查看: 4882|回复: 12
收起左侧

我修改的启动项怎么又回复到原来了

[复制链接]
fanuq
发表于 2007-5-22 22:38:50 | 显示全部楼层 |阅读模式
我曾用运行的msconfig修改了启动项。禁止了很多没用的进程。今天我运行System Repair Engineer (SREng)后看到了3个带颜色的启动,刷新后就都没有了。原后看msconfig和优化大师中的启动项都回来了,是不是种病毒了?
wangjay1980
发表于 2007-5-22 23:39:11 | 显示全部楼层
既然有SRE,就扫个报告
fanuq
 楼主| 发表于 2007-5-23 07:55:50 | 显示全部楼层

回复 #2 wangjay1980 的帖子

那三个蓝色的进程是WPDshserviceObj;winlogonNotify:Navlogon和winlogonNotify:wgalogon
我同时把报告也上传了

20070523.rar

6.52 KB, 下载次数: 55

wangjay1980
发表于 2007-5-23 09:22:15 | 显示全部楼层


  1. 2007-05-23,07:47:22

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <ApabiAgent><; "d:\Program Files\Founder\Apabi Reader 3.0\ApabiAgent.exe">  []
  18.     <Super Rabbit IEPro><; D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [N/A]
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  20.     <run><>  [N/A]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  22.     <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  23.     <Logitech Hardware Abstraction Layer><; KHALMNPR.EXE>  [N/A]
  24.     <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
  25.     <vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe>  [(Verified)Symantec Corporation]
  26.     <Babylon Client><; D:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart>  [Babylon Ltd.]
  27.     <DAEMON Tools-2052><"D:\Program Files\D-Tools\daemon.exe"  -lang 2052>  [DAEMON'S HOME]
  28.     <HControl><; C:\WINDOWS\ATK0100\HControl.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  29.     <High Definition Audio 属性页快捷方式><; HDAShCut.exe>  [(Verified)Microsoft Windows XP Publisher]
  30.     <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  31.     <KsgUpdateRun><; C:\Program Files\Common Files\Kingsoft\KSG\client.exe>  [N/A]
  32.     <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  33.     <nwiz><; nwiz.exe /install>  []
  34.     <Power_Gear><; C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1>  [N/A]
  35.     <runeip><; C:\Program Files\Rising\AntiSpyware\runiep.exe>  [N/A]
  36.     <SMSERIAL><; C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  37.     <StormCodec_Helper><; "D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
  38.     <switch><; c:\windows\system32\壁纸自动换.exe>  []
  39.     <SynTPEnh><; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  40.     <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [N/A]
  41.     <LiveUpatePower><rem MyUpdate.exe>  [N/A]
  42. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  43.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  44.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
  45. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  46.     <AppInit_DLLs><>  [N/A]
  47. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  48.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  50.     <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
  52.     <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  [(Verified)Symantec Corporation]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
  54.     <WinlogonNotify: WgaLogon><WgaLogon.dll>  [(Verified)Microsoft Corporation]
  55. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  56.     <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
  57. [HKEY_CURRENT_USER\Control Panel\Desktop]
  58.     <SCRNSAVE.EXE><C:\WINDOWS\system32\梦幻水~1.SCR>  []

  59. ==================================
  60. 启动文件夹
  61. N/A

  62. ==================================
  63. 服务
  64. [Symantec Event Manager / ccEvtMgr][Running/Auto Start]
  65.   <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
  66. [Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
  67.   <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
  68. [Symantec Settings Manager / ccSetMgr][Running/Auto Start]
  69.   <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
  70. [Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
  71.   <"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
  72. [Human Interface Device Access / HidServ][Stopped/Disabled]
  73.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  74. [LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
  75.   <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
  76. [MazeSvr / MazeSvr][Running/Auto Start]
  77.   <D:\Program Files\天网Maze\MazeSvr.exe><N/A>
  78. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  79.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
  80. [SavRoam / SavRoam][Stopped/Manual Start]
  81.   <"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
  82. [Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
  83.   <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
  84. [Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
  85.   <"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
  86. [Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
  87.   <"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>

  88. ==================================
  89. 驱动程序
  90. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  91.   <system32\drivers\ac97intc.sys><Intel Corporation>
  92. [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
  93.   <system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
  94. [AliIde / AliIde][Running/Boot Start]
  95.   <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  96. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  97.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  98. [bootdrv / bootdrv][Stopped/Boot Start]
  99.   <\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
  100. [CmdIde / CmdIde][Running/Boot Start]
  101.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  102. [d347bus / d347bus][Running/Boot Start]
  103.   <\SystemRoot\system32\DRIVERS\d347bus.sys><>
  104. [Symantec Eraser Control driver / eeCtrl][Running/System Start]
  105.   <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
  106. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  107.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  108. [Microsoft 用于 High Definition Audio 服务的 UAA 功能驱动程序 / HdAudAddService][Stopped/Manual Start]
  109.   <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
  110. [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  111.   <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
  112. [Logitech SetPoint USB Receiver device driver / LHidUsbK][Stopped/Manual Start]
  113.   <System32\Drivers\LHidUsbK.Sys><Logitech, Inc.>
  114. [Logitech SetPoint Mouse Filter Driver / LMouKE][Stopped/Manual Start]
  115.   <System32\Drivers\LMouKE.sys><N/A>
  116. [ATK0100 ACPI UTILITY / MTsensor][Running/Manual Start]
  117.   <system32\DRIVERS\ATKACPI.sys><>
  118. [NAVENG / NAVENG][Running/Manual Start]
  119.   <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070521.019\naveng.sys><Symantec Corporation>
  120. [NAVEX15 / NAVEX15][Running/Manual Start]
  121.   <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070521.019\navex15.sys><Symantec Corporation>
  122. [npkcrypt / npkcrypt][Running/Auto Start]
  123.   <\??\D:\Program Files\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  124. [nv / nv][Running/Manual Start]
  125.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  126. [PnpWmkDrv / PnpWmkDrv][Running/System Start]
  127.   <\??\C:\WINDOWS\system32\drivers\PnpWmkDrv.sys><N/A>
  128. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  129.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  130. [rclili / rclili][Stopped/Boot Start]
  131.   <\SystemRoot\System32\drivers\rclili.sys><N/A>
  132. [rimmptsk / rimmptsk][Running/Manual Start]
  133.   <system32\DRIVERS\rimmptsk.sys><REDC>
  134. [rimsptsk / rimsptsk][Running/Manual Start]
  135.   <system32\DRIVERS\rimsptsk.sys><REDC>
  136. [Ricoh xD-Picture Card Driver / rismxdp][Running/Manual Start]
  137.   <system32\DRIVERS\rixdptsk.sys><REDC>
  138. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  139.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
  140. [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  141.   <system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
  142. [SAVRT / SAVRT][Running/System Start]
  143.   <\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
  144. [SAVRTPEL / SAVRTPEL][Running/System Start]
  145.   <\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
  146. [Secdrv / Secdrv][Stopped/Manual Start]
  147.   <system32\DRIVERS\secdrv.sys><N/A>
  148. [SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  149.   <system32\DRIVERS\smcirda.sys><SMC>
  150. [smserial / smserial][Running/Manual Start]
  151.   <system32\DRIVERS\smserial.sys><Motorola Inc.>
  152. [SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
  153.   <\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
  154. [sptd / sptd][Running/Boot Start]
  155.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  156. [SymEvent / SymEvent][Running/Manual Start]
  157.   <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
  158. [SYMREDRV / SYMREDRV][Running/Manual Start]
  159.   <\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
  160. [SYMTDI / SYMTDI][Running/System Start]
  161.   <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
  162. [Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  163.   <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
  164. [vaxscsi / vaxscsi][Running/Manual Start]
  165.   <\SystemRoot\System32\Drivers\vaxscsi.sys><N/A>
  166. [Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
  167.   <system32\DRIVERS\w39n51.sys><Intel? Corporation>

  168. ==================================
  169. 浏览器加载项
  170. [ThunderAtOnce Class]
  171.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  172. [Thunder Browser Helper]
  173.   {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  174. [AcroIEHlprObj Class]
  175.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  176. [AcroIEToolbarHelper Class]
  177.   {AE7CD045-E861-484f-8273-0445EE161910} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
  178. [Adobe PDF]
  179.   {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
  180. [SSReaderPlug]
  181.   {1DE88635-1C72-401E-B23B-93FA86D30F3B} <C:\WINDOWS\system32\ssreaderplug.dll, 北京超星>
  182. [Microsoft Outlook 8.0 Object Library]
  183.   {0006F033-0000-0000-C000-000000000046} <, N/A>
  184. [Microsoft Office Outlook]
  185.   {0006F03A-0000-0000-C000-000000000046} <, N/A>
  186. [ThunderAtOnce Class]
  187.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  188. [Thunder Browser Helper]
  189.   {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  190. [AcroIEHlprObj Class]
  191.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  192. [PeerDraw Class]
  193.   {10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\WINDOWS\system32\dllcache\vgx.dll, Microsoft Corporation>
  194. [Windows Genuine Advantage Validation Tool]
  195.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
  196. [SSReaderPlug]
  197.   {1DE88635-1C72-401E-B23B-93FA86D30F3B} <C:\WINDOWS\system32\ssreaderplug.dll, 北京超星>
  198. [Windows Media Player]
  199.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  200. [HTML Document]
  201.   {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
  202. [XML DOM Document]
  203.   {2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  204. [DHTML Edit Control Safe for Scripting for IE5]
  205.   {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation>
  206. [SSReaderPlug Control]
  207.   {3359C0B1-2363-40B3-AFCA-1ABC799AC486} <C:\WINDOWS\system32\SSREAD~1.OCX, CX>
  208. [Adobe PDF]
  209.   {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
  210. [XML Document]
  211.   {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  212. [Thunder Agent Class]
  213.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  214. [Shell Name Space]
  215.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
  216. [WUWebControl Class]
  217.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  218. [Windows Media Player]
  219.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  220. [Active Desktop Mover]
  221.   {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
  222. [Microsoft Web Browser]
  223.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
  224. [Thunder Browser Helper]
  225.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  226. [XML DOM Document 4.0]
  227.   {88D969C0-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
  228. [AcroIEToolbarHelper Class]
  229.   {AE7CD045-E861-484F-8273-0445EE161910} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
  230. [RDS.DataSpace]
  231.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  232. [CheckReader Class]
  233.   {C9E75CAD-ACA5-4074-81CC-5448FCCFE987} <d:\Program Files\Founder\Apabi Reader 3.0\Check.dll, >
  234. [AUDIO__MP3 Moniker Class]
  235.   {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  236. [AUDIO__X_MS_WMA Moniker Class]
  237.   {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  238. [VIDEO__X_MS_ASF Moniker Class]
  239.   {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  240. [RealPlayer G2 Control]
  241.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
  242. [Shockwave Flash Object]
  243.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  244. [QuickTimeCheck Class]
  245.   {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <D:\Program Files\Ringz Studio\Storm Codec\QTSystem\QTCheck.ocx, Apple Computer, Inc.>
  246. [RevealTrans]
  247.   {E31E87C4-86EA-4940-9B8A-5BD5D179A737} <C:\WINDOWS\system32\Dxtmsft.dll, Microsoft Corporation>
  248. [XML HTTP Request]
  249.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  250. [XML DOM Document 3.0]
  251.   {F5078F32-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  252. [XML HTTP 3.0]
  253.   {F5078F35-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  254. [XML DOM Document]
  255.   {F6D90F11-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  256. [XML HTTP]
  257.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
  258. [使用迅雷下载]
  259.   <D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
  260. [使用迅雷下载全部链接]
  261.   <D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
  262. [转换为 Adobe PDF]
  263.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
  264. [转换为现有 PDF]
  265.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
  266. [转换选定的链接为 Adobe PDF]
  267.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
  268. [转换选定的链接为现有 PDF]
  269.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
  270. [转换选项为 Adobe PDF]
  271.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
  272. [转换选项为现有 PDF]
  273.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
  274. [转换链接目标为 Adobe PDF]
  275.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
  276. [转换链接目标为现有 PDF]
  277.   <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>

  278. ==================================
  279. 正在运行的进程
  280. [PID: 1392][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  281. [PID: 1440][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  282. [PID: 1472][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  283.     [C:\WINDOWS\system32\WgaLogon.dll]  [Microsoft Corporation, 1.7.0018.5]
  284.     [C:\WINDOWS\system32\NavLogon.dll]  [Symantec Corporation, 10.0.0.359]
  285.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  286. [PID: 1516][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  287.     [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
  288. [PID: 1528][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  289. [PID: 3436][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  290.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  291.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  292.     [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  293.     [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  294.     [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  295.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  296.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  297.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  298.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
  299.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  300.     [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
  301.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
  302.     [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  303.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  304. [PID: 3648][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 103.5.1.9]
  305.     [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  306.     [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  307.     [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  [Symantec Corporation, 103.5.1.9]
  308.     [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 103.5.1.9]
  309.     [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 103.5.1.9]
  310.     [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  [Symantec Corporation, 103.5.1.9]
  311.     [C:\WINDOWS\system32\SYMREDIR.DLL]  [Symantec Corporation, 5.5.1.6]
  312.     [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 103.5.1.9]
  313.     [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 103.5.1.9]
  314.     [C:\Program Files\Symantec AntiVirus\SavEmail.dll]  [Symantec Corporation, 10.0.0.359]
  315. [PID: 3656][C:\PROGRA~1\SYMANT~1\VPTray.exe]  [Symantec Corporation, 10.0.0.359]
  316.     [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  317.     [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  318.     [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.5.0.44]
  319.     [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 10.0.0.359]
  320.     [C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  [Symantec Corporation, 10.0.0.359]
  321.     [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  [Symantec Corporation, 10.0.0.359]
  322.     [C:\WINDOWS\system32\nts.dll]  [Intel? Corporation, 6.12.0.130 E]
  323.     [C:\WINDOWS\system32\cba.dll]  [Intel? Corporation, 6.12.0.130 E]
  324.     [C:\WINDOWS\system32\MsgSys.dll]  [Intel? Corporation, 6.12.0.130 E]
  325.     [C:\WINDOWS\system32\PDS.DLL]  [Intel? Corporation, 6.12.0.130 E]
  326. [PID: 3696][D:\Program Files\D-Tools\daemon.exe]  [DAEMON'S HOME, 3.47.0.0]
  327.     [C:\WINDOWS\daemon.dll]  [, 3.47.0.0]
  328.     [D:\Program Files\D-Tools\PFCTOC.DLL]  [Padus(R), Inc., 1, 0, 0, 12]
  329.     [D:\Program Files\D-Tools\Plugins\Images\ccdmount.dll]  [GENERIC, 1.02.0.0]
  330.     [D:\Program Files\D-Tools\Plugins\Images\mdsmount.dll]  [GENERIC, 1.01.0.0]
  331.     [D:\Program Files\D-Tools\Plugins\Images\pdimount.dll]  [GENERIC, 1.01.0.0]
  332.     [D:\Program Files\D-Tools\Plugins\Images\nrgmount.dll]  [GENERIC, 1.02.0.0]
  333.     [D:\Program Files\D-Tools\Plugins\Images\bw5mount.dll]  [, 1.0.2.0]
  334. [PID: 3832][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  335. [PID: 4076][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
  336.     [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
  337. [PID: 1624][D:\Program Files\Babylon\Babylon-Pro\Babylon.exe]  [Babylon Ltd., 6.0.0.27]
  338.     [D:\Program Files\Babylon\Babylon-Pro\BException.dll]  [Babylon Ltd., 6.0.0.27]
  339.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  340.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  341.     [D:\Program Files\Babylon\Babylon-Pro\BabyServices.DLL]  [Babylon Ltd., 6.0.0.27]
  342.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  343.     [D:\Program Files\Babylon\Babylon-Pro\BContentServer.DLL]  [Babylon Ltd., 6.0.0.27]
  344.     [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  345. [PID: 3160][D:\Program Files\完美卸载V2007 完整版\MainCon.exe]  [, 20.xx.xx]
  346.     [D:\Program Files\完美卸载V2007 完整版\SkinMagic.dll]  [Appspeed Inc., 2, 4, 1, 1]
  347.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  348.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  349.     [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  350.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  351.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  352.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  353. [PID: 300][D:\Program Files\完美卸载V2007 完整版\MyUpdate.exe]  [, 2.0.0.0]
  354.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  355.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  356.     [D:\Program Files\完美卸载V2007 完整版\SkinMagic.dll]  [Appspeed Inc., 2, 4, 1, 1]
  357.     [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  358.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  359. [PID: 2540][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  360.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  361.     [C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  362.     [C:\WINDOWS\system32\IEUI.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
  363.     [C:\WINDOWS\system32\xmllite.dll]  [Microsoft Corporation, 1.00.1018.0]
  364.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  365.     [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
  366.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  367.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  368.     [D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.0.4]
  369.     [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
  370.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
  371.     [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  372.     [D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll]  [Adobe Systems Incorporated, 7.0.0.0]
  373.     [C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
  374.     [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  375.     [D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.CHS]  [Adobe Systems Incorporated, 7.0.0.0]
  376.     [C:\WINDOWS\system32\ieapfltr.dll]  [Microsoft Corporation, 7.0.6000.16461]
  377.     [C:\WINDOWS\system32\msfeeds.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  378.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  379.     [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
  380. [PID: 2024][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
  381.     [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  382.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  383.     [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  384.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]
  385.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  386.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  387.     [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  388. [PID: 1040][C:\DOCUME~1\asus\LOCALS~1\Temp\Rar$EX00.703\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  389.     [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
  390.     [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
  391.     [D:\Program Files\Babylon\Babylon-Pro\CAPTLIB.DLL]  [Babylon Ltd., 6.0.0.27]

  392. ==================================
  393. 文件关联
  394. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  395. .EXE  OK. ["%1" %*]
  396. .COM  OK. ["%1" %*]
  397. .PIF  OK. ["%1" %*]
  398. .REG  OK. [regedit.exe "%1"]
  399. .BAT  OK. ["%1" %*]
  400. .SCR  OK. ["%1" /S]
  401. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  402. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  403. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  404. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  405. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  406. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  407. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  408. ==================================
  409. Winsock 提供者
  410. N/A

  411. ==================================
  412. Autorun.inf
  413. N/A

  414. ==================================
  415. HOSTS 文件
  416. N/A

  417. ==================================
  418. API HOOK
  419. N/A

  420. ==================================
  421. 隐藏进程
  422. N/A

  423. ==================================


复制代码
wangjay1980
发表于 2007-5-23 09:27:07 | 显示全部楼层
没问题,不过确实启动项太多,你可以直接用SRE去掉一些软件的启动项。
fanuq
 楼主| 发表于 2007-5-25 21:20:51 | 显示全部楼层
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion下所有以“run”开头的键值;
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion下所有以“run”开头的键值;
HKEY-USERS\Default\Software\Microsoft\Windows\CurrentVersion下所有以“run”开头的键值。
启动项除了这三个还有哪些,怎么改呢?
fanuq
 楼主| 发表于 2007-5-25 22:09:56 | 显示全部楼层
我的启动改为:不知道还有什么可以删的不?
Iceword启动组.jpg
shuipao
发表于 2007-5-25 22:21:21 | 显示全部楼层
你以前中过毒吗?有几个驱动感觉像是病毒残留。
xffsfy
发表于 2007-5-26 10:21:07 | 显示全部楼层
是比较多....
有些自启动项(比如real)会自己恢复,比较郁闷

[ 本帖最后由 xffsfy 于 2007-5-26 10:22 编辑 ]
fanuq
 楼主| 发表于 2007-6-4 07:25:13 | 显示全部楼层

回复 #8 shuipao 的帖子

中过病毒,那怎样才能把病毒残留去掉呢?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-9 21:54 , Processed in 0.148089 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表