123   2  /  3  页   跳转

帮帮忙!!开机后自动运行。

查的时候,弹出了一个对话框:Unable to find the window's owning process in the current process list。 确定
gototop
 

启动项目: desktop.ini
命令:C:\Documents and Settings\all users\[开始]菜单\程序\启动\desktop.ini (但我按照路径去寻找,启动项里为空)
位置:Common Starup

另外我下了个卡巴斯基,扫描了一下扫到了一个称为“存在危险的程序”c:\windows\desktop.html删除后,重启了还是不行,但在这个文件夹中,我看到了一个desktop带齿轮的记事本文件,里面内容为空,还有一个control的齿轮记事本文件,同样记录为空,光标在第二行停留。不知道这些有没有用。
gototop
 

我把卡卡助手中查找到启动项里的desktop.ini项删了,还是不行,这个东东真难弄。。。
想问一下注删中能找到这个程序吗?
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KAVPersonal50Kaspersky Anti-Virus GUI PartKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus personal\kav.exe

HKLM\System\CurrentControlSet\Services
kavsvcKaspersky Anti-Virus ServiceKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus personal\kavsvc.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
金山毒霸2005\
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
IeCatch2 Classjccatch ModuleAmaze Softd:\program files\flashget\flashget\jccatch.dll
QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\qq\qqiehelper.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions&FlashGetFlashGetAmaze Softd:\program files\flashget\flashget\flashget.exe
访问卡卡社区File not found: http://www.ikaka.com
访问瑞星网站File not found: http://www.rising.com.cn
腾讯QQQQTENCENTd:\program files\qq\qq.exe
gototop
 

ProcessPIDCPUDescriptionCompany Name
System Idle Process088.99
Interruptsn/aHardware Interrupts
DPCsn/aDeferred Procedure Calls
System40.92
  smss.exe436Windows NT Session ManagerMicrosoft Corporation
  csrss.exe492Client Server Runtime ProcessMicrosoft Corporation
  winlogon.exe516Windows NT Logon ApplicationMicrosoft Corporation
    SERVICES.EXE5603.67Services and Controller appMicrosoft Corporation
    SVCHOST.EXE768Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE820Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE888Generic Host Process for Win32 ServicesMicrosoft Corporation
      wscntfy.exe1224Windows Security Center Notification AppMicrosoft Corporation
    SVCHOST.EXE1004Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE1120Generic Host Process for Win32 ServicesMicrosoft Corporation
    netdde.exe1576Network DDE - DDE CommunicationMicrosoft Corporation
    clipsrv.exe1692Windows NT DDE ServerMicrosoft Corporation
    kavsvc.exe1736
    SVCHOST.EXE1792Generic Host Process for Win32 ServicesMicrosoft Corporation
    alg.exe1216Application Layer Gateway ServiceMicrosoft Corporation
    LSASS.EXE572LSA Shell (Export Version)Microsoft Corporation
explorer.exe16002.75Windows ExplorerMicrosoft Corporation
kav.exe1996
iexplore.exe1132Internet ExplorerMicrosoft Corporation
WinRAR.exe3168
  procexp.exe35243.67Sysinternals Process ExplorerSysinternals

Process: System Idle Process Pid: 0

TypeName
gototop
 

ProcessPIDCPUDescriptionCompany Name
System Idle Process050.45
Interruptsn/a0.90Hardware Interrupts
DPCsn/a1.80Deferred Procedure Calls
System40.90
  smss.exe436Windows NT Session ManagerMicrosoft Corporation
  csrss.exe4922.70Client Server Runtime ProcessMicrosoft Corporation
  winlogon.exe516Windows NT Logon ApplicationMicrosoft Corporation
    SERVICES.EXE5604.50Services and Controller appMicrosoft Corporation
    SVCHOST.EXE768Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE820Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE8880.90Generic Host Process for Win32 ServicesMicrosoft Corporation
      wscntfy.exe1224Windows Security Center Notification AppMicrosoft Corporation
    SVCHOST.EXE1004Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE1120Generic Host Process for Win32 ServicesMicrosoft Corporation
    netdde.exe1576Network DDE - DDE CommunicationMicrosoft Corporation
    clipsrv.exe1692Windows NT DDE ServerMicrosoft Corporation
    kavsvc.exe17361.80
    SVCHOST.EXE17920.90Generic Host Process for Win32 ServicesMicrosoft Corporation
    alg.exe1216Application Layer Gateway ServiceMicrosoft Corporation
    LSASS.EXE5721.80LSA Shell (Export Version)Microsoft Corporation
explorer.exe16001.80Windows ExplorerMicrosoft Corporation
kav.exe1996
iexplore.exe1132Internet ExplorerMicrosoft Corporation
WinRAR.exe3168
  procexp.exe342431.53Sysinternals Process ExplorerSysinternals
NOTEPAD.EXE1268记事本Microsoft Corporation

Process: Procexp Pid: -2

TypeName
gototop
 

网页那栏什么都没有,之前我中了SPYWARE后桌面被改成被恐怖的样子,我就把那项给删了。
锁定桌面项目为空。
gototop
 

ProcessPIDCPUDescriptionCompany Name
System Idle Process083.93
Interruptsn/a0.89Hardware Interrupts
DPCsn/a0.89Deferred Procedure Calls
System4
  smss.exe436Windows NT Session ManagerMicrosoft Corporation
  csrss.exe492Client Server Runtime ProcessMicrosoft Corporation
  winlogon.exe516Windows NT Logon ApplicationMicrosoft Corporation
    SERVICES.EXE5604.46Services and Controller appMicrosoft Corporation
    SVCHOST.EXE760Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE816Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE8961.79Generic Host Process for Win32 ServicesMicrosoft Corporation
      wscntfy.exe1252Windows Security Center Notification AppMicrosoft Corporation
    SVCHOST.EXE1024Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE1128Generic Host Process for Win32 ServicesMicrosoft Corporation
    netdde.exe1596Network DDE - DDE CommunicationMicrosoft Corporation
    clipsrv.exe1680Windows NT DDE ServerMicrosoft Corporation
    kavsvc.exe1716
    SVCHOST.EXE1784Generic Host Process for Win32 ServicesMicrosoft Corporation
    alg.exe1216Application Layer Gateway ServiceMicrosoft Corporation
    LSASS.EXE572LSA Shell (Export Version)Microsoft Corporation
explorer.exe15882.68Windows ExplorerMicrosoft Corporation
kav.exe1996
WinRAR.exe1508
  procexp.exe4963.57Sysinternals Process ExplorerSysinternals
iexplore.exe23761.79Internet ExplorerMicrosoft Corporation
rundll32.exe1928Run a DLL as an AppMicrosoft Corporation

Process: Procexp Pid: -2

TypeName
gototop
 

好的,真的很感谢你哦。辛苦你了。
gototop
 

引用:
【BlackStone的贴子】不知你是怎么中的这个东东的?
...........................


HEHE,秘密。哈。。。。
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT