瑞星完全瘫痪了,电脑还会蓝屏,请高手帮忙看看该删些杀,杀些啥:default2:
[table=50%][tr][td][code]2008-06-07,13:58:04
System Repair Engineer 2.5.16.900
Smallfrogs (
http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><D:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<ATIPTA><D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IMJPMIG8.1><"D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Component Publisher]
<RfwMain><"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
<RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><D:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><H:\beatmania 5\desk\LOGON\logonui\green glass diy.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><D:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
<WinlogonNotify: MCPClient><D:\Program Files\Common Files\Stardock\mcpstub.dll> [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
<WinlogonNotify: WBSrv><D:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll> [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection D:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><D:\WINDOWS\system32\Rundll32.exe D:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
==================================
启动文件夹
[Stardock ObjectDock]
<D:\Documents and Settings\gao\「开始」菜单\程序\启动\Stardock ObjectDock.lnk --> C:\PROGRA~1\OBJECT~1\OBJECT~1.EXE [Stardock]><N>
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Antiy live update / Alive Auto-Update Service][Stopped/Disabled]
<><N/A>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<D:\WINDOWS\system32\Ati2evxx.exe><>
[ATI Smart / ATI Smart][Stopped/Manual Start]
<D:\WINDOWS\system32\ati2sgag.exe><>
[##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## / Bonjour Service][Stopped/Auto Start]
<><N/A>
[Crypkey License / Crypkey License][Stopped/Disabled]
<crypserv.exe><Kenonic Controls Ltd.>
[FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
<"D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Machine Debug Manager / MDM][Running/Auto Start]
<"D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"><Microsoft Corporation>
[Chinese Paladin 4 CN Drivers Auto Removal (pr2ach4f) / pr2ach4f][Stopped/Auto Start]
<D:\WINDOWS\system32\pr2ach4f.exe svc><SOFTSTAR>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><N/A>
[SolidPDFConverterReadSpool / ScReadSpool][Stopped/Disabled]
<><N/A>
==================================
驱动程序
[a347bus / a347bus][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\a347bus.sys><N/A>
[a347scsi / a347scsi][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\a347scsi.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[BM Win32 Network Adapter / bmnadapter][Running/Manual Start]
<system32\DRIVERS\bmnet.sys><The OpenVPN Project>
[dbhhbgbh / dbhhbgbh][Stopped/Boot Start]
<\SystemRoot\system32\drivers\dbhhbgbh.sys><N/A>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\ExpScan.sys><N/A>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
<\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><N/A>
[HookCont / HookCont][Running/System Start]
<\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Technology Co., Ltd>
[HookNtos / HookNtos][Running/System Start]
<\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Technology Co., Ltd>
[HookReg / HookReg][Running/System Start]
<\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Technology Co., Ltd>
[HookSys / HookSys][Running/System Start]
<\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Technology Co., Ltd>
[HookUrl / HookUrl][Running/Auto Start]
<\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\D:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120 / libusb0][Stopped/Manual Start]
<system32\DRIVERS\libusb0.sys><
http://libusb-win32.sourceforge.net>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><N/A>
[mProcRs / mProcRs][Stopped/Auto Start]
<\??\d:\program files\rising\rfw\mProcRs.sys><N/A>
[Chinese Paladin 4 CN Environment Driver (pe3ach4f) / pe3ach4f][Running/Boot Start]
<\SystemRoot\system32\drivers\pe3ach4f.sys><SOFTSTAR>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Chinese Paladin 4 CN Synchronization Driver (ps6ach4f) / ps6ach4f][Running/Boot Start]
<\SystemRoot\system32\drivers\ps6ach4f.sys><SOFTSTAR>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[rfwbase / rfwbase][Running/Auto Start]
<\SystemRoot\System32\Drivers\rfwbase.SYS><Beijing Rising Technology Co., Ltd.>
[RsFwDrv / RsFwDrv][Running/System Start]
<\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[StarForce Protection Environment Driver (version 1.x.a) / sfdrv01a][Running/Boot Start]
<\SystemRoot\System32\drivers\sfdrv01a.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04][Running/Boot Start]
<\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology (StarForce)>
[StarForce Protection VFS Driver (version 2.x) / sfvfs02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfvfs02.sys><Protection Technology (StarForce)>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
<\??\D:\WINDOWS\system32\SVKP.sys><AntiCracking>
[ycsud / ycsud][Stopped/Manual Start]
<\??\D:\WINDOWS\system32\drivers\ycsud.sys><N/A>
[NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter / yukonwxp][Running/Manual Start]
<system32\DRIVERS\yukonwxp.sys><Marvell Semiconductor Inc.>
==================================
浏览器加载项
[Thunder Browser Helper]
{1F364305-AA45-47B5-9F9D-39A8B94E7EF1} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[FG2CatchUrl]
{1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <G:\Program Files\FlashGet\ComDlls\bhoCATCH.dll, FlashGet>
[Loader Class]
{F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} <C:\Program Files\FindeXer\FindeXer.dll, A Part of the LessCliX Suite by Alianyn>
[StylerToolBar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <D:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[Dldrv2 Control]
{0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} <D:\WINDOWS\DOWNLO~1\Dldrv.ocx, GIGA>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <D:\WINDOWS\system32\aliedit\aliedit.dll, >
[ICBC Security Ctrl]
{5AB9367B-DD7F-411D-A030-DF7DE5E17AAE} <D:\WINDOWS\DOWNLO~1\NETBAN~1.OCX, Industrial and Commercial Bank of China>
[ImageShack Toolbar]
{6932D140-ABC4-4073-A44C-D4A541665E35} <D:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll, ImageShack Corp.>
[Java Plug-in]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} <D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_07]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <D:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[ファイルバンクランチャー]
{E0BE586C-7C66-4909-94D6-D18BBBDD6373} <D:\WINDOWS\DOWNLO~1\fbx2.ocx, Gretech Japan>
[Thunder Browser Helper]
{00000000-12C2-4305-82F9-43058F20E8D2} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[]
{105E4D0C-5E21-41ED-90F9-013EEF271BD6} <D:\WINDOWS\system32\widgetdownload.dll, 鱼鱼桌面秀widget插件下载工具>
[Thunder Browser Helper]
{1F364305-AA45-47B5-9F9D-39A8B94E7EF1} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[FG2CatchUrl]
{1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <G:\Program Files\FlashGet\ComDlls\bhoCATCH.dll, FlashGet>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <D:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <H:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[ImageShack Toolbar]
{6932D140-ABC4-4073-A44C-D4A541665E35} <D:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll, ImageShack Corp.>
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <E:\Program Files\淘宝旺旺\WangWangX6.dll, 阿里巴巴软件(上海)有限公司>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <H:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[StylerToolBar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <D:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[Loader Class]
{F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} <C:\Program Files\FindeXer\FindeXer.dll, A Part of the LessCliX Suite by Alianyn>
[使用迅雷下载]
<H:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<H:\Program Files\Thunder\Program\getallurl.htm, N/A>
==================================
用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; WPS; InfoPath.1; MAXTHON 2.0)