【回复“花落花又开”的帖子】
IE修复工具我没用
这是我用SREng扫的
2005-12-03,20:09:14
System Repair Engineer 1.1.0.269
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<vptray><C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AddrPlus><; RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll,Rundll32>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><; SOUNDMAN.EXE>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<迅雷4><; C:\迅雷(Thunder) 4.5.1.35 完全绿\MediaIssue\TDUpdate.exe>
==================================
启动文件夹
[内存扫把]
<C:\Documents and Settings\user\「开始」菜单\程序\启动\内存扫把.lnk><N>
==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk, Inc.>
[DefWatch / DefWatch]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Symantec AntiVirus Client / Norton AntiVirus Server]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[StdService / StdService]
<C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\STDSVER.DLL,Service><N/A>
==================================
浏览器加载项
[ThunderIEHelper Class]
<C:\WINDOWS\system32\xunleibho_v8.dll>
[QQBrowserHelper
Object Class]
<C:\Program Files\Tencent\QQ\QQIEHelper.dll>
[DragSearch BHO]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[std software]
<C:\WINDOWS\SYSTEM32\stdup.dll>
[IeCatch2 Class]
<C:\PROGRA~1\FLASHGET\jccatch.dll>
[浩方对战平台]
<D:\wc3\浩方对战平台\GameClient.exe>
[QQ]
<C:\Program Files\Tencent\QQ\QQ.EXE>
[QQIEFloatBarCfgCmd Class]
<C:\Program Files\Tencent\QQ\QQIEHelper.dll>
[ThunderIEHelper Class]
<C:\WINDOWS\system32\xunleibho_v8.dll>
[QQBrowserHelper
Object Class]
<C:\Program Files\Tencent\QQ\QQIEHelper.dll>
[DragSearch BHO]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[std software]
<C:\WINDOWS\SYSTEM32\stdup.dll>
[IeCatch2 Class]
<C:\PROGRA~1\FLASHGET\jccatch.dll>
[Shockwave Flash
Object]
<C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx>
[&使用迅雷下载]
<C:\迅雷(Thunder) 4.5.1.35 完全绿\geturl.htm>
[&使用迅雷下载全部链接]
<C:\迅雷(Thunder) 4.5.1.35 完全绿\getallurl.htm>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm>
[使用IS下载]
<>
[使用网际快车下载]
<C:\Program Files\FlashGet\jc_link.htm>
[使用网际快车下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm>
==================================
正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 512][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\NavLogon.dll] <N/A><N/A>
[PID: 556][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 576][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 784][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 844][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 900][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 976][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1216][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[PID: 1316][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1492][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] <Autodesk, Inc.><2.51.000>
[PID: 1528][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><8.00.00.9374>
[PID: 1588][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><8.00.00.9374>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\i2ldvp3.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPI32.DLL] <Symantec Corp.><4.1.0.15>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051130.006\NAVEX32a.DLL] <Symantec Corporation><20051.3.0.16>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051130.006\NAVENG32.DLL] <Symantec Corporation><20051.3.0.16>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL] <Symantec Corporation><9.0.0.14>
[PID: 1676][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 204][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 228][C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll] <Symantec Corporation><8.00.00.9374>
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[PID: 312][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3275>
[PID: 404][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 348][C:\Program Files\内存扫把\ram.exe] <jfzlnyf><1.09.0004>
[C:\Program Files\内存扫把\Command.ocx] <随想软件工作室 Capricciososoft><3.00.0915>
[C:\Program Files\内存扫把\TrayForm.ocx] <Eduardo Morcillo><1.03.0007>
[PID: 2016][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 412][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\xunleibho_v8.dll] <N/A><4, 5, 1, 33>
[C:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\WINDOWS\system32\PYJJU.IME] <北京六合源软件技术有限公司><2, 2, 0, 4>
[PID: 2592][C:\WINDOWS\system32\PYINTAU.EXE] <北京六合源软件技术有限公司><2, 2, 1, 4>
[C:\WINDOWS\system32\PYCODEU.dll] <北京六合源软件技术有限公司><2, 2, 0, 4>
[C:\WINDOWS\system32\PYJJCZU.dll] <北京六合源软件技术有限公司><2, 2, 0, 0>
[PID: 3668][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[PID: 3664][C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX07.558\SREng.exe] <Smallfrogs Studio><1.1.0.269>
==================================
文件关联
.TXT OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\System32\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
==================================