这是WDS清理助手的诊断日志,太大,就分开发了,各位帮好好看看,谢谢了!
[CODE]
2008-12-11,22:36:50
SysLog Scanner 1.0 - build 20080726
Arswp (
http://www.arswp.com)
Windows XP Home Edition Service Pack 3 (build 2600) - Administrators
========================================
注册项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2004-08-17 12:00 M:2008-04-14 10:14|(Verified)NVIDIA Corporation, 6.14.10.9380, C:2005-02-23 23:32 M:2006-10-26 10:31]
<360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)360安全中心, 2, 4, 2, 1002, C:2008-12-01 10:30 M:2008-12-01 10:30]
<360Safetray><D:\网络资源工具\360safe\safemon\360Tray.exe /start> [(Verified)奇虎网, 5, 0, 0, 1002, C:2008-08-25 14:12 M:2008-08-25 14:12]
<RavTask><"E:\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.24, C:2008-04-25 08:54 M:2008-07-27 15:55]
<runeip><"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Co., Ltd., 21.0.0.16, C:2008-08-05 11:32 M:2008-09-12 07:45]
<Adobe Reader Speed Launcher><"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"> [(Verified)Adobe Systems Incorporated, 9.0.0.2008061200, C:2008-06-12 02:38 M:2008-06-12 02:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe> [(Verified)Beijing Rising Information Technology Co., Ltd., 19, 0, 0, 3, C:2008-04-25 14:42 M:2008-08-05 11:31]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_Dlls><kmon.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33, C:2008-08-05 11:32 M:2008-11-07 16:03]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.18, C:2008-04-25 08:54 M:2008-07-29 17:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\使用迅雷下载]
<><D:\网络资源工具\XL````\Program\GetUrl.htm> []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\使用迅雷下载全部链接]
<><D:\网络资源工具\XL````\Program\GetAllUrl.htm> []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\完美安全助手]
<><res://C:\WINDOWS\system32\PerfectToolbar.dll/MENUSEARCH.HTM> []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\导出到 Microsoft Office Excel(&X)]
<><res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000> []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\添加到QQ表情]
<><D:\网络资源工具\AddEmotion.htm> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2004-08-17 12:00 M:2008-04-14 10:14|(Verified)Microsoft Corporation, 7.00.6000.16762 (vista_gdr.081013-1507), C:2004-08-17 12:00 M:2008-10-17 04:04|(Verified)N/A, C:2004-08-17 12:00 M:2004-08-17 12:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2004-08-17 12:00 M:2008-04-14 10:14|(Verified)Microsoft Corporation, 7.00.6000.16762 (vista_gdr.081013-1507), C:2004-08-17 12:00 M:2008-10-17 04:04|(Verified)N/A, C:2004-08-17 12:00 M:2004-08-17 12:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2004-08-17 12:00 M:2008-04-14 10:14|(Verified)Microsoft Corporation, 7.00.6000.16762 (vista_gdr.081013-1507), C:2004-08-17 12:00 M:2008-10-17 04:04|(Verified)N/A, C:2004-08-17 12:00 M:2008-04-14 09:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608}]
<Fax><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2004-08-17 12:00 M:2008-04-14 10:14|(Verified)Microsoft Corporation, 7.00.6000.16762 (vista_gdr.081013-1507), C:2004-08-17 12:00 M:2008-10-17 04:04|(Verified)N/A, C:2004-08-17 12:00 M:2004-08-17 12:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}]
<启动迅雷5><D:\网络资源工具\XL````\Thunder.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}]
<联想><
http://www.lenovo.com> []
========================================
启动项
========================================
计划任务
========================================
组件
ShellExecuteHook
[ShlExecHack Class]
{32CD708B-60A7-4C00-9377-D73EAA495F0F} <C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.18, C:2008-04-25 08:54 M:2008-07-29 17:57]
Shell Extension
[Display Panning CPL Extension]
{42071714-76d4-11d1-8b24-00a0c9068ff3} <deskpan.dll> []
[HyperTerminal Icon Ext]
{88895560-9AA2-1069-930E-00AA0030EBC8} <C:\WINDOWS\system32\hticons.dll> [(Verified)Hilgraeve, Inc., 5.1.2600.0, C:2005-10-09 13:58 M:2004-08-17 20:00]
[NvCpl DesktopContext Class]
{A70C977A-BF00-412C-90B7-034C51DA2439} <C:\WINDOWS\system32\nvcpl.dll> [(Verified)NVIDIA Corporation, 6.14.10.9380, C:2005-02-23 23:32 M:2006-10-26 10:31]
[Play on my TV helper]
{FFB699E0-306A-11d3-8BD1-00104B6F7516} <C:\WINDOWS\system32\nvcpl.dll> [(Verified)NVIDIA Corporation, 6.14.10.9380, C:2005-02-23 23:32 M:2006-10-26 10:31]
[Desktop Explorer]
{1CDB2949-8F65-4355-8456-263E7C208A5D} <C:\WINDOWS\system32\nvshell.dll> [N/A, C:2006-11-24 15:54 M:2006-10-26 10:31]
[Desktop Explorer Menu]
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} <C:\WINDOWS\system32\nvshell.dll> [N/A, C:2006-11-24 15:54 M:2006-10-26 10:31]
[nView Desktop Context Menu]
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} <C:\WINDOWS\system32\nvshell.dll> [N/A, C:2006-11-24 15:54 M:2006-10-26 10:31]
[WinRAR shell extension]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} <C:\Program Files\WinRAR\rarext.dll> [N/A, C:2008-04-23 15:45 M:2007-09-05 17:12]
[RISING]
{1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} <C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.18, C:2008-04-25 08:54 M:2008-07-29 17:57]
BrowserHelperObject
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\网络资源工具\XL````\ComDlls\TDAtOnce_Now.dll> []
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll> [(Verified)Adobe Systems Incorporated, 9.0.0.2008061100, C:2008-06-11 22:33 M:2008-06-11 22:33]
[BOC ProcessProtect Class]
{776B71E2-B4CC-4C94-BC7C-09103AA690B6} <ProcessProtection.dll> [(Verified)
www.ISRA.org.cn, 1, 2, 2, 5, C:2008-10-15 07:27 M:2008-10-14 16:26]
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\网络资源工具\XL````\ComDlls\xunleiBHO_Now.dll> []
[卡卡上网安全助手]
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\urlFilter.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15, C:2008-08-05 11:32 M:2008-08-05 11:31]
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\网络资源工具\360safe\safemon\safemon.dll> [(Verified)360.CN, 4, 2, 0, 1005, C:2008-04-03 20:55 M:2008-07-10 17:42]
ActiveX Extension
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\网络资源工具\XL````\ComDlls\TDAtOnce_Now.dll> []
[PhotoDrawEx Class]
{05F5F404-7C24-4B39-B5CC-340CEDEB9C0D} <C:\WINDOWS\system32\QQPhotoDrawEx.dll> [(Verified)TENCENT, 1, 9, 109, 144, C:2007-11-03 12:06 M:2007-11-03 12:06]
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll> [(Verified)Adobe Systems Incorporated, 9.0.0.2008061100, C:2008-06-11 22:33 M:2008-06-11 22:33]
[GerneralPeerID Class]
{0A47E819-F82E-4D5D-B806-6A9EA94D68CD} <D:\网络资源工具\XL````\Components\InMedia\peerid.dll> []
[完美安全助手]
{0E1230F8-EA50-42A9-983C-E33ABC2EED3D} <C:\WINDOWS\system32\PerfectToolbar.dll> [Copyright 2001, 1, 0, 0, 1, C:2008-03-19 12:14 M:2008-03-19 12:14]
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll> [(Verified)Adobe Systems Incorporated, 9.0.0.2008061100, C:2008-06-11 22:33 M:2008-06-11 22:33]
[IEBuddyExtControl Class]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <D:\网络资源工具\Kingsoft Internet Security 2008\Antispy\IEBuddyExt.DLL> []
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\网络资源工具\XL````\ComDlls\ThunderAgent_Now.dll> []
[UploadControl Control]
{52FF336D-A05D-4A14-A3A1-7B6B4B427F88} <C:\WINDOWS\system32\UPLOAD~1.OCX> [网易(杭州)网络有限公司, 1.0.0.39, C:2008-04-21 10:51 M:2008-08-25 20:04]
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work> [Xunlei Networking Technologies,LTD, 2, 1, 8, 85, C:2008-04-25 09:29 M:2008-09-23 17:39]
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work> [Copyright XunLei 2007, 1, 0, 0, 7, C:2008-04-25 09:29 M:2008-08-25 17:25]
[StormPlayer Object]
{6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} <D:\网络资源工具\mps.dll> []
[js5mBho Class]
{72578201-3A99-4164-88E9-9799393159C8} <C:\WINDOWS\system32\perfectBHO.dll> [Copyright 2004, 1, 0, 0, 1, C:2008-03-19 12:15 M:2008-03-19 12:15]
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\网络资源工具\XL````\Components\InMedia\MediaAddin18.dll> []
[BOC ProcessProtect Class]
{776B71E2-B4CC-4C94-BC7C-09103AA690B6} <ProcessProtection.dll> [(Verified)
www.ISRA.org.cn, 1, 2, 2, 5, C:2008-10-15 07:27 M:2008-10-14 16:26]
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\网络资源工具\360safe\live.dll> [(Verified)360.cn, 1, 0, 1, 1029, C:2008-11-25 09:42 M:2008-11-25 09:42]
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\网络资源工具\XL````\ComDlls\xunleiBHO_Now.dll> []
[卡卡上网安全助手]
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\urlFilter.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15, C:2008-08-05 11:32 M:2008-08-05 11:31]
[DapCtrl Class]
{ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.1.5804.63.(957).dll> [(Verified)ShenZhen Thunder Networking Technologies Ltd., 2, 1, 5804, 63, C:2008-10-25 11:06 M:2008-09-19 16:30]
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\网络资源工具\360safe\safemon\safemon.dll> [(Verified)360.CN, 4, 2, 0, 1005, C:2008-04-03 20:55 M:2008-07-10 17:42]
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx> [QQ, 1, 0, 200, 50, C:2006-03-13 14:00 M:2006-03-13 14:00]
[QQPlayerCtrl Class]
{CD108273-D434-43E6-AA90-1469F97EB398} <D:\网络资源工具\QzoneMusic.dll> []
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <D:\网络资源工具\Codec\rmoc3260.dll> [(Verified)RealNetworks, Inc., 6.0.9.2568, C:2006-10-18 23:05 M:2006-10-18 23:05]
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx> [(Verified)Adobe Systems, Inc., 10,0,12,36, C:2008-10-05 11:16 M:2008-10-05 11:16]
[PlayerCtrl Class]
{E05BC2A3-9A46-4A32-80C9-023A473F5B23} <D:\网络资源工具\QzoneMusic.dll> []
[BOC Edit Class]
{E61E8363-041F-455C-8AD0-8A61F1D8E540} <KeyboardProtection.dll> [(Verified)
www.ISRA.org.cn, 1, 1, 7, 14, C:2008-10-15 07:27 M:2008-10-14 16:24]
[PasswordEditCtrl Class]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll> [(Verified)腾讯科技(深圳)有限公司, 1, 1, 0, 5, C:2008-01-07 17:08 M:2008-01-07 17:08]
[TimwpDll.TimwpCheck]
{ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} <D:\网络资~1\Timwp.dll> []
[Thunder DapPlayer]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <D:\网络资源工具\XL````\Components\DownAndPlay\DapPlayer3.0.5712.71.741.dll> []
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.1.5853.212.(276).dll> [(Verified)Xunlei Networking Technologies,LTD, 2, 1, 5853, 212, C:2008-10-29 10:46 M:2008-09-24 11:03]
Context Menu
[RisingRavExt]
{1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} <C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.18, C:2008-04-25 08:54 M:2008-07-29 17:57]
[WinRAR]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} <C:\Program Files\WinRAR\rarext.dll> [N/A, C:2008-04-23 15:45 M:2007-09-05 17:12]
========================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<%SystemRoot%\system32\svchost.exe -k netsvcs --> "%SystemRoot%\System32\appmgmts.dll"> [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2004-08-17 12:00 M:2008-04-14 10:14]
[Contrl Center of Storm Media / ccosm][Stopped/Auto Start]
<D:\网络资源工具\stormliv.exe /asservice> []
[Human Interface Device Access / HidServ][Stopped/Disabled]
<%SystemRoot%\System32\svchost.exe -k netsvcs --> "%SystemRoot%\System32\hidserv.dll"> [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2004-08-17 12:00 M:2008-04-14 10:14]
[lenovo live update / Lenovo Upgrade Service.bis.release][Running/Auto Start]
<C:\Program Files\Lenovo\LiveUpdate\liveupdate.exe> [新思软件技术有限公司, 3, 2, 4, 18, C:2007-01-13 14:29 M:2006-09-29 00:22]
[PnpWMmng / PnpWMmng][Stopped/Auto Start]