主要状况:杀毒软件不能使用,防火墙关闭。其它一切正常,安全模式也能进入。
% ]3 c& v# ^2 \ A& [9 ^' I这是扫描报告:
5 I9 D5 Q, h8 n. ]$ F0 a[CODE]
/ x: t( a( [' H; Z2008-06-15,17:11:15
. K; @2 n. r' _+ Q$ }
System Repair Engineer 2.5.16.900
0 X& d+ F2 N8 A5 V3 V$ e
Smallfrogs (
http://www.KZTechs.com)
5 Q$ T0 m' v/ @7 q3 \) aWindows Vista Home Basic Edition (Build 6000) - 管理权限用户 - 完整功能
* a6 g! `# ?& W1 m以下内容被选中:
" g8 B: T( S2 j4 S5 K- _! t
所有的启动项目(包括注册表、启动文件夹、服务等)
B( g+ E6 Q! e% m# V/ `* W
浏览器加载项
" D/ t: I& c8 Z/ G& W* a
正在运行的进程(包括进程模块信息)
, {6 [( I* {6 h: P 文件关联
, y# s9 k! L2 G Winsock 提供者
) G8 n6 p1 z8 U' s- B; N/ w! z
Autorun.inf
! Z. R6 o7 x+ [4 b+ }
HOSTS 文件
7 E. V+ h; d D, Z3 o& w# o 进程特权扫描
. y, |0 E& L! p! s" X7 Y
- I, s5 W/ }$ K$ J启动项目
. q7 h/ b0 d# R9 C5 \
注册表
" `1 u# i+ V2 S, ^1 j, J[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
* [5 Q; j' ]$ m, x# S3 l <Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun> [(Verified)]
$ ~- P2 n8 W0 Z- Q- Q% U <KavPFW><"D:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPFW32.EXE" -startup> [Kingsoft Corporation]
; j* b) b% ]0 Y, I3 s5 K/ e, T5 F <Power2GoExpress><; "d:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup> [Cyberlink]
# ^3 `1 f/ {% R" e5 M j3 C2 ]8 R# I
<QQ2009><; "d:\Program Files\Tencent\QQ2009\Bin\QQ.exe" /background> [Tencent]
. y) U2 }8 `. B3 Q j/ ]/ ? s[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
( u1 ^; t# W' D
<load><> [N/A]
' Q$ K0 b- r3 V/ O1 C9 s$ O; h* S1 l
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
/ L! ?; Z, y/ b* P: F3 V <Windows Defender><%ProgramFiles%\Windows Defender\MSASCui.exe -hide> [(Verified)]
, A. d$ J5 @" X0 G+ ~* A" E <EnergyCut><d:\Program Files\Lenovo\EnergyCut\EnergyCut.exe> [联想(北京)有限公司]
/ S- D5 d6 A$ O2 \: N7 b! ^# J
<EnergyUtility><d:\Program Files\Lenovo\EnergyCut\utilty.exe> [TODO: <Company name>]
6 {7 I/ [# E! S i9 ^, s$ v <EzButton><D:\PROGRA~1\EzButton\EzButton.EXE> [Dritek System Inc.]
9 W# U. y1 x6 F
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
$ w4 P' q- X$ ` <MSConfig><"C:\Windows\system32\msconfig.exe" /auto> [(Verified)]
- J* o; L. I2 X$ E; ^( {5 _
<NvSvc><RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart> [NVIDIA Corporation]
8 O6 ~2 H/ ^4 F <NvCplDaemon><RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
4 r* b: M- r/ Q/ [+ h& S; Z7 G$ [
<NvMediaCenter><RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
3 k# r* z8 {" K8 k
<!AVG Anti-Spyware><"D:\Program Files\AVG Anti-Spyware 7.5\Cnavgas.exe" /minimized> [GRISOFT s.r.o.]
5 M M \# h" ` <360Safetray><d:\Program Files\360safe\safemon\360tray.exe /start> [奇虎网]
2 ~6 I: m! {! H( [# A& I1 n
<KavStart><"d:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [Kingsoft Corporation]
$ C9 E5 U- |* C2 ?/ r" |
<360Antiarp><D:\Program Files\360safe\antiarp\antiarp.exe /start> [360安全中心]
4 e- c2 E/ t9 U! _: q+ p
<ALUAlert><; C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe> [N/A]
& p& t; x- {% P' o6 ]9 T <Apoint><; C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
, d% P- T1 h8 `* e7 H0 T
<ccApp><; "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [N/A]
! F) ~" _0 n6 t/ o9 o0 J+ i3 l
<miniqqlive><; "d:\Program Files\Tencent\QQLive\MiniQQLive.exe"> [Tencent]
2 Z' D! m H* K2 ^5 N& I
<PCMService><; "C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe"> [CyberLink Corp.]
/ W, u I5 x. j1 P- a) b6 o+ o4 s- L: K1 W
<RtHDVCpl><; RtHDVCpl.exe> [Realtek Semiconductor]
9 J0 q$ |/ c( X& D4 |
<Storm2Set><; C:\Windows\system32\rundll32.exe "d:\PROGRA~1\StormII\StormSet.dll",CheckEnv> [N/A]
0 A$ l5 l# b& |4 s( U ? <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
: B- X( O9 x B! N2 l
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
, x& C2 q9 E: C) Q& k: t
<shell><Explorer.exe> [(Verified)]
* [* b% W" T* j1 a3 e
<Userinit><C:\Windows\system32\UserInit.exe,> [(Verified)]
4 L. G, \/ H( g5 t2 N9 t" x5 T[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
1 ~4 r! r$ Q, w) L7 F
<AppInit_DLLs><> [N/A]
6 b' Z+ G8 Q5 _1 l) v5 U1 A[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
8 C8 c4 @0 g: K0 x8 n <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
6 l, z; R$ X( m4 R4 D3 r" W
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
5 Y8 F( b/ G* r <Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [N/A]
) b) p, w, a5 v( ^==================================
+ H/ J k j @' S; w( \
启动文件夹
. |* M+ V$ o {6 F1 G
[AutoCAD 启动加速器]
2 t$ X2 D0 w* k3 J; I <C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
/ ]! _7 {! Z3 S1 ^( @5 A& u4 b9 e[AutoCAD 启动加速器]
% t y) X1 V7 G" ~. f8 B8 _
<C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
|1 k, i- c2 k+ n# a/ h$ u8 V7 c==================================