查看: 10437|回复: 5
收起左侧

诺顿为什么蓝屏 原来是这样

[复制链接]
zlq7zj
发表于 2007-5-18 13:23:00 | 显示全部楼层 |阅读模式
今天打电话致电dell  dell 工程师说的是因为中病毒了  backdoor 的病毒 (他们今天接到的电话都是诺顿用户打过来的,电话都打爆了 )    于是打了半个小时电话修复安装了一下,  最后装上小红伞扫面一下 一个后门都没有扫面出来  之扫描了2个 一个是 360安全卫士  还有一个是大话西游的外挂程序   一个后门都没扫面出来



蓝屏的错误代码是:  C000021A UNKONOW HARD ERROR


  修复安装后我的C盘双击打不开了 之可以用右键打开    怎么解决啊

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zlq7zj
 楼主| 发表于 2007-5-18 13:23:40 | 显示全部楼层
下面是下红三的扫描报告:

AntiVir PersonalEdition Classic
Report file date: 2007年5月18日  12:11
Scanning for 779547 virus strains and unwanted programs.
Licensed to:      Avira AntiVir PersonalEdition Classic
Serial number:    0000149996-ADJIE-0001
Platform:         Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Username:         Owner
Computer name:    WSHMA-28A4E8CDE
Version information:
BUILD.DAT    : 247           14437 Bytes   2007-5-10 11:55:00
AVSCAN.EXE   : 7.0.4.15     282664 Bytes   2007-4-20 05:37:14
AVSCAN.DLL   : 7.0.4.4       33832 Bytes   2007-3-27 05:31:54
LUKE.DLL     : 7.0.4.11     143400 Bytes   2007-3-27 05:26:04
LUKERES.DLL  : 7.0.4.0       10280 Bytes   2007-3-19 05:18:59
ANTIVIR0.VDF : 6.35.0.1    7371264 Bytes   2006-5-31 06:14:26
ANTIVIR1.VDF : 6.37.1.151  4303360 Bytes   2007-2-23 07:04:16
ANTIVIR2.VDF : 6.38.1.100  1168384 Bytes    2007-5-6 07:04:16
ANTIVIR3.VDF : 6.38.1.152   137728 Bytes   2007-5-16 07:04:16
AVEWIN32.DLL : 7.4.0.23    2454016 Bytes   2007-5-16 06:35:50
AVWINLL.DLL  : 1.0.0.7       14376 Bytes   2007-2-26 03:36:26
AVPREF.DLL   : 7.0.2.1       24616 Bytes   2007-3-27 05:31:50
AVREP.DLL    : 7.0.0.1      155688 Bytes   2007-5-16 07:03:16
AVPACK32.DLL : 7.3.0.8      360488 Bytes   2007-3-27 01:48:28
AVREG.DLL    : 7.0.1.2       31784 Bytes   2007-3-15 02:05:08
AVEVTLOG.DLL : 7.0.0.18      86056 Bytes   2007-3-27 05:16:05
AVARKT.DLL   : 1.0.0.17     278568 Bytes    2007-5-2 04:32:26
NETNT.DLL    : 7.0.0.0        7720 Bytes    2007-3-8 04:09:42
RCIMAGE.DLL  : 7.0.1.15    2228264 Bytes   2007-3-13 03:46:18
RCTEXT.DLL   : 7.0.45.0      86056 Bytes   2007-3-19 05:42:42
Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: delete
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: high
Deviating risk categories........: +JOKE,
Start of the scan: 2007年5月18日  12:11
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'dvdupgrd.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
25 processes with 25 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
      [NOTE]      No virus was found!
Boot sector 'D:\'
      [NOTE]      No virus was found!
Boot sector 'E:\'
      [NOTE]      No virus was found!
Boot sector 'F:\'
      [NOTE]      No virus was found!
Starting to scan the registry.
The registry was scanned ( '15' files ).

Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
      [WARNING]   The file could not be opened!
Begin scan in 'D:\'
D:\360safe\AntiAdwa.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46c129fb.qua'!
Begin scan in 'E:\'
E:\大话外挂\SFer_v3.23.7\shaofa.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '46ae2e9e.qua'!
Begin scan in 'F:\'
F:\ebbbcf90198767bf641296ad\advpack.dll
      [WARNING]   The file could not be opened!
F:\ebbbcf90198767bf641296ad\browseui.dll
      [WARNING]   The file could not be opened!
F:\ebbbcf90198767bf641296ad\corpol.dll
      [WARNING]   The file could not be opened!
F:\ebbbcf90198767bf641296ad\custsat.dll
      [WARNING]   The file could not be opened!

End of the scan: 2007年5月18日  13:12
Used time:  1:01:04 min
The scan has been done completely.
   3673 Scanning directories
170666 Files were scanned
      2 viruses and/or unwanted programs were found
      2 classified as suspicious:
      0 files were deleted
      0 files were repaired
      2 files were moved to quarantine
      0 files were renamed
      5 Files cannot be scanned
170662 Files not concerned
   2178 Archives were scanned
      5 Warnings
      0 Notes
      0 Hidden objects were found
spiderman_xu
发表于 2007-5-18 13:26:48 | 显示全部楼层
我这里的笔记本HP,都这样了。
只有重装,连安全模式都进不去。
zlq7zj
 楼主| 发表于 2007-5-18 13:29:42 | 显示全部楼层
你有没有打电话去hp 问下    dell 的服务还不错呢
spiderman_xu
发表于 2007-5-18 13:41:19 | 显示全部楼层
原帖由 zlq7zj 于 2007-5-18 13:29 发表
你有没有打电话去hp 问下    dell 的服务还不错呢



已经有帖子写解决方案了。http://bbs.kafan.cn/viewthread.php?tid=86177&

反正机器重启之后就没戏了。
nczhivago
发表于 2007-5-18 16:06:49 | 显示全部楼层
关掉symantec antivirus 服务,如果netapi32.dll和lsasrc.dll文件存在,且修改日期不是今天,说明没有被完全隔离(应该是部分)
;从隔离区里面恢复这两个文件,或者从没有问题的电脑copy这两个文件到C:\windows\system32。

然后把C:\program files\common files\symantecshared\virusdefs\下把20070517这个文件夹删掉。

Blue screen fix 出现蓝屏的解决方案

1。使用安装盘启动

2。进入系统恢复控制台。

3。删除C:\Program Files\Common Files\SymantecShared\VirusDefs\20070517.018 这个目录

4。使用安装盘I386目录下的netapi32.dll和lsasrv.dll文件替换系统system32下的文件

5。重启电脑

Apply [05/17/2007, rev071] will fix the issue

ftp://ftp.symantec.com/public/en ... idrelease/sequence/


Sequence folder later than 68638

Or

Run live update after 3:00 p.m.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 16:14 , Processed in 0.122593 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表