查看: 5422|回复: 12
收起左侧

[已解决] 请教高手:当前系统无法修改时间,安全模式却可以。。。。

 关闭 [复制链接]
踏雪飞鸿
发表于 2008-3-8 18:58:31 | 显示全部楼层 |阅读模式
在XP系统里一改时间,点“应用”后,时间立马 回到改前的时间,不过在安全模式下可以改时间,改好了重起,时间不会回到改前的状态。可为什么会在当前系统无法更改呢?郁闷,哪位高手能帮忙解决呀


我正确用了360TimeProtect时间保护工具。还是不行,卸载360TimeProtect后,再在XP系统里改时间,点“应用”后,时间立马 回到改前的时间,不过在安全模式下可以改时间,改好了重起,时间不会回到改前的状态。郁闷,哪位高手能帮忙解决呀

[ 本帖最后由 踏雪飞鸿 于 2008-3-8 19:03 编辑 ]
llj4862
发表于 2008-3-8 20:16:54 | 显示全部楼层
使用系统管理员的帐号登陆进入系统,打开“开始”-“运行”,在运行输入框中输入“gpedit.msc”,进入“组策略”设置界面,依次展开“计算机配置”--“Windows 设置”--“安全设置”--“本地策略”--“用户权利指派”,
然后,选择“更改系统时间”
chen_c_yaun
发表于 2008-3-8 20:47:17 | 显示全部楼层
看一下软件下载区的一篇文章
http://www.kpfans.com/bbs/viewth ... p;extra=&page=1
355254265
发表于 2008-3-8 22:45:54 | 显示全部楼层
ARP防火墙都有防止修改时间的!
踏雪飞鸿
 楼主| 发表于 2008-3-9 19:05:23 | 显示全部楼层
试了2楼的方法,还是不行
踏雪飞鸿
 楼主| 发表于 2008-3-10 19:46:27 | 显示全部楼层
sreng"智能扫描"的结果,请高手分析分析
  1. 2008-03-10,19:40:43

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.       [3L软件工作室(3LSoft)]
  20.       []
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  22.       [(Verified)Microsoft Windows Component Publisher]
  23.       [(Verified)Microsoft Windows Publisher]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  25.     <>  [N/A]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  27.       [(Verified)Microsoft Windows Publisher]
  28. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
  29.       [Intel Corporation]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  31.       [(Verified)Microsoft Corporation]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  33.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  35.     <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  37.     <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  39.       [(Verified)Microsoft Windows Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  41.       [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  43.       [(Verified)Microsoft Windows Component Publisher]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  45.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  47.       [Microsoft Corporation]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  49.     <; >  [N/A]

  50. ==================================
  51. 启动文件夹
  52. N/A

  53. ==================================
  54. 服务
  55. [Avira Premium Security Suite WebGuard / antivirwebservice][Stopped/Disabled]
  56.   <>
  57. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Manual Start]
  58.   <>
  59. [Contrl Center of Storm Media / ccosm][Stopped/Manual Start]
  60.   <北京暴风网际科技有限公司>
  61. [KVSrvXP / KVSrvXP][Running/Auto Start]
  62.   
  63. [MPSVC Service / MPSVCService][Running/Auto Start]
  64.   
  65. [O&O Defrag / O&O Defrag][Stopped/Auto Start]
  66.   
  67. [O&O CleverCache / OOCleverCacheAgent][Stopped/Auto Start]
  68.   
  69. [PnpWMmng / PnpWMmng][Stopped/Disabled]
  70.   <完美卸载>
  71. [User Profile Hive Cleanup / UPHClean][Running/Auto Start]
  72.   

  73. ==================================
  74. 驱动程序
  75. [360TimeProt / 360TimeProt][Running/Auto Start]
  76.   <\??\C:\WINDOWS\system32\drivers\360TimeProt.sys>
  77. [Lenovo Virtual Power Controller Driver / ACPIVPC][Running/Manual Start]
  78.   
  79. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start]
  80.   <\??\F:\TaoMengLiang\杀毒软件\木马流氓软件查杀\AVG Anti-Spyware(原eWido)7.5.1.43汉化绿色破解版(可在线升级、整合0702病毒库\AVGAntiSpywarelse\AVG Anti-Spyware\guard.sys>
  81. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  82.   
  83. [avgio / avgio][Stopped/System Start]
  84.   <\??\D:\Program Files\Avira\Avira Premium Security Suite\avgio.sys>
  85. [avgntflt / avgntflt][Stopped/Manual Start]
  86.   <\??\D:\Program Files\Avira\Avira Premium Security Suite\avgntflt.sys>
  87. [avipbb / avipbb][Running/System Start]
  88.   
  89. [Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
  90.   

  91. [BsDeamon / BsDeamon][Running/System Start]
  92.   <\??\D:\Program Files\JiangMin\AntiVirus\BsDeamon.sys>
  93. [Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
  94.   
  95. [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  96.   
  97. [HSFHWAZL / HSFHWAZL][Running/Manual Start]
  98.   
  99. [HSF_DPV / HSF_DPV][Running/Manual Start]
  100.   
  101. [ialm / ialm][Running/Manual Start]
  102.   
  103. [KAVBootC / KAVBootC][Running/Boot Start]
  104.   <\SystemRoot\system32\Drivers\KAVBootC.sys>
  105. [KRegEx / KRegEx][Running/Auto Start]
  106.   <\??\D:\Program Files\JiangMin\antivirus\KRegEx.sys>
  107. [Jiangmin Antivirus Software - SysCall Services / KSysCall][Running/System Start]
  108.   <\??\D:\Program Files\JiangMin\common\KSysCall.sys>
  109. [KVFileGuard From Jiangmin / KVFileGuard][Running/Manual Start]
  110.   <\??\D:\Program Files\JiangMin\AntiVirus\KVfg.sys>
  111. [mdmxsdk / mdmxsdk][Running/Auto Start]
  112.   
  113. [mp110001 / mp110001][Running/Auto Start]
  114.   
  115. [mp110002 / mp110002][Stopped/Auto Start]
  116.   
  117. [mp110003 / mp110003][Running/Boot Start]
  118.   <\SystemRoot\system32\drivers\mp110003.sys>
  119. [mp110004 / mp110004][Running/Auto Start]
  120.   
  121. [mp110005 / mp110005][Running/Manual Start]
  122.   
  123. [mp110006 / mp110006][Running/System Start]
  124.   
  125. [mp110007 / mp110007][Running/System Start]
  126.   
  127. [mp110008 / mp110008][Running/Auto Start]
  128.   
  129. [mp110009 / mp110009][Running/System Start]
  130.   
  131. [mp110010 / mp110010][Running/Boot Start]
  132.   <\SystemRoot\system32\drivers\mp110010.sys>
  133. [mp110011 / mp110011][Stopped/System Start]
  134.   
  135. [mp110012 / mp110012][Stopped/Manual Start]
  136.   
  137. [mp110013 / mp110013][Running/Boot Start]
  138.   <\SystemRoot\system32\drivers\mp110013.sys>
  139. [PC-CDMA Serial port driver / oxser][Running/System Start]
  140.   
  141. [PnpWmkDrv / PnpWmkDrv][Running/System Start]
  142.   <\??\C:\WINDOWS\system32\drivers\PnpWmkDrv.sys>
  143. [Powertweak NT helper / Powert][Stopped/Auto Start]
  144.   <\??\F:\TAOMEN~2\优化软件\POWERT~1.02R\pt202-1\pt202-1\powert2k.sys>
  145. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  146.   
  147. [Secdrv / Secdrv][Stopped/Manual Start]
  148.   
  149. [ssmdrv / ssmdrv][Running/System Start]
  150.   
  151. [Jiangmin AntiVirus Software - System Guard / SysGuard][Running/Boot Start]
  152.   <\SystemRoot\system32\Drivers\SysGuard.sys>
  153. [tifm21 / tifm21][Running/Manual Start]
  154.   
  155. [Conexant Setup API / UIUSys][Stopped/Manual Start]
  156.   
  157. [Virtual CD-ROM Device Driver / vcdrom][Running/System Start]
  158.   <\??\E:\WinPE纯净硬盘版配合微软虚拟光驱,再不用刻盘装系统了\微软虚拟光驱18K\微软虚拟光驱\虚拟光驱\VCdRom.sys>
  159. [winachsf / winachsf][Running/Manual Start]
  160.   

  161. ==================================
  162. 浏览器加载项
  163. [ThunderAtOnce Class]
  164.   {01443AEC-0FD1-40fd-9C87-E93D1494C233}
  165. [IeCatch5 Class]
  166.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
  167. [BrowseHelper Class]
  168.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}
  169. [Thunder Browser Helper]
  170.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  171. [RegisterHelper Class]
  172.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4}
  173. [FlashGet]
  174.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
  175. [江民杀毒工具栏]
  176.   {B5A34A93-D538-43A7-8371-864CB6148D12}
  177. [DrvCert Class]
  178.   {2FD68643-4BCE-4EF5-B7B8-F0F1192FDE86}
  179. [InputPassWd Class]
  180.   {3A4C8311-C151-4462-BDE9-F777ABEE0063}
  181. [WUWebControl Class]
  182.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  183. [MUWebControl Class]
  184.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
  185. [ThunderAtOnce Class]
  186.   {01443AEC-0FD1-40FD-9C87-E93D1494C233}
  187. [Windows Genuine Advantage Validation Tool]
  188.   {17492023-C23A-453E-A040-C7C580BBF700}
  189. [XML DOM Document]
  190.   {2933BF90-7B36-11D2-B20E-00C04F983E60}
  191. [DrvCert Class]
  192.   {2FD68643-4BCE-4EF5-B7B8-F0F1192FDE86}
  193. [Thunder Agent Class]
  194.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE}
  195. [DrvINFReader Class]
  196.   {631AC624-4EA0-49AB-ABD7-64409592AE15}
  197. [WUWebControl Class]
  198.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  199. [MUWebControl Class]
  200.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
  201. [BrowseHelper Class]
  202.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}
  203. [360SafeLive]
  204.   {87515F61-A66C-4319-A0E0-D416CB8059E3}
  205. [Microsoft Web Browser]
  206.   {8856F961-340A-11D0-A96B-00C04FD705A2}
  207. [Thunder Browser Helper]
  208.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  209. [DrvInst Class]
  210.   {9222E48D-8985-4BE2-B9DB-EBE734CBE7B5}
  211. [江民杀毒工具栏]
  212.   {B5A34A93-D538-43A7-8371-864CB6148D12}
  213. [Shockwave Flash Object]
  214.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  215. [XML HTTP Request]
  216.   {ED8C108E-4349-11D2-91A4-00C04F7969E8}
  217. [XML DOM Document 3.0]
  218.   {F5078F32-C551-11D3-89B9-0000F81FE221}
  219. [XML HTTP 3.0]
  220.   {F5078F35-C551-11D3-89B9-0000F81FE221}
  221. [XML HTTP]
  222.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4}
  223. [RegisterHelper Class]
  224.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4}
  225. [使用 IDM 下载]
  226.   <54A24-B490-4D4F-8EEC-B3ACD6E681A4}, N/A>
  227. [使用 IDM 下载所有链接]
  228.   <, N/A>
  229. [使用 IDM 下载视频内容]
  230.   <, N/A>
  231. [使用网际快车下载]
  232.   
  233. [使用网际快车下载全部链接]
  234.   
  235. [使用迅雷下载]
  236.   
  237. [使用迅雷下载全部链接]
  238.   

  239. ==================================
  240. 正在运行的进程
  241. [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  242. [PID: 808 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  243. [PID: 836 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  244.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  245. [PID: 884 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  246. [PID: 896 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  247. [PID: 1108 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  248.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  249. [PID: 1292 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  250.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  251. [PID: 1584 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  252.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  253. [PID: 1800 / wuliu][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
  254.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  255.     [F:\TaoMengLiang\重装系统首要必装软件\WinRAR 绿色版\winrar卡饭专用版\rarext.dll]  [N/A, ]
  256.     [F:\TaoMengLiang\杀毒软件\木马流氓软件查杀\unlocker\Unlocker[1].v1.7.8.中文免安装版\强行解锁删除软件专家Unlocker.v1.7.8.中文免安装版\UnlockerCOM.dll]  [N/A, ]
  257.     [D:\Program Files\JiangMin\AntiVirus\KVshell.dll]  [Jiangmin Co.Ltd, 2, 0, 7, 1018]
  258.     [C:\WINDOWS\system32\HiveBase.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 717]
  259.     [C:\WINDOWS\system32\kvinstall.dll]  [Jiangmin Co.,Ltd, 2, 0, 7, 831]
  260.     [D:\Program Files\JiangMin\AntiVirus\lang\KvXP0804.lng]  [N/A, ]
  261.     [F:\DrWeb\drwsxtn.dll]  [Doctor Web, Ltd., 4, 44, 0, 8080]
  262. [PID: 1972 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  263. [PID: 1992 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  264. [PID: 2040 / SYSTEM][D:\Program Files\UPHClean\uphclean.exe]  [Microsoft Corporation, 1.5.5.21]
  265. [PID: 1612 / wuliu][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  266. [PID: 484 / wuliu][M:\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  267.     [M:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  268.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]

  269. ==================================
  270. 文件关联
  271. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  272. .EXE  OK. ["%1" %*]
  273. .COM  OK. ["%1" %*]
  274. .PIF  OK. ["%1" %*]
  275. .REG  OK. [regedit.exe "%1"]
  276. .BAT  OK. ["%1" %*]
  277. .SCR  OK. ["%1" /S]
  278. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  279. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  280. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  281. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  282. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  283. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  284. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  285. ==================================
  286. Winsock 提供者
  287. N/A

  288. ==================================
  289. Autorun.inf
  290. N/A

  291. ==================================
  292. HOSTS 文件
  293. 127.0.0.1       localhost
  294. 127.0.0.1        registeridm.com
  295. 127.0.0.1        www.internetdownloadmanager.com
  296. 127.0.0.1        internetdownloadmanager.com
  297. 127.0.0.1        www.registeridm.com
  298. 127.0.0.1        secure.registeridm.com
  299. 127.0.0.1        secure.internetdownloadmanager.com
  300. 127.0.0.1        mirror.internetdownloadmanager.com
  301. 127.0.0.1        mirror2.internetdownloadmanager.com
  302. 127.0.0.1        mirror3.internetdownloadmanager.com
  303. 127.0.0.1        www.tonec.com
  304. 127.0.0.1        tonec.com
  305. 127.0.0.1        207.44.199.159
  306. 127.0.0.1        207.44.199.16

  307. ==================================
  308. 进程特权扫描
  309. N/A

  310. ==================================
  311. API HOOK
  312. N/A

  313. ==================================
  314. 隐藏进程
  315. N/A

  316. ==================================
复制代码
踏雪飞鸿
 楼主| 发表于 2008-3-10 19:47:42 | 显示全部楼层
sreng"智能扫描"的结果,请高手分析分析
  1. 2008-03-10,19:40:43

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.       [3L软件工作室(3LSoft)]
  20.       []
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  22.       [(Verified)Microsoft Windows Component Publisher]
  23.       [(Verified)Microsoft Windows Publisher]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  25.     <>  [N/A]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  27.       [(Verified)Microsoft Windows Publisher]
  28. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
  29.       [Intel Corporation]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  31.       [(Verified)Microsoft Corporation]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  33.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  35.     <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  37.     <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  39.       [(Verified)Microsoft Windows Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  41.       [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  43.       [(Verified)Microsoft Windows Component Publisher]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  45.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  47.       [Microsoft Corporation]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  49.     <; >  [N/A]

  50. ==================================
  51. 启动文件夹
  52. N/A

  53. ==================================
  54. 服务
  55. [Avira Premium Security Suite WebGuard / antivirwebservice][Stopped/Disabled]
  56.   <>
  57. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Manual Start]
  58.   <>
  59. [Contrl Center of Storm Media / ccosm][Stopped/Manual Start]
  60.   <北京暴风网际科技有限公司>
  61. [KVSrvXP / KVSrvXP][Running/Auto Start]
  62.   
  63. [MPSVC Service / MPSVCService][Running/Auto Start]
  64.   
  65. [O&O Defrag / O&O Defrag][Stopped/Auto Start]
  66.   
  67. [O&O CleverCache / OOCleverCacheAgent][Stopped/Auto Start]
  68.   
  69. [PnpWMmng / PnpWMmng][Stopped/Disabled]
  70.   <完美卸载>
  71. [User Profile Hive Cleanup / UPHClean][Running/Auto Start]
  72.   

  73. ==================================
  74. 驱动程序
  75. [360TimeProt / 360TimeProt][Running/Auto Start]
  76.   <\??\C:\WINDOWS\system32\drivers\360TimeProt.sys>
  77. [Lenovo Virtual Power Controller Driver / ACPIVPC][Running/Manual Start]
  78.   
  79. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start]
  80.   <\??\F:\TaoMengLiang\杀毒软件\木马流氓软件查杀\AVG Anti-Spyware(原eWido)7.5.1.43汉化绿色破解版(可在线升级、整合0702病毒库\AVGAntiSpywarelse\AVG Anti-Spyware\guard.sys>
  81. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  82.   
  83. [avgio / avgio][Stopped/System Start]
  84.   <\??\D:\Program Files\Avira\Avira Premium Security Suite\avgio.sys>
  85. [avgntflt / avgntflt][Stopped/Manual Start]
  86.   <\??\D:\Program Files\Avira\Avira Premium Security Suite\avgntflt.sys>
  87. [avipbb / avipbb][Running/System Start]
  88.   
  89. [Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
  90.   

  91. [BsDeamon / BsDeamon][Running/System Start]
  92.   <\??\D:\Program Files\JiangMin\AntiVirus\BsDeamon.sys>
  93. [Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
  94.   
  95. [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  96.   
  97. [HSFHWAZL / HSFHWAZL][Running/Manual Start]
  98.   
  99. [HSF_DPV / HSF_DPV][Running/Manual Start]
  100.   
  101. [ialm / ialm][Running/Manual Start]
  102.   
  103. [KAVBootC / KAVBootC][Running/Boot Start]
  104.   <\SystemRoot\system32\Drivers\KAVBootC.sys>
  105. [KRegEx / KRegEx][Running/Auto Start]
  106.   <\??\D:\Program Files\JiangMin\antivirus\KRegEx.sys>
  107. [Jiangmin Antivirus Software - SysCall Services / KSysCall][Running/System Start]
  108.   <\??\D:\Program Files\JiangMin\common\KSysCall.sys>
  109. [KVFileGuard From Jiangmin / KVFileGuard][Running/Manual Start]
  110.   <\??\D:\Program Files\JiangMin\AntiVirus\KVfg.sys>
  111. [mdmxsdk / mdmxsdk][Running/Auto Start]
  112.   
  113. [mp110001 / mp110001][Running/Auto Start]
  114.   
  115. [mp110002 / mp110002][Stopped/Auto Start]
  116.   
  117. [mp110003 / mp110003][Running/Boot Start]
  118.   <\SystemRoot\system32\drivers\mp110003.sys>
  119. [mp110004 / mp110004][Running/Auto Start]
  120.   
  121. [mp110005 / mp110005][Running/Manual Start]
  122.   
  123. [mp110006 / mp110006][Running/System Start]
  124.   
  125. [mp110007 / mp110007][Running/System Start]
  126.   
  127. [mp110008 / mp110008][Running/Auto Start]
  128.   
  129. [mp110009 / mp110009][Running/System Start]
  130.   
  131. [mp110010 / mp110010][Running/Boot Start]
  132.   <\SystemRoot\system32\drivers\mp110010.sys>
  133. [mp110011 / mp110011][Stopped/System Start]
  134.   
  135. [mp110012 / mp110012][Stopped/Manual Start]
  136.   
  137. [mp110013 / mp110013][Running/Boot Start]
  138.   <\SystemRoot\system32\drivers\mp110013.sys>
  139. [PC-CDMA Serial port driver / oxser][Running/System Start]
  140.   
  141. [PnpWmkDrv / PnpWmkDrv][Running/System Start]
  142.   <\??\C:\WINDOWS\system32\drivers\PnpWmkDrv.sys>
  143. [Powertweak NT helper / Powert][Stopped/Auto Start]
  144.   <\??\F:\TAOMEN~2\优化软件\POWERT~1.02R\pt202-1\pt202-1\powert2k.sys>
  145. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  146.   
  147. [Secdrv / Secdrv][Stopped/Manual Start]
  148.   
  149. [ssmdrv / ssmdrv][Running/System Start]
  150.   
  151. [Jiangmin AntiVirus Software - System Guard / SysGuard][Running/Boot Start]
  152.   <\SystemRoot\system32\Drivers\SysGuard.sys>
  153. [tifm21 / tifm21][Running/Manual Start]
  154.   
  155. [Conexant Setup API / UIUSys][Stopped/Manual Start]
  156.   
  157. [Virtual CD-ROM Device Driver / vcdrom][Running/System Start]
  158.   <\??\E:\WinPE纯净硬盘版配合微软虚拟光驱,再不用刻盘装系统了\微软虚拟光驱18K\微软虚拟光驱\虚拟光驱\VCdRom.sys>
  159. [winachsf / winachsf][Running/Manual Start]
  160.   

  161. ==================================
  162. 浏览器加载项
  163. [ThunderAtOnce Class]
  164.   {01443AEC-0FD1-40fd-9C87-E93D1494C233}
  165. [IeCatch5 Class]
  166.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
  167. [BrowseHelper Class]
  168.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}
  169. [Thunder Browser Helper]
  170.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  171. [RegisterHelper Class]
  172.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4}
  173. [FlashGet]
  174.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
  175. [江民杀毒工具栏]
  176.   {B5A34A93-D538-43A7-8371-864CB6148D12}
  177. [DrvCert Class]
  178.   {2FD68643-4BCE-4EF5-B7B8-F0F1192FDE86}
  179. [InputPassWd Class]
  180.   {3A4C8311-C151-4462-BDE9-F777ABEE0063}
  181. [WUWebControl Class]
  182.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  183. [MUWebControl Class]
  184.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
  185. [ThunderAtOnce Class]
  186.   {01443AEC-0FD1-40FD-9C87-E93D1494C233}
  187. [Windows Genuine Advantage Validation Tool]
  188.   {17492023-C23A-453E-A040-C7C580BBF700}
  189. [XML DOM Document]
  190.   {2933BF90-7B36-11D2-B20E-00C04F983E60}
  191. [DrvCert Class]
  192.   {2FD68643-4BCE-4EF5-B7B8-F0F1192FDE86}
  193. [Thunder Agent Class]
  194.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE}
  195. [DrvINFReader Class]
  196.   {631AC624-4EA0-49AB-ABD7-64409592AE15}
  197. [WUWebControl Class]
  198.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  199. [MUWebControl Class]
  200.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
  201. [BrowseHelper Class]
  202.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}
  203. [360SafeLive]
  204.   {87515F61-A66C-4319-A0E0-D416CB8059E3}
  205. [Microsoft Web Browser]
  206.   {8856F961-340A-11D0-A96B-00C04FD705A2}
  207. [Thunder Browser Helper]
  208.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  209. [DrvInst Class]
  210.   {9222E48D-8985-4BE2-B9DB-EBE734CBE7B5}
  211. [江民杀毒工具栏]
  212.   {B5A34A93-D538-43A7-8371-864CB6148D12}
  213. [Shockwave Flash Object]
  214.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  215. [XML HTTP Request]
  216.   {ED8C108E-4349-11D2-91A4-00C04F7969E8}
  217. [XML DOM Document 3.0]
  218.   {F5078F32-C551-11D3-89B9-0000F81FE221}
  219. [XML HTTP 3.0]
  220.   {F5078F35-C551-11D3-89B9-0000F81FE221}
  221. [XML HTTP]
  222.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4}
  223. [RegisterHelper Class]
  224.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4}
  225. [使用 IDM 下载]
  226.   <54A24-B490-4D4F-8EEC-B3ACD6E681A4}, N/A>
  227. [使用 IDM 下载所有链接]
  228.   <, N/A>
  229. [使用 IDM 下载视频内容]
  230.   <, N/A>
  231. [使用网际快车下载]
  232.   
  233. [使用网际快车下载全部链接]
  234.   
  235. [使用迅雷下载]
  236.   
  237. [使用迅雷下载全部链接]
  238.   

  239. ==================================
  240. 正在运行的进程
  241. [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  242. [PID: 808 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  243. [PID: 836 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  244.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  245. [PID: 884 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  246. [PID: 896 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  247. [PID: 1108 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  248.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  249. [PID: 1292 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  250.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  251. [PID: 1584 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  252.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  253. [PID: 1800 / wuliu][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
  254.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]
  255.     [F:\TaoMengLiang\重装系统首要必装软件\WinRAR 绿色版\winrar卡饭专用版\rarext.dll]  [N/A, ]
  256.     [F:\TaoMengLiang\杀毒软件\木马流氓软件查杀\unlocker\Unlocker[1].v1.7.8.中文免安装版\强行解锁删除软件专家Unlocker.v1.7.8.中文免安装版\UnlockerCOM.dll]  [N/A, ]
  257.     [D:\Program Files\JiangMin\AntiVirus\KVshell.dll]  [Jiangmin Co.Ltd, 2, 0, 7, 1018]
  258.     [C:\WINDOWS\system32\HiveBase.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 717]
  259.     [C:\WINDOWS\system32\kvinstall.dll]  [Jiangmin Co.,Ltd, 2, 0, 7, 831]
  260.     [D:\Program Files\JiangMin\AntiVirus\lang\KvXP0804.lng]  [N/A, ]
  261.     [F:\DrWeb\drwsxtn.dll]  [Doctor Web, Ltd., 4, 44, 0, 8080]
  262. [PID: 1972 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  263. [PID: 1992 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  264. [PID: 2040 / SYSTEM][D:\Program Files\UPHClean\uphclean.exe]  [Microsoft Corporation, 1.5.5.21]
  265. [PID: 1612 / wuliu][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  266. [PID: 484 / wuliu][M:\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  267.     [M:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  268.     [d:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10043]

  269. ==================================
  270. 文件关联
  271. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  272. .EXE  OK. ["%1" %*]
  273. .COM  OK. ["%1" %*]
  274. .PIF  OK. ["%1" %*]
  275. .REG  OK. [regedit.exe "%1"]
  276. .BAT  OK. ["%1" %*]
  277. .SCR  OK. ["%1" /S]
  278. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  279. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  280. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  281. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  282. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  283. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  284. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  285. ==================================
  286. Winsock 提供者
  287. N/A

  288. ==================================
  289. Autorun.inf
  290. N/A

  291. ==================================
  292. HOSTS 文件
  293. 127.0.0.1       localhost
  294. 127.0.0.1        registeridm.com
  295. 127.0.0.1        www.internetdownloadmanager.com
  296. 127.0.0.1        internetdownloadmanager.com
  297. 127.0.0.1        www.registeridm.com
  298. 127.0.0.1        secure.registeridm.com
  299. 127.0.0.1        secure.internetdownloadmanager.com
  300. 127.0.0.1        mirror.internetdownloadmanager.com
  301. 127.0.0.1        mirror2.internetdownloadmanager.com
  302. 127.0.0.1        mirror3.internetdownloadmanager.com
  303. 127.0.0.1        www.tonec.com
  304. 127.0.0.1        tonec.com
  305. 127.0.0.1        207.44.199.159
  306. 127.0.0.1        207.44.199.16

  307. ==================================
  308. 进程特权扫描
  309. N/A

  310. ==================================
  311. API HOOK
  312. N/A

  313. ==================================
  314. 隐藏进程
  315. N/A

  316. ==================================
复制代码
dujie7023
发表于 2008-3-10 19:59:48 | 显示全部楼层
你中奖了。。。。
换个杀毒试试   pe系统下杀毒
踏雪飞鸿
 楼主| 发表于 2008-3-11 09:29:55 | 显示全部楼层
原帖由 dujie7023 于 2008-3-10 19:59 发表
你中奖了。。。。
换个杀毒试试   pe系统下杀毒




请教一下高手,PE下如何杀毒呀?麻烦你 详细说说吧,谢谢了
踏雪飞鸿
 楼主| 发表于 2008-3-11 17:32:14 | 显示全部楼层
???????没有回答呀?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-13 11:31 , Processed in 0.171688 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表