诊断时间: 2008-11-23, 16:36
诊断平台: Windows Vista [6.0.6001] Service Pack 1
IE版本: Internet Explorer V7.0.18000.6001
清理专家版本: 2008.06.13.404
恶意软件库版本: 0.00.00.0
漏洞库版本: 0.00.00.0
Common Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Startup: C:\Users\lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Common Startup: %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup
==============================================================
Host File
==============================================================
127.0.0.1 c0mo.com
127.0.0.1 gxgxy.net
127.0.0.1 union.daqi.com
127.0.0.1 121.15.247.22
127.0.0.1 61.155.140.4
127.0.0.1 219.129.239.251
127.0.0.1 61.164.118.208
127.0.0.1
www.zmjjjyy.cn127.0.0.1 user9.78-10.net
127.0.0.1 444.gmwo07.com
127.0.0.1 333.gmwo07.com
127.0.0.1 222.gmwo07.com
127.0.0.1 111.gmwo07.com
127.0.0.1 haha.yaoyao09.com
127.0.0.1
www.noseqing.cn127.0.0.1 fg.pvs360.com
127.0.0.1 cw.pvs360.com
127.0.0.1 ta.pvs360.com
127.0.0.1 dl.pvs360.com
127.0.0.1 ok.sl8cjs.cn
127.0.0.1 nc.mskess.com
127.0.0.1 idc.windowsupdeta.cn
127.0.0.1 pvs360.com
127.0.0.1 sl8cjs.cn
127.0.0.1 windowsupdeta.cn
127.0.0.1 up.22x44.com
127.0.0.1 my.531jx.cn
127.0.0.1 nx.51ylb.cn
127.0.0.1 llboss.com
127.0.0.1 down.malasc.cn
127.0.0.1 d2.llsging.com
127.0.0.1 171817.171817.com
127.0.0.1 wg.47255.com
127.0.0.1
www.tomwg.com 127.0.0.1 tp.shpzhan.cn
127.0.0.1 1.joppnqq.com
127.0.0.1 xx.exiao01.com
127.0.0.1
www.22aaa.com127.0.0.1 ilove.com
127.0.0.1 xxx.mmma.biz
127.0.0.1
www.868wg.com127.0.0.1 2.joppnqq.com
127.0.0.1 1.jopanqc.com
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopmmqq.com
127.0.0.1 cao.kv8.info
127.0.0.1 xtx.kv8.info
127.0.0.1 new.749571.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 1.jopenkk.com
127.0.0.1 d.93se.com
127.0.0.1 3.joppnqq.com
127.0.0.1 xxx.j41m.com
127.0.0.1 1.jopenqc.com
127.0.0.1 xxx.m111.biz
127.0.0.1 down.18dd.net
127.0.0.1
www.333292.com127.0.0.1 qqq.hao1658.com
127.0.0.1 qqq.dzydhx.com
127.0.0.1
www.exiao01.com 127.0.0.1
www.cike007.cn ==============================================================
系统服务
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds
[StartupPrograms] [已启用] <rdpclip>
==============================================================
驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
[SENTINEL] [已启用] <snti386.dll>
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[IpInIp] [已启用] <system32\DRIVERS\ipinip.sys>
[npkcrypt] [已启用] <\??\C:\Windows\system32\npkcrypt.sys>
[npkycryp] [已启用] <\??\C:\Windows\system32\npkycryp.sys>
[NwlnkFlt] [已启用] <system32\DRIVERS\nwlnkflt.sys>
[NwlnkFwd] [已启用] <system32\DRIVERS\nwlnkfwd.sys>
[Sentinel] [已启用] <\SystemRoot\System32\Drivers\SENTINEL.SYS>
[sptd] [已启用] <System32\Drivers\sptd.sys>
文件路径: C:\Windows\system32\Drivers\sptd.sys [文件无法访问]
[wdnfcg] [已启用] <system32\drivers\frejfpd.sys>
文件路径: C:\Windows\system32\drivers\frejfpd.sys [未知]
==============================================================
BHO
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
[yFlashDl Class]
{F166BC04-3C84-44cc-A6E9-2315EC4844B9} <C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll>
==============================================================
当前进程
==============================================================
名称: 金-山-诊-断及粉-碎-器.exe [已启用]
命令行: "C:\Users\lenovo\Desktop\程序\金-山-诊-断及粉-碎-器.exe"
文件路径: C:\Users\lenovo\Desktop\程序\金-山-诊-断及粉-碎-器.exe [未知]
模块文件: C:\Windows\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\ADVAPI32.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\COMDLG32.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\OLE32.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\ShimEng.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\apphelp.dll (Microsoft Corporation)
模块文件: C:\Windows\AppPatch\AcGenral.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\UxTheme.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\WINMM.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\OLEACC.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\NETAPI32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\PSAPI.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\MSACM32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\sfc.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\sfc_os.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\USERENV.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\dwmapi.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\urlmon.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\iertutil.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\MPR.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\MSCTF.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\riched32.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\RICHED20.dll (Microsoft Corporation)
模块文件: C:\Windows\system32\CLBCatQ.DLL (Microsoft Corporation)
模块文件: C:\Windows\system32\PROPSYS.dll (Microsoft Corporation)