjan Program><; >  [N/A]
    <winla><; >  [N/A]
    <xy><; >  [N/A]
    <YLive.exe><; >  [N/A]

==================================
启动文件夹
[1DCD34]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\1DCD34.exe -->  [N/A]><N>
[1DCD34]
  <C:\Documents and Settings\lostseven\「开始」菜单\程序\启动\1DCD34.exe -->  [N/A]><N>

==================================
服务
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
  <d:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[host Service For Windows / mshosts]
  <><N/A>
[Local Connection Manager / SPSCAR]
  <C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL,Export 1087><N/A>

==================================
驱动程序
[ESS Allegro Audio Driver (WDM) / allegro]
  <system32\drivers\es198x.sys><ESS Technology, Inc.>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
  <\??\d:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[ExpScaner / ExpScaner]
  <\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[D-Link DFE-530TX PCI Fast Ethernet Adapter Driver / FETNDIS]
  <system32\DRIVERS\dlkfet5b.sys><D-Link>
[HookCont / HookCont]
  <\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[mapmem / mapmem]
  <\??\C:\WINDOWS\system32\Drivers\mapmem.sys><EPoX Inc.>
[MEMSCAN / MEMSCAN]
  <\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[paraudio / paraudio]
  <\??\C:\WINDOWS\system32\drivers\paraudio.sys><Microsoft Corporation>
[portio / portio]
  <\??\C:\WINDOWS\system32\Drivers\portio.sys><Epox Inc.>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[SkyProcs / SkyProcs]
  <\??\D:\PROGRA~1\SKYNET\FIREWALL\SkyProcs.sys><N/A>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>

==================================
gototop
 

浏览器加载项
[酷热影音]
  {7D73FF86-05F1-39ed-C850-A423120EC338} <www.kuree.com/index.htm?id=00011001, N/A>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[IEMonitor Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <, N/A>
[]
  {69D23154-CA31-43E9-BEEB-F78E6D1642B3} <C:\WINDOWS\system32\3721.6.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 528][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 668][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 896][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 992][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1048][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1624][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [d:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [d:\Program Files\ewido anti-spyware 4.0\context.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [C:\Program Files\Common Files\SYSTEM\E11DD34C.dll]  [N/A, N/A]
[PID: 1776][d:\Program Files\ewido anti-spyware 4.0\guard.exe]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [d:\Program Files\ewido anti-spyware 4.0\engine.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 2032][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 340][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 716][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\SYSTEM\E11DD34C.dll]  [N/A, N/A]
[PID: 1560][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\SYSTEM\E11DD34C.dll]  [N/A, N/A]
[PID: 844][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll]  [N/A, N/A]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\Program Files\Common Files\SYSTEM\E11DD34C.dll]  [N/A, N/A]
    [C:\Documents and Settings\lostseven\桌面\sreng2\SREng\SREng.com]  [Smallfrogs Studio, 2.2.6.605]
    [C:\Program Files\Common Files\SYSTEM\E11DD34C.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [hh.exe %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [notepad.exe %1]
.INF  Error. [notepad.exe %1]
.VBS  Error. [wscript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 3:45:11, on 2006-10-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
d:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\lostseven\桌面\hijackthis\HijackThis.com

F3 - REG:win.ini: load=; 鹸?粒?粒粒?
????粓?
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [!ewido] ; "d:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Desktop] ; C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [iparmor] ;
O4 - HKLM\..\Run: [IpWins] ;
O4 - HKLM\..\Run: [MoveSearch] ;
O4 - HKLM\..\Run: [msmsgs] ;
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pucivce] ;
O4 - HKLM\..\Run: [RavTask] ; "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavUpes] ;
O4 - HKLM\..\Run: [RfwMain] ; "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [rzt] ;
O4 - HKLM\..\Run: [Secure] ; Rem d:\Program Files\Secure\Start.exe
O4 - HKLM\..\Run: [StormCodec_Helper] ; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Torjan Program] ;
O4 - HKLM\..\Run: [winla] ;
O4 - HKLM\..\Run: [xy] ;
O4 - HKLM\..\Run: [YLive.exe] ;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 酷热影音 - {7D73FF86-05F1-39ed-C850-A423120EC338} - www.kuree.com/index.htm?id=00011001 (file missing)
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C393965F-80DB-4EB2-ACB7-34BBE85D52C9}: NameServer = 202.97.224.69 202.97.224.68
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: themeadp - {64274C93-3CE7-4663-9C8D-CD2DC8A3590B} - C:\WINDOWS\system32\themeadp.dll (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - d:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Local Connection Manager (SPSCAR) - Unknown owner - C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE (file missing)

gototop
 

修复
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe

用sreng
删除启动项目=>注册表
<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
<themeadp><C:\WINDOWS\system32\themeadp.dll> [N/A]
<MoveSearch><; > [N/A]
<msmsgs><; > [N/A]
<RavUpes><; > [N/A]
<pucivce><; > [N/A]
<rzt><; > [N/A]
<Torjan Program><; > [N/A]
<winla><; > [N/A]
<xy><; > [N/A]
<YLive.exe><; > [N/A]
删除
C:\Program Files\Common Files\SYSTEM\E11DD34C.dll(安全模式下)
C:\WINDOWS\system32\themeadp.dll

<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
参考顶置帖..
http://forum.ikaka.com/topic.asp?board=28&artid=8201339

<Load> 编辑改为 空值

用sreng
删除启动项目=>服务
[host Service For Windows / mshosts]
<><N/A>
[Local Connection Manager / SPSCAR]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL,Export 1087><N/A>
删除文件
C:\WINDOWS\SYSTEM32\WBEM\QOWGSB04.DLL
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE

<Secure><; Rem d:\Program Files\Secure\Start.exe> [N/A]
自己确认一下是否是正常文件..

重装下瑞星 安全模式下查杀..
gototop
 

多谢斑竹了
但是
O4 - Startup: 1DCD34.exe
O4 - Global Startup: 1DCD34.exe
这两个修复完了还能查出来

另外<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
这两个珊不掉,其他的都能删掉,就这两个珊完又回来

你说让参考置顶帖,我看了几遍不是很懂
麻烦在说明下好么十分3Q...

另外这个C:\Program Files\Common Files\SYSTEM\E11DD34C.dll
在安全模式下也无法删除

gototop
 

麻烦斑竹还在么

<{E11EEDC3-DC3D-3DDC-411E-D4D41EDC3D1E}><C:\Program Files\Common Files\SYSTEM\E11DD34C.dll> [N/A]
<{11ED3D41-3D41-1EDC-411E-D41EDD411EDC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\3D411EDC.dll> [N/A]
这两个珊不掉,其他的都能删掉,就这两个珊完又回来

安全模式也珊不掉

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT