==============================================================
金山清理专家系统诊断报告
该诊断报告由金山清理专家提供
http://www.duba.net
==============================================================
诊断时间: 2008-07-25, 12:09
诊断平台: Windows XP [5.1.2600] Service Pack 2
IE版本: Internet Explorer V6.0.2180.2900
计算机物理内存: 959(MB)
当前可用内存: 622(MB)
硬盘总大小: 66(GB)
硬盘可用空间: 56(GB)
清理专家版本: 2007,12,28,3
恶意软件库版本: 2007.12.21.2
漏洞库版本: 2007.12.18.1
==============================================================
App Init DLLs
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
[AppInit_DLLs] <msspcyn.dll longasus.dll fackwir.dll welycz.dll offecao.dll theralte.dll>
文件路径: C:\WINDOWS\system32\theralte.dll [分析中]
==============================================================
延迟加载
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
[cliconfgzx.dll] <C:\WINDOWS\system32\cliconfgzx.dll>
[ofkpymbx.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[kbdswjr.dll] <C:\WINDOWS\system32\kbdswjr.dll>
文件路径: C:\WINDOWS\system32\kbdswjr.dll [未知]
[dispexcb.dll] <C:\WINDOWS\system32\dispexcb.dll>
文件路径: C:\WINDOWS\system32\dispexcb.dll [未知]
[adsntzt.dll] <C:\WINDOWS\system32\adsntzt.dll>
文件路径: C:\WINDOWS\system32\adsntzt.dll [未知]
[imgutilhx2.dll] <C:\WINDOWS\system32\imgutilhx2.dll>
文件路径: C:\WINDOWS\system32\imgutilhx2.dll [未知]
[slbiopfs2.dll] <C:\WINDOWS\system32\slbiopfs2.dll>
[dnsubroi.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[fzsiypep.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[bpaoxglh.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[wrtsscog.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[hlvsapwd.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[sumenyqf.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[jalogmjx.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[npccfwjo.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[vccqvbkw.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[nyegqofe.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[msceyird.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[bootvidgj.dll] <C:\WINDOWS\system32\bootvidgj.dll>
文件路径: C:\WINDOWS\system32\bootvidgj.dll [未知]
[pargzpmf.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[uvawqthx.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[lpbzdhnt.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[daorleoa.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[bfjozfvb.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[avispgpn.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[sknepxaz.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[nmrbneyn.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[jlkuqgyr.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[ujbtncnu.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[medfsbel.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[ficfuqzn.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[lebcajgy.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[xroxcbpz.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[cryzszue.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[lxybrlua.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[dlxgcntb.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[lcxoiuxn.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[gbqymowz.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[skwzoucn.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[nfdxgkve.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[jatcyion.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[oadepgut.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[kkwlcpst.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[jauikqtf.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
[vylppmji.dll] <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
==============================================================
执行挂钩
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{841529CB-7F77-4B99-A895-B5441E0D302F}> <C:\WINDOWS\system32\jfrwdh.dll>
文件路径: C:\WINDOWS\system32\jfrwdh.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}> <C:\WINDOWS\system32\ddserh.dll>
文件路径: C:\WINDOWS\system32\ddserh.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}> <C:\WINDOWS\system32\zycdex.dll>
文件路径: C:\WINDOWS\system32\zycdex.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}> <C:\WINDOWS\system32\hhrdxd.dll>
文件路径: C:\WINDOWS\system32\hhrdxd.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}> <C:\WINDOWS\system32\wklsdd.dll>
文件路径: C:\WINDOWS\system32\wklsdd.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00150015-0015-0015-0015-00150015BB15}> <C:\WINDOWS\system32\vylppmji.dll>
文件路径: C:\WINDOWS\system32\vylppmji.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00120012-0012-0012-0012-00120012BB15}> <C:\WINDOWS\system32\kbdswjr.dll>
文件路径: C:\WINDOWS\system32\kbdswjr.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00060006-0006-0006-0006-00060006BB15}> <C:\WINDOWS\system32\dispexcb.dll>
文件路径: C:\WINDOWS\system32\dispexcb.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00010001-0001-0001-0001-00010001BB15}> <C:\WINDOWS\system32\adsntzt.dll>
文件路径: C:\WINDOWS\system32\adsntzt.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189}> <C:\WINDOWS\system32\kgfghd.dll>
文件路径: C:\WINDOWS\system32\kgfghd.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00300030-0030-0030-0030-00300030BB15}> <C:\WINDOWS\system32\imgutilhx2.dll>
文件路径: C:\WINDOWS\system32\imgutilhx2.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{28766E1C-74B0-4417-8C75-F12AE309EF35}> <C:\WINDOWS\system32\wzcfsw.dll>
文件路径: C:\WINDOWS\system32\wzcfsw.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00030003-0003-0003-0003-00030003BB15}> <C:\WINDOWS\system32\bootvidgj.dll>
文件路径: C:\WINDOWS\system32\bootvidgj.dll [未知]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00050005-0005-0005-0005-00050005BB15}> <C:\WINDOWS\system32\cliconfgzx.dll>
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{021F087F-4378-545F-74FA-37D345AD7A8C}> <C:\WINDOWS\system32\mttwfh.dll>
文件路径: C:\WINDOWS\system32\mttwfh.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}> <C:\WINDOWS\system32\sgdewg.dll>
文件路径: C:\WINDOWS\system32\sgdewg.dll [分析中]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{00250025-0025-0025-0025-00250025BB15}> <C:\WINDOWS\system32\slbiopfs2.dll>
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{C0595A7E-2E2F-4B34-A83A-019270A0A464}> <C:\WINDOWS\system32\tdffdl.dll>
文件路径: C:\WINDOWS\system32\tdffdl.dll [病毒程序]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
<{000F087F-4378-545F-74FA-37D345AD7A8C}> <C:\WINDOWS\system32\mttwfh.dll>
文件路径: C:\WINDOWS\system32\mttwfh.dll [分析中]
==============================================================
启动文件夹位置
==============================================================
Common Startup: C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Startup: C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
Host File
==============================================================
127.0.0.1 localhost
==============================================================
驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[HiddFldy] [已启用] <\??\C:\WINDOWS\system32\d32dx9.sys>
[IIS Manager ] [已启用] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp>
==============================================================
其他安全区域
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
[显示摇曳 CPL 扩展] <deskpan.dll>