1   1  /  1  页   跳转

注册表UserInit被修改为非正常值

注册表UserInit被修改为非正常值

今天用seng2点击启动项,就会弹出对话框:
警告!注册表UserInit被修改为非正常值.
(对于windows2000默认值类似于:c:\winnt\system32\userinit.exe,对于windowsxp或更高版本,默认值类似于:c:\windows\system32\userinit.exe,)请检查系统中可能存在的病毒.
这个东西以前都没见过,是干什么用的,对电脑影响有好大哦,各位帮小弟看看
最后编辑2006-12-02 14:45:32
分享到:
gototop
 

日志
gototop
 

2006-12-01,11:40:58

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<KavPFW><"C:\KAV2007\KPFW32.EXE"> [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KavStart><"C:\KAV2007\KAVStart.exe" -startup> [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\Userinit.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><LogonUI.EXE> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<!ewido><; "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [N/A]
<AGRSMMSG><; AGRSMMSG.exe> [(Verified)Agere Systems]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Corporation]
<CursorXP><; > [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ExFilter><; Rundll32.exe C:\WINDOWS\system32\hookdll.dll,ExecFilter solo> [N/A]
<fscp><; C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe> [N/A]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<KavPFW><; "D:\KAV2007\KPFW32.EXE"> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<mhs><; > [N/A]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<QkOnBtn><; C:\Program Files\QBU\QkOnBtn.EXE> [Dritek System Inc.]
<r><; C:\WINDOWS\down\rundll32.exe> [N/A]
<RavAV><; > [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ravshell><; > [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RemoteControl><; > [N/A]
<rzt><; > [N/A]
<SiS Windows KeyHook><; C:\WINDOWS\system32\keyhook.exe> [Silicon Integrated Systems Corporation]
<SiSPower><; Rundll32.exe SiSPower.dll,ModeAgent> [Silicon Integrated Systems Corporation]
<SKYNET Personal FireWall><; C:\Program Files\SkyNet\FireWall\pfw.exe> [psgl破解]
<SoundMan><; SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
<spoolsv><; > [N/A]
<StormCodec_Helper><; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<stup.exe><; C:\PROGRA~1\TENCENT\Adplus\stup.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<STYLEXP><; > [N/A]
<Super Rabbit IEPro><; C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
<swg><; C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<System Manager><; > [N/A]
<thunder_mini><; D:\Program Files\Maxthon\Thundermini\ThunderMini.exe> [深圳市三代科技开发有限公司]
<Torjan Program><; C:\WINDOWS\WINLOGON.EXE> [N/A]
<wcmdmgr><; C:\WINDOWS\wt\wcmdmgrl.exe -launch> [WildTangent, Inc.]
<wdfmgr32.exe><; C:\WINDOWS\system32\wdfmgr32.exe> [N/A]
<wdfmgr32x.exe><; C:\WINDOWS\system32\wdfmgr32x.exe> [N/A]
<WebThunder><; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<wl><; > [N/A]
<xy><; > [N/A]
<YLive.exe><; > [N/A]
gototop
 

启动文件夹
N/A

==================================
服务
[Application Management / AppMgmt]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[FspadSvc / FspadSvc]
<C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe><N/A>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc]
<><N/A>
[Kingsoft Personal Firewall Service / KPfwSvc]
<"C:\KAV2007\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc]
<C:\KAV2007\KWatch.EXE><Kingsoft Corporation>
[Provisioning Transaction Service / ttt_14]
<C:\WINDOWS\system32\winrar.exe><N/A>
[Windows DHCP Service / WinDHCPsvc]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[Windows Updata / Windows Updata]
<C:\WINDOWS\system32\TCPlus.exe><1.1.1>

==================================
驱动程序
[Agere Systems Soft Modem / AgereSoftModem]
<system32\DRIVERS\AGRSM.sys><Agere Systems>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Dritek HotKey Keyboard Filter Driver / DKbFltr]
<System32\Drivers\DKbFltr.sys><Dritek System Inc.>
[FileDisk / FileDisk]
<C:\WINDOWS\SYSTEM32\DRIVERS\FileDisk.SYS><Bo Brantén>
[AVC Finger-sensing Pad Driver for Windows 2000/XP / fspad]
<system32\DRIVERS\fspad.sys><Asia Vital Components Co.,Ltd.>
[hotcore2 / hotcore2]
<\SystemRoot\system32\drivers\hotcore2.sys><Paragon Software Group>
[HpaFilt / HpaFilt]
<C:\WINDOWS\SYSTEM32\DRIVERS\HpaFilt.SYS><Lenovo Software inc.>
[kl1 / kl1]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[Klmc / Klmc]
<System32\drivers\klmc.sys><Kaspersky Lab>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[KNetWch / KNetWch]
<\??\C:\KAV2007\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3]
<\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[Netgroup Packet Filter / NPF]
<system32\drivers\npf.sys><N/A>
[npkcrypt / npkcrypt]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[SiS300i / SiS300i]
<system32\DRIVERS\sis300ip.sys><Silicon Integrated Systems Corporation>
[SiS315 / SiS315]
<system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiSkp / SiSkp]
<system32\DRIVERS\srvkp.sys><Silicon Integrated Systems Corporation>
[SiS PCI Fast Ethernet Adapter Driver / SISNIC]
<system32\DRIVERS\sisnic.sys><SiS Corporation>
[SiS PCI Fast Ethernet Adapter Driver for NDIS51 / SISNICXP]
<system32\DRIVERS\sisnicxp.sys><SiS Corporation>
[SKNFW / SKNFW]
<\??\C:\WINDOWS\system32\Drivers\SKNFW.sys><N/A>
[SkyProcs / SkyProcs]
<\??\C:\Program Files\SkyNet\FireWall\SkyProcs.sys><N/A>

==================================
浏览器加载项
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <D:\TDdownload\BitComet_0.77\tools\BitCometBHO.dll, BitComet>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, N/A>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <, N/A>
[联想]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
{DE607141-AC19-421e-860A-0D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_015.dll, Thunder Networking Technologies,LTD>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\Program Files\DeskAdTop\deskipn.dll, N/A>
[ui Class]
{16DCA182-CFB2-4A4D-9E6A-6292559688CE} <C:\WINDOWS\system32\SPORD0R.dll, >
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\MSHTML.DLL, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <D:\TDdownload\BitComet_0.77\tools\BitCometBHO.dll, BitComet>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[MainBHO Class]
{DE63E1D9-B5DB-4E7E-8902-5F4F3E3EC532} <C:\WINDOWS\system32\shdoclc2.dll, N/A>
[&使用BitComet下载]
<res://D:\TDdownload\BitComet_0.77\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
<res://D:\TDdownload\BitComet_0.77\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
<res://D:\TDdownload\BitComet_0.77\BitComet.exe/AddVideo.htm, N/A>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[金山毒霸反钓鱼...]
<C:\KAV2007\KAF\ShowSet.htm, N/A>
gototop
 

【回复“邀月无缺”的帖子】
先给楼主一个提示:
若楼主的动手操作能力比较差的话
本人建议楼主重装系统
gototop
 

正在运行的进程
[PID: 508][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 588][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 632][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 792][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 868][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1056][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1092][C:\KAV2007\KWatch.EXE] [Kingsoft Corporation, 2005, 9, 27, 51]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2006, 10, 26, 69]
[PID: 1332][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[PID: 1424][C:\KAV2007\KAVStart.exe] [Kingsoft Corporation, 2006, 9, 7, 210]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2007\SvcTimer.DLL] [Kingsoft Corporation, 2006.7.24.80]
[C:\KAV2007\PopSprt3.dll] [Kingsoft Corporation, 2006, 9, 26, 38]
[C:\KAV2007\KAVPassp.dll] [Kingsoft Corporation, 2006, 9, 7, 270]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1436][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1444][C:\KAV2007\KPFW32.EXE] [Kingsoft Corporation, 2006, 11, 15, 659]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2006, 10, 30, 39]
[C:\KAV2007\FiltList.dll] [N/A, N/A]
[C:\KAV2007\KAVPassp.DLL] [Kingsoft Corporation, 2006, 9, 7, 270]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1500][C:\KAV2007\KMailMon.EXE] [Kingsoft Corporation, 2006, 9, 7, 918]
[C:\KAV2007\KAntiSpm.dll] [Kingsoft Corporation, 2006, 8, 19, 104]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2007\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2006, 10, 26, 69]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2006, 10, 30, 39]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[PID: 1560][C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe] [N/A, N/A]
[PID: 1588][C:\KAV2007\KPfwSvc.EXE] [Kingsoft Corporation, 2005, 9, 5, 28]
[PID: 1644][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 608][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1084][C:\Program Files\ChinaNetSn\bin\Dialterminal.exe] [陕西电信有限公司, 0, 0, 1, 8]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\ChinaNetSn\bin\detector.dll] [西安信利软件系统有限公司, 1, 0, 0, 3]
[C:\WINDOWS\system32\wpcap.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\system32\packet.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\system32\WanPacket.dll] [CACE Technologies, 3, 1, 0, 27]
[PID: 1384][D:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 2, 21]
[D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2006, 11, 13, 70]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2006, 10, 26, 69]
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5091]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 392][D:\Program Files\TotalCmd\TOTALCMD.EXE] [C. Ghisler & Co., 6.53]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1796][D:\TDdownload\BitComet_0.77\BitComet.exe] [www.BitComet.com, 0.77]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\TDdownload\BitComet_0.77\tools\luacurl.dll] [N/A, N/A]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2006, 11, 13, 70]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2006, 10, 26, 69]
[PID: 124][D:\Program Files\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 9, 7, 132]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]

==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 localhost


<Torjan Program><; C:\WINDOWS\WINLOGON.EXE> [N/A]
<wdfmgr32.exe><; C:\WINDOWS\system32\wdfmgr32.exe> [N/A]
<r><; C:\WINDOWS\down\rundll32.exe> [N/A]
<wdfmgr32x.exe><; C:\WINDOWS\system32\wdfmgr32x.exe> [N/A]
删除
在用seng2把文件关联出错给修复一下!


Torjan Program><; C:\WINDOWS\WINLOGON.EXE> [N/A
wdfmgr32.exe><; C:\WINDOWS\system32\wdfmgr32.exe>
wdfmgr32x.exe><; C:\WINDOWS\system32\wdfmgr32x.exe
大哥,windows下我找不到这个文件啊

这个是我先前发的日志,也把注册表上面的这些删除了
但是这几个文件找不到,没有隐藏
gototop
 

引用:
【不言放弃的贴子】【回复“邀月无缺”的帖子】
先给楼主一个提示:
若楼主的动手操作能力比较差的话
本人建议楼主重装系统
………………

gototop
 

我不怕手动啊
没办法啊,我用的是本本,光驱坏了,一键还原也坏了,想装都没办法了,又没又DOS启动盘,没法啊
问题很多吗??
gototop
 

运行(双击)System Repair Engineer,使用“启动项目,注册表”选中要修复的项C:\WINDOWS\system32\userinit.exe点“编辑”在“值”里改为C:\WINDOWS\system32\userinit.exe,

我加了一个逗号了
然后就没有那个显示了
在注册表里消失了←我指的是SREng里面没有了

没有是正常的吧?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT