本报告由QQ医生提供 http://doctor.qq.com诊断时间: 2009-7-23 19:6:53操作系统: Windows XP Service Pack 2QQ医生版本:QQDoctor.exe 3.0.15.201DrUpdate.exe 3, 0, 15, 201TSELoder.DAT 2008, 1, 28, 13TSEngine.DAT 2008, 4, 7, 25TSEPB.DAT 2009, 3, 5, 35TSFSEngine.DAT 2009, 3, 11, 7TSFileFilter.DAT 2007, 12, 5, 01TSKsp.sys 2009, 6, 25, 17TSKSPLIB.dat 2009, 7, 1, 16TSVulMon.DAT 2009, 6, 25, 22TSVulChk.dat 2009, 7, 15, 30====================进程项==================== C:\WINDOWS\Explorer.EXE [Microsoft Corporation] C:\WINDOWS\system32\ntdll.dll [Microsoft Corporation] C:\WINDOWS\system32\kernel32.dll [Microsoft Corporation] C:\WINDOWS\system32\ADVAPI32.dll [Microsoft Corporation] C:\WINDOWS\system32\RPCRT4.dll [Microsoft Corporation] C:\WINDOWS\system32\Secur32.dll [Microsoft Corporation] C:\WINDOWS\system32\BROWSEUI.dll [Microsoft Corporation] C:\WINDOWS\system32\GDI32.dll [Microsoft Corporation] C:\WINDOWS\system32\USER32.dll [Microsoft Corporation] C:\WINDOWS\system32\msvcrt.dll [Microsoft Corporation] C:\WINDOWS\system32\ole32.dll [Microsoft Corporation] C:\WINDOWS\system32\SHLWAPI.dll [Microsoft Corporation] C:\WINDOWS\system32\OLEAUT32.dll [Microsoft Corporation] C:\WINDOWS\system32\SHDOCVW.dll [Microsoft Corporation] C:\WINDOWS\system32\CRYPT32.dll [Microsoft Corporation] C:\WINDOWS\system32\MSASN1.dll [Microsoft Corporation] C:\WINDOWS\system32\CRYPTUI.dll [Microsoft Corporation] C:\WINDOWS\system32\WINTRUST.dll [Microsoft Corporation] C:\WINDOWS\system32\IMAGEHLP.dll [Microsoft Corporation] C:\WINDOWS\system32\NETAPI32.dll [Microsoft Corporation] C:\WINDOWS\system32\WININET.dll [Microsoft Corporation] C:\WINDOWS\system32\WLDAP32.dll [Microsoft Corporation] C:\WINDOWS\system32\VERSION.dll [Microsoft Corporation] C:\WINDOWS\system32\SHELL32.dll [Microsoft Corporation] C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation] C:\WINDOWS\system32\ShimEng.dll [Microsoft Corporation] C:\WINDOWS\AppPatch\AcGenral.DLL [Microsoft Corporation] C:\WINDOWS\system32\WINMM.dll [Microsoft Corporation] C:\WINDOWS\system32\MSACM32.dll [Microsoft Corporation] C:\WINDOWS\system32\USERENV.dll [Microsoft Corporation] C:\WINDOWS\system32\IMM32.DLL [Microsoft Corporation] C:\WINDOWS\system32\LPK.DLL [Microsoft Corporation] C:\WINDOWS\system32\USP10.dll [Microsoft Corporation] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll [Microsoft Corporation] C:\WINDOWS\system32\comctl32.dll [Microsoft Corporation] C:\WINDOWS\system32\urlmon.dll [Microsoft Corporation] C:\WINDOWS\system32\msctfime.ime [Microsoft Corporation] C:\WINDOWS\system32\MSIMG32.dll [Microsoft Corporation] C:\WINDOWS\system32\NTMARTA.DLL [Microsoft Corporation] C:\WINDOWS\system32\SAMLIB.dll [Microsoft Corporation] C:\WINDOWS\system32\appHelp.dll [Microsoft Corporation] C:\WINDOWS\system32\CLBCATQ.DLL [Microsoft Corporation] C:\WINDOWS\system32\COMRes.dll [Microsoft Corporation] C:\WINDOWS\System32\cscui.dll [Microsoft Corporation] C:\WINDOWS\System32\CSCDLL.dll [Microsoft Corporation] C:\WINDOWS\system32\themeui.dll [Microsoft Corporation] C:\WINDOWS\system32\xpsp2res.dll [Microsoft Corporation] C:\WINDOWS\system32\msutb.dll [Microsoft Corporation] C:\WINDOWS\system32\MSCTF.dll [Microsoft Corporation] C:\WINDOWS\system32\LINKINFO.dll [Microsoft Corporation] C:\WINDOWS\system32\ntshrui.dll [Microsoft Corporation] C:\WINDOWS\system32\ATL.DLL [Microsoft Corporation] C:\WINDOWS\system32\SETUPAPI.dll [Microsoft Corporation] C:\WINDOWS\system32\NETSHELL.dll [Microsoft Corporation] C:\WINDOWS\system32\rtutils.dll [Microsoft Corporation] C:\WINDOWS\system32\credui.dll [Microsoft Corporation] C:\WINDOWS\system32\WS2_32.dll [Microsoft Corporation] C:\WINDOWS\system32\WS2HELP.dll [Microsoft Corporation] C:\WINDOWS\system32\iphlpapi.dll [Microsoft Corporation] C:\WINDOWS\system32\WINSTA.dll [Microsoft Corporation] C:\WINDOWS\system32\webcheck.dll [Microsoft Corporation] C:\WINDOWS\system32\WSOCK32.dll [Microsoft Corporation] C:\WINDOWS\system32\stobject.dll [Microsoft Corporation] C:\WINDOWS\system32\BatMeter.dll [Microsoft Corporation] C:\WINDOWS\system32\POWRPROF.dll [Microsoft Corporation] C:\WINDOWS\system32\WTSAPI32.dll [Microsoft Corporation] C:\WINDOWS\system32\wdmaud.drv [Microsoft Corporation] C:\WINDOWS\system32\msacm32.drv [Microsoft Corporation] C:\WINDOWS\system32\midimap.dll [Microsoft Corporation] C:\WINDOWS\system32\rsaenh.dll [Microsoft Corporation] C:\WINDOWS\system32\PSAPI.DLL [Microsoft Corporation] C:\WINDOWS\system32\MPR.dll [Microsoft Corporation] C:\WINDOWS\System32\drprov.dll [Microsoft Corporation] C:\WINDOWS\System32\ntlanman.dll [Microsoft Corporation] C:\WINDOWS\System32\NETUI0.dll [Microsoft Corporation] C:\WINDOWS\System32\NETUI1.dll [Microsoft Corporation] C:\WINDOWS\System32\NETRAP.dll [Microsoft Corporation] C:\WINDOWS\System32\davclnt.dll [Microsoft Corporation] C:\WINDOWS\system32\RASDLG.dll [Microsoft Corporation] C:\WINDOWS\system32\MPRAPI.dll [Microsoft Corporation] C:\WINDOWS\system32\ACTIVEDS.dll [Microsoft Corporation] C:\WINDOWS\system32\adsldpc.dll [Microsoft Corporation] C:\WINDOWS\system32\RASAPI32.dll [Microsoft Corporation] C:\WINDOWS\system32\rasman.dll [Microsoft Corporation] C:\WINDOWS\system32\TAPI32.dll [Microsoft Corporation] C:\WINDOWS\system32\msv1_0.dll [Microsoft Corporation] C:\WINDOWS\system32\SXS.DLL [Microsoft Corporation] C:\WINDOWS\system32\services.exe (Microsoft Corporation, 108.0 KB, 5.1.2600.3520 (xpsp_sp2_qfe.090206-1239)) f60e20250bb18917d416769af3877a21====================IE右键菜单====================Easy-WebPrint打印 [res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html]Easy-WebPrint高速打印 [res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html]Easy-WebPrint添加到打印列表 [res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html]Easy-WebPrint预览 [res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html]使用iTudou下载节目 [C:\Program Files\Tudou\iTudou\iTudou_Link.HTM]使用迅雷下载 [C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm]使用迅雷下载全部链接 [C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm]====================IE工具栏====================Easy-WebPrint [] {327C2873-E90D-4c37-AA9D-10AC9BABA46C} "c:\program files\canon\easy-webprint\toolband.dll" 启用 3d3a15d5f7c44868ff26c2a73377d7ee====================ActiveX对象====================AxInputControl Class [] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} "c:\windows\downloaded program files\inputcontrol.dll" 启用 f43fdbd955390b14db8da489d0ccd5c2====================系统服务====================DcomLaunch [Microsoft Corporation] "C:\WINDOWS\system32\rpcss.dll" 启用 c48d4b25b6d57a52eb6c1cbc245037cdEventlog [Microsoft Corporation] "C:\WINDOWS\system32\services.exe" 启用 f60e20250bb18917d416769af3877a21PlugPlay [Microsoft Corporation] "C:\WINDOWS\system32\services.exe" 启用 f60e20250bb18917d416769af3877a21RpcSs [Microsoft Corporation] "C:\WINDOWS\system32\rpcss.dll" 启用 c48d4b25b6d57a52eb6c1cbc245037cd====================协议相关====================about [Microsoft Corporation] {3050F406-98B5-11CF-BB82-00AA00BDCE0B} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277dfcdl [Microsoft Corporation] {3dd53d40-7b8b-11D0-b013-00aa0059ce02} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6Class Install Handler [Microsoft Corporation] {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6deflate [Microsoft Corporation] {8f6b0360-b80d-11d0-a9b3-006097942311} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6file [Microsoft Corporation] {79eac9e7-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6ftp [Microsoft Corporation] {79eac9e3-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6gopher [Microsoft Corporation] {79eac9e4-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6gzip [Microsoft Corporation] {8f6b0360-b80d-11d0-a9b3-006097942311} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6http [Microsoft Corporation] {79eac9e2-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6https [Microsoft Corporation] {79eac9e5-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6javascript [Microsoft Corporation] {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277dflocal [Microsoft Corporation] {79eac9e7-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6lzdhtml [Microsoft Corporation] {8f6b0360-b80d-11d0-a9b3-006097942311} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6mailto [Microsoft Corporation] {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277dfmk [Microsoft Corporation] {79eac9e6-baf9-11ce-8c82-00aa004ba90b} "c:\windows\system32\urlmon.dll" 启用 d8379f264c759e5716c9068be775b2f6res [Microsoft Corporation] {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277dfsysimage [Microsoft Corporation] {76E67A63-06E9-11D2-A840-006008059382} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277dfvbscript [Microsoft Corporation] {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} "c:\windows\system32\mshtml.dll" 启用 a72c5dbc40133ec0dcaa03ce90d277df====================已知DLL====================rpcrt4 [Microsoft Corporation] "c:\windows\system32\rpcrt4.dll" 禁用 d43500cc6e3218cb99de4bcab55ccc3curlmon [Microsoft Corporation] "c:\windows\system32\urlmon.dll" 禁用 d8379f264c759e5716c9068be775b2f6wininet [Microsoft Corporation] "c:\windows\system32\wininet.dll" 禁用 e11c746440d461eeede92777b80868fa====================打印监控====================Canon BJ Language Monitor iP1600 [CANON INC.] "c:\windows\system32\cnmlm75.dll" 启用 3ecdb7680d803d20c1ce22ca99009dfcLocal Port [Microsoft Corporation] "c:\windows\system32\localspl.dll" 启用 ac10ee25c5127751a4681134275854f9====================随系统加载的其它模块====================igfxcui [Intel Corporation] (igfxsrvc.dll) "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" 91f37fd6912030de26ac282f34294900====================驱动程序====================AlcwWmDrv [Windows (R) 2000 DDK provider] 启用 "\??\C:\WINDOWS\system32\drivers\AlcwWmDrv.sys" ac97a72dd6ea3ca54700b52522f88b01ALCXWDM [Realtek Semiconductor Corp.] 启用 "system32\drivers\ALCXWDM.SYS" f3e15607ba53249c765e36388b332c2fialm [Intel Corporation] 启用 "system32\DRIVERS\ialmnt5.sys" d4405bd2b6e95efdc8e674ed4032874fIdeBusDr [Intel Corporation] 启用 "system32\DRIVERS\IdeBusDr.sys" 791f0829de88dd0ca77192f0dfad03b6IdeChnDr [Intel Corporation] 启用 "system32\DRIVERS\IdeChnDr.sys" 7d2b8be9e89628663c1fb571f7c34062Tcpip [Microsoft Corporation] 启用 "system32\DRIVERS\tcpip.sys" 43333b1b7e6ae2d4367c7f0b366a85a6Update [Microsoft Corporation] 启用 "system32\DRIVERS\update.sys" 5a51b4cd1709c6a12fe6715b51229ed0usbprint [Microsoft Corporation] 启用 "system32\DRIVERS\usbprint.sys" a42369b7cd8886cd7c70f33da6fcbcf5WmRegProDrv [Windows (R) 2000 DDK provider] 启用 "System32\Drivers\WmRegProDrv.sys" bc7979aecdcccb9cd2ec2b1b0c849fbbyvmb [] 启用 "system32\drivers\onztj.sys" ====================桌面快捷方式====================酷狗音乐2008.lnk "C:\Program Files\KuGou\KuGou2008\KuGoo.exe " (酷狗音乐, 4.4 MB, 5.3.33.361) a3584719d659a7a08878b7676285f4dcMicrosoft Office Word 2003.lnk "C:\Program Files\Microsoft Office\WINWORD.EXE " (Microsoft Corporation, 11.5 MB, 11.0.6568) 34f4f1fe3b49ed6c86f7b5881d699e87Microsoft Office Excel 2003.lnk "C:\Program Files\Microsoft Office\EXCEL.EXE " (Microsoft Corporation, 9.6 MB, 11.0.5612) f0c364edb0c2b5686fab79c7c633ad0e启动有道桌面词典.lnk "C:\Program Files\Youdao\DeskDict2\RunDict.exe " (网易公司, 177.4 KB, 2, 0, 11, 8000) eb7b0ab44d2d29afc89d834da682733b腾讯QQ.lnk "C:\Program Files\Tencent\QQ\Bin\QQ.exe " (Tencent, 153.3 KB, 1, 25, 660, 0) 71500cb9fb912a2cc947658308dfeff2暴风影音.lnk "D:\暴风影音\Storm.exe " (北京暴风网际科技有限公司, 1.4 MB, 3, 9, 7, 8) a1ea27b7c0b4ad6dc83a0d476472da83瑞星卡卡上网安全助手.lnk "C:\Program Files\Rising\AntiSpyware\ras.exe " (Beijing Rising Information Technology Co., Ltd., 38.1 KB, 6.0.0.7) 324645bf53d6c2a677cc135eacd91c91宽带连接.lnk " " (, , ) iP1600 电子手册.lnk "C:\Program Files\Canon\IJ Manual\IP1600\Simplified_Chinese\Windows\Contents75.chm " (, 26.1 KB, ) c8cefbea543eb29c0533eb67ebcc99a7Easy-PhotoPrint.lnk "C:\Program Files\Canon\Easy-PhotoPrint\BJEZPRN.EXE " (CANON INC., 484.0 KB, 3, 3, 0, 0) d12d2227c8d24157d92f137d052428a7Canon Easy-PrintToolBox.lnk "C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE " (CANON INC., 400.0 KB, 1, 1, 0, 0) 3ba7a1cb1f48c581af58ded411d33317修复瑞星软件.lnk "C:\Documents and Settings\All Users\Application Data\Rising\Ris\Data\Repair.url " (, 155 Bytes, ) 6046caca3f94704bcbc38771720fe5bf瑞星全功能安全软件.lnk "C:\Program Files\Rising\Ris\RsMain.exe " (Beijing Rising Information Technology Co., Ltd., 70.6 KB, 21, 0, 0, 5) b73cd1c3e48d64b4acb171ea11b87b40账号保险柜.lnk "C:\Program Files\Rising\Ris\rssafety.exe " (Beijing Rising Information Technology Co., Ltd., 1.2 MB, 3.0.0.63) 0ade337c962a061aac13d427e948b4bcWindows清理助手3.lnk "C:\Program Files\arswp3\arswp3.exe " (, 2.8 MB, 3.0.6.628) 533cd2052e26536dbec799d4da161e85