瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】查杀ghost.pif病毒后不能重起怎么办?(附新日志)

12   1  /  2  页   跳转

【求助】查杀ghost.pif病毒后不能重起怎么办?(附新日志)

【求助】查杀ghost.pif病毒后不能重起怎么办?(附新日志)

请指教:
查杀ghost.pif病毒后,安全模式可以进入,但正常起动时,在进入桌面的画面时死机,怎样修复呢?
最后编辑2007-08-23 17:03:05
分享到:
gototop
 

在D盘(双硬盘)重装第二系统,进入后用瑞星杀毒,未发现病毒!
gototop
 

【回复“sphwei”的帖子】
是进不了桌面
gototop
 

而且新装了第二个系统后,马上又不能用了,网络联上后,断不开,但上不去网了.网络联接也不能打开.
但用最新升级的瑞星也查不到病毒.
gototop
 

第二系统起动后日`志:

附件附件:

下载次数:108
文件类型:application/octet-stream
文件大小:
上传时间:2007-8-22 20:04:17
描述:

gototop
 

第一系统日志:

附件附件:

下载次数:102
文件类型:application/octet-stream
文件大小:
上传时间:2007-8-22 20:26:52
描述:

gototop
 

【回复“轩辕小聪”的帖子】感谢!
gototop
 

多帮忙啊
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><EXPLORER.EXE>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><; C:\WINDOWS\system32\ssstars.scr>  [(Verified)Microsoft Windows Publisher]
gototop
 

启动文件夹
N/A

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Disabled]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><>
[Application Management / AppMgmt][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Local Connection Manager / BRGNS][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE C:\WINDOWS\SYSTEM32\WBEM\EIKXC.DLL,Export 1087><Microsoft Corporation>
[Symantec Event Manager / ccEvtMgr][Stopped/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Stopped/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Stopped/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[D28AF8CC / D28AF8CC][Stopped/Auto Start]
  <C:\WINDOWS\system32\855CDAB6.EXE -k><N/A>
[Symantec AntiVirus Definition Watcher / DefWatch][Stopped/Auto Start]
  <"C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Disabled]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
[ms NCPA / NCPA][Stopped/Auto Start]
  <C:\WINDOWS\system32\ncpa.exe><N/A>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SavRoam / SavRoam][Stopped/Auto Start]
  <"C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Stopped/Manual Start]
  <"C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Symantec SecurePort / SymSecurePort][Stopped/Auto Start]
  <"C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe"><Symantec Corporation>
[TrueVector Internet Monitor / vsmon][Stopped/Auto Start]
  <C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service><Zone Labs Inc.>
[WinWMServiceNow / WinWMServiceNow][Stopped/Auto Start]
  <><N/A>
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT