============================================================== 金山清理专家系统诊断报告 该诊断报告由金山清理专家提供 http://www.duba.net ============================================================== 诊断时间: 2008-11-03, 03:32 诊断平台: Windows XP [5.1.2600] Service Pack 2 IE版本: Internet Explorer V6.0.2180.2900 计算机物理内存: 1278(MB) 当前可用内存: 703(MB) 硬盘总大小: 204(GB) 硬盘可用空间: 16(GB) 清理专家版本: 2008,03,26,471 恶意软件库版本: 2008.04.24.3 漏洞库版本: 2008.04.09.1 ============================================================== 常规启动项 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [QkOnBtn] 文件路径: C:\Program Files\QBU\QkOnBtn.EXE [服务器忙] [EnergyUtility] 文件路径: C:\Program Files\Lenovo\EnergyCut\utilty.exe [服务器忙] [EnergyCut] 文件路径: C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe [服务器忙] [fscp] 文件路径: C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe [服务器忙] [nwiz] 文件路径: C:\WINDOWS\system32\nwiz.exe [服务器忙] [TkBellExe] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> 文件路径: C:\Program Files\Common Files\Real\Update_OB\realsched.exe [服务器忙] ============================================================== 启动文件夹位置 ============================================================== Common Startup: C:\Documents and Settings\All Users\「开始」菜单\程序\启动 Startup: C:\Documents and Settings\Administrator\「开始」菜单\程序\启动 Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动 ============================================================== 文件扩展名关联 ============================================================== .AVI <"d:\Final Codecs\myplayer.exe" "%1"> 文件路径: d:\Final Codecs\myplayer.exe [服务器忙] .M3U <"C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"> 文件路径: C:\Program Files\Real\RealPlayer\RealPlay.exe [服务器忙] .WMA <"C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"> 文件路径: C:\Program Files\Real\RealPlayer\RealPlay.exe [服务器忙] .MP3 <"C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"> 文件路径: C:\Program Files\Real\RealPlayer\RealPlay.exe [服务器忙] .MPG(.MPEG) <"d:\Final Codecs\myplayer.exe" "%1"> 文件路径: d:\Final Codecs\myplayer.exe [服务器忙] ============================================================== Host File ============================================================== 127.0.0.1 localhost ============================================================== 系统服务 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services [Adobe LM Service] [已启用] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> 文件路径: C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [服务器忙] [Bonjour Service] [已启用] <"C:\Program Files\Bonjour\mDNSResponder.exe"> 文件路径: C:\Program Files\Bonjour\mDNSResponder.exe [服务器忙] [FLEXnet Licensing Service] [已启用] <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"> 文件路径: C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [服务器忙] [FspadSvc] [已启用] 文件路径: C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe [服务器忙] [HidServ] [已禁用] <%SystemRoot%\System32\hidserv.dll> ============================================================== 驱动程序 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 [vidc.iv50] [已启用] 文件路径: C:\WINDOWS\system32\ir50_32.dll [服务器忙] [msacm.voxacm160] [已启用] 文件路径: C:\WINDOWS\system32\vct3216.acm [服务器忙] [vidc.DIVX] [已启用] 文件路径: C:\WINDOWS\system32\DivX.dll [服务器忙] [vidc.yv12] [已启用] 文件路径: C:\WINDOWS\system32\yv12vfw.dll [服务器忙] [VIDC.HFYU] [已启用] 文件路径: C:\WINDOWS\system32\huffyuv.dll [服务器忙] [vidc.VP60] [已启用] 文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙] [vidc.VP61] [已启用] 文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙] [vidc.VP62] [已启用] 文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙] [vidc.VP70] [已启用] 文件路径: C:\WINDOWS\system32\vp7vfw.dll [服务器忙] [VIDC.WMV3] [已启用] 文件路径: C:\WINDOWS\system32\wmv9vcm.dll [服务器忙] [VIDC.XVID] [已启用] 文件路径: C:\WINDOWS\system32\xvidvfw.dll [服务器忙] [msacm.lameacm] [已启用] 文件路径: C:\WINDOWS\system32\lameACM.acm [服务器忙] [msacm.ac3acm] [已启用] 文件路径: C:\WINDOWS\system32\AC3ACM.acm [服务器忙] [msacm.l3codecp] [已启用] 文件路径: C:\WINDOWS\system32\l3codecp.acm [服务器忙] [msacm.vorbis] [已启用] 文件路径: C:\WINDOWS\system32\vorbis.acm [服务器忙] [vidc.ffds] [已启用] 文件路径: C:\WINDOWS\system32\ff_vfw.dll [服务器忙] -------------------------------------------------------------- 该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services [CMB8100] [已启用] <\??\C:\WINDOWS\system32\Drivers\CertClient.dat> 文件路径: C:\WINDOWS\system32\Drivers\CertClient.dat [服务器忙] [CMBProtector] [已启用] <\??\C:\WINDOWS\system32\Drivers\CMBProtector.dat> 文件路径: C:\WINDOWS\system32\Drivers\CMBProtector.dat [服务器忙] [DKbFltr] [已启用] 文件路径: C:\WINDOWS\system32\Drivers\DKbFltr.sys [服务器忙] [npkcrypt] [已启用] <\??\e:\Tencent\QQ\npkcrypt.sys> [prodrv06] [已启用] <\SystemRoot\System32\drivers\prodrv06.sys> 文件路径: C:\WINDOWS\System32\drivers\prodrv06.sys [服务器忙] [prohlp02] [已启用] 文件路径: C:\WINDOWS\system32\drivers\prohlp02.sys [服务器忙] [prosync1] [已启用] 文件路径: C:\WINDOWS\system32\drivers\prosync1.sys [服务器忙] [QKeyService] [已启用] 文件路径: C:\WINDOWS\system32\KeyCrypt.sys [服务器忙] [sfdrv01] [已启用] 文件路径: C:\WINDOWS\system32\drivers\sfdrv01.sys [服务器忙] [sfhlp01] [已启用] 文件路径: C:\WINDOWS\system32\drivers\sfhlp01.sys [服务器忙] [sfhlp02] [已启用] 文件路径: C:\WINDOWS\system32\drivers\sfhlp02.sys [服务器忙] [sfsync04] [已启用] 文件路径: C:\WINDOWS\system32\drivers\sfsync04.sys [服务器忙] [sptd] [已启用] 文件路径: C:\WINDOWS\system32\Drivers\sptd.sys [文件无法访问] ============================================================== BHO ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} 文件路径: d:\Thunder\ComDlls\XunLeiBHO_004.dll [服务器忙] ============================================================== 当前进程 ============================================================== 名称: mDNSResponder.exe [已启用] 命令行: "C:\Program Files\Bonjour\mDNSResponder.exe" 文件路径: C:\Program Files\Bonjour\mDNSResponder.exe [服务器忙] (Apple Computer, Inc.) 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\hnetcfg.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\System32\wshtcpip.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MPRAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ACTIVEDS.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\adsldpc.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WLDAP32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ATL.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SAMLIB.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\comctl32.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\CLBCATQ.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMRes.dll (Microsoft Corporation) 名称: FspadSvr.exe [已启用] 命令行: "C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe" 文件路径: C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe [服务器忙] 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMCTL32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 名称: QkOnBtn.EXE [已启用] 命令行: "C:\Program Files\QBU\QkOnBtn.EXE" 文件路径: C:\Program Files\QBU\QkOnBtn.EXE [服务器忙] (Dritek System Inc.) 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: C:\Program Files\QBU\ComFnUtl.dll (Dritek System Inc.) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\Program Files\QBU\Wnd2File.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\SzUPFUtl.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\OSDUtl.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\RgnMaker.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\CDRomUtl.dll (Dritek System Inc.) 模块文件: C:\WINDOWS\system32\WINMM.dll (Microsoft Corporation) 模块文件: C:\Program Files\QBU\MixerUtl.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\LgKCUtl.dll (Dritek System Inc.) 模块文件: C:\Program Files\QBU\MMDUtl.dll (Dritek System Inc.) 模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINTRUST.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMAGEHLP.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msacm32.drv (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSACM32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\midimap.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WTSAPI32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINSTA.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation) 名称: utilty.exe [已启用] 命令行: "C:\Program Files\Lenovo\EnergyCut\utilty.exe" 文件路径: C:\Program Files\Lenovo\EnergyCut\utilty.exe [服务器忙] (TODO: ) 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINMM.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINSPOOL.DRV (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\oledlg.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINTRUST.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMAGEHLP.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msacm32.drv (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSACM32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\midimap.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation) 名称: EnergyCut.exe [已启用] 命令行: "C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe" 文件路径: C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe [服务器忙] 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\POWRPROF.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation) 模块文件: C:\Program Files\Lenovo\EnergyCut\HookLib.dll 模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINSPOOL.DRV (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\oledlg.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\CLBCATQ.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMRes.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\hnetcfg.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\NETSHELL.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\credui.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ATL.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation) 名称: fscp.exe [已启用] 命令行: "C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe" 文件路径: C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe [服务器忙] 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMCTL32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHELL32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLE32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEPRO32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WTSAPI32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WINSTA.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation) 名称: realsched.exe [已启用] 命令行: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot 文件路径: C:\Program Files\Common Files\Real\Update_OB\realsched.exe [服务器忙] (RealNetworks, Inc.) 模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\kmon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\ijt_base.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\comctl32.dll (Microsoft Corporation) 模块文件: c:\program files\rising\rfw\olemon.dll (Beijing Rising Information Technology Co., Ltd.) 模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\CLBCATQ.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\COMRes.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\NTMARTA.DLL (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\WLDAP32.dll (Microsoft Corporation) 模块文件: C:\WINDOWS\system32\SAMLIB.dll (Microsoft Corporation) ============================================================== 协议 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter 文件路径: C:\WINDOWS\system32\mscoree.dll [服务器忙] 文件路径: C:\WINDOWS\system32\mscoree.dll [服务器忙] 文件路径: C:\WINDOWS\system32\mscoree.dll [服务器忙] -------------------------------------------------------------- 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler 文件路径: C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [服务器忙] ============================================================== 第3方IE插件 ============================================================== 名称: nprfxins.dll [已启用] 文件路径: C:\Program Files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll [服务器忙] 名称: nptgeqplugin.dll [已启用] 文件路径: C:\Program Files\Internet Explorer\PLUGINS\nptgeqplugin.dll [服务器忙] ============================================================== IE扩展按钮 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions [启动迅雷5] <{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}> 文件路径: d:\Thunder\Thunder.exe [服务器忙] [联想] <{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}> ============================================================== IE扩展菜单 ============================================================== 该项来源: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt <&使用迅雷下载> 文件路径: d:\Thunder\Program\GetUrl.htm [服务器忙] <&使用迅雷下载全部链接> 文件路径: d:\Thunder\Program\GetAllUrl.htm [服务器忙] <使用 Mega 管理器下载链接...> 文件路径: D:\Megaupload\Mega Manager\mm_file.htm [服务器忙] <添加到QQ表情> 文件路径: d:\QQ\AddEmotion.htm [服务器忙] ============================================================== ActiveX控件 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] <{89B4C1CD-B018-4511-B0A1-5476DBF70820}> 文件路径: C:\WINDOWS\system32\mscories.dll [服务器忙] -------------------------------------------------------------- 该项来源: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats [Edit Class] <{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}> 文件路径: C:\WINDOWS\system32\CMBEdit.dll [服务器忙] [XWrapper Control] <{1A65F0C5-AC05-11D5-AF77-00E02998142A}> 文件路径: C:\PROGRA~1\INTERN~1\Plugins\xwrapper.ocx [服务器忙] [RealPlayer RAM Download Handler] <{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}> 文件路径: C:\WINDOWS\system32\rmoc3260.dll [服务器忙] [TTestGenXInstallObject] <{37A273C2-5129-11D5-BF37-00A0CCE8754B}> 文件路径: C:\WINDOWS\DOWNLO~1\TESTGE~1.DLL [服务器忙] [{41A31A45-6E0E-45EB-A1E3-0A692943C3B7}] <{41A31A45-6E0E-45EB-A1E3-0A692943C3B7}> [{51EF787E-F358-4CC9-8688-4E73E9DCDB8D}] <{51EF787E-F358-4CC9-8688-4E73E9DCDB8D}> [163Uploader Control] <{8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE}> 文件路径: C:\WINDOWS\system32\163UPL~1.OCX [服务器忙] [Thunder Browser Helper] <{889D2FEB-5411-4565-8998-1DD2C5261283}> 文件路径: d:\Thunder\ComDlls\XunLeiBHO_004.dll [服务器忙] [Pearson Installation Assistant 2] <{95D88B35-A521-472B-A182-BB1A98356421}> 文件路径: C:\WINDOWS\DOWNLO~1\PEARSO~1.OCX [服务器忙] [RealPlayer G2 Control] <{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}> 文件路径: C:\WINDOWS\system32\rmoc3260.dll [服务器忙] ============================================================== 其他安全区域 ============================================================== 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [显示摇曳 CPL 扩展] [WdmidleDeviceShellExtension] 文件路径: c:\program files\lenovo\energycut\powcpl.dll [服务器忙] [Desktop Explorer] 文件路径: C:\WINDOWS\system32\nvshell.dll [服务器忙] [{1E9B04FB-F9E5-4718-997B-B8DA88302A47}] 文件路径: C:\WINDOWS\system32\nvshell.dll [服务器忙] [nView Desktop Context Menu] 文件路径: C:\WINDOWS\system32\nvshell.dll [服务器忙] [WinRAR] 文件路径: C:\Program Files\WinRAR\rarext.dll [服务器忙] [RealOne Player Context Menu Class] 文件路径: C:\Program Files\Real\RealPlayer\rpshell.dll [服务器忙] [ShellLink for Application References] 文件路径: C:\WINDOWS\system32\dfshim.dll [服务器忙] [Shell Icon Handler for Application References] 文件路径: C:\WINDOWS\system32\dfshim.dll [服务器忙] -------------------------------------------------------------- 该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers [PDF Shell Extension] 文件路径: D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll [服务器忙]