电脑在运行时总有50多个进程在运行,打开网页也很慢.可是用瑞星最新20.73.43查杀了什么也没发现,没办法只能用sreng2把扫描后的情况给发上来,希望热心的朋友帮个忙,看看问题出在哪?先谢了![code]2008-12-06,12:56:28
System Repair Engineer 2.7.0.1210
Smallfrogs (
http://www.KZTechs.com)
Windows Server 2003 Enterprise Edition Service Pack 2 (Build 3790) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited]
<MSConfig><"C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto> [(Verified)Microsoft Windows Component Publisher]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Windows Component Publisher]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Component Publisher]
<NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Component Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Component Publisher]
<Thunder><; "C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s> [Thunder Networking Technologies,LTD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}]
<%IEHARDENADMIN_BASE_DESC%><%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenAdmin> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}]
<%IEHARDENUSER_DESC%><%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenUser> [(Verified)Microsoft Windows Component Publisher]
==================================
启动文件夹
N/A
==================================
服务
[CAS Balance Server / CASBalanceServer][Stopped/Auto Start]
<C:\Program Files\RealFriend\Rap Server\bin\CASBalanceServer.exe><>
[CAS Licence Server / CASLicenceServer][Stopped/Auto Start]
<"C:\Program Files\RealFriend\Licence Server\bin\CASLicenceServer.exe" -k runservice><RealFriend Software Corp.>
[CAS Web Server / CASWebServer][Stopped/Disabled]
<"C:\Program Files\RealFriend\Rap Server\bin\CASWebServer.exe" -k runservice><RealFriend Software Corp.>
[CAS XML Service / CASXMLService][Stopped/Disabled]
<"C:\Program Files\RealFriend\Rap Server\bin\CASXMLService.exe" --defaults-file="C:\Program Files\RealFriend\Rap Server\Conf\CasDB.ini" CASXMLService><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[KDDelegateService / KDDelegateService][Stopped/Manual Start]
<C:\Program Files\Kingdee\KIS\Advance\KDDelegateService.exe><KINGDEE>
[KDSvrMgrService / KDSvrMgrService][Running/Auto Start]
<C:\WINDOWS\system32\KDCOM\KDSvrMgrService.exe><KINGDEE>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled]
<C:\WINDOWS\system32\mnmsrvc.exe><(File is missing)>
[Microsoft Search / MSSEARCH][Running/Auto Start]
<"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[PeanutHull DDNS Service / Peanuthull5Core][Stopped/Manual Start]
<C:\Program Files\Oray\PeanutHull5\PhCore.exe><上海贝锐>
[Rising Proxy Service / RfwProxySrv][Running/Auto Start]
<C:\Program Files\Rising\Rfw\rfwProxy.exe><Beijing Rising Information Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Information Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Information Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Information Technology Co., Ltd.>
[SQLSERVERAGENT / SQLSERVERAGENT][Running/Auto Start]
<C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe -i MSSQLSERVER><Microsoft Corporation>
[Terminal Server Licensing / TermServLicensing][Running/Auto Start]
<C:\WINDOWS\system32\lserver.exe><Microsoft Corporation>
[WinHTTP Web Proxy Auto-Discovery Service / WinHttpAutoProxySvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->winhttp.dll><Microsoft Corporation>
==================================
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
<system32\drivers\ac97intc.sys><N/A>
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ACPI.sys><N/A>
[Microsoft Kernel Acoustic Echo Canceller / aec][Stopped/Manual Start]
<system32\drivers\aec.sys><N/A>
[AFD / AFD][Running/System Start]
<\SystemRoot\System32\drivers\afd.sys><N/A>
[Intel AGP Bus Filter / agp440][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\agp440.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><N/A>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
<system32\DRIVERS\asyncmac.sys><N/A>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\atapi.sys><N/A>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
<system32\DRIVERS\atmarpc.sys><N/A>
[音频存根驱动程序 / audstub][Running/Manual Start]
<system32\DRIVERS\audstub.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><N/A>
[bbdaacaf / bbdaacaf][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\bbdaacaf.sys><N/A>
[CD-ROM Driver / Cdrom][Stopped/System Start]
<system32\DRIVERS\cdrom.sys><N/A>
[群集磁盘驱动程序 / ClusDisk][Stopped/Disabled]
<system32\DRIVERS\ClusDisk.sys><N/A>
[CRC 磁盘筛选驱动程序 / crcdisk][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\crcdisk.sys><N/A>
[Game Port for Creative SB Live! / ctljystk][Stopped/Manual Start]
<system32\DRIVERS\ctljystk.sys><N/A>
[DfsDriver / DfsDriver][Running/Boot Start]
<\SystemRoot\system32\drivers\Dfs.sys><N/A>
[磁盘驱动程序 / Disk][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\disk.sys><N/A>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><N/A>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><N/A>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><N/A>
[Microsoft Kernel DLS Syntheiszer / DMusic][Stopped/Manual Start]
<system32\drivers\DMusic.sys><N/A>
[Microsoft Kernel DRM Audio Descrambler / drmkaud][Stopped/Manual Start]
<system32\drivers\drmkaud.sys><N/A>
[Floppy Disk Controller Driver / Fdc][Running/Manual Start]
<system32\DRIVERS\fdc.sys><N/A>
[FltMgr / FltMgr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\fltMgr.sys><N/A>
[FsVga / FsVga][Running/System Start]
<system32\DRIVERS\fsvga.sys><N/A>
[Volume Manager Driver / Ftdisk][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ftdisk.sys><N/A>
[Game Port Enumerator / gameenum][Stopped/Manual Start]
<system32\DRIVERS\gameenum.sys><N/A>
[Generic Packet Classifier / Gpc][Running/Manual Start]
<system32\DRIVERS\msgpc.sys><N/A>
[hardlock / hardlock][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hardlock.sys><Aladdin Knowledge Systems>
[Haspnt / Haspnt][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Haspnt.sys><Aladdin Knowledge Systems>
[Microsoft HID Class Driver / HidUsb][Running/Manual Start]
<system32\DRIVERS\hidusb.sys><N/A>
[HookCont / HookCont][Running/System Start]
<\SystemRoot\system32\drivers\HookCont.sys><N/A>
[HookNtos / HookNtos][Running/System Start]
<\SystemRoot\system32\drivers\HookNtos.sys><N/A>
[HookReg / HookReg][Running/System Start]
<\SystemRoot\system32\drivers\HookReg.sys><N/A>
[HookSys / HookSys][Running/System Start]
<\SystemRoot\system32\drivers\HookSys.sys><N/A>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Information Technology Co., Ltd.>
[HTTP / HTTP][Running/Manual Start]
<System32\Drivers\HTTP.sys><N/A>
[i8042 Keyboard and PS/2 Mouse Port Driver / i8042prt][Running/System Start]
<system32\DRIVERS\i8042prt.sys><N/A>
[CD-Burning Filter Driver / imapi][Stopped/System Start]
<system32\DRIVERS\imapi.sys><N/A>
[IntelIde / IntelIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\intelide.sys><N/A>
[Intel Processor Driver / intelppm][Running/Manual Start]
<system32\DRIVERS\intelppm.sys><N/A>
[IPv6 Windows Firewall Driver / Ip6Fw][Stopped/Manual Start]
<system32\DRIVERS\Ip6Fw.sys><N/A>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
<system32\DRIVERS\ipfltdrv.sys><N/A>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[IP Network Address Translator / IpNat][Running/Manual Start]
<system32\DRIVERS\ipnat.sys><N/A>
[IPSEC driver / IPSec][Running/System Start]
<system32\DRIVERS\ipsec.sys><N/A>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\isapnp.sys><N/A>
[ISO DVD/CD-ROM Device Driver / ISODrive][Running/System Start]
<\??\C:\Program Files\UltraISO\drivers\ISODrive.sys><EZB Systems, Inc.>
[Keyboard Class Driver / Kbdclass][Running/System Start]
<system32\DRIVERS\kbdclass.sys><N/A>
[Microsoft Kernel Wave Audio Mixer / kmixer][Stopped/Manual Start]
<system32\drivers\kmixer.sys><N/A>
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)