我認為termsrv.dll被摧毀了。首先,從其他正常的XP-SP2中復制termsrv.dll(位於c:\windows\System32下)。再次檢查註冊表,查看HKEY _ local _ machine \ system \ current control set \ services \ TERM service \ parameters下的ServiceDll類型是否為REG_EXPAND_SZ,後面的數據是否為% systemroot % \ system32 \ termsrv.dll。如果沒有,請更正它(創建壹個新的擴展字符串)。
=======================================================================
完整的$ TermService註冊表如下所示:
另存為reg文件導入
Windows註冊表編輯器5.00版
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 001 \ Services \ term service]
" error control " = dword:00000001
" ObjectName"="LocalSystem "
" Start"=dword:00000003
" Description"= "允許多個用戶連接和控制壹臺機器,並在遠程計算機上顯示桌面和應用程序。這是遠程桌面(包括管理員遠程桌面)、快速用戶轉換、遠程協助和終端服務器的基礎設施。”
" DisplayName"= "終端服務"
" DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00,00,00
" Type"=dword:00000020
" ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73
00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,6b,00,20,00,44,00,43,00,\
6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 001 \ Services \ term service \ Parameters]
" ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,00,00
" Certificate"=hex:01,00,00,00,01,00,00,00,00,06,00,5c,00,52,53,41,31,\
48,00,00,00,00,02,00,00,3f,00,00,00,01,00,01,00,ff,5a,31,e7,24,74,29,89,6d,\
c6,94,fa,22,9b,9c,fe,bb,98,e0,8b,37,f9,e3,1f,c0,2c,a2,29,30,ed,c6,8a,06,74,\
61,61,1a,b9,a3,77,37,d0,eb,eb,ab,61,65,c2,c4,27,52,5c,bb,d1,87,0a,c2,79,a8,\
b6,b0,9b,b5,bd,00,00,00,00,00,00,00,00,08,00,48,00,b8,db,ea,c8,83,06,6d,8d,\
86,06,c7,46,66,17,1a,c9,89,67,97,57,5b,c9,dd,45,df,59,25,58,27,b4,57,4e,32,\
1c,02,03,aa,22,81,59,c6,2f,d0,1d,b7,c8,56,36,51,fb,44,51,89,13,b6,3c,ae,a8,\
2e,85,a8,40,d2,30,00,00,00,00,00,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 001 \ Services \ term service \ Performance]
"關閉" = "關閉對象"
“收集超時”=dword:000003e8
" Collect"="CollectTSObjectData "
“打開超時”=dword:000003e8
" Open " = " OpenTSObject "
" Library"="perfts.dll "
"最後壹個計數器" =dword:00000886
"最後的幫助" =dword:00000887
“第壹計數器”=dword:00000806
“第壹次幫助”=dword:00000807
"對象列表" ="2054 2176 2054 2176 "
“庫驗證碼”=十六進制:00,40,b2,d3,5c,e7,a8,01,00,30,00,00,00,00,00,00,00
" WbemAdapFileSignature"=hex:f5,d 1.57,f 1.28,23,81,b9,d3,e6,83,68,2d,64,70,47
" WbemAdapFileTime " =十六進制:00,40,b2,d3,5c,e7,a8,01
" WbemAdapFileSize " = dword:00003000
" WbemAdapStatus"=dword:00000000
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 001 \ Services \ term service \ Enum]
" 0 " = " Root \ \ LEGACY _ TERMSERVICE \ \ 0000 "
" Count"=dword:00000001
" next instance " = dword:0000001
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 002 \ Services \ term service]
" error control " = dword:00000001
" ObjectName"="LocalSystem "
" Start"=dword:00000003
" Description"= "允許多個用戶連接和控制壹臺機器,並在遠程計算機上顯示桌面和應用程序。這是遠程桌面(包括管理員遠程桌面)、快速用戶轉換、遠程協助和終端服務器的基礎設施。”
" DisplayName"= "終端服務"
" DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00,00,00
" Type"=dword:00000020
" ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73
00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,6b,00,20,00,44,00,43,00,\
6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 002 \ Services \ term service \ Parameters]
" ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,00,00
" Certificate"=hex:01,00,00,00,01,00,00,00,00,06,00,5c,00,52,53,41,31,\
48,00,00,00,00,02,00,00,3f,00,00,00,01,00,01,00,ff,5a,31,e7,24,74,29,89,6d,\
c6,94,fa,22,9b,9c,fe,bb,98,e0,8b,37,f9,e3,1f,c0,2c,a2,29,30,ed,c6,8a,06,74,\
61,61,1a,b9,a3,77,37,d0,eb,eb,ab,61,65,c2,c4,27,52,5c,bb,d1,87,0a,c2,79,a8,\
b6,b0,9b,b5,bd,00,00,00,00,00,00,00,00,08,00,48,00,b8,db,ea,c8,83,06,6d,8d,\
86,06,c7,46,66,17,1a,c9,89,67,97,57,5b,c9,dd,45,df,59,25,58,27,b4,57,4e,32,\
1c,02,03,aa,22,81,59,c6,2f,d0,1d,b7,c8,56,36,51,fb,44,51,89,13,b6,3c,ae,a8,\
2e,85,a8,40,d2,30,00,00,00,00,00,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ control set 002 \ Services \ term service \ Performance]
"關閉" = "關閉對象"
“收集超時”=dword:000003e8
" Collect"="CollectTSObjectData "
“打開超時”=dword:000003e8
" Open " = " OpenTSObject "
" Library"="perfts.dll "
"最後壹個計數器" =dword:00000886
"最後的幫助" =dword:00000887
“第壹計數器”=dword:00000806
“第壹次幫助”=dword:00000807
"對象列表" ="2054 2176 2054 2176 "
“庫驗證碼”=十六進制:00,40,b2,d3,5c,e7,a8,01,00,30,00,00,00,00,00,00,00
" WbemAdapFileSignature"=hex:f5,d 1.57,f 1.28,23,81,b9,d3,e6,83,68,2d,64,70,47
" WbemAdapFileTime " =十六進制:00,40,b2,d3,5c,e7,a8,01
" WbemAdapFileSize " = dword:00003000
" WbemAdapStatus"=dword:00000000
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ current control set \ Services \ term service]
" error control " = dword:00000001
" ObjectName"="LocalSystem "
" Start"=dword:00000003
" Description"= "允許多個用戶連接和控制壹臺機器,並在遠程計算機上顯示桌面和應用程序。這是遠程桌面(包括管理員遠程桌面)、快速用戶轉換、遠程協助和終端服務器的基礎設施。”
" DisplayName"= "終端服務"
" DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00,00,00
" Type"=dword:00000020
" ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73
00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,6b,00,20,00,44,00,43,00,\
6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ current control set \ Services \ term service \ Parameters]
" ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,00,00
" Certificate"=hex:01,00,00,00,01,00,00,00,00,06,00,5c,00,52,53,41,31,\
48,00,00,00,00,02,00,00,3f,00,00,00,01,00,01,00,ff,5a,31,e7,24,74,29,89,6d,\
c6,94,fa,22,9b,9c,fe,bb,98,e0,8b,37,f9,e3,1f,c0,2c,a2,29,30,ed,c6,8a,06,74,\
61,61,1a,b9,a3,77,37,d0,eb,eb,ab,61,65,c2,c4,27,52,5c,bb,d1,87,0a,c2,79,a8,\
b6,b0,9b,b5,bd,00,00,00,00,00,00,00,00,08,00,48,00,b8,db,ea,c8,83,06,6d,8d,\
86,06,c7,46,66,17,1a,c9,89,67,97,57,5b,c9,dd,45,df,59,25,58,27,b4,57,4e,32,\
1c,02,03,aa,22,81,59,c6,2f,d0,1d,b7,c8,56,36,51,fb,44,51,89,13,b6,3c,ae,a8,\
2e,85,a8,40,d2,30,00,00,00,00,00,00,00,00,00
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ current control set \ Services \ term service \ Performance]
"關閉" = "關閉對象"
“收集超時”=dword:000003e8
" Collect"="CollectTSObjectData "
“打開超時”=dword:000003e8
" Open " = " OpenTSObject "
" Library"="perfts.dll "
"最後壹個計數器" =dword:00000886
"最後的幫助" =dword:00000887
“第壹計數器”=dword:00000806
“第壹次幫助”=dword:00000807
"對象列表" ="2054 2176 2054 2176 "
“庫驗證碼”=十六進制:00,40,b2,d3,5c,e7,a8,01,00,30,00,00,00,00,00,00,00
" WbemAdapFileSignature"=hex:f5,d 1.57,f 1.28,23,81,b9,d3,e6,83,68,2d,64,70,47
" WbemAdapFileTime " =十六進制:00,40,b2,d3,5c,e7,a8,01
" WbemAdapFileSize " = dword:00003000
" WbemAdapStatus"=dword:00000000
[HKEY _ LOCAL _ MACHINE \ SYSTEM \ current control set \ Services \ term service \ Enum]
" 0 " = " Root \ \ LEGACY _ TERMSERVICE \ \ 0000 "
" Count"=dword:00000001
" next instance " = dword:0000001