==============================================================
金山清理专家系统诊断报告
该诊断报告由金山清理专家提供
http://www.duba.net
==============================================================
诊断时间: 2008-02-15, 22:35
诊断平台: Windows XP [5.1.2600] Service Pack 2
IE版本: Internet Explorer V6.0.2180.2900
计算机物理内存: 509(MB)
当前可用内存: 210(MB)
硬盘总大小: 70(GB)
硬盘可用空间: 50(GB)
清理专家版本: 2007,12,28,3
恶意软件库版本: 2008.01.29.2
漏洞库版本: 2008.01.23.1
==============================================================
常规启动项
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[NvCplDaemon] <; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
[Antispy ARP] <D:\游戏大厅\firewall\Antiarp\KASArp.EXE>
[360Safetray] <REM D:\安全卫士\360safe\safemon\360Tray.exe /start>
[Alcmtr] <REM ; ALCMTR.EXE>
[BigDogPath] <REM ; C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera (ZC0301PL)>
文件路径: C:\WINDOWS\VM_STI.EXE [服务器忙]
[LanguageShortcut] <REM ; "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe">
文件路径: C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [服务器忙]
==============================================================
启动文件夹位置
==============================================================
Common Startup: C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Startup: C:\Documents and Settings\user\「开始」菜单\程序\启动
Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
Host File
==============================================================
127.0.0.1 yu.8s7.net
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com
127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com
127.0.0.1
www.177dvd.cn
127.0.0.1
www.cike007.cn
127.0.0.1
www.22aaa.com
127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com
127.0.0.1
www.exiao01.com
==============================================================
系统服务
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[HidServ] [已禁用] <%SystemRoot%\System32\hidserv.dll>
==============================================================
驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[WmNdisDrv] [已启用] <System32\Drivers\WmNdisDrv.sys>
[WmRegProDrv] [已启用] <System32\Drivers\WmRegProDrv.sys>
==============================================================
BHO
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\安全卫士4.0\360safe\safemon\safemon.dll>
文件路径: D:\安全卫士4.0\360safe\safemon\safemon.dll [分析中]
==============================================================
当前进程
==============================================================
名称: 360Tray.exe [已启用]
命令行: "D:\安全卫士4.0\360safe\safemon\360Tray.exe"
文件路径: D:\安全卫士4.0\360safe\safemon\360Tray.exe [分析中] (奇虎网)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WININET.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MFC42LOC.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)
模块文件: C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL (Kingsoft Corporation)
模块文件: C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll (Kingsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RICHED32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RICHED20.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: D:\安全卫士4.0\360safe\safemon\safemon.dll (奇虎网)
模块文件: C:\WINDOWS\system32\PSAPI.DLL (Microsoft Corporation)
模块文件: D:\安全卫士4.0\360safe\safemon\SafeKrnl.dll (奇虎网)
模块文件: D:\安全卫士4.0\360safe\AntiAdwa.dll (360Safe.com)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: D:\安全卫士4.0\360safe\live.dll (360safe.com)
模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RASAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasman.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\TAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINMM.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\sensapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USERENV.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\DNSAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\mslbui.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\hnetcfg.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\wshtcpip.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Cabinet.dll (Microsoft Corporation)
==============================================================
IE扩展按钮
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions
[启动迅雷5]
<{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}> <D:\迅雷\Thunder.exe>
文件路径: D:\迅雷\Thunder.exe [分析中]
==============================================================
ActiveX控件
==============================================================
该项来源: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
[XMP Class]
<{6483F145-A768-4C41-AACC-52D4D7845851}> <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work>
文件路径: C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work [分析中]
[QQMusicCreator Class]
<{6927992D-6A89-4549-8A32-95901BF5D920}> <D:\Program Files\Tencent\QQ\QQMusic.exe>
文件路径: D:\Program Files\Tencent\QQ\QQMusic.exe [分析中]
[360SafeLive]
<{87515F61-A66C-4319-A0E0-D416CB8059E3}> <D:\安全卫士4.0\360safe\live.dll>
文件路径: D:\安全卫士4.0\360safe\live.dll [分析中]
[SafeMon Class]
<{B69F34DD-F0F9-42DC-9EDD-957187DA688D}> <D:\安全卫士4.0\360safe\safemon\safemon.dll>
文件路径: D:\安全卫士4.0\360safe\safemon\safemon.dll [分析中]
[Thunder Browser Helper]
<{4E8A5277-C04E-4FE3-BF78-8A7CCD6EF333}> <F:\讯雷\Thunder\ComDlls\xunleiBHO_Now.dll>
[XMP Class]
<{6483F145-A768-4C41-AACC-52D4D7845851}> <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work>
文件路径: C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work [分析中]
==============================================================
其他安全区域
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
[显示摇曳 CPL 扩展] <deskpan.dll>