win7 64-bit stuck in safemode at aswArDisk.sys, using FRST64 to scan and got a FRST.txt. but i have to get the fixlist.txt to solve this problem. the content of FRST.txt is below. Pls help me if you know the right the fixlist.txt. thanks.
关于…的扫描结果 Farbar Recovery Scan Tool (FRST) (x64) 版本: 30-05-2020 01
通过…运行 SYSTEM 启动 MININT-INMOLUG (31-05-2020 04:03:25)
从运行 i:
Platform: Windows 7 Ultimate Service Pack 1 (X64) 语言: 中文(简体,中国)
Internet Explorer 版本 11
启动模式: Recovery
放弃: ControlSet001
注意!:=====> 如果系统是可引导的FRST,必须从正常或安全模式运行,以创建一个完整的日志。
教程 Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== 档案 (将列入优先名单) ===================
(如果条目包含在固定列表中,则注册表项目将恢复为默认或删除。 文件不会被移除。)
HKLM.…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2015-01-13] (Realtek Semiconductor Corp → Realtek Semiconductor)
HKLM.…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2780400 2013-09-05] (Synaptics Incorporated → Synaptics Incorporated)
HKLM.…\Policies\Explorer\Run: [BtvStack] => “F:\bluetooth components\bluetooth and wlan\Bluetooth Suite\BtvStack.exe”
HKU\Administrator.dell-PC.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKU\dell.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKU\dell.dell-PC.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKU\dell.dell-PC.000.…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd → Piriform Software Ltd)
HKU\TEMP.dell-PC.000.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKU\TEMP.dell-PC.001.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKU\TEMP.dell-PC.003.…\Run: [360sd] => “F:\dnf\360sd\360sdrun.exe”
HKLM.…\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] ()
HKLM.…\Windows x64\Print Processors\HP1100PrintProc: C:\Windows\System32\spool\prtprocs\x64\HP1100PP.DLL [74240 2012-08-31] ()
HKLM.…\Windows x64\Print Processors\winprint: C:\Windows\System32\spool\prtprocs\x64\winprint.dll [38912 2016-06-26] (Microsoft Corporation)
HKLM.…\Print\Monitors\HP1100LM: C:\Windows\system32\HP1100LM.DLL [288768 2012-08-31] ()
HKLM.…\Print\Monitors\HPLJ1020LM: C:\Windows\system32\zlhp1020.dll [192512 2012-09-18] ()
HKLM.…\Print\Monitors\Local Port: C:\Windows\system32\localspl.dll [970240 2016-06-26] (Microsoft Corporation)
HKLM.…\Print\Monitors\Microsoft Shared Fax Monitor: C:\Windows\system32\FXSMON.DLL [41984 2010-11-21] (Microsoft Corporation)
HKLM.…\Print\Monitors\PDF-XChange5-ABBYY-FR: C:\Windows\system32\pxc50pmaf.dll [57536 2016-10-03] (Tracker Software Products (Canada) Ltd → Tracker Software Products (Canada) Ltd.)
HKLM.…\Print\Monitors\Standard TCP/IP Port: C:\Windows\system32\tcpmon.dll [195072 2009-07-14] (Microsoft Corporation)
HKLM.…\Print\Monitors\USB Monitor: C:\Windows\system32\usbmon.dll [45056 2009-07-14] (Microsoft Corporation)
HKLM.…\Print\Monitors\WSD Port: C:\Windows\system32\WSDMon.dll [224768 2009-07-14] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177624 2015-01-09] (NVIDIA Corporation PE Sign v2014 → NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-01-09] (NVIDIA Corporation PE Sign v2014 → NVIDIA Corporation)
BootExecute:
GroupPolicy: 限制 ? <==== 注意
==================== 以安排的任务 (将列入优先名单) ============
(如果一个条目包含在固定列表中,它将从注册表中删除。 除非单独列出,否则文件将不会被移动。.)
Task: {0449C489-5613-46D5-BFD9-4962053230FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd → Piriform Software Ltd)
Task: {0AB48375-7A91-4822-8367-CC903ECC28DE} - \kuaizip_update → 无文件 <==== 注意
Task: {0D2D7A48-4396-4014-94F7-557C4B6FE853} - System32\Tasks\微软设备健康助手设备检查 => C:\Program Files (x86)\Microsoft Device Health\PluginManager\DhPluginMgrScheduler.exe [105112 2015-01-30] (Microsoft Corporation → Microsoft Corporation)
Task: {1150DE02-94FF-4F6F-8E14-EDECA1D33028} - System32\Tasks\MeLogo_{67679FCB-7ECA-4db5-B5AE-E6B4E178D0BA} => D:\yygamestore\emulator\3.4.0.12\me.exe
Task: {160861BB-38E9-4B4F-8A6B-7DA40B4445B9} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-05-04] (Avast Software s.r.o. → Avast Software)
Task: {23F40803-9DA4-4F22-B82F-0583473143E7} - System32\Tasks\PowerWord-Notify-dell-PC_dell => F:\Kingsoft\Power Word 2016\2016.3.3.0316\ktpcntr.exe
Task: {240FEA1B-EB28-4BB4-BDBA-DDB95933883B} - System32\Tasks\LuckyTab => C:\Program Files (x86)\LuckyTab\LuckyTab.exe [1394112 2015-02-19] (T Module Gmbh → hxxp://lucky-tab.com/) <==== 注意
Task: {382976F7-97FD-43F0-BB53-E626F648548B} - System32\Tasks\sogouimemgr => C:\Program Files (x86)\SogouInput\SogouExe\SogouExe.exe [412568 2019-12-31] (Beijing Sogou Technology Development Co., Ltd. → Sogou.com Inc.)
Task: {38C40019-1D37-4AED-8C53-D72F2CE744B0} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2015-01-13] (Realtek Semiconductor Corp → Realtek Semiconductor)
Task: {51F10271-70F5-43E9-A550-BF438ABC3063} - System32\Tasks\微软设备健康助手自动更新 => C:\Program Files (x86)\Microsoft Device Health\DhUpdate.exe [186520 2015-01-30] (Microsoft Corporation → Microsoft Corporation)
Task: {559AC119-F1CD-4EFC-892E-5E819F9E1738} - \360SuperKiller\360SuperKiller → 无文件 <==== 注意
Task: {561FC19A-2332-481A-B89B-60097DB3B889} - System32\Tasks{DBEFB31E-AC5F-428D-ABF9-19777C881D79} => C:\Windows\system32\pcalua.exe -a F:\闪电战[闪电战官方纪念合集及资料片全面挑战全集].Blitzkrieg_Anthology_CD3.iso\Setup.exe -d F:\闪电战[闪电战官方纪念合集及资料片全面挑战全集].Blitzkrieg_Anthology_CD3.iso
Task: {7074B659-A4BC-4B53-BA6B-3C4960FAF226} - System32\Tasks\haozip_2345upgrade task => F:\Haozip\Haozip_2345Upgrade.exe
Task: {729BC3AE-B473-4091-A07C-E59C90BE148F} - System32\Tasks\微软设备健康助手开机检测 => C:\Program Files (x86)\Microsoft Device Health\DhUpdate.exe [186520 2015-01-30] (Microsoft Corporation → Microsoft Corporation)
Task: {753C47AE-EC5E-44B3-95A9-2C8E553F0E39} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => by user disabled
Task: {9106BB7C-76A1-4D2A-9AAB-7BB9B9B06B5A} - System32\Tasks{1E51D547-2A78-4BBB-8F63-2D18DFBD0F31} => C:\Windows\system32\pcalua.exe -a “C:\Users\dell\Desktop\essay1,更改9.6\Blitzkrieg 3-Installer.exe” -d C:\Users\dell\Desktop\essay1,更改9.6
Task: {92722E94-300B-4B7F-B309-799596008431} - System32\Tasks\glaryinitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [135120 2018-04-16] (Glarysoft LTD → Glarysoft Ltd)
Task: {A7445998-A2E6-45CB-9448-F46FAA4F7D5C} - System32\Tasks\Avast Emergency Update => F:\avast\AvEmUpdate.exe
Task: {B1977D04-5857-4BA0-8C6E-1BB79EBE7AB9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1187864 2018-03-21] (Adobe Systems, Incorporated → Adobe Systems Incorporated)
Task: {B525EB5C-04A5-4B10-AC7A-97CFE9625D8F} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2562222455-3494385764-2129142305-1000 => C:\Users\dell\AppData\Local\MEGAsync\MEGAupdater.exe
Task: {B9630E5D-F624-4913-9CD8-B971CECEB8ED} - System32\Tasks\adobeaamupdater-1.0-dell-pc-dell => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated → Adobe Systems Incorporated)
Task: {BDEB49FA-17DD-434F-BA4C-192757C2F602} - \360safe\360APMainProg → 无文件 <==== 注意
Task: {D12DEA96-7803-4DFA-BB67-E3CD5528EC4E} - System32\Tasks{0BF75A0D-0539-4FD1-A122-F31E8AEE4101} => C:\Windows\system32\pcalua.exe -a F:\闪电战\1\Setup.exe -d F:\闪电战\1
Task: {D3257DFE-52EC-4D01-95CF-8DFED5675EB0} - System32\Tasks\powerword-update-dell-pc_dell => F:\Kingsoft\Power Word 2016\2016.3.3.0333\update.exe
Task: {E4E1A065-EC7C-410D-9F26-09C0ACF2B8B6} - System32\Tasks\powerword-search-dell-pc_dell => F:\Kingsoft\Power Word 2016\2016.3.3.0333\pwsearch.exe
Task: {EB3670AC-C127-48E4-B5CC-3890E81DADD0} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd → Piriform Software Ltd)
(如果在固定列表中包含一个条目,则将移动任务(.Cob)文件。将不会移动由任务运行的文件。)
Task: C:\Windows\Tasks\PowerWord-Notify-dell-PC_dell.job => F:\Kingsoft\Power Word 2016\2016.3.3.0316\ktpcntr.exeLpowerword 2016.3.3.0316 hxxp:/download.iciba.com
Task: C:\Windows\Tasks\powerword-search-dell-pc_dell.job => F:\Kingsoft\Power Word 2016\2016.3.3.0333\pwsearch.exe
Task: C:\Windows\Tasks\powerword-update-dell-pc_dell.job => F:\Kingsoft\Power Word 2016\2016.3.3.0333\update.exe
Task: C:\Windows\Tasks\微软设备健康助手开机检测.job => C:\Program Files (x86)\Microsoft Device Health\DhUpdate.exe/EnableDHSYSTEMH此任务用于微软设备健康助手的状态检测和自我修复。了解更多请查阅hxxp:/support.microsoft.com
Task: C:\Windows\Tasks\微软设备健康助手自动更新.job => C:\Program Files (x86)\Microsoft Device Health\DhUpdate.exeSYSTEMZ此服务属于微软设备健康助手用于获取最新的版本有助于提高设备健康度及保障支付安全。了解更多请查阅hxxp:/support.microsoft.com
Task: C:\Windows\Tasks\微软设备健康助手设备检查.job => C:\Program Files (x86)\Microsoft Device Health\PluginManager\DhPluginMgrScheduler.exeSYSTEMC此任务用于微软设备健康助手的设备检查。了解更多请查阅hxxp:/support.microsoft.com
==================== 服务 (将列入优先名单) ===================
(如果一个条目包含在固定列表中,它将从注册表中删除。 除非单独列出,否则文件将不会被移动。.)
S3 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [817760 2017-09-20] (Adobe Systems Incorporated → Adobe Systems Incorporated)
S3 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems Incorporated → Adobe Systems, Incorporated)
S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] (Autodesk, Inc. → )
S3 CAJ Service Host; C:\Program Files (x86)\TTKN\CAJVD\CAJSHost.exe [69040 2012-05-29] (Tongfang Knowledge Network Technology (Beijing) Co.,Ltd. → Tongfang Knowledge Network Technology(Beijing) Co., Ltd.)
S2 DeviceHealth; C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe [196760 2015-01-30] (Microsoft Corporation → Microsoft Corporation)
S2 DeviceHealthPluginMgr; C:\Program Files (x86)\Microsoft Device Health\PluginManager\DhPluginMgr.exe [244376 2015-01-30] (Microsoft Corporation → Microsoft Corporation)
S3 dg597; C:\Windows\SysWOW64\dg597\dg597.dll [134720 2019-10-04] (Beijing Kingsoft Security software Co.,Ltd → )
S2 Flash Helper Service; C:\Windows\SysWOW64\Macromed\Flash\FlashHelperService.exe [2757488 2020-05-16] (重庆重橙网络科技有限公司 → 重庆重橙网络科技有限公司)
S2 ICBC Daemon Service; C:\Program Files (x86)\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN64\IcbcDaemon_64.exe [486536 2014-06-20] (Industrial and Commercial Bank of China Limited → )
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2015-01-05] (Intel Corporation - pGFX → Intel Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation → Microsoft Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2015-01-09] (NVIDIA Corporation → NVIDIA Corporation)
S3 OnKey Service _ICBC; C:\Windows\SysWOW64\D4Ser_ICBC.exe [84280 2014-08-19] (Tendyron Corporation → Tendyron Corporation)
S3 pcas; C:\Program Files (x86)\alipay\aliedit\5.3.0.3807\pcas.exe [592856 2015-03-23] (Alipay.com Co.,Ltd → Alipay.com Inc.)
S3 Protect_2345chrome; C:\Program Files (x86)\Protect_2345chrome\Protect_2345chrome.exe [58344 2014-05-20] (2345.com → 2345.com)
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [293080 2015-01-13] (Realtek Semiconductor Corp → Realtek Semiconductor)
S3 secbizsrv; C:\Program Files (x86)\alipay\aliedit\5.3.0.3807\secbizsrv.exe [594904 2015-03-23] (Alipay.com Co.,Ltd → Alipay.com Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 XMPService; C:\Users\Public\Thunder Network\Pusher\XmpSvc\XMPService.dll [166544 2017-05-03] (深圳市迅雷网络技术有限公司 → 深圳市迅雷网络技术有限公司)
S3 AdClean; C:\Program Files (x86)\AdClean\AcSvr.exe
S3 aswbIDSAgent; “F:\avast\aswidsagent.exe”
S2 AtherosSvc; “F:\bluetooth components\bluetooth and wlan\Bluetooth Suite\adminservice.exe”
S2 avast! Antivirus; “F:\avast\AvastSvc.exe” /runassvc
S2 BBDemon; “F:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe” -service
S3 BDMiniDlUpdate; C:\Users\dell\AppData\Roaming\baidu\BaiduRJDownloader\1.3.0.52\BDMiniDlUpdate_591.exe
S3 DGPNPSEV; D:\DriverGenius\DgService.exe
S2 DS License Server; “F:\Program Files\Dassault Systemes\DS License Server\win_b64\code\bin\DSLicSrv.exe” -startServer
S2 FCService; “F:\FlashRepair\FCService.exe”
S2 HaoZipSvc; F:\Haozip\protect\HaozipSvc.exe
S3 lpser; D:\Program Files (x86)\Xianshuabao\Personal\SpeedEngines.dll
S2 MSSQL$ENOVIA_DB; “F:\Program Files\Microsoft SQL Server\MSSQL10_50.ENOVIA_DB\MSSQL\Binn\sqlservr.exe” -sENOVIA_DB
S3 MSSQLFDLauncher$ENOVIA_DB; “F:\Program Files\Microsoft SQL Server\MSSQL10_50.ENOVIA_DB\MSSQL\Binn\fdlauncher.exe” -s MSSQL10_50.ENOVIA_DB
S2 QPCore; “C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtect.exe”
S3 SQLAgent$ENOVIA_DB; “F:\Program Files\Microsoft SQL Server\MSSQL10_50.ENOVIA_DB\MSSQL\Binn\SQLAGENT.EXE” -i ENOVIA_DB
S4 TBSecSvc; C:\Users\dell\AppData\Roaming\TaobaoProtect\TBSecSvc.exe
S3 ThunderSecurityDoctor; D:\Program Files (x86)\Thunder Network\Thunder\Thunder BHO Platform\tdservicedelegate.dll
S3 Tomcat9; F:\apache-tomcat-9.0.35\bin\Tomcat9.exe //RS//Tomcat9
S2 ZAtheros Wlan Agent; F:\bluetooth components\bluetooth and wlan\Ath_WlanAgent.exe