==============================================================
金山清理专家系统诊断报告
该诊断报告由金山清理专家提供
http://www.duba.net
==============================================================
诊断时间: 2008-06-27, 16:27
诊断平台: Windows 2000 [5.0.2195] Service Pack 4
IE版本: Internet Explorer V6.0.1106.2800
计算机物理内存: 2047(MB)
当前可用内存: 1491(MB)
硬盘总大小: 148(GB)
硬盘可用空间: 143(GB)
清理专家版本: 2008.06.13.404
恶意软件库版本: 2008.06.03.1
漏洞库版本: 2008.06.02.1
==============================================================
启动文件夹位置
==============================================================
Common Startup: C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Startup: C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
开始菜单启动项
==============================================================
<NPPDJVYNHLXL.lnk> <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\NPPDJVYNHLXL.lnk>
文件路径: C:\WINNT\QNHIY.exe [分析中]
==============================================================
Host File
==============================================================
127.0.0.1 localhost
127.0.0.1 mmsk.cn
127.0.0.1 bbs.mmsk.cn
127.0.0.1
www.mmsk.cn
127.0.0.1 soudong.com
127.0.0.1
www.soudong.com
127.0.0.1 c0mo.com
127.0.0.1 gxgxy.net
127.0.0.1 444.gmwo07.com
127.0.0.1 333.gmwo07.com
127.0.0.1 222.gmwo07.com
127.0.0.1 111.gmwo07.com
127.0.0.1 haha.yaoyao09.com
127.0.0.1
www.noseqing.cn
127.0.0.1 fg.pvs360.com
127.0.0.1 cw.pvs360.com
127.0.0.1 ta.pvs360.com
127.0.0.1 dl.pvs360.com
127.0.0.1 ok.sl8cjs.cn
127.0.0.1 nc.mskess.com
127.0.0.1 idc.windowsupdeta.cn
127.0.0.1 pvs360.com
127.0.0.1 sl8cjs.cn
127.0.0.1 windowsupdeta.cn
127.0.0.1 up.22x44.com
127.0.0.1 my.531jx.cn
127.0.0.1 nx.51ylb.cn
127.0.0.1 llboss.com
127.0.0.1 down.malasc.cn
127.0.0.1 d2.llsging.com
127.0.0.1 171817.171817.com
127.0.0.1 wg.47255.com
127.0.0.1
www.tomwg.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1 1.joppnqq.com
127.0.0.1 xx.exiao01.com
127.0.0.1
www.22aaa.com
127.0.0.1 ilove.com
127.0.0.1 xxx.mmma.biz
127.0.0.1
www.868wg.com
127.0.0.1 2.joppnqq.com
127.0.0.1 1.jopanqc.com
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopmmqq.com
127.0.0.1 cao.kv8.info
127.0.0.1 xtx.kv8.info
127.0.0.1 new.749571.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 1.jopenkk.com
127.0.0.1 d.93se.com
127.0.0.1 3.joppnqq.com
127.0.0.1 xxx.j41m.com
127.0.0.1 1.jopenqc.com
127.0.0.1 xxx.m111.biz
127.0.0.1 down.18dd.net
127.0.0.1
www.333292.com
127.0.0.1 qqq.hao1658.com
127.0.0.1 qqq.dzydhx.com
127.0.0.1
www.exiao01.com
127.0.0.1
www.cike007.cn
==============================================================
当前进程
==============================================================
名称: Iparmor.exe [已启用]
命令行: "E:\Program Files\Iparmor\Iparmor.exe"
文件路径: E:\Program Files\Iparmor\Iparmor.exe [分析中] (luosoft.com)
模块文件: C:\WINNT\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\user32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\advapi32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RPCRT4.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\oleaut32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mpr.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\version.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\LZ32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\winspool.drv (Microsoft Corporation)
模块文件: C:\WINNT\system32\shell32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\wininet.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSASN1.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\urlmon.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\comdlg32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\wsock32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2_32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2HELP.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\oledlg.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\netapi32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\NTDSAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\DNSAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WLDAP32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NETRAP.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SAMLIB.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\winmm.dll (Microsoft Corporation)
模块文件: E:\Program Files\Iparmor\hookhookdll.dll
模块文件: C:\WINNT\system32\IMM32.DLL (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL (Kingsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll (Kingsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\INDICDLL.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RICHED20.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\olepro32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\USERENV.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\CLBCATQ.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\cscui.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\CSCDLL.DLL (Microsoft Corporation)
模块文件: E:\Program Files\Iparmor\iparmor4.dll
模块文件: E:\Program Files\Iparmor\unrar.dll
模块文件: C:\WINNT\system32\shdocvw.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mydocs.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ntshrui.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ATL.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\wdmaud.drv (Microsoft Corporation)
模块文件: C:\WINNT\system32\msacm32.drv (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSACM32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mlang.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msafd.dll (Microsoft Corporation)
模块文件: C:\WINNT\System32\wshtcpip.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\icmp.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASMAN.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\TAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RTUTILS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\System32\rnr20.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MPRAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ACTIVEDS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\ADSLDPC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\SETUPAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\DHCPCSVC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\System32\winrnr.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\LINKINFO.DLL (Microsoft Corporation)
名称: sersc.exe [已启用]
文件路径: C:\WINNT\sersc.exe [未知] (Remote ABC)
模块文件: C:\WINNT\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\user32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\advapi32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RPCRT4.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\oleaut32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mpr.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\version.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\LZ32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\shell32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\wininet.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSASN1.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\wsock32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2_32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2HELP.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\IMAGEHLP.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\winmm.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSVFW32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\CLBCATQ.DLL (Microsoft Corporation)
模块文件: C:\WINNT\System32\rnr20.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\DNSAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ICMP.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MPRAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SAMLIB.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NETAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NTDSAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WLDAP32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NETRAP.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ACTIVEDS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\ADSLDPC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RTUTILS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\SETUPAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\USERENV.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASAPI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASMAN.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\TAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\DHCPCSVC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\System32\winrnr.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msafd.dll (Microsoft Corporation)
模块文件: C:\WINNT\System32\wshtcpip.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\rasadhlp.dll (Microsoft Corporation)
名称: ArSwp.exe [已启用]
命令行: "E:\工具\arswp2\arswp2\ArSwp.exe"
文件路径: E:\工具\arswp2\arswp2\ArSwp.exe [分析中] (ArSwp.com)
模块文件: C:\WINNT\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\KERNEL32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RPCRT4.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WININET.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSASN1.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\imagehlp.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\comdlg32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\COMCTL32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\SHELL32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WINSPOOL.DRV (Microsoft Corporation)
模块文件: C:\WINNT\system32\MPR.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\oledlg.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\OLEPRO32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\urlmon.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\LZ32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WSOCK32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2_32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WS2HELP.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ICMP.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MPRAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\SAMLIB.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NETAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NTDSAPI.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\DNSAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\WLDAP32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\NETRAP.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\ACTIVEDS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\ADSLDPC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RTUTILS.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\SETUPAPI.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\USERENV.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASAPI32.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\RASMAN.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\TAPI32.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\DHCPCSVC.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSVCP60.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\WINTRUST.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\IMM32.DLL (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL (Kingsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll (Kingsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll (Microsoft Corporation)
模块文件: E:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll (Microsoft Corporation)
模块文件: E:\Program Files\Iparmor\iparmor4.dll
模块文件: C:\WINNT\system32\INDICDLL.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\CLBCATQ.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\shdocvw.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\asycfilt.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mlang.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\msafd.dll (Microsoft Corporation)
模块文件: C:\WINNT\System32\wshtcpip.dll (Microsoft Corporation)
模块文件: C:\WINNT\System32\rnr20.dll (Microsoft Corporation)
模块文件: C:\WINNT\System32\winrnr.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\shdoclc.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\mshtml.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\c_is2022.dll (Microsoft Corporation)
模块文件: C:\WINNT\system32\MSLS31.DLL (Microsoft Corporation)
模块文件: C:\WINNT\system32\Cabinet.dll (Microsoft Corporation)
模块文件: E:\工具\arswp2\arswp2\plugin\ArFix.dll (ArSwp.Com)
==============================================================
IE扩展菜单
==============================================================
该项来源: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
<&使用超级旋风下载> <E:\Program Files\Tencent\QQDownload\geturl.htm>
文件路径: E:\Program Files\Tencent\QQDownload\geturl.htm [分析中]
<&使用超级旋风下载全部链接> <E:\Program Files\Tencent\QQDownload\getAllurl.htm>
文件路径: E:\Program Files\Tencent\QQDownload\getAllurl.htm [分析中]
==============================================================
其他安全区域
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
[显示摇曳 CPL 扩展] <deskpan.dll>