各位高手: 非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助! 该诊断报告由360安全卫士提供 http://www.360.cn 诊断时间: 2009-01-20 00:13:33 诊断平台: Microsoft Windows XP Service Pack 2 IE版本: Internet Explorer V7.0.5730.13 Build:75730 计算机物理内存:2.00GB - 当前可用内存:1.48GB 100 - 未知 - Process: ATKOSD2.exe [ATKOSD2] - C:\Program Files\ATKOSD2\ATKOSD2.exe 100 - 未知 - Process: DMedia.exe [DMedia] - C:\Program Files\ASUS\ATK Media\DMEDIA.EXE 100 - 未知 - Process: HControl.exe [HControl] - C:\Program Files\ATK Hotkey\Hcontrol.exe 100 - 未知 - Process: ACMON.exe [ACMON ] - C:\Program Files\ASUS\Splendid\ACMON.exe 100 - 未知 - Process: PPSAP.exe [PPS 网络加速器] - C:\Program Files\PPStream\ppsap.exe 100 - 未知 - Process: ACEngSvr.exe [ACEngSvr Module] - C:\WINDOWS\system32\ACEngSvr.exe -Embedding 100 - 未知 - Process: ATKOSD.exe [ATKOSD] - C:\Program Files\ATK Hotkey\ATKOSD.exe 100 - 未知 - Process: WDC.exe [WDC Application] - C:\Program Files\ATK Hotkey\WDC.exe O4 - 未知 - HKLM\..\Run: [ATKOSD2] [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe" O4 - 未知 - HKLM\..\Run: [ATKMEDIA] [DMedia] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE O4 - 未知 - HKLM\..\Run: [ATKHOTKEY] [HControl] "C:\Program Files\ATK Hotkey\Hcontrol.exe" O4 - 未知 - HKLM\..\Run: [ACMON] [ACMON ] "C:\Program Files\ASUS\Splendid\ACMON.exe" O4 - 未知 - HKCU\..\Run: [PPS Accelerator] [PPS 网络加速器] C:\Program Files\PPStream\ppsap.exe O4 - 未知 - Startup folder: [CCC.lnk] [] C:\Documents and Settings\123\「开始」菜单\程序\启动\CCC.lnk O15 - 未知 - Trusted Zone: https://b2b.ccb.cn O15 - 未知 - Trusted Zone: https://www.ccb.com O15 - 未知 - Trusted Zone: https://*.ccb.com.cn O15 - 未知 - Trusted Zone: https://ca2.ccb.com.cn O15 - 未知 - Trusted Zone: https://ca3.ccb.com.cn O15 - 未知 - Trusted Zone: https://ibsbjstar.ccb.com.cn O15 - 未知 - Trusted Zone: https://mybank.ccb.com.cn O21 - 未知 - Protocol Icons: HKCR\http\shell\open\command - "C:\360safe\360se\360SE.exe" "%1" O21 - 未知 - Protocol Icons: HKCR\https\shell\open\command - "C:\360safe\360se\360SE.exe" "%1" O21 - 未知 - Protocol Icons: HKCR\htmlfile\shell\open\command - "C:\360safe\360se\360SE.exe" "%1" O23 - 未知 - Service: 36963 [36963] - C:\WINDOWS\system32\drivers\etc\Jl5M6pXf.dll - (not running) O23 - 未知 - Service: ccosm [Contrl Center of Storm Media] - C:\Program Files\StormII\stormliv.exe /asservice - (running) O23 - 未知 - Service: DNS system [为此计算机解析和缓冲域名系统。] - - (not running) O23 - 未知 - Service: NRS_Service [] - C:\WINDOWS\system32\srvany.exe - (not running) O23 - 未知 - Service: Qvod Terminal [QVOD媒体播放服务] - - (not running) O23 - 未知 - Service: WinIP_server [通过注册和更改 IP 地址以及 DNS 名称来管理] - C:\WINDOWS\System32\bptbwr.dll - (not running) O30 - 未知 - HKCU\..\Desktop: [Scrnsave.exe] [Default Screen Saver] C:\WINDOWS\system32\scrnsave.scr ======================================= 100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe 100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base 100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe 100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe 100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe 100 - 安全 - Process: ati2evxx.exe [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss 100 - 安全 - Process: CCenter.exe [瑞星杀毒软件控制台相关程序。] - C:\Program Files\Rising\Rav\CCENTER.EXE 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs 100 - 安全 - Process: S24EvMon.exe [无线网卡相关驱动程序,用于事件监控。] - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService 100 - 安全 - Process: ati2evxx.exe [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService 100 - 安全 - Process: RavMonD.exe [瑞星杀毒软件的一部分。] - C:\Program Files\Rising\Rav\RavMonD.exe 100 - 安全 - Process: rsnetsvr.exe [瑞星2009相关程序。] - C:\Program Files\Rising\Rav\rsnetsvr.exe 100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe 100 - 安全 - Process: stormliv.exe [暴风影音的应用程序] - C:\Program Files\StormII\stormliv.exe 100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE 100 - 安全 - Process: EvtEng.exe [英特尔公司出品的相关产品。] - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe 100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe 100 - 安全 - Process: MDM.EXE [debug除错管理用于调试应用程序和microsoft office中的microsoft script editor脚本编辑器。] - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 100 - 安全 - Process: RavTask.exe [瑞星出品的杀毒软件相关程序。] - C:\Program Files\Rising\Rav\RavTask.exe 100 - 安全 - Process: RegSrvc.exe [intel公司出品的安置在网卡驱动程序(intel proset)旁,用以通信服务。] - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe 100 - 安全 - Process: ScanFrm.exe [瑞星2009相关程序。] - C:\Program Files\Rising\Rav\ScanFrm.exe 100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k imgsvc 100 - 安全 - Process: msiexec.exe [windows installer的一部分。用来帮助windows installer package files (msi)格式的安装文件。] - C:\WINDOWS\system32\msiexec.exe /V 100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe 100 - 安全 - Process: RsTray.exe [瑞星2009相关程序。] - C:\Program Files\Rising\Rav\RsTray.exe 100 - 安全 - Process: ZCfgSvc.exe [intel无线网卡相关程序。] - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe 100 - 安全 - Process: iFrmewrk.exe [英特尔公司产品的无线局域网相关程序。] - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe 100 - 安全 - Process: Portctrl.exe [三星打印机驱动程序。] - C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE 100 - 安全 - Process: 360tray.exe [360安全卫士实时监控程序。] - C:\Program Files\360safe\safemon\360tray.exe 100 - 安全 - Process: AntiArp.exe [360安全卫士ARP防火墙相关程序。] - C:\Program Files\360safe\antiarp\antiarp.exe 100 - 安全 - Process: RTHDCPL.EXE [瑞昱出品的声卡相关程序。] - C:\WINDOWS\RTHDCPL.EXE 100 - 安全 - Process: safeboxtray.exe [360安全卫士保险箱相关程序。] - C:\Program Files\360Safebox\safeboxtray.exe 100 - 安全 - Process: Dot1XCfg.exe [Intel无线网卡的驱动文件。] - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe 100 - 安全 - Process: 360SE.exe [360安全浏览器] - C:\360safe\360se\360SE.exe 100 - 安全 - Process: taskmgr.exe [windows自带的任务管理器程序,用于察看系统中的进程信息。] - C:\WINDOWS\system32\taskmgr.exe 100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360Safe.exe O2 - 安全 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块。] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll O2 - 安全 - BHO: (Download_Bho Class) - [PPLive相关文件。] - {A986E409-30CC-4185-89BB-AB212C104524} - D:\PPLiveVA\DownloaderManager.dll O4 - 安全 - HKLM\..\Run: [RavTray] [瑞星公司出品的杀毒软件相关程序。] "C:\Program Files\Rising\Rav\RsTray.exe" -system O4 - 安全 - HKLM\..\Run: [IntelZeroConfig] [intel零配置mfc程序。] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - 安全 - HKLM\..\Run: [IntelWireless] [intel无线网卡相关软件。] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - 安全 - HKLM\..\Run: [IMJPMIG8.1] [微软Microsoft输入法编辑器程序。] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - 安全 - HKLM\..\Run: [GW Port Controller] [三星多功能一体机附带的管理软件。] C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE O4 - 安全 - HKLM\..\Run: [360Safetray] [360safe实时保护功能模块。] C:\Program Files\360safe\safemon\360tray.exe /start O4 - 安全 - HKLM\..\Run: [360Antiarp] [360安全卫士ARP防火墙相关程序。] C:\Program Files\360safe\antiarp\antiarp.exe /start O4 - 安全 - HKLM\..\Run: [RTHDCPL] [realtek声卡特性设置软件相关程序。] RTHDCPL.EXE O4 - 安全 - HKLM\..\Run: [Alcmtr] [一款声卡相关程序。] ALCMTR.EXE O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe O8 - 安全 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm O8 - 安全 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm O9 - 安全 - Extra button: 启动迅雷5(HKLM)(HKLM) - C:\Program Files\Thunder Network\Thunder\Thunder.exe O9 - 安全 - Extra button: 电台(HKLM) - C:\WINDOWS\web\related.htm O11 - 安全 - Options Group: International* O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL O18 - 安全 - Protocol: OFFICE 相关 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL O23 - 安全 - Service: Ati HotKey Poller [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe - (running) O23 - 安全 - Service: EvtEng [EvtEng相关模块,用于支持Intel无线网络连接硬件。] - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe - (running) O23 - 安全 - Service: RavCCenter [瑞星2009的相关服务。] - C:\Program Files\Rising\Rav\CCENTER.EXE - (not running) O23 - 安全 - Service: RavTask [瑞星2009的相关服务。] - "C:\Program Files\Rising\Rav\RavTask.exe" RavTask - (running) O23 - 安全 - Service: RegSrvc [Intel网络通讯软件相关程序。 ] - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - (running) O23 - 安全 - Service: RsRavMon [是瑞星杀毒软件相关监控程序。] - C:\Program Files\Rising\Rav\RavMonD.exe - (not running) O23 - 安全 - Service: RsScanSrv [瑞星2009的相关服务。] - C:\Program Files\Rising\Rav\ScanFrm.exe - (not running) O23 - 安全 - Service: S24EventMonitor [无线网卡配置和诊断程序。] - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe - (running) ======================================= O31 - 未知 - Notify: AtiExtEvent - C:\WINDOWS\system32\Ati2evxx.dll - ATI Technologies Inc. - ATI External Event Utility DLL Module - 6.14.10.4177 - 139264 - 4f42a636efdf4f778e0ba33470458774 O31 - 未知 - SODL: {8923C707-4FC3-438D-A0D4-99486583000E} - C:\WINDOWS\system32\opijcngn.dll - - - - 0 - O31 - 未知 - SODL: {0ECC6723-61ED-4E6B-975E-CC3C2A0E24E0} - C:\WINDOWS\system32\geccmnij.dll - - - - 0 - O31 - 未知 - SODL: {00074A9E-008F-4B53-AC4A-40CFE56AA5F3} - C:\WINDOWS\system32\gggnkape.dll - - - - 0 - O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 - O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 - O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 - O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 - O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 - O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 - O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 129024 - 60fe004235a8108446dcfc1e526fde0e O31 - 未知 - SEApproved: {e82a2d71-5b2f-43a0-97b8-81be15854de8} - C:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141 O31 - 未知 - SEApproved: {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} - C:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141 O31 - 未知 - SEApproved: {5E2121EE-0300-11D4-8D3B-444553540000} - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll - - ACE Context Menu - 2.0.0.0 - 73728 - 3a9f70479a886dcc8e5151326156472d O31 - 未知 - SEApproved: {6C125022-639D-43cc-9F3D-647E6CC69EF1} - C:\WINDOWS\ContextBG.dll - Grigri - Apply a background to the shell context menu - 1.0.0.1 - 622592 - 951509bda77ecf5f8652b8b723096355 O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 129024 - 60fe004235a8108446dcfc1e526fde0e O31 - 未知 - BootExecute: bsmain - - - - 0 - O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 - O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 - ======================================= O40 - winlogon.exe - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.dll - ATI External Event Utility DLL Module - 4f42a636efdf4f778e0ba33470458774 O40 - Explorer.EXE - Microsoft Corporation - C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL - Microsoft CHS Handwriting Input UI - f57acc08bf1cf65ec1865e23f77138ea O40 - Explorer.EXE - Grigri - C:\WINDOWS\ContextBG.dll - Apply a background to the shell context menu - 951509bda77ecf5f8652b8b723096355 O40 - Explorer.EXE - - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll - ACE Context Menu - 3a9f70479a886dcc8e5151326156472d O40 - Explorer.EXE - Intel Corporation - c:\windows\system32\netprovcredman.dll - Network Provider Credentials Manager - 5e71babeba08543514c60c43df72b02b O40 - Explorer.EXE - Thunder Networking Technologies,LTD - C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll - DsBho - 43ec0e81f50edd0fa8ef4c9818f75cfb O40 - Explorer.EXE - Thunder Networking Technologies,LTD - C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll - DataProcessor - 62e988f76c9c88f100af64c2b1177526 O40 - Explorer.EXE - Microsoft Corporation - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll - Microsoft GDI+ - a08ef2fc9b3e688128e89d9c193f7652 O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll - Microsoft GDI+ - a08ef2fc9b3e688128e89d9c193f7652 ======================================= O41 - IntcAzAudAddService - Realtek(r) High Definition Audio Function Driver - C:\WINDOWS\system32\drivers\RtkHDAud.sys - (running) - Realtek(r) High Definition Audio Function Driver - Realtek Semiconductor Corp. - O41 - QKeyService - KeyCrypt - C:\WINDOWS\system32\KeyCrypt.sys - (running) - KeyCrypt - Tencent Technology (Shenzhen) Company Limited - ecaa6d40a70bee079f3817601bec1692 O41 - RTLE8023xp - Realtek 10/100/1000 NDIS 5.1 Driver - C:\WINDOWS\system32\drivers\Rtenicxp.sys - (running) - Realtek 10/100/1000 NDIS 5.1 Driver - Realtek Semiconductor Corporation - 839141088ad7ee90f5b441b2d1afd22c O41 - DgiVecp - Windows NT 4.0 IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes - C:\WINDOWS\system32\drivers\DgivEcp.sys - (not running) - Windows NT 4.0 IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes - DeviceGuys, Inc. - a5034f77b278f07e224fe07cf98a8b76 O41 - EagleNT - EagleNT - C:\WINDOWS\system32\drivers\EagleNT.sys - (not running) - - - O41 - NPF - NPF Driver - TME extensions - C:\WINDOWS\system32\drivers\npf.sys - (not running) - NPF Driver - TME extensions - Politecnico di Torino - d687bb15cd0994d1c816e99818213bf2 O41 - p2pfilter - p2pfilter - D:\p2pover\p2pfilter.sys - (not running) - - - O41 - ykbyyrmn - ykbyyrmn - C:\WINDOWS\system32\drivers\bptbwr.sys - (not running) - - - ======================================= 360Safe.exe=4.4.1.1009 AntiAdwa.dll=4.2.0.1001 AntiEng.dll=4.4.0.1001 AntiActi.dll=2.0.0.3000 CleanHis.dll=4.2.0.1002 live.dll=1.0.1.1029 ======================================= 操作历史报告: ======================================= 360安全卫士,彻底查杀各种流氓软件,全面保护系统安全 最新免费下载:http://www.360.cn/download.html