|
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2008-04-25 19:48:39
诊断平台: Microsoft Windows XP Service Pack 2
IE版本: Internet Explorer V7.0.5730.13 Build:75730
计算机物理内存:223.48MB - 当前可用内存:41.91MB
100 - 未知 - Process: MPSVC.exe [MPSVC] -
100 - 未知 - Process: MPSVC2.exe [MPSVC2] -
100 - 未知 - Process: MPSVC1.exe [MPSVC1] -
100 - 未知 - Process: MPMon.exe [MPMon] -
100 - 未知 - Process: AppleMobileDeviceService.exe [Apple Mobile Device Service] - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
100 - 未知 - Process: DevSvc.exe [Capture Device Service] - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
100 - 未知 - Process: 360tray.exe [360安全卫士实时保护模块] - F:\360safe\safemon\360Tray.exe
O2 - 未知 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - F:\Thunder.v5.6.1.292\Thunder.v5.6.1.292\ComDlls\TDAtOnce_Now.dll
O4 - 未知 - HKCU\..\Run: [输入法补丁] [Keyboard Language Indicator Applet] C:\WINDOWS\system32\internat.exe
O8 - 未知 - Extra context menu item: iSee 保存所有图片 - F:\Program Files\iSee\iSeeSavePicAll.htm
O8 - 未知 - Extra context menu item: iSee保存Flash - F:\Program Files\iSee\iSeeSaveFlash.htm
O8 - 未知 - Extra context menu item: iSee保存所有图片 - F:\Program Files\iSee\iSeeSavePicAll.htm
O8 - 未知 - Extra context menu item: iSee读取Exif - F:\Program Files\iSee\iSeeReadExif.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载 - F:\Thunder.v5.6.1.292\Thunder.v5.6.1.292\Program\geturl.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载全部链接 - F:\Thunder.v5.6.1.292\Thunder.v5.6.1.292\Program\getallurl.htm
O16 - 未知 - DPF: 无效的CLSID:{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ({8FFBE65D-2C9C-4669-84BD-5829DC0B603C}) - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O18 - 未知 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - 未知 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O23 - 未知 - Service: Apple Mobile Device [为 Apple 移动设备提供接口。] - "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" - (running)
O23 - 未知 - Service: Capture Device Service [Manages device arrival and removal event. This service is provided by InterVideo.] - "C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe" - (running)
O23 - 未知 - Service: gusvc [Google Updater Service] - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" - (not running)
O23 - 未知 - Service: MPSVCService [微点主动防御软件] - F:\Program Files\Micropoint\MPSVC.exe - (running)
O23 - 未知 - Service: NHLscA [提供域名系统 (DNS) 名称解析扩展,有效提高网络访问速度。] - C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087 - (not running)
O30 - 未知 - HKCU\..\Desktop: [Scrnsave.exe] [My Pictures Slideshow Screensaver] C:\WINDOWS\system32\ssmypics.scr
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe
100 - 安全 - Process: ULCDRSvr.exe [友立资讯公司(ulead systems, inc.)出品的dvd编辑软件的一部分。] - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe
100 - 安全 - Process: iexplore.exe [microsoft internet explorer浏览器用于浏览网页。] - C:\Program Files\Internet Explorer\iexplore.exe
100 - 安全 - Process: Dialterminal.exe [星空极速是陕西电信研究和开发的新一代的个人宽、窄带用户上网的用户端客户软件。] - C:\Program Files\ChinaNetSn\bin\Dialterminal.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINDOWS\system32\conime.exe
100 - 安全 - Process: NOTEPAD.EXE [notepad字符编辑器用于打开文档。在windows中附带。] - C:\WINDOWS\notepad.exe
100 - 安全 - Process: 360安全卫士诊断工具.exe [] - C:\Documents and Settings\gr\桌面\CheckTool\360安全卫士诊断工具.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=about:blank
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=about:blank
O2 - 安全 - BHO: (超级兔子上网精灵) - [超级兔子上网精灵相关插件。] - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - F:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\Thunder.v5.6.1.292\Thunder.v5.6.1.292\ComDlls\xunleiBHO_Now.dll
O3 - 安全 - Toolbar: (超级兔子上网精灵) - [超级兔子上网精灵工具条,随超级兔子软件捆绑安装。] - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - F:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - 安全 - HKLM\..\Run: [AVP] [卡巴斯基杀毒软件相关程序。] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O11 - 安全 - Options Group: International*
O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O18 - 安全 - Protocol: OFFICE 相关 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O23 - 安全 - Service: Adobe LM Service [adobe公司相关产品的许可服务程序。] - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" - (not running)
O23 - 安全 - Service: AVP [卡巴斯基杀毒软件相关程序。] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r - (running)
O23 - 安全 - Service: UleadBurningHelper [Ulead DVD workshop相关产品的一部分,该程序用于烧录DVD和CD媒体。] - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe - (running)
=======================================
O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -
O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -
O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 -
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 126464 - 614e5de28be4fb712f81298978d07a19
O31 - 未知 - SEApproved: {9DED7A30-D572-4D21-8D82-6945EA697400} - E:\0\flashpaper2\FlashPaper2.2\FlashPaperContextMenu.dll - - FlashPaper ContextMenu Module - 2.2.2302.0 - 163840 - aba29f38f4ba09b07923db7fa687306b
O31 - 未知 - SEApproved: {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll - Kaspersky Lab - Script Monitor Internet Explorer plugin - 6.0.1.411 - 184430 - 4cc929e541f65b096342840a7e62cd36
O31 - 未知 - SEApproved: {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - F:\Program Files\iTunes\iTunesMiniPlayer.dll - - - - 0 -
O31 - 未知 - SEApproved: {B62954A8-2446-4AEA-A2EE-489863352A51} - C:\Program Files\FileForceKiller\FileForceKiller.dll - DSW Lab - Anti Spyware Toolkit File Force Killer - 1.0.0.5 - 348160 - af70615d38fe8a654d8e8472dbae5e34
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 126464 - 614e5de28be4fb712f81298978d07a19
O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - winlogon.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - services.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - lsass.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - svchost.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - svchost.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - svchost.exe - Apple Inc. - C:\Program Files\Bonjour\mdnsNSP.dll - Bonjour Namespace Provider - eddec321b128328bc370a5447f7f8d69
O40 - svchost.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - svchost.exe - Apple Inc. - C:\Program Files\Bonjour\mdnsNSP.dll - Bonjour Namespace Provider - eddec321b128328bc370a5447f7f8d69
O40 - svchost.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - svchost.exe - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - Explorer.EXE - Micropoint Corporation - F:\Program Files\Micropoint\mp110031.dll - mp110031 - 7a8b4e67898a153b363143ba16683f83
O40 - Explorer.EXE - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll - Script Checker - e4f4b2a19754604fce54d33ac326cc1a
O40 - Explorer.EXE - 360.CN - F:\360safe\safemon\safemon.dll - 360安全卫士实时保护模块 - 24d9168c672c82fc2c8b670cd5434880
O40 - Explorer.EXE - DSW Lab - C:\Program Files\FileForceKiller\FileForceKiller.dll - Anti Spyware Toolkit File Force Killer - af70615d38fe8a654d8e8472dbae5e34
O40 - Explorer.EXE - - E:\0\flashpaper2\FlashPaper2.2\FlashPaperContextMenu.dll - FlashPaper ContextMenu Module - aba29f38f4ba09b07923db7fa687306b
O40 - Explorer.EXE - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll - Windows Shell Extension - 836a580b5800c8070854060be5ca94c7
=======================================
O41 - kl1 - Kaspersky Unified Driver - C:\WINDOWS\system32\drivers\kl1.sys - (running) - Kaspersky Unified Driver - Kaspersky Lab - bc02a8e0dd5dc266e5cc3636dd454403
O41 - klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Lab - f0653e5e164123cad51edda22418c2a3
O41 - KWatch3 - Kingsoft Antivirus KWatch Driver - C:\WINDOWS\system32\drivers\KWatch3.SYS - (running) - Kingsoft Antivirus KWatch Driver - Kingsoft Corporation - 12e5c78d3b802e8928dd4ffd8ba4d7fc
O41 - mp110001 - mp110001 - C:\WINDOWS\system32\drivers\mp110001.sys - (running) - mp110001 - MicroPoint Corporation - a9b4ea4aaeb3b1f691e80ad00ee9a822
O41 - mp110002 - mp110002 - C:\WINDOWS\system32\drivers\mp110002.sys - (running) - mp110002 - Micropoint Corporation - 404d55e5bbb0af942b54280009f91758
O41 - mp110003 - mp110003 - C:\WINDOWS\system32\drivers\mp110003.sys - (running) - mp110003 - Micropoint Corporation - f605fcc427896583226cc6b3173d2c3d
O41 - mp110004 - mp110004 - C:\WINDOWS\system32\drivers\mp110004.sys - (running) - mp110004 - Micropoint Corporation - e2f5019a8677b6b5eaeb1e6fd4e8c17e
O41 - mp110005 - mp110005 - C:\WINDOWS\system32\drivers\mp110005.sys - (running) - mp110005 - Micropoint Corporation - 31e351ad402febbb7471d5b1138d32bd
O41 - mp110006 - mp110006 - C:\WINDOWS\system32\drivers\mp110006.sys - (running) - mp110006 - Micropoint Corporation - 791d93fc7d02d43a225afdf2f6f762ca
O41 - mp110007 - mp110007 - C:\WINDOWS\system32\drivers\mp110007.sys - (running) - mp110007 - Micropoint Corporation - 3cdd1407c2959d0fcbb253bd7464ce9d
O41 - mp110008 - mp110008 - C:\WINDOWS\system32\drivers\mp110008.sys - (running) - mp110008 - Micropoint Corporation - fe5e48f05ccae50f4556d1898331169d
O41 - mp110009 - mp110009 - C:\WINDOWS\system32\drivers\mp110009.sys - (running) - mp110009 - Micropoint Corporation - 8caa2fa3858b6c5755051dbd57ca53dc
O41 - mp110010 - mp110010 - C:\WINDOWS\system32\drivers\mp110010.sys - (running) - mp110010 - Micropoint Corporation - f579fb3f7800a99c1dc93b35717418f4
O41 - mp110011 - mp110011 - C:\WINDOWS\system32\drivers\mp110011.sys - (running) - mp110011 - Micropoint Corporation - 8bbe523d2f31a6dc658cf88e39945705
O41 - mp110012 - mp110012 - C:\WINDOWS\system32\drivers\mp110012.sys - (running) - mp110012 - Micropoint Corporation - 3652c9ac7b8b886e7a41c533c1cb03b7
O41 - mp110013 - mp110013 - C:\WINDOWS\system32\drivers\mp110013.sys - (running) - mp110013 - Micropoint Corporation - 95ae9c794edadd5ba65e333ab5b58707
O41 - NPF - npf - C:\WINDOWS\system32\drivers\npf.sys - (running) - npf - CACE Technologies - d21fee8db254ba762656878168ac1db6
O41 - npkcrypt - nProtect KeyCrypt Driver - D:\QQ\npkcrypt.sys - (running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - PxHelp20 - Px Engine Device Driver for Windows 2000/XP - C:\WINDOWS\system32\drivers\pxhelp20.sys - (running) - Px Engine Device Driver for Windows 2000/XP - Sonic Solutions - f7bb4e7a7c02ab4a2672937e124e306e
O41 - WIBUKEY - WIBU-KEY Windows NT Kernel Driver - C:\WINDOWS\system32\drivers\Wibukey.sys - (running) - WIBU-KEY Windows NT Kernel Driver - WIBU-SYSTEMS AG - 2d14ac5df0fabf2f641b052d15e539ba
O41 - TesSafe - TesSafe NT Driver - C:\WINDOWS\system32\TesSafe.sys - (not running) - TesSafe NT Driver - TENCENT - 16a95cb4d80459d2e8f40660e33194aa
=======================================
[userinit.exe情况]
MD5: FD5CCDA253E5875C03E7EE2FC5E96022
文件大小: 23552
版本信息: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
是否签名: 是
未被感染
=======================================
[桌面快捷方式情况]
F:\360safe\360Safe.exe
=======================================
|
|