==============================================================
金山清理
专家系统诊断报告
该诊断报告由金山清理专家提供
http://www.duba.net
==============================================================
诊断时间: 2008-01-28, 23:57
诊断平台:
Windows XP [5.1.2600] Service Pack 2
IE版本:
Internet Explorer V7.0.13.5730
计算机物理
内存: 511(MB)
当前可用内存: 187(MB)
硬盘总大小: 144(GB)
硬盘可用空间: 34(GB)
清理专家版本: 2007,12,28,3
恶意软件库版本: 2008.01.21.1
漏洞库版本: 2008.01.23.1
==============================================================
常规启动项
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[360Safetray] <E:\Program
Files\360safe\safemon\360Tray.
exe /start>
文件路径: E:\Program Files\360safe\safemon\360Tray.exe [分析中]
[360Antiarp] <E:\Program Files\360safe\antiarp\Anti
Arp.exe /start>
文件路径: E:\Program Files\360safe\antiarp\AntiArp.exe [分析中]
==============================================================
启动文件夹位置
==============================================================
Common Startup: C:\Documents and Settings\All Users\「开始」菜单\
程序\启动
Startup: C:\Documents and Settings\Owner\「开始」菜单\程序\启动
Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
Host File
==============================================================
127.0.0.1 localhost
==============================================================
系统服务
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[AppMgmt] [已禁用] <%SystemRoot%\System32\appmgmts.
dll>
[HidServ] [已禁用] <%SystemRoot%\System32\hidserv.dll>
[SENS] [已启用] <%SystemRoot%\system32\sens.dll>
文件路径: C:\WINDOWS\system32\sens.dll [分析中]
[Wireless Zero Configuration Messenger] [已禁用] <C:\WINDOWS\system32\winmessenger.exe>
文件路径: C:\WINDOWS\system32\winmessenger.exe [分析中]
==============================================================
驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[360AntiArp] [已启用] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys>
文件路径: C:\WINDOWS\system32\drivers\360AntiArp.sys [分析中]
[ATSpy] [已启用] <\??\C:\WINDOWS\system32\ATSpy.sys>
==============================================================
BHO
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\KASDisabled
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <d:\QQ\QQIEHelper.dll>
[IE_ADS Class]
{F8E2D735-5D21-4B00-B6DE-D82ED0CA8B63} <C:\WINDOWS\system32\yg.dll>
==============================================================
当前进程
==============================================================
名称: 360Tray.exe [已启用]
命令行: "E:\Program Files\360safe\safemon\360Tray.exe" /start
文件路径: E:\Program Files\360safe\safemon\360Tray.exe [分析中] (奇虎网)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iertutil.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42LOC.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RICHED32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RICHED20.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: E:\Program Files\360safe\safemon\safemon.dll (奇虎网)
模块文件: E:\Program Files\360safe\safemon\SafeKrnl.dll (奇虎网)
模块文件: E:\Program Files\360safe\AntiAdwa.dll (360Safe.com)
模块文件: C:\WINDOWS\system32\WININET.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Normaliz.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\psapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)
模块文件: D:\Program Files\KPP\KPPShell.dll (
Kingsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42u.DLL (Microsoft Corporation)
名称: AntiArp.exe [已启用]
命令行: "E:\Program Files\360safe\antiarp\AntiArp.exe" /start
文件路径: E:\Program Files\360safe\antiarp\AntiArp.exe [分析中] (奇虎网)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WININET.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Normaliz.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iertutil.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\icmp.dll (Microsoft Corporation)
模块文件: E:\Program Files\360safe\safemon\safemon.dll (奇虎网)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RASAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasman.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\TAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINMM.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USERENV.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\sensapi.dll (Microsoft Corporation)
模块文件: D:\Program Files\KPP\KPPShell.dll (Kingsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42u.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42LOC.DLL (Microsoft Corporation)
==============================================================
IE扩展按钮
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions
[联想]
<{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}> <
http://www.lenovo.com>
==============================================================
IE扩展菜单
==============================================================
该项来源: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
<导出到 Microsoft Office Excel(&X)> <res://D:\PROGRA~1\MICROS~1\
OFFICE11\EXCEL.EXE/3000>
==============================================================
ActiveX控件
==============================================================
该项来源: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
[XMP Class]
<{6483F145-A768-4C41-AACC-52D4D7845851}> <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\x
player.dll_1_work>
文件路径: C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work [分析中]
[QQBrowserHelperObject Class]
<{54EBD53A-9BC1-480B-966A-843A333CA162}> <d:\QQ\QQIEHelper.dll>
[IE_ADS Class]
<{F8E2D735-5D21-4B00-B6DE-D82ED0CA8B63}> <C:\WINDOWS\system32\yg.dll>