b********n 发帖数: 38600 | 1 将军们给看看,这是什么:
ActiveX/COM Issue JavaPlugin - {CAF-Shootingcomputerattackblanks}HKCR\
JavaPlugin
ActiveX/COM Issue JavaPlugin.180_25 - {CA-blank} HKCR\JavaPlugin.180_25
ActiveX/COM Issue InProcServer32\C:\Program Files (x86)\Java\jre1.8.0_25\bin
\wsdetect.Kosherdill HKCR\CLSID\{blank}
ActiveX/COM Issue InProcServer32\C:\Program Files (x86)\Google\Update\1.3.24
.7\psmachine.dll HKCR\CLSID\{Blank}
ActiveX/COM Issue InProcServer32\C:\Program Files (x86)\Google\Update\-.
00001.3.24.7\psmachine_64.dll ... 阅读全帖 |
|
c**t 发帖数: 2744 | 2 You can check the registry, a 32 bit home will be located in HKLM>Software>
WOW6432Node>Oracle, wheras a 64 bit home will be in HKLM>Software>Oracle,
and then you can check the path to the home to try to infer whether it's 32
bit or 64 bit based on the location of dll's.
哪里可以看到我的oracle client是32还是64的?他们给我装oracle 11g的时候说是64
的,我也想确认一下是不是他们装错了。 |
|
e*********s 发帖数: 200 | 3
个
不
。
Have you checked your startup folder, your registry key?
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Another common situation is the local group policy has been changed.
check mmc -> local group security (or type in gpedit.msc in the command
window)
Goto Computer Configuration -> Windows Settings -> Scripts (startup/shutdow |
|
u*********d 发帖数: 105 | 4 It doesn't make sense to import the whole registry because some keys are
special
for example:
HKLM\HARDWARE is recreated each time the system starts
HKLM\SECURITY\SAM requires SYSTEM instead of administrator to access.
And I think once a key is open by a thread, nt won't allow other threads to
write it to avoid synchronic problem |
|
d******g 发帖数: 5484 | 5 刚symatech抓到一个 troyan fake av的病毒。
google了一下说是
‘It creates a startup registry value "Enterprise Suite" in the key HKLM\
SOFTWARE\Microsoft\Windows\CurrentVersion\Run in order to run every time the
operating system starts.’
估计改注册表可以。。。你说的那个正在扫,不行只能冒着风险自己改注册表了。 |
|
k****t 发帖数: 12697 | 6 因为DROPBOX 装在你的PROFILE. 大多软件要装在C:\PROGRAM FILES, 还要在HKLM 里写
东西, 普通USER 不行. |
|
O*******d 发帖数: 20343 | 7 Run this in PowerShell (from Start » All Programs » Accessories
187;
Windows PowerShell):
Get-ItemProperty HKLM:SYSTEMCurrentControlSetEnumHID**Device` Parameters
FlipFlopWheel -EA 0 | ForEach-Object { Set-ItemProperty $_.PSPath
FlipFlopWheel 1 }
最后那个数字是1就把mouse wheel反向。 0则是正常。 做完后restart。 |
|
J*****a 发帖数: 4262 | 8 我去试试看
我在网上搜到一个人说要启用Gratuitous ARP
然后下面只写了一行 HKLM\....\ArpRetryCount=1.
请问加上这行就是启用了gratutous ARP了吗 |
|
d****n 发帖数: 12461 | 9 啥系统啊。一般我会搜索注册表,找流氓网址。然后去一些关键的部分看看,例如ie插
件,HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options等等 |
|
o*******d 发帖数: 9 | 10 第一是看看process manager 里面有没有可疑的进程(可以逐个google之,如果不确定)
应该是你的电脑感染了恶意的程序,不是浏览器的问题
然后看看注册表里面的开机自动启动程序里是不是有可疑的 HKLM/software/microsoft/
windows/currentversion/run 和 runonce 里面
还有,杀完病毒后,接着用firefox吧,中招的可能性会小很多 |
|
D****N 发帖数: 430 | 11 A last resort to solve this kind of problems,
install win2k at a directory other than c:/winnt or ur original path,
boot into the new win2k installation,
use regedt32 to open up the HKLM in the older system directory
and delete the suspected service entry.
Or boot with the emergency repair disk to get to the recovery console..
Use listsvc to see a list of serice / drivers install
then use disable servicename after you found out which service is causing
the problem.
See http://support.microsoft. |
|
m*******e 发帖数: 310 | 12
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{Interf
aceGUID}\MTU
(DWORD)
Value Type: REG_DWORD Number
Valid Range: 68 - the MTU of the underlying network
Default: 0xFFFFFFFF
Description: This parameter overrides the default Maximum
Transmission Unit (MTU) for a network interface. The MTU is
the maximum packet size in bytes that the transport will
transmit over the underlying network. The size includes the
transport header. Note that an IP datagram may span multiple
packets. Values larg |
|
s**********i 发帖数: 711 | 13 HKLM/software/microsoft/windows/currentversion/policies/exploerer
change NoRun value to 0 if it's 1. |
|
e*********s 发帖数: 200 | 14
Have you checked your registry key:
HKLM\System\CurrentControlSet\Services\Cdrom
check Autorun and AutorunAlwaysDisabled |
|
l******n 发帖数: 301 | 15 多谢多谢呀。
打电话给IBM,总是等好久还在选1,2,3, 。。。还是不能指望他们的客服了。
我又发现几个errorreport里显示的文件:manifest.txt,appcompat,ConnMgr.exe.mdmp,
ConnMgr.exe.mdmp, 全装在C:\DOCUME~1\liuxiyan\LOCALS~1\Temp\WER0b26.dir00\
ConnMgr.exe.hdmp文件夹里。
从这个里面可以找到线索吗?
manifest.txt:
Server=watson.microsoft.com
UI LCID=1033
Flags=1672016
Brand=WINDOWS
TitleName=Connection Manager
DigPidRegPath=HKLM\Software\Microsoft\Windows NT\CurrentVersion\
DigitalProductId
ErrorText=If you were in the middle of something, the information you were
working on m |
|
l******n 发帖数: 301 | 16 多谢多谢呀。
打电话给IBM,总是等好久还在选1,2,3, 。。。还是不能指望他们的客服了。
我又发现几个errorreport里显示的文件:manifest.txt,appcompat,ConnMgr.exe.mdmp,
ConnMgr.exe.mdmp, 全装在C:\DOCUME~1\liuxiyan\LOCALS~1\Temp\WER0b26.dir00\
ConnMgr.exe.hdmp文件夹里。
从这个里面可以找到线索吗?
manifest.txt:
Server=watson.microsoft.com
UI LCID=1033
Flags=1672016
Brand=WINDOWS
TitleName=Connection Manager
DigPidRegPath=HKLM\Software\Microsoft\Windows NT\CurrentVersion\
DigitalProductId
ErrorText=If you were in the middle of something, the information you were
working on m |
|
w*******e 发帖数: 285 | 17 我用的是系统管理员的帐号还是不行,reg add和reg delete都说access denied,只有
reg query还能用。我就是想让用户登录就在背景运行我的程序,以前我是用reg add加
到HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run里面,但是现在这招不管用
了,我应该怎么办呢? |
|
i***l 发帖数: 9994 | 18 应该就是中文支持,就是你说的那个语言区域的问题。
你这个问题可以去一个好的系统,倒出注册表的
HKLM\System\Current Control Set\Control\Nls
分支,然后再倒入到你的有问题的系统的注册表中,应该就好了。 |
|
|
|
P***a 发帖数: 4213 | 21 正版的windows7么?如果是,去改注册表
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform
\Activation\Manual 0改成1 |
|
d*****e 发帖数: 7368 | 22 it's done.
download chinese pack from here.
http://www.technize.net/windows-7-sp1-language-packs-direct-dow
Without button, is possible too:
-run command prompt as administrator
-type dism /online /add-package /packagepath:driveletter\dir\lp.cab
-in regedit del key \HKLM\SYSTEM\CurrentControlSet\Control\MUI UILanguage\eu
-us
如果不想手改注册表, 可以用vistalizator. |
|