Board logo

标题: [求助] 紧急求助,系统无法正常运行 [打印本页]

作者: 神雕大侠    时间: 2007-10-5 19:13     标题: 紧急求助,系统无法正常运行

无法正常安装及运行某些软件,比如无法安装WinRAR,提示找不到C:/WINDOWS/msutl.exe,

重新安装系统也解决不了问题,请问msutl.exe是什么程序,能不能给我上传一个,麻烦高手帮助
作者: eric00    时间: 2007-10-5 20:32

我搜了自己的硬盘,ms没有这个文件
作者: 晨风鸟    时间: 2007-10-5 21:30

这个有可能不是系统文件,有可能是你的电脑中了病毒或者木马,

可以查杀系统以后再次运行安装,或者在安全模式下面试试能否正常安装。
作者: ldsystem    时间: 2007-10-5 22:17

这个不是系统文件,可能是中毒了,请下载IceSword,先结束可疑进程,再用arswp清理,建议装上微点...
最好用SREng扫描一份日志贴上来...

相关软件请到这里下载
http://bbs.liulanghome.com/thread-49234-1-1.html
作者: 神雕大侠    时间: 2007-10-5 23:09

  1. 2007-10-05,23:06:20

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <KavPFW><"C:\KAV2007\KPFW32.EXE">  [Kingsoft Corporation]
  18.     <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  19. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <Lskbdrv><C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe>  []
  21.     <LenSoft><C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe>  []
  22.     <KavStart><"C:\KAV2007\KAVStart.exe" -startup>  [Kingsoft Corporation]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  24.     <KASTask><C:\KAV2007\KASTask.EXE>  [Kingsoft Corporation]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  26.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  27.     <Userinit><C:\windows\system32\Userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  28.     <UIHost><"\Program Files\Logonui\Logonui.exe">  [N/A]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  30.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  32.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  34.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  36.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  38.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  40.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  42.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  44.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

  45. ==================================
  46. 启动文件夹
  47. N/A

  48. ==================================
  49. 服务
  50. [Ati HotKey Poller / Ati HotKey Poller][Stopped/Auto Start]
  51.   <C:\windows\system32\Ati2evxx.exe><>
  52. [ATI Smart / ATI Smart][Stopped/Auto Start]
  53.   <><N/A>
  54. [Help and Support / helpsvc][Stopped/Disabled]
  55.   <C:\windows\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
  56. [Human Interface Device Access / HidServ][Stopped/Disabled]
  57.   <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  58. [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  59.   <"C:\KAV2007\KPfwSvc.EXE"><Kingsoft Corporation>
  60. [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  61.   <C:\KAV2007\KWatch.EXE><Kingsoft Corporation>

  62. ==================================
  63. 驱动程序
  64. [aeaudio / aeaudio][Stopped/Manual Start]
  65.   <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
  66. [Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
  67.   <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
  68. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  69.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  70. [ati2mtag / ati2mtag][Stopped/Manual Start]
  71.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  72. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  73.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  74. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Stopped/Manual Start]
  75.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  76. [HSFHWBS2 / HSFHWBS2][Running/Manual Start]
  77.   <system32\DRIVERS\HSFHWBS2.sys><Conexant Systems>
  78. [HSF_DP / HSF_DP][Running/Manual Start]
  79.   <system32\DRIVERS\HSF_DP.sys><Conexant Systems>
  80. [KAVBootC / KAVBootC][Running/Boot Start]
  81.   <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
  82. [KNetWch / KNetWch][Running/System Start]
  83.   <\??\C:\KAV2007\KNetWch.SYS><Kingsoft Corporation>
  84. [KWatch3 / KWatch3][Running/System Start]
  85.   <\??\C:\windows\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
  86. [mdmxsdk / mdmxsdk][Running/Auto Start]
  87.   <system32\DRIVERS\mdmxsdk.sys><Conexant>
  88. [NTSIM / NTSIM][Stopped/Manual Start]
  89.   <\??\C:\WINDOWS\system32\ntsim.sys><VIA Technologies, Inc.>
  90. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  91.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  92. [Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
  93.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  94. [Secdrv / Secdrv][Stopped/Manual Start]
  95.   <system32\DRIVERS\secdrv.sys><N/A>
  96. [SiS315 / SiS315][Running/Manual Start]
  97.   <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
  98. [SiS AGP Filter / sisagp][Running/Boot Start]
  99.   <\SystemRoot\system32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
  100. [SiSide / SiSide][Running/Boot Start]
  101.   <\SystemRoot\system32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
  102. [sisidex / sisidex][Running/Boot Start]
  103.   <\SystemRoot\system32\drivers\sisidex.sys><Windows (R) 2000 DDK provider>
  104. [SiSkp / SiSkp][Running/System Start]
  105.   <system32\drivers\srvkp.sys><N/A>
  106. [Add Performance Filter Driver / sisperf][Running/Boot Start]
  107.   <\SystemRoot\system32\drivers\sisperf.sys><Silicon Integrated Systems Corp.>
  108. [smwdm / smwdm][Stopped/Manual Start]
  109.   <system32\drivers\smwdm.sys><Analog Devices, Inc.>
  110. [Conexant Setup API / UIUSys][Stopped/Manual Start]
  111.   <system32\drivers\UIUSys.sys><Conexant>
  112. [ViaIde / ViaIde][Running/Boot Start]
  113.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  114. [winachsf / winachsf][Running/Manual Start]
  115.   <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems>
  116. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  117.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  118. [Driver for XLPPoEPC Device / XLPPoEPC][Running/Manual Start]
  119.   <system32\DRIVERS\XLPPoEPC.sys><西安信利软件系统公司>
  120. [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Stopped/Manual Start]
  121.   <System32\Drivers\usbVM31b.sys><VM>

  122. ==================================
  123. 浏览器加载项
  124. [CBrowseStakeout Class]
  125.   {55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
  126. [WUWebControl Class]
  127.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  128. [CBrowseStakeout Class]
  129.   {55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
  130. [WUWebControl Class]
  131.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  132. [360SafeLive]
  133.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <E:\360\360safe\live.dll, 360safe.com>
  134. [SearchAssistantOC]
  135.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  136. [Shockwave Flash Object]
  137.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
  138. [金山毒霸反钓鱼...]
  139.   <C:\KAV2007\KAF\ShowSet.htm, N/A>

  140. ==================================
  141. 正在运行的进程
  142. [PID: 660][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  143. [PID: 720][\??\C:\windows\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  144. [PID: 744][\??\C:\windows\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  145.     [C:\windows\system32\Ati2evxx.dll]  [, ]
  146. [PID: 788][C:\windows\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  147. [PID: 800][C:\windows\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  148. [PID: 976][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  149. [PID: 1068][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  150. [PID: 1192][C:\windows\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  151. [PID: 1256][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  152. [PID: 1300][C:\KAV2007\KWatch.EXE]  [Kingsoft Corporation, 2007, 8, 13, 78]
  153.     [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
  154.     [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 6, 19, 64]
  155.     [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
  156.     [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 9, 17, 134]
  157.     [C:\KAV2007\KAVQuara.DLL]  [Kingsoft Corporation, 2007, 6, 15, 4]
  158. [PID: 1368][C:\KAV2007\KPfwSvc.EXE]  [Kingsoft Corporation, 2007, 8, 17, 39]
  159. [PID: 1380][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  160. [PID: 1584][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  161.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  162.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  163.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  164.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  165.     [C:\Program Files\Winrar3.7\rarext.dll]  [N/A, ]
  166.     [C:\KAV2007\KAVEXT.DLL]  [Kingsoft Corporation, 2007, 6, 21, 29]
  167.     [C:\windows\system32\LgdGuard.dll]  [, ]
  168.     [D:\Unlocker绿色版\unlockercom.dll]  [N/A, ]
  169.     [C:\KAV2007\KAScript.DLL]  [Kingsoft Corporation, 2007, 3, 6, 75]
  170.     [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 6, 19, 64]
  171.     [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
  172.     [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 9, 17, 134]
  173.     [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
  174. [PID: 1728][C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe]  [N/A, ]
  175.     [C:\Program Files\Lenovo\幸福一键通\lxkeyled.dll]  [N/A, ]
  176.     [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
  177.     [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
  178.     [C:\Program Files\Lenovo\幸福一键通\tgekb.dll]  [N/A, ]
  179.     [C:\Program Files\Lenovo\幸福一键通\XPNyGet.dll]  [N/A, ]
  180. [PID: 1740][C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe]  [, 1, 0, 0, 1]
  181.     [C:\Program Files\Lenovo\幸福一键通\CLxUI.dll]  [联想(北京)有限公司, 1, 0, 0, 1]
  182.     [C:\Program Files\Lenovo\幸福一键通\SKOSD.DLL]  [Silitek Corp., 1, 0, 6, 0]
  183.     [C:\Program Files\Lenovo\幸福一键通\SKUtil.DLL]  [Silitek Corp., 1, 0, 9, 0]
  184.     [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
  185.     [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
  186.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  187.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  188.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  189.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  190. [PID: 1752][C:\KAV2007\KAVStart.exe]  [Kingsoft Corporation, 2007, 8, 15, 289]
  191.     [C:\windows\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
  192.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  193.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  194.     [C:\windows\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
  195.     [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
  196.     [C:\KAV2007\SvcTimer.DLL]  [Kingsoft Corporation, 2006.12.22.84]
  197.     [C:\KAV2007\KAVPassp.dll]  [Kingsoft Corporation, 2006, 12, 30, 271]
  198.     [C:\KAV2007\PopSprt3.dll]  [Kingsoft Corporation, 2007, 3, 20, 48]
  199.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  200. [PID: 1784][C:\KAV2007\KPFW32.EXE]  [Kingsoft Corporation, 2007, 8, 17, 726]
  201.     [C:\windows\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
  202.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  203.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  204.     [C:\windows\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
  205.     [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
  206.     [C:\KAV2007\KAConfig.DLL]  [Kingsoft Corporation, 2007, 1, 11, 41]
  207.     [C:\KAV2007\FiltList.dll]  [N/A, ]
  208.     [C:\KAV2007\KAVPassp.DLL]  [Kingsoft Corporation, 2006, 12, 30, 271]
  209.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  210.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  211. [PID: 1848][C:\windows\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  212. [PID: 2028][C:\KAV2007\KMailMon.EXE]  [Kingsoft Corporation, 2007, 8, 16, 967]
  213.     [C:\KAV2007\KAntiSpm.dll]  [Kingsoft Corporation, 2007, 2, 25, 129]
  214.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  215.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  216.     [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
  217.     [C:\KAV2007\KAECall2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 7]
  218.     [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 6, 19, 64]
  219.     [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
  220.     [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 9, 17, 134]
  221.     [C:\KAV2007\KAConfig.DLL]  [Kingsoft Corporation, 2007, 1, 11, 41]
  222.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  223.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  224. [PID: 172][C:\DOCUME~1\rjzj.net\LOCALS~1\Temp\Rar$EX00.094\usbkill.exe]  [ooVista 软件团队, 8, 3, 0, 0]
  225.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  226.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  227.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  228.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  229. [PID: 996][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  230.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  231.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  232.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  233.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  234.     [C:\KAV2007\KAVAFish.DLL]  [Kingsoft Corporation, 2006, 10, 25, 27]
  235.     [C:\KAV2007\KAScript.DLL]  [Kingsoft Corporation, 2007, 3, 6, 75]
  236.     [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 6, 19, 64]
  237.     [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
  238.     [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 9, 17, 134]
  239.     [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
  240.     [C:\windows\system32\msdmo.dll]  [, ]
  241.     [C:\Program Files\Common Files\Ahead\DSFilter\NeSplitter.ax]  [Nero AG, 3,2,0,20c]
  242. [PID: 708][D:\杀毒日志\新建文件夹\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  243.     [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
  244.     [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  245.     [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  246.     [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2007, 3, 18, 241]
  247.     [D:\杀毒日志\新建文件夹\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

  248. ==================================
  249. 文件关联
  250. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  251. .EXE  OK. ["%1" %*]
  252. .COM  OK. ["%1" %*]
  253. .PIF  OK. ["%1" %*]
  254. .REG  OK. [regedit.exe "%1"]
  255. .BAT  OK. ["%1" %*]
  256. .SCR  OK. ["%1" /S]
  257. .CHM  OK. ["C:\windows\hh.exe" %1]
  258. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  259. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  260. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  261. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  262. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  263. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  264. ==================================
  265. Winsock 提供者
  266. N/A

  267. ==================================
  268. Autorun.inf
  269. N/A

  270. ==================================
  271. HOSTS 文件
  272. 127.0.0.1       localhost

  273. ==================================
  274. 进程特权扫描
  275. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1728, C:\PROGRAM FILES\LENOVO\幸福一键通\KBDRIVER.EXE]
  276. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1740, C:\PROGRAM FILES\LENOVO\幸福一键通\FLYSHUTTLE.EXE]
  277. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1784, C:\KAV2007\KPFW32.EXE]
  278. 特殊特权被允许: SeDebugPrivilege [PID = 2028, C:\KAV2007\KMAILMON.EXE]
  279. 特殊特权被允许: SeDebugPrivilege [PID = 172, C:\DOCUME~1\RJZJ.NET\LOCALS~1\TEMP\RAR$EX00.094\USBKILL.EXE]
  280. 特殊特权被允许: SeLoadDriverPrivilege [PID = 172, C:\DOCUME~1\RJZJ.NET\LOCALS~1\TEMP\RAR$EX00.094\USBKILL.EXE]

  281. ==================================
  282. API HOOK
  283. 入口点错误:LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: C:\KAV2007\KASocket.dll)

  284. ==================================
  285. 隐藏进程
  286. N/A

  287. ==================================
复制代码

作者: ldsystem    时间: 2007-10-6 08:34

看日志没什么问题,请搜索注册表,将查找到的msutl.exe键值全部删掉, 用AUTO病毒专杀扫描并免疫,再用SREng修复,最后用arswp清理,强烈建议楼主装微点...
相关软件请到这里下载
http://bbs.liulanghome.com/thread-49234-1-1.html
作者: 神雕大侠    时间: 2007-10-6 08:52     标题: 反馈,谢谢老大帮忙

1.已经利用RegWorkshop.exe 删除了msutl.exe相关键值共4处,不过删除后
有时还会出现一处键值目前发现,我电脑内以前收藏的WINRAR以及绿鹰万能
精灵安装程序无法安装,而重新下载的WINRAR以及绿鹰万能精灵安装程序可
以正常使用,还有优化大师单文件版重新下载的也可以使用,还有一种现象经
过压缩收藏的程序也可以正常使用

2.目前利用杀毒软件与arswp清理已经没有病毒报告,不过电脑中以前收藏的程序很
多都无法使用,启动它们防火墙会提示是否允许连网并且出现一个与msutl.exe相关
的注册表键值,这些应该是受到感染的文件吧?是否应该全部删除

3.请问老大如何查看SREng扫描日志有没有问题,有参照吗?

[ 本帖最后由 神雕大侠 于 2007-10-6 08:59 编辑 ]
作者: ldsystem    时间: 2007-10-6 09:38

如果被感染的EXE文件无法修复,那就只能删除了.
SREng扫描日志,可以借助SREngLog分析助手来看,不过这个助手只是给你项目分类,方便查看,但是不会自动分析,最终还是需要自己凭经验去分析判断....
相关软件请到这里下载
http://bbs.liulanghome.com/thread-49234-1-1.html




欢迎光临 IT家园 (http://bbs.it998.com/) Powered by Discuz! 7.2