1   1  /  1  页   跳转

今天发生了一件奇怪的事情

今天发生了一件奇怪的事情

IE原来一切正常,norton也正常工作,但windows升级被劫持了,使用windows update出现乱码,根本无法登陆。norton可以升级,但不能扫描,显示扫描失败。
有没有其他人也出现这样的情况?请大侠指导
最后编辑2007-06-05 15:36:55
分享到:
gototop
 

其他的好像正常,可以在baidu搜索带病毒字样的东西
gototop
 

下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝分段贴上来,不要修改
gototop
 

[CODE]

2007-06-05,13:46:52

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><ctfmon.exe>  []
    <swg><C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Windows 2000 Publisher]
    <OrderReminder><C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe>  []
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  []
    <Userinit><C:\WINNT\system32\userinit.exe,>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINNT\system32\ssbezier.scr>  [(Verified)Microsoft Windows 2000 Publisher]
gototop
 

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [N/A]><N>
[VPTray]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\VPTray.exe -->  [N/A]><N>

==================================
服务
[Alerter / Alerter][Stopped/Manual Start]
  <C:\WINNT\system32\services.exe><N/A>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINNT\system32\services.exe><N/A>
[Background Intelligent Transfer Service / BITS][Stopped/Manual Start]
  <C:\WINNT\system32\svchost.exe -k BITSgroup-->%SystemRoot%\System32\qmgr.dll><>
[Computer Browser / Browser][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Bluetooth Service / btwdins][Running/Auto Start]
  <C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe><N/A>
[DefWatch / DefWatch][Running/Auto Start]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><N/A>
[DHCP Client / Dhcp][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Logical Disk Manager / dmserver][Running/Auto Start]
  <C:\WINNT\System32\services.exe><N/A>
[DNS Client / Dnscache][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Event Log / Eventlog][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[COM+ Event System / EventSystem][Running/Manual Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->C:\WINNT\system32\es.dll><>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Infrared Monitor / Irmon][Running/Auto Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\irmon.dll><>
[Server / lanmanserver][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Workstation / lanmanworkstation][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[TCP/IP NetBIOS Helper Service / LmHosts][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"><N/A>
[Messenger / Messenger][Stopped/Disabled]
  <C:\WINNT\system32\services.exe><N/A>
[Net Logon / Netlogon][Stopped/Manual Start]
  <C:\WINNT\system32\lsass.exe><N/A>
[Network Connections / Netman][Running/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\netman.dll><>
[NMSAccess / NMSAccess][Running/Auto Start]
  <d:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe><N/A>
[Symantec AntiVirus Client / Norton AntiVirus Server][Running/Auto Start]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><N/A>
[NT LM Security Support Provider / NtLmSsp][Stopped/Manual Start]
  <C:\WINNT\system32\lsass.exe><N/A>
[Removable Storage / NtmsSvc][Running/Auto Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\NtmsSvc.dll><>
[Plug and Play / PlugPlay][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[IPSEC Policy Agent / PolicyAgent][Running/Auto Start]
  <C:\WINNT\system32\lsass.exe><N/A>
[PPPoE Service / PPPoEService][Running/Auto Start]
  <C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe><N/A>
[Protected Storage / ProtectedStorage][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><>
[Remote Access Connection Manager / RasMan][Running/Manual Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasmans.dll><>
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><>
[Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
  <C:\WINNT\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><>
[Security Accounts Manager / SamSs][Running/Auto Start]
  <C:\WINNT\system32\lsass.exe><N/A>
[Task Scheduler / Schedule][Running/Auto Start]
  <C:\WINNT\system32\MSTask.exe><N/A>
[Spyware Doctor Auxiliary Service / sdAuxService][Stopped/]
  <2 - 系统找不到指定的文件。
><N/A>
[RunAs Service / seclogon][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[System Event Notification / SENS][Running/Auto Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><>
[Internet Connection Sharing / SharedAccess][Stopped/Manual Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\ipnathlp.dll><>
[Print Spooler / Spooler][Running/Auto Start]
  <C:\WINNT\system32\spoolsv.exe><N/A>
[Telephony / TapiSrv][Running/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\tapisrv.dll><>
[Distributed Link Tracking Client / TrkWks][Running/Auto Start]
  <C:\WINNT\system32\services.exe><N/A>
[Windows Time / W32Time][Stopped/Manual Start]
  <C:\WINNT\System32\services.exe><N/A>
[Windows Management Instrumentation / WinMgmt][Running/Auto Start]
  <C:\WINNT\System32\WBEM\WinMgmt.exe><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><>
[Windows Management Instrumentation Driver Extensions / Wmi][Running/Manual Start]
  <C:\WINNT\system32\Services.exe><N/A>
[Automatic Updates / wuauserv][Running/Auto Start]
  <C:\WINNT\system32\svchost.exe -k wugroup-->C:\WINNT\system32\wuauserv.dll><>
[Wireless Configuration / WZCSVC][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wzcsvc.dll><>
gototop
 

==================================
驱动程序
[altio / altio][Running/Auto Start]
  <\??\C:\WINNT\system32\altio.sys><Altium Limited>
[Bluetooth Audio Device / btaudio][Running/Manual Start]
  <system32\drivers\btaudio.sys><WIDCOMM, Inc.>
[Bluetooth Protocol Stack / BTKRNL][Running/Boot Start]
  <\SystemRoot\system32\drivers\btkrnl.sys><WIDCOMM, Inc.>
[Bluetooth Serial Driver / BTSERIAL][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\btserial.sys><WIDCOMM, Inc.>
[Bluetooth Port Client Driver / BTSLBCSP][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\btslbcsp.sys><WIDCOMM, Inc.>
[Conexant AMC 2 Channel Audio / CAMCAUD][Running/Manual Start]
  <system32\drivers\camc6aud.sys><Conexant Systems Inc.>
[CAMCHALA / CAMCHALA][Running/Manual Start]
  <system32\drivers\camc6hal.sys><Conexant Systems Inc.>
[Cisco Systems VPN Adapter / CVirtA][Stopped/Manual Start]
  <system32\DRIVERS\CVirtA.sys><Cisco Systems, Inc.>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Deterministic Network Enhancer Miniport / DNE][Running/Manual Start]
  <system32\DRIVERS\dne2000.sys><Deterministic Networks, Inc.>
[ENIMSR / ENIMSR][Stopped/Manual Start]
  <\??\C:\PROGRA~1\EFFICI~1\ENTERN~1\app\ENIMSR.SYS><Microsoft Corporation>
[HSFHWICH / HSFHWICH][Running/Manual Start]
  <system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Running/Manual Start]
  <system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[File Filter Driver / IKFileFlt][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[File Security Driver / IKFileSec][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[System Filter Driver / IkSysFlt][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[System Security Driver / IKSysSec][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[JUYANG USB Driver (JYusb.sys) / JYUSB][Stopped/Auto Start]
  <System32\Drivers\jyusb.sys><cypress semiconductor>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVAP / NAVAP][Running/Manual Start]
  <\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><Symantec Corporation>
[NAVAPEL / NAVAPEL][Running/Auto Start]
  <\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><Symantec Corporation>
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070604.017\NAVENG.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070604.017\NAVEX15.sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[Efficient Networks Enternet P.P.P.o.E LAN  Miniport Driver / NTSPPPOE][Running/Manual Start]
  <system32\DRIVERS\ntspppoe.sys><Microsoft Corporation>
[NTSTAP1 / NTSTAP1][Stopped/Manual Start]
  <\??\C:\PROGRA~1\EFFICI~1\ENTERN~1\app\NTSTAP1.SYS><Network TeleSystems, Inc.>
[NTSTAP2 / NTSTAP2][Stopped/Manual Start]
  <\??\C:\PROGRA~1\EFFICI~1\ENTERN~1\app\NTSTAP2.SYS><Network TeleSystems, Inc.>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
  <\SystemRoot\System32\drivers\prodrv06.sys><StarForce Technologies, Inc.>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\prohlp02.sys><StarForce Technologies, Inc.>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
  <\SystemRoot\System32\drivers\prosync1.sys><StarForce Technologies, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RAWESR / RAWESR][Stopped/Manual Start]
  <\??\C:\PROGRA~1\EFFICI~1\ENTERN~1\app\RAWESR.SYS><Microsoft Corporation>
[WAN Miniport (PPP over Ethernet Protocol) / RMSPPPOE][Running/Manual Start]
  <system32\DRIVERS\RMSPPPOE.SYS><Robert Schlabbach>
[Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start]
  <system32\DRIVERS\Rtlnic.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SMSC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  <system32\DRIVERS\smcirda.sys><SMSC>
[Sony Memory Stick Driver(SONYPVM1) / SONYPVM1][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\SONYPVM1.SYS><Sony Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TAPBIND / TAPBIND][Stopped/Manual Start]
  <\??\C:\PROGRA~1\EFFICI~1\ENTERN~1\app\TAPBIND1.SYS><Network TeleSystems, Inc.>
[tifm21 / tifm21][Running/Manual Start]
  <system32\drivers\tifm21.sys><Texas Instruments>
[vsdatant / vsdatant][Stopped/Manual Start]
  <\??\C:\WINNT\system32\vsdatant.sys><Zone Labs LLC>
[用于 Windows 2000 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n50][Running/Manual Start]
  <system32\DRIVERS\w29n50.sys><Intel? Corporation>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Xeltek USB Driver (Xeltekusb.sys) / XELTEK][Stopped/Auto Start]
  <System32\Drivers\Xeusb.sys><anchor chips>
[ZSMC USB PC Camera / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar3.dll, Google Inc.>
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
[MSN 搜索工具栏 Helper]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\zh-cn\msntb.dll, Microsoft Corporation>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <d:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <d:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <d:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[MSN 搜索工具栏]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\zh-cn\msntb.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar3.dll, Google Inc.>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[DopStreamer Class]
  {65DEDD9B-24D3-4EDD-A8BA-371A06679A09} <C:\WINNT\DopCom.dll, 北京闪动科技有限公司>
[Tencent Safety Online Base Module]
  {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINNT\DOWNLO~1\TSOBase.ocx, Tencent Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Send To &Bluetooth]
  <C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\Program Files\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[导出当前页到超星阅览器(&A)]
  <D:\Program Files\studa.com\ss_all.htm, N/A>
[导出选中部分到超星阅览器(&S)]
  <D:\Program Files\studa.com\ss_select.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
N/A

==================================
文件关联
.TXT  Error. [C:\WINNT\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINNT\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7170000B)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

吃不消了

格盘重装系统去吧。

别耽误时间了。

再新系统装好后,必须先升级杀软至最新版本全盘杀毒,切记不能使用原机任何文件。
gototop
 

把诺顿重装一下应该就可以升级病毒和扫描了~~系统就不知道了~
gototop
 

这都是些什么服务哦?.....
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT