(接上帖)
这些是QQ医生的诊断报告:
本报告由QQ医生提供 http://doctor.qq.com
诊断时间: 2009-7-28 18:31:7
操作系统: Windows XP Service Pack 3
QQ医生版本:
QQDoctor.exe 3.0.16.201
DrUpdate.exe 3, 0, 16, 201
TSELoder.DAT 2008, 1, 28, 13
TSEngine.DAT 2008, 4, 7, 25
TSEPB.DAT 2009, 3, 5, 35
TSFSEngine.DAT 2009, 3, 11, 7
TSFileFilter.DAT 2007, 12, 5, 01
TSKsp.sys 2009, 6, 25, 17
TSKSPLIB.dat 2009, 7, 1, 16
TSVulMon.DAT 2009, 6, 25, 22
TSVulChk.dat 2009, 7, 28, 36
====================进程项====================
C:\WINDOWS\System32\alg.exe (Microsoft Corporation, 43.5 KB, 5.1.2600.5512 (xpsp.080413-0852)) f031c127d798e1549861317064066287
(, , )
(, , )
(, , )
C:\WINDOWS\Explorer.EXE (Microsoft Corporation, 955.5 KB, 6.00.2900.5512 (xpsp.080413-2105)) 9eb867933136ad37eaf7f2ecb97e3a4d
C:\WINDOWS\Explorer.EXE [Microsoft Corporation]
C:\WINDOWS\system32\ntdll.dll [Microsoft Corporation]
C:\WINDOWS\system32\kernel32.dll [Microsoft Corporation]
C:\WINDOWS\system32\ADVAPI32.dll [Microsoft Corporation]
C:\WINDOWS\system32\RPCRT4.dll [Microsoft Corporation]
C:\WINDOWS\system32\Secur32.dll [Microsoft Corporation]
C:\WINDOWS\system32\BROWSEUI.dll [Microsoft Corporation]
C:\WINDOWS\system32\GDI32.dll [Microsoft Corporation]
C:\WINDOWS\system32\USER32.dll [Microsoft Corporation]
C:\WINDOWS\system32\msvcrt.dll [Microsoft Corporation]
C:\WINDOWS\system32\ole32.dll [Microsoft Corporation]
C:\WINDOWS\system32\SHLWAPI.dll [Microsoft Corporation]
C:\WINDOWS\system32\OLEAUT32.dll [Microsoft Corporation]
C:\WINDOWS\system32\SHDOCVW.dll [Microsoft Corporation]
C:\WINDOWS\system32\CRYPT32.dll [Microsoft Corporation]
C:\WINDOWS\system32\MSASN1.dll [Microsoft Corporation]
C:\WINDOWS\system32\CRYPTUI.dll [Microsoft Corporation]
C:\WINDOWS\system32\NETAPI32.dll [Microsoft Corporation]
C:\WINDOWS\system32\VERSION.dll [Microsoft Corporation]
C:\WINDOWS\system32\WININET.dll [Microsoft Corporation]
C:\WINDOWS\system32\Normaliz.dll [Microsoft Corporation]
C:\WINDOWS\system32\urlmon.dll [Microsoft Corporation]
C:\WINDOWS\system32\iertutil.dll [Microsoft Corporation]
C:\WINDOWS\system32\WINTRUST.dll [Microsoft Corporation]
C:\WINDOWS\system32\IMAGEHLP.dll [Microsoft Corporation]
C:\WINDOWS\system32\WLDAP32.dll [Microsoft Corporation]
C:\WINDOWS\system32\SHELL32.dll [Microsoft Corporation]
C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation]
C:\WINDOWS\system32\ShimEng.dll [Microsoft Corporation]
C:\WINDOWS\AppPatch\AcGenral.DLL [Microsoft Corporation]
C:\WINDOWS\system32\WINMM.dll [Microsoft Corporation]
C:\WINDOWS\system32\MSACM32.dll [Microsoft Corporation]
C:\WINDOWS\system32\USERENV.dll [Microsoft Corporation]
C:\WINDOWS\system32\IMM32.DLL [Microsoft Corporation]
C:\WINDOWS\system32\LPK.DLL [Microsoft Corporation]
C:\WINDOWS\system32\USP10.dll [Microsoft Corporation]
C:\WINDOWS\system32\PSAPI.DLL [Microsoft Corporation]
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [Microsoft Corporation]
C:\WINDOWS\system32\comctl32.dll [Microsoft Corporation]
C:\WINDOWS\system32\apphelp.dll [Microsoft Corporation]
C:\WINDOWS\system32\msctfime.ime [Microsoft Corporation]
C:\WINDOWS\system32\MSIMG32.dll [Microsoft Corporation]
C:\WINDOWS\system32\NTMARTA.DLL [Microsoft Corporation]
C:\WINDOWS\system32\SAMLIB.dll [Microsoft Corporation]
C:\WINDOWS\system32\CLBCATQ.DLL [Microsoft Corporation]
C:\WINDOWS\system32\COMRes.dll [Microsoft Corporation]
C:\WINDOWS\System32\cscui.dll [Microsoft Corporation]
C:\WINDOWS\System32\CSCDLL.dll [Microsoft Corporation]
C:\WINDOWS\system32\themeui.dll [Microsoft Corporation]
C:\WINDOWS\system32\xpsp2res.dll [Microsoft Corporation]
C:\WINDOWS\system32\actxprxy.dll [Microsoft Corporation]
C:\WINDOWS\system32\msutb.dll [Microsoft Corporation]
C:\WINDOWS\system32\MSCTF.dll [Microsoft Corporation]
C:\WINDOWS\system32\LINKINFO.dll [Microsoft Corporation]
C:\WINDOWS\system32\ntshrui.dll [Microsoft Corporation]
C:\WINDOWS\system32\ATL.DLL [Microsoft Corporation]
C:\WINDOWS\system32\msi.dll [Microsoft Corporation]
C:\WINDOWS\system32\SETUPAPI.dll [Microsoft Corporation]
C:\WINDOWS\system32\ieframe.dll [Microsoft Corporation]
C:\WINDOWS\system32\MLANG.dll [Microsoft Corporation]
C:\WINDOWS\system32\rsaenh.dll [Microsoft Corporation]
C:\WINDOWS\system32\NETSHELL.dll [Microsoft Corporation]
C:\WINDOWS\system32\credui.dll [Microsoft Corporation]
C:\WINDOWS\system32\dot3api.dll [Microsoft Corporation]
C:\WINDOWS\system32\rtutils.dll [Microsoft Corporation]
C:\WINDOWS\system32\dot3dlg.dll [Microsoft Corporation]
C:\WINDOWS\system32\OneX.DLL [Microsoft Corporation]
C:\WINDOWS\system32\WTSAPI32.dll [Microsoft Corporation]
C:\WINDOWS\system32\WINSTA.dll [Microsoft Corporation]
C:\WINDOWS\system32\eappcfg.dll [Microsoft Corporation]
C:\WINDOWS\system32\MSVCP60.dll [Microsoft Corporation]
C:\WINDOWS\system32\eappprxy.dll [Microsoft Corporation]
C:\WINDOWS\system32\iphlpapi.dll [Microsoft Corporation]
C:\WINDOWS\system32\WS2_32.dll [Microsoft Corporation]
C:\WINDOWS\system32\WS2HELP.dll [Microsoft Corporation]
C:\WINDOWS\system32\webcheck.dll [Microsoft Corporation]
C:\WINDOWS\system32\stobject.dll [Microsoft Corporation]
C:\WINDOWS\system32\BatMeter.dll [Microsoft Corporation]
C:\WINDOWS\system32\POWRPROF.dll [Microsoft Corporation]
C:\WINDOWS\system32\WPDShServiceObj.dll [Microsoft Corporation]
C:\WINDOWS\system32\WINHTTP.dll [Microsoft Corporation]
C:\WINDOWS\system32\wdmaud.drv [Microsoft Corporation]
C:\WINDOWS\system32\msacm32.drv [Microsoft Corporation]
C:\WINDOWS\system32\midimap.dll [Microsoft Corporation]
C:\WINDOWS\system32\mydocs.dll [Microsoft Corporation]
C:\WINDOWS\system32\PortableDeviceTypes.dll [Microsoft Corporation]
C:\WINDOWS\system32\PortableDeviceApi.dll [Microsoft Corporation]
C:\WINDOWS\system32\MPR.dll [Microsoft Corporation]
C:\WINDOWS\System32\drprov.dll [Microsoft Corporation]
C:\WINDOWS\System32\ntlanman.dll [Microsoft Corporation]
C:\WINDOWS\System32\NETUI0.dll [Microsoft Corporation]
C:\WINDOWS\System32\NETUI1.dll [Microsoft Corporation]
C:\WINDOWS\System32\NETRAP.dll [Microsoft Corporation]
C:\WINDOWS\System32\davclnt.dll [Microsoft Corporation]
C:\WINDOWS\system32\quartz.dll [Microsoft Corporation]
C:\WINDOWS\system32\SXS.DLL [Microsoft Corporation]
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation, 152.1 KB, 6.14.10.9148) 986d6666e076afd2b60acafd5b01a00f
C:\WINDOWS\system32\services.exe (Microsoft Corporation, 108.0 KB, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)) 803423c13395019f2dd004ff5a3c0290
C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation, 56.5 KB, 5.1.2600.5512 (xpsp.080413-0852)) 6475496dea6eae2046e15cf422c205fa
C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, 14.0 KB, 5.1.2600.5512 (xpsp.080413-2111)) e31fb4f13f5949b868c117714bb44375
C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, 14.0 KB, 5.1.2600.5512 (xpsp.080413-2111)) e31fb4f13f5949b868c117714bb44375
C:\WINDOWS\System32\svchost.exe (Microsoft Corporation, 14.0 KB, 5.1.2600.5512 (xpsp.080413-2111)) e31fb4f13f5949b868c117714bb44375
C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, 14.0 KB, 5.1.2600.5512 (xpsp.080413-2111)) e31fb4f13f5949b868c117714bb44375
C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, 14.0 KB, 5.1.2600.5512 (xpsp.080413-2111)) e31fb4f13f5949b868c117714bb44375
====================启动项====================
AlternateShell [Microsoft Corporation] (cmd.exe)
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot" 83ba7e22bf529858a345f483d7e94c16
AlternateShell [Microsoft Corporation] (cmd.exe)
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot" 83ba7e22bf529858a345f483d7e94c16
BootExecute [Microsoft Corporation] (autochk *)
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" 0d96293ea4bf2838ddaadc9bc52d9ef9
NvCplDaemon [NVIDIA Corporation] (RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" bf992604adfe10d8f7343d9df2e91ff6
NvMediaCenter [NVIDIA Corporation] (RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" 9ffa0f0822246ba7cec9e55ad1c77ff8
nwiz [NVIDIA Corporation] (nwiz.exe /install)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" bf40c88ceebd9ea8f5d1ec858d9cc92e
Shell [Microsoft Corporation] (Explorer.exe)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 9eb867933136ad37eaf7f2ecb97e3a4d
UIHost [Microsoft Corporation] (logonui.exe)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 585c5b365163cc8c4767987beea4866b
Userinit [Microsoft Corporation] (C:\WINDOWS\system32\userinit.exe)
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 431fed77e71b1831cd485890159d467c
====================BHO====================
HKbar Class [北京千兆时代科技有限公司] {9D9E8E93-78DE-4c43-9951-571BE86D5060}
"d:\program files\刘禹的文件夹\魔法兔子\haokanbar.dll" 启用 fbeb54ddd10534fa6d061dc4c62af3b1
====================IE右键菜单====================
&使用超级旋风下载 [D:\My Documents超级旋风\geturl.htm]
&使用超级旋风下载本页视频 [D:\My Documents超级旋风\geturlflv.htm]
使用迅雷下载 [C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm]
使用迅雷下载全部链接 [C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm]
添加为广告拦截图片 [D:\Program Files\刘禹的文件夹\魔法兔子\AddBlock.htm]
====================ActiveX对象====================
AxInputControl Class [] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD}
"c:\windows\downloaded program files\inputcontrol.dll" 启用 f43fdbd955390b14db8da489d0ccd5c2
DLM Control [Akamai Technologies, Inc.] {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
"c:\windows\downloaded program files\downloadmanagerv2.ocx" 启用 8fdc3e87529429bb5fbc60cfc46e4e4a
InfoSecNetSign Class [Infosec Technologies Co., Ltd.] {62B938C4-4190-4F37-8CF0-A92B0A91CC77}
"c:\windows\downloaded program files\netsign.dll" 启用 46d86abf53081fe91ff70940f722e8ae
====================系统服务====================
AppMgmt [Microsoft Corporation] "C:\WINDOWS\System32\appmgmts.dll" 启用 28b700b7fdc38f343197798e0403c584
AudioSrv [Microsoft Corporation] "C:\WINDOWS\System32\audiosrv.dll" 启用 0c03a81067bfe60ab076fb866eeb7d44
BITS [Microsoft Corporation] "C:\WINDOWS\system32\qmgr.dll" 启用 77136d334eebb32f38fddd74e6d20380
Browser [Microsoft Corporation] "C:\WINDOWS\System32\browser.dll" 禁用 b5030062dc5d227b063b65fef328e36f
CiSvc [Microsoft Corporation] "C:\WINDOWS\system32\cisvc.exe" 禁用 7fb470ae06a28a8cb035593d820d9497
ClipSrv [Microsoft Corporation] "C:\WINDOWS\system32\clipsrv.exe" 禁用 1c8773b346a2e789f1729fc1c5ff4e6f
COMSysApp [Microsoft Corporation] "C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" 禁用 eddfaaa9db2c1f6aa9631b621352ca83
CryptSvc [Microsoft Corporation] "C:\WINDOWS\System32\cryptsvc.dll" 启用 30f1c6eddba5d5b1da054b07d31843db
DcomLaunch [Microsoft Corporation] "C:\WINDOWS\system32\rpcss.dll" 启用 e9d71100b51af947485c1a1d5bb96420
Dhcp [Microsoft Corporation] "C:\WINDOWS\System32\dhcpcsvc.dll" 启用 1a93467e7bd9eaad9049488f3b45c0e8
dmadmin [Microsoft Corp., Veritas Software] "C:\WINDOWS\System32\dmadmin.exe /com" 禁用 65b12edacdcf3c7866615955cb3ab3ef
dmserver [Microsoft Corp.] "C:\WINDOWS\System32\dmserver.dll" 启用 d22b022857d2c8618a92837648156752
Dnscache [Microsoft Corporation] "C:\WINDOWS\System32\dnsrslvr.dll" 禁用 025abcb78f69dd458199745194fb53e2
Dot3svc [Microsoft Corporation] "C:\WINDOWS\System32\dot3svc.dll" 禁用 2977b1a2f8273f55ccd0158e1ed6578a
EapHost [Microsoft Corporation] "C:\WINDOWS\System32\eapsvc.dll" 禁用 b347c2edeacc53a98beafe41835ae1a1
EQService [EQSecure] "C:\Program Files\EQSecure\EQService.exe" 启用 c672a61c4d80ce80457380b9c34f4a32
ERSvc [Microsoft Corporation] "C:\WINDOWS\System32\ersvc.dll" 禁用 34bf0b68949d77e60cebcdbb35cfbe77
Eventlog [Microsoft Corporation] "C:\WINDOWS\system32\services.exe" 启用 803423c13395019f2dd004ff5a3c0290
EventSystem [Microsoft Corporation] "C:\WINDOWS\system32\es.dll" 启用 de60a74e82358cedbe8c94151f134dc3
FastUserSwitchingCompatibility [Microsoft Corporation] "C:\WINDOWS\System32\shsvcs.dll" 启用 5daa2d4ebd23f1458bdcf1804ac99c5a
helpsvc [Microsoft Corporation] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll" 禁用 01f1dc4933a4607962a4d2341ef4f0f1
HidServ [] "C:\WINDOWS\System32\hidserv.dll" 禁用
hkmsvc [Microsoft Corporation] "C:\WINDOWS\System32\kmsvc.dll" 禁用 5c3907a0fcf9e3940ee6c6414fc47ae7
HTTPFilter [Microsoft Corporation] "C:\WINDOWS\System32\w3ssl.dll" 禁用 f73a83fea9ea0ea702f6b36203c8fa9f
ImapiService [Microsoft Corporation] "C:\WINDOWS\system32\imapi.exe" 禁用 4dba71b5715badfbe82a628261c199b7
Irmon [Microsoft Corporation] "C:\WINDOWS\System32\irmon.dll" 启用 93f80e478bdb6d7117631f562d0a4ca1
lanmanserver [Microsoft Corporation] "C:\WINDOWS\System32\srvsvc.dll" 禁用 d62596b55a2b7e4df4fb4e396c7f8d96
lanmanworkstation [Microsoft Corporation] "C:\WINDOWS\System32\wkssvc.dll" 启用 7f47851da6ab84a2a11bfe55f983c134
LmHosts [Microsoft Corporation] "C:\WINDOWS\System32\lmhsvc.dll" 启用 b503b858d30afd561208aed67588a47d
Messenger [Microsoft Corporation] "C:\WINDOWS\System32\msgsvc.dll" 禁用 6a0e18bc3e2b2f795b5f1b0bec181e7a
mnmsrvc [Microsoft Corporation] "C:\WINDOWS\system32\mnmsrvc.exe" 禁用 f2ab0bc6bd8ef7b86cbe1e52b8c15924
MSDTC [Microsoft Corporation] "C:\WINDOWS\system32\msdtc.exe" 禁用 d9ff5f8b58d1e71933fbcf4dc6b3b492
MSIServer [Microsoft Corporation] "C:\WINDOWS\system32\msiexec.exe /V" 禁用 6c985ebcd34f92d666b365b28272195f
napagent [Microsoft Corporation] "C:\WINDOWS\System32\qagentrt.dll" 禁用 ca624a432dfafd9d2765e56d4dc686c7
NetDDE [Microsoft Corporation] "C:\WINDOWS\system32\netdde.exe" 禁