飞跃哥哥,上一贴是修复后用HB扫描出来的,这个是用SRE扫描出来的!你指导一下正确否?
2005-12-11,17:47:40
System Repair Engineer 1.1.0.269
Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SKYNET Personal FireWall><C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RealTray><; C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\System32\Userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\Bluewater\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><N/A>
==================================
浏览器加载项
[@shdoclc.dll,-866]
<>
[电台(&R)]
<C:\WINDOWS\System32\msdxm.ocx>
[AxInputControl Class]
<C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL>
[Shockwave Flash
Object]
<C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm>
==================================
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 596][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 628][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 672][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 684][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 840][C:\WINDOWS\System32\Ati2evxx.exe] <N/A><N/A>
[C:\WINDOWS\System32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2494>
[PID: 864][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 988][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1136][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1216][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1380][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1676][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] <N/A><2, 0, 5, 1031>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[PID: 1864][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] <ATI Technologies, Inc.><6.14.10.5113>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] <ATI Technologies, Inc.><6.14.10.5113>
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] <ATI Technologies, Inc.><6.14.10.5113>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] <ATI Technologies, Inc.><6.14.10.5113>
[PID: 1880][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.1622>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 1888][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] < ><2, 0, 0, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] <N/A><2, 0, 5, 1031>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll] <N/A><1, 0, 0, 5>
[PID: 1896][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] <Yahoo!><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] <Yahoo><1, 0, 0, 2>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] <Yahoo><1, 0, 1, 1006>
[PID: 1904][C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe] <广州众达天网技术有限公司><2.7.7.1000>
[C:\PROGRA~1\SKYNET\FIREWALL\SKYMISC.DLL] <N/A><N/A>
[C:\PROGRA~1\SKYNET\FIREWALL\COMPRESSWRAP.DLL] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 1912][C:\Program Files\CNNIC\Cdn\cdnup.exe] <N/A><2, 2, 0, 2>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 1936][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 1840][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] <N/A><2, 0, 5, 1031>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 1464][C:\WINDOWS\notepad.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 304][D:\HB\HijackThis1991汉化版\HijackThis1991zww.exe] <Soeperman Enterprises Ltd.><1.99.0001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 472][C:\WINDOWS\System32\notepad.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 1784][D:\HB\SREng.exe] <Smallfrogs Studio><1.1.0.269>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP OK. [C:\WINDOWS\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [notepad.exe %1]
==================================