100 - 未知 - Process: 保护控制端2.1.exe [] - F:\arp2.1控制端\保护控制端2.1.exe
100 - 未知 - Process: Tuotu.exe [TuoTu] - E:\Tuotu\Tuotu.exe
O4 - 未知 - HKCU\..\Run: [aa] [] c:\autoexec.bat
O8 - 未知 - Extra context menu item: 使用脱兔下载 - e:\Tuotu\TT_one.htm
O8 - 未知 - Extra context menu item: 使用脱兔下载全部链接 - e:\Tuotu\TT_all.htm
O8 - 未知 - Extra context menu item: 添加到QQ表情 - F:\网络游戏2\qq2007b3\AddEmotion.htm
O23 - 未知 - Service: AVPCC [AVP Control Centre Service] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service - (not running)
O23 - 未知 - Service: KAVMonitorService [KAV Monitor Service] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service - (not running)
O23 - 未知 - Service: TrkSvr [保存文件在域中卷之间移动的信息。] - C:\WINNT\system32\services.exe - (not running)
=======================================
100 - 安全 - Process: smss.exe [该进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINNT\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINNT\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512,512 Windows=On SubSystemType=Windows ServerDll=ba
100 - 安全 - Process: WINLOGON.EXE [windows nt用户登陆程序。] - C:\WINNT\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINNT\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINNT\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost -k rpcss
100 - 安全 - Process: SPOOLSV.EXE [windows打印任务控制程序,用以打印机就绪。] - C:\WINNT\system32\spoolsv.exe
100 - 安全 - Process: msdtc.exe [microsoft distributed transaction coordinator控制多个服务器的传输,被安装在microsoft personal web server和microsoft sql server。] - C:\WINNT\system32\msdtc.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost.exe -k netsvcs
100 - 安全 - Process: llssrv.exe [windows自带的许可证日志记录服务。] - C:\WINNT\System32\llssrv.exe
100 - 安全 - Process: winmgmt.exe [windows management service透过windows management instrumentation data (wmi)技术处理来自应用客户端的请求。] - C:\WINNT\System32\WBEM\WinMgmt.exe
100 - 安全 - Process: dfssvc.exe [管理分布于局域网或广域网的逻辑卷的程序。] - C:\WINNT\system32\Dfssvc.exe
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINNT\Explorer.EXE
100 - 安全 - Process: 360tray.exe [360安全卫士实时保护模块] - F:\360safe\safemon\360Tray.exe
100 - 安全 - Process: internat.exe [输入控制图标用于更改类似国家设置、键盘类型和日期格式。] - C:\WINNT\system32\internat.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINNT\system32\conime.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\System32\svchost.exe -k tapisrv
100 - 安全 - Process: firefox.exe [mozilla firefox浏览器相关程序,支持弹出广告拦截。] - C:\Program Files\Mozilla Firefox\firefox.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士] - F:\360safe\360safe.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=
about:blank
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=
about:blank
O2 - 安全 - BHO: (超级兔子上网精灵) - [超级兔子上网精灵相关插件。] - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O3 - 安全 - Toolbar: (超级兔子上网精灵) - [超级兔子上网精灵工具条,随超级兔子软件捆绑安装。] - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - 安全 - HKLM\..\Run: [AVPCC] [kaspersky avp反病毒软件。] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /wait
O4 - 安全 - HKLM\..\Run: [360Safetray] [360safe实时保护功能模块。] F:\360safe\safemon\360Tray.exe /start
O4 - 安全 - HKCU\..\Run: [Internat.exe] [输入法在任务栏里的图标] internat.exe
O9 - 安全 - Extra button: 电台(HKLM) - C:\WINNT\web\related.htm
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - 安全 - Service: Ati HotKey Poller [是ATI显示卡增强工具。] - C:\WINNT\system32\Ati2evxx.exe - (not running)
O23 - 安全 - Service: ATI Smart [是一个ati图形显示卡驱程的相关进程。] - C:\WINNT\system32\ati2sgag.exe - (not running)
O23 - 安全 - Service: Fax [微软Microsoft传真服务相关程序,该服务允许用户创建和发送传真到微软Office组件中。] - C:\WINNT\system32\faxsvc.exe - (not running)
O23 - 安全 - Service: GemServ [清凉安静技术Cool\\\'n\\\'Quiet的相关服务。] - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe - (not running)
O23 - 安全 - Service: NtFrs [在多个服务器间维护文件目录内容的文件同步。] - C:\WINNT\system32\ntfrs.exe - (not running)
=======================================
O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -
O31 - 未知 - SEApproved: {5E2121EE-0300-11D4-8D3B-444553540000} - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - - ACE Context Menu - 1.0.0.1 - 73728 - 649e3ab705eb0f3af213dcd4378515cf
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 124416 - 1b089bd70767a1ca5419a24b581cc753
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 124416 - 1b089bd70767a1ca5419a24b581cc753
O31 - 未知 - BootExecute: fsInit - - - - 0 -
O31 - 未知 - LSA: Notification Packages - ASSFM.dll - - - - 0 -
O31 - 未知 - LSA: Notification Packages - DCSVC.dll - - - - 0 -
O31 - 未知 - LSA: Notification Packages - cecli.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - Explorer.EXE - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpscrch.dll - Kaspersky Anti-Virus Script Checker Main Module - 6717a2abc916f95a839e9d31ee364ca4
O40 - Explorer.EXE - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\concl.dll - Kaspersky Anti-Virus Script Checker Conclusion Module - c466b8b189aaf589204d1bd071e5e51b
O40 - Explorer.EXE - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\dinfo.dll - Kaspersky Anti-Virus Script Checker Intreface Module - 1353b03d2175836c481c02806acd6d4f
O40 - Explorer.EXE - Kaspersky Lab. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\locscrch.dll - Localization DLL - 11858a7b3ce47947f48399069a13c408
O40 - Explorer.EXE - - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - ACE Context Menu - 649e3ab705eb0f3af213dcd4378515cf
O40 - Explorer.EXE - Kaspersky Labs. - C:\Program Files\Common Files\KAV Shared Files\AvpShlEx.dll - KAV Shell extension DLL - 3caf6ff3e484f427e66a2f0f87027b56
O40 - Explorer.EXE - Kaspersky Lab. - C:\Program Files\Common Files\KAV Shared Files\avp32Loc.dll - Localization DLL - 833207822f48d41f0ddbb04d5ebcdab3
=======================================
O41 - Klif - spuper-ptor - C:\WINNT\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Labs - 39f33d0df3eb39fc99dbb93ef6930259
O41 - MTsensor - ATK0110 ACPI Utility - C:\WINNT\system32\drivers\ASACPI.sys - (running) - ATK0110 ACPI Utility - - d48659bb24c48345d926ecb45c1ebdf5
O41 - NVENETFD - NVIDIA Networking Function Driver. - C:\WINNT\system32\drivers\NVENETFD.sys - (running) - NVIDIA Networking Function Driver. - NVIDIA Corporation - b7dd8b562487cf0f0c5d93b38ebd8c61
O41 - nvnetbus - NVIDIA Networking Bus Driver. - C:\WINNT\system32\drivers\nvnetbus.sys - (running) - NVIDIA Networking Bus Driver. - NVIDIA Corporation - 1eeb58effdf5d151b93face79635e4bf
O41 - oreans32 - oreans32 - C:\WINNT\system32\drivers\oreans32.sys - (running) - - - 63617de4a5178dc455a75c8c2cbfe823
O41 - AMDMSRIO - AMDMSRIO - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys - (not running) - - -
O41 - EagleNT - EagleNT - C:\WINNT\system32\drivers\EagleNT.sys - (not running) - - -
O41 - TesSafe - TesSafe - C:\WINNT\system32\TesSafe.sys - (not running) - - - 1770d643671f932464de3a945de0f5cc
=======================================
360Safe.exe=3.5.0.1002
AntiAdwa.dll=3.5.0.1001
AntiEng.dll=3.5.0.1001
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
live.dll=1.0.1.1016
=======================================
操作历史报告:
----------清理系统插件历史----------
2007-06-17 05:13
清理恶评软件 - 搜狗工具条 -
2007-06-15 05:08
清理恶评插件 - LgSy0.dll - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll
2007-06-16 07:40
清理恶评插件 - 搜狗工具条 - C:\Program Files\P4P
2007-07-02 07:56
清理恶评插件 - 搜狗工具条 - C:\Program Files\P4P
----------全面诊断修复历史----------
2007-06-15 04:38
O6 - 危险 - 禁止IE相关功能 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions
O6 - 危险 - 禁止IE相关功能 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
2007-06-15 05:59
O14 - 未知 - Web原始设置IERESET.INF - C:\WINNT\inf\iereset.inf