额外的扫描结果 Farbar Recovery Scan Tool (x64) 版本: 14-02-2022 01 通过...运行 19183 (24-02-2022 12:25:42) 从运行 C:\Users\19183\Downloads Microsoft Windows 11 家庭中文版 版本 21H2 22000.493 (X64) (2021-11-03 10:19:13) 启动模式: Normal ========================================================== ==================== 账户: ============================= (如果条目包含在固定列表中,它将被删除。) 19183 (S-1-5-21-2099732615-3400469919-2622180112-1001 - Administrator - Enabled) => C:\Users\19183 Administrator (S-1-5-21-2099732615-3400469919-2622180112-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2099732615-3400469919-2622180112-503 - Limited - Disabled) Guest (S-1-5-21-2099732615-3400469919-2622180112-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-2099732615-3400469919-2622180112-504 - Limited - Disabled) ==================== 安全中心 ======================== (如果条目包含在固定列表中,它将被删除。) AV: Spybot - Search and Destroy (Enabled - Up to date) {F77C7796-45C4-531E-0DAE-B4A8229B11C8} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== 已安装的程序 ====================== (只有带有"隐藏"标志的广告软件可以添加到固定列表中,以将它们隐藏起来。应该手动卸载广告软件程序。) Adobe Photoshop 2020 (HKLM-x32\...\PHSP_21_0_1) (Version: 21.0.1 - Adobe Inc.) Adobe Premiere Pro 2020 (HKLM-x32\...\PPRO_14_0) (Version: 14.0 - Adobe Inc.) Aegisub 3.2.2 (HKLM-x32\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.2.2 - Aegisub Team) Application Verifier x64 External Package (HKLM\...\{B27BC1FC-8474-9E32-73C2-6F7CD58AD1E3}) (Version: 10.1.17763.132 - Microsoft) Hidden ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach) Assassin's Creed IV Black Flag Asia (HKLM-x32\...\Uplay Install 442) (Version: - Ubisoft) Audacity 3.0.2 (HKLM-x32\...\Audacity_is1) (Version: 3.0.2 - Audacity Team) BitComet(比特彗星) 1.80 (HKLM-x32\...\BitComet_x64) (Version: 1.80 - CometNetwork) BlueStacks 5 (HKLM\...\BlueStacks_nxt) (Version: 5.3.145.1002 - BlueStack Systems, Inc.) BlueStacks X (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\BlueStacks X) (Version: 0.11.1.9 - BlueStack Systems, Inc.) CLIP STUDIO 1.8.0 (HKLM-x32\...\{49274EB8-4598-47E6-8039-9BB7CE07627E}) (Version: 1.8.0 - CELSYS) CLIP STUDIO PAINT 1.8.2 (HKLM-x32\...\{1E4572D2-28BC-4BC9-B743-13DC6CFD71DB}) (Version: 1.8.2 - CELSYS) ControlCenter2.0 v1.0.75 (HKLM-x32\...\{2F385B5D-5F23-4513-B3CE-9F5E4F4B882A}) (Version: 1.0.75 - Control Center) DeepVocal_beta_1.1.0 版本 beta_1.1.0 (HKLM-x32\...\{AA1C45DE-7027-4424-9AE2-3B73DE461609}_is1) (Version: beta_1.1.0 - Boxstar) DeepVocalToolBox_beta_1.1.0 版本 beta_1.1.0 (HKLM-x32\...\{6D3C7B6D-E66D-4A68-8BF5-D2D36B595BF9}_is1) (Version: beta_1.1.0 - Boxstar) Discord (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\Discord) (Version: 1.0.9002 - Discord Inc.) EDIT 1.0 (HKLM-x32\...\EDIT) (Version: 1.0 - 成都艾美互娱科技有限公司) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Etterna (HKLM-x32\...\Etterna) (Version: 0.70.3 - Etterna Team) FireAlpaca 2.2.10 (64bit) (HKLM\...\FireAlpaca64_is1) (Version: 2.2.10 - firealpaca.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 98.0.4758.102 - Google LLC) Google Cloud SDK (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\Google Cloud SDK) (Version: - Google Inc.) HECATE GAMING HEADSET (HKLM-x32\...\{D5E5798D-4B61-4513-ACEF-63D3DFD46D74}) (Version: [removed] - Dongguan Edifier Esports Technology Co.,Ltd) HiSuite (HKLM-x32\...\Hi Suite) (Version: 10.0.1.100 - ) Hyper Scape (HKLM-x32\...\Uplay Install 11957) (Version: - Ubisoft) IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line) Inkscape (HKLM-x32\...\Inkscape) (Version: 1.1.1- - Inkscape) Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation) Intel(R) HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 2.2.1.375 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1846.12.0.1177 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6519 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.2.0.1009 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.50.638.1 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{99ee3c29-c7cd-450f-8db9-d43cc49de1c7}) (Version: 1.50.638.1 - Intel Corporation) Hidden KiCad 5.1.10_1 (HKLM-x32\...\KiCad) (Version: 5.1.10_1 - KiCad) Kits Configuration Installer (HKLM-x32\...\{29B915AE-013F-151F-3E61-67F7363C3A09}) (Version: 10.1.17763.132 - Microsoft) Hidden K-Lite Codec Pack 9.4.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.4.0 - ) KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.2.37 - PandoraTV) KMPlayer 64X (remove only) (HKLM\...\KMPlayer 64X) (Version: 2021.05.26.23 - PandoraTV) Krita (x64) 4.4.1 (HKLM\...\Krita_x64) (Version: 4.4.1.100 - Krita Foundation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LibreOffice 6.4.1.2 (HKLM\...\{F420EC75-FB16-4786-951E-67CAC0FB9B86}) (Version: 6.4.1.2 - The Document Foundation) LMMS 1.2.2 (HKLM-x32\...\LMMS) (Version: 1.2.2 - LMMS Developers) Lrc歌词编辑器 V2012 02.08 (HKLM-x32\...\Lrc歌词编辑器) (Version: V2012 02.08 - 蒋南) Microsoft .NET Core SDK 2.1.511 (x64) (HKLM-x32\...\{1a9b2512-eef0-4931-a9ec-0e8b044b2806}) (Version: 2.1.511 - Microsoft Corporation) Microsoft 365 - zh-cn (HKLM\...\O365HomePremRetail - zh-cn) (Version: 16.0.14827.20198 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 98.0.1108.56 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 98.0.1108.56 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\OneDriveSetup.exe) (Version: 22.012.0117.0003 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{572E990E-67FD-4014-884C-A730BFC7E1D7}) (Version: 4.65.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{1b103cea-f037-4504-81de-956057b442c3}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{49e969a1-2990-464d-92b5-25f6f34573c6}) (Version: 12.0.40664.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{5e4b593b-ca3c-429c-bc49-b51cbf46e72a}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{d2c8df0e-f15d-4426-9e51-f13f329f9cb4}) (Version: 12.0.40664.0 - Корпорация Майкрософт) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29334 (HKLM-x32\...\{a9cfe9c7-e54f-46cd-9c5c-542ff8e3e8c4}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29913 (HKLM-x32\...\{03d1453c-7d5c-479c-afea-8482f406e036}) (Version: 14.28.29913.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) MSI Development Tools (HKLM-x32\...\{6C961B30-A670-8A05-3BFE-3947E84DD4E4}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.9.5 - Notepad++ Team) NVIDIA CUDA Development 10.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDADevelopment_10.2) (Version: 10.2 - NVIDIA Corporation) NVIDIA CUDA Documentation 10.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDADocument_10.2) (Version: 10.2 - NVIDIA Corporation) NVIDIA CUDA Runtime 10.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDARuntimes_10.2) (Version: 10.2 - NVIDIA Corporation) NVIDIA CUDA Samples 10.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_samples_10.2) (Version: 10.2 - NVIDIA Corporation) NVIDIA CUDA Samples 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDASamples_7.0) (Version: 7.0 - NVIDIA Corporation) NVIDIA CUDA Toolkit 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDAToolkit_7.0) (Version: 7.0 - NVIDIA Corporation) NVIDIA CUDA Visual Studio Integration 10.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_visual_studio_integration_10.2) (Version: 10.2 - NVIDIA Corporation) NVIDIA CUDA Visual Studio Integration 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDAVisualStudioIntegration_7.0) (Version: 7.0 - NVIDIA Corporation) NVIDIA GPU Deployment Kit 347.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GDK) (Version: 347.62 - NVIDIA Corporation) NVIDIA Nsight Compute 2019.5.0 (HKLM\...\{E7E5A75F-BCB9-4753-A212-DDC3917EB94F}) (Version: 19.5.0.0 - NVIDIA Corporation) NVIDIA Nsight Systems 2019.5.2 (HKLM\...\{1705FB38-B9C3-474A-9B0E-58E5E35525BC}) (Version: 19.5.2.16 - NVIDIA Corporation) NVIDIA PhysX 系统软件 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) NVIDIA Tools Extension SDK (NVTX) - 64 bit (HKLM\...\{B56D2F88-8865-40FD-B7AC-F074EE4D201D}) (Version: 1.00.00.00 - NVIDIA Corporation) NVIDIA 图形驱动程序 462.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 462.30 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 24.0.3 - OBS Project) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14827.20198 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20198 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20198 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0804-0000-0000000FF1CE}) (Version: 16.0.14827.20198 - Microsoft Corporation) Hidden Online Application (HKLM-x32\...\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}) (Version: 2.7.0 - Microleaves) Hidden <==== 注意 OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenVPN 2.4.5-I601 (HKLM\...\OpenVPN) (Version: 2.4.5-I601 - OpenVPN Technologies, Inc.) osu! (HKLM-x32\...\{e14f4895-4b91-4b68-9218-2775db0ce922}) (Version: latest - ppy Pty Ltd) osu!lazer (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\osulazer) (Version: 2021.212.0 - ppy Pty Ltd) Pentablet 版本 3.0.5.201022 (HKLM\...\{5DAB8C1A-6D8E-467D-BE62-AC13087AA950}_is1) (Version: 3.0.5.201022 - XP-PEN Technology) PureVPN (HKLM-x32\...\{c676d648-f124-439f-86d1-94a6737e951d}) (Version: 7.0.4.0 - ) Hidden Rave 1.2.0-alpha.1 (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\be557dd2-1201-5931-9663-5f29db56628a) (Version: 1.2.0-alpha.1 - Rave Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.17763.21310 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.31.828.2018 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8633 - Realtek Semiconductor Corp.) SDK ARM Additions (HKLM-x32\...\{0B5D6FB7-05A5-271B-5B99-82384219A471}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden SDK ARM Redistributables (HKLM-x32\...\{4A5F6E94-7967-A333-8231-CA9AF35E03BD}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden ShanaEncoder 5.0.0.4 (HKLM-x32\...\ShanaEncoder) (Version: 5.0.0.4 - LEE RINA) Spotify (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\Spotify) (Version: 1.1.79.763.gc2965cdf - Spotify AB) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.8.68.0 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Streamlabs OBS 1.1.2 (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.1.2 - General Workings, Inc.) TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - ) TIM (HKLM-x32\...\TIM) (Version: 3.3.8.22043 - 腾讯科技(深圳)有限公司) Twitch Leecher 1.8.4 (HKLM\...\{4871CA2A-E8D6-429D-B3AD-DA09410AF346}) (Version: 1.8.4.0 - Franiac) Hidden Twitch Leecher 1.8.4 (HKLM-x32\...\{904941a6-1120-4eaa-a150-30df49e3939c}) (Version: 1.8.4.0 - Franiac) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 103.2 - Ubisoft) Universal CRT Extension SDK (HKLM-x32\...\{7D225043-6CC5-7B56-11DD-AFF90E4C1C0C}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (HKLM-x32\...\{CB19DBA2-C210-5646-9522-695A1317CD34}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Universal CRT Redistributable (HKLM-x32\...\{5F577A45-3C65-352B-061D-D6A57F05402C}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Universal CRT Tools x64 (HKLM\...\{3B588BBE-EB02-D1B2-5CD5-7DB85AD8A3E7}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Universal CRT Tools x86 (HKLM-x32\...\{D2DC1EDF-EE04-9B5F-BDD7-06645D859EC3}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Universal General MIDI DLS Extension SDK (HKLM-x32\...\{CE83D0BD-418A-F3D1-D6CE-687E96D1EBD0}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden VdhCoApp 1.6.3 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper) WinAppDeploy (HKLM-x32\...\{716AE8F2-1BE3-7657-DF6B-F23DEEC75AF9}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Windows Installer (HKLM-x32\...\{8DA41662-F681-47F9-B114-9657FC5799EF}) (Version: 4.98.0 - AdvancedWindowsManager) Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation) Windows SDK AddOn (HKLM-x32\...\{1E76DFA7-96F3-4281-8E41-8A226C3E42EE}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.17763.132 (HKLM-x32\...\{5fe95b9d-9219-4d8b-a031-71323ae48a81}) (Version: 10.1.17763.132 - Microsoft Corporation) Windows 电脑健康状况检查 (HKLM\...\{87CEFC15-9DEF-4665-BCC2-C0432FF46721}) (Version: 3.2.2110.14001 - Microsoft Corporation) Windows 驱动程序包 - Qtechknow (qtechknow.com) Qduino Mini USB Driver (08/25/2015 1.0.0.0) (HKLM\...\C0FCEB136DA5CE170A05B2E6172893719DEA5BDE) (Version: 08/25/2015 1.0.0.0 - Qtechknow (qtechknow.com)) Windows 驱动程序包 - SparkFun Electronics SparkFun AVR USB Driver (04/22/2016 ) (HKLM\...\865CE3301B539B68CCF0C6E8F339811A5D10A441) (Version: 04/22/2016 - SparkFun Electronics) WinRAR 5.71 beta 1 (64-位) (HKLM\...\WinRAR archiver) (Version: 5.71.1 - win.rar GmbH) WinRT Intellisense Desktop - en-us (HKLM-x32\...\{00B12DF9-5428-9406-DE2C-8E8A1A062B05}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{E82A4A6C-C21C-35FE-B805-3E44318F6D63}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense IoT - en-us (HKLM-x32\...\{7E898893-9C42-A572-7F57-FDE55CE812F7}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{E8B1CB29-5C24-D882-3CEF-F8A7263BC63D}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense Mobile - en-us (HKLM-x32\...\{F6F11150-93DE-0507-FCA0-F746E0207017}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense PPI - en-us (HKLM-x32\...\{8329C3A0-8582-D1C2-67FF-800654BFDF45}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{771C9DEF-7C0B-85DA-6426-7A20F06BEC94}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense UAP - en-us (HKLM-x32\...\{B047C746-63E8-41C7-A5C0-7ABD390CF3E6}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{0063AF94-397B-9C64-1C71-D404B27C5D96}) (Version: 10.1.17763.132 - Microsoft Corporation) Hidden Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version: - DOSBox Team) Zoom (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\ZoomUMX) (Version: 5.2.2 (45108.0831) - Zoom Video Communications, Inc.) 剪映专业版 (HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\JianyingPro) (Version: 2.1.0.4424 - Shenzhen Lianmeng Technology) 哔哩哔哩直播姬 (HKLM-x32\...\{81F6F736-F774-4965-A593-1AFD31ABBB35}_is1) (Version: 3.12.5.1551 - 上海幻电信息科技有限公司) 小丸工具箱 (HKLM-x32\...\{7EEB2DD0-264B-4340-B6BE-F05D99066D3C}) (Version: 236 - Maruko Toolbox Project) 微信 (HKLM-x32\...\WeChat) (Version: 2.9.5.56 - 腾讯科技(深圳)有限公司) 招商银行专业版 (HKLM-x32\...\CMBPB40) (Version: - ) 狸窝全能视频转换器 版本 4.2.0.2 (HKLM-x32\...\{331ED3CF-3A1B-467C-9A62-899E2D3B20C4}_is1) (Version: 4.2.0.2 - 狸窝软件有限公司.) 百度网盘 (HKLM-x32\...\百度云管家) (Version: 6.8.7 - 百度在线网络技术(北京)有限公司) 网易云音乐 (HKLM-x32\...\网易云音乐) (Version: 2.9.7.199711 - 网易公司) 英特尔(R) 无线 Bluetooth(R) (HKLM-x32\...\{00000110-0200-2052-84C8-B8D95FA3C8C3}) (Version: 20.110.0.3 - Intel Corporation) 英特尔® PROSet/无线软件 (HKLM-x32\...\{6aa2484c-1a35-428e-a857-8ee0a874d2d1}) (Version: 20.110.0 - Intel Corporation) 英特尔® 芯片组设备软件 (HKLM-x32\...\{fcfc894b-0d54-4d39-826f-dcb39ce5dde7}) (Version: 10.1.17861.8101 - Intel(R) Corporation) 逆水寒(NGP游戏平台) (HKLM-x32\...\逆水寒(NGP游戏平台)) (Version: 2.0.6394 - Netease, Inc.) 钉钉 (HKLM-x32\...\钉钉) (Version: 4.6.28-Release.5200 - Alibaba (China) Network Technology Co.,Ltd.) Packages: ========= Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc [2020-02-23] (Adobe Systems Incorporated) AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.41601.0_x64__8wekyb3d8bbwe [2021-12-21] (Microsoft Corporation) Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2020-02-18] (INTEL CORP) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-11-03] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-11-03] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.2180.0_x64__8wekyb3d8bbwe [2022-02-23] (Microsoft Studios) [MS Ad] Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10201.5809.0_x64__8wekyb3d8bbwe [2022-02-04] (Microsoft Corporation) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-01-18] (NVIDIA Corp.) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.17.230.0_x64__dt26b99r8h8gj [2021-01-20] (Realtek Semiconductor Corp) Sound Blaster Connect -> C:\Program Files\WindowsApps\CreativeTechnologyLtd.SoundBlasterConnect_2.2.15.0_x86__13fcda18mhdz2 [2020-07-11] (Creative Technology Ltd.) Surfshark -> C:\Program Files\WindowsApps\account.shark-china.com-DB5B0F07_1.0.0.3_neutral__2zynga10kdkra [2022-02-23] (account.shark-china.com) 照片加载项 -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-12-13] (Microsoft Corporation) 照片媒体引擎加载项 -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-01-22] (Microsoft Corporation) 英特尔® 显卡控制中心 -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3407.0_x64__8j3eq9eme6ctt [2021-12-04] (INTEL CORP) [Startup Task] ==================== 自定义 CLSID (将列入优先名单): ============== (如果一个条目包含在固定列表中,它将从注册表中删除。 除非单独列出,否则文件将不会被移动。.) CustomCLSID: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-C2E8887E3C2A} -> [Creative Cloud Files] => C:\Users\19183\Creative Cloud Files [2020-02-25 16:15] CustomCLSID: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001_Classes\CLSID\{1248BD21-B584-4EB8-85D0-8EC479CD043B}\Shell\Open\Command -> C:\Program Files (x86)\HiSuite\HiSuite.exe (Huawei Technologies Co., Ltd. -> Huawei) CustomCLSID: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001_Classes\CLSID\{1248BD21-B584-4EB8-85D0-8EC479CD043B} -> [华为手机助手] => C:\Program Files (x86)\HiSuite [2020-06-03 02:22] CustomCLSID: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll => 无文件 ShellIconOverlayIdentifiers: [ DingSyncDone] -> {820379E5-9924-4D5A-8589-FE6C0547D5CF} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers: [ DingSyncError] -> {D1FA3F7A-E2DD-4C30-A986-BBA6BE7083DA} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers: [ DingSyncIgnore] -> {C42307BA-CA49-4DF5-9326-4A80843CB9EC} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers: [ DingSyncSyncing] -> {15FF64D1-4170-4257-87FC-B405EC9A60E1} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers-x32: [ DingSyncDone] -> {820379E5-9924-4D5A-8589-FE6C0547D5CF} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers-x32: [ DingSyncError] -> {D1FA3F7A-E2DD-4C30-A986-BBA6BE7083DA} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers-x32: [ DingSyncIgnore] -> {C42307BA-CA49-4DF5-9326-4A80843CB9EC} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ShellIconOverlayIdentifiers-x32: [ DingSyncSyncing] -> {15FF64D1-4170-4257-87FC-B405EC9A60E1} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ContextMenuHandlers1: [ DingSyncContextMenu] -> {970A26B5-2B84-4B60-8067-1440C229672D} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => D:\Program Files (x86)\Notepad++\NppShell_06.dll [2021-03-22] (Notepad++ -> ) ContextMenuHandlers1: [cloudmusic] -> {5C6A637C-9780-4D0F-A379-4732EDCCE7C3} => -> 无文件 ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => E:\Program Files\Spybot - Search & Destroy 2\SDECon64.dll [2019-04-15] (Safer-Networking Ltd. -> Safer-Networking Ltd.) ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => E:\Program Files\Spybot - Search & Destroy 2\SDECon64.dll [2019-04-15] (Safer-Networking Ltd. -> Safer-Networking Ltd.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-02] (Alexander Roshal) [文件未签名] ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-02] (Alexander Roshal) [文件未签名] ContextMenuHandlers1: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\19183\AppData\Roaming\baidu\BaiduNetdisk\YunShellExt64.dll [2020-12-16] (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) ContextMenuHandlers3: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => E:\Program Files\ShellExt\QQShellExt64.dll [2021-09-07] (Tencent Technology(Shenzhen) Company Limited -> Tencent) ContextMenuHandlers4: [ DingSyncContextMenu] -> {970A26B5-2B84-4B60-8067-1440C229672D} => F:\Systemx64\DingDing\Shell\ShellExtension_x64_4.6.28-Release.5200.dll -> 无文件 ContextMenuHandlers4: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\19183\AppData\Roaming\baidu\BaiduNetdisk\YunShellExt64.dll [2020-12-16] (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvcvegpu.inf_amd64_538e668538abf17f\nvshext.dll [2021-04-27] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers6: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => E:\Program Files\ShellExt\QQShellExt64.dll [2021-09-07] (Tencent Technology(Shenzhen) Company Limited -> Tencent) ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => E:\Program Files\Spybot - Search & Destroy 2\SDECon64.dll [2019-04-15] (Safer-Networking Ltd. -> Safer-Networking Ltd.) ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => E:\Program Files\Spybot - Search & Destroy 2\SDECon64.dll [2019-04-15] (Safer-Networking Ltd. -> Safer-Networking Ltd.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-02] (Alexander Roshal) [文件未签名] ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-02] (Alexander Roshal) [文件未签名] ==================== Codecs (将列入优先名单) ==================== (如果条目包含在固定列表中,则注册表项目将恢复为默认或删除。 文件不会被移除。) HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\system32\vorbis.acm [1470976 2015-03-11] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [文件未签名] HKLM\...\Drivers32: [msacm.voxacm160] => C:\Windows\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [文件未签名] HKLM\...\Drivers32: [msacm.scg726] => C:\Windows\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [文件未签名] HKLM\...\Drivers32: [msacm.alf2cd] => C:\Windows\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [文件未签名] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [文件未签名] HKLM\...\Drivers32: [msacm.lame] => C:\Windows\system32\lame.ax [245760 2005-08-01] () [文件未签名] HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [文件未签名] HKLM\...\Drivers32: [vidc.mpg4] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [文件未签名] HKLM\...\Drivers32: [vidc.mp42] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [文件未签名] HKLM\...\Drivers32: [vidc.mp43] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [文件未签名] HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\system32\xvidvfw.dll [139264 2004-07-03] () [文件未签名] HKLM\...\Drivers32: [vidc.DIVX] => C:\Windows\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [文件未签名] HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [文件未签名] HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [文件未签名] HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [文件未签名] HKLM\...\Drivers32: [vidc.LAGS] => C:\Windows\system32\lagarith.dll [216064 2011-12-07] () [文件未签名] HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\SysWOW64\vorbis.acm [1554944 2015-03-11] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [文件未签名] HKLM\...\Drivers32: [msacm.msaudio1] => C:\Windows\SysWOW64\msaud32.acm [292944 1999-08-09] (Microsoft Corporation) [文件未签名] HKLM\...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll HKLM\...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll HKLM\...\Drivers32: [VIDC.ZMBV] => C:\Windows\SysWOW64\zmbv.dll [94208 2010-04-10] () [文件未签名] ==================== 捷径 & WMI ======================== (条目可以被列出用以恢复或删除.) ShortcutWithArgument: C:\Users\19183\Desktop\mas.to.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=igogikkndncglkaogojacfpippbclkdb ShortcutWithArgument: C:\Users\19183\Desktop\Podchaser.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jidghebejpknkjplakobfjaacfhgibhc ShortcutWithArgument: C:\Users\19183\Desktop\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jgeocpdicgmkeemopbanhokmhcgcflmi ShortcutWithArgument: C:\Users\19183\Desktop\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Cloud SDK\Google Cloud SDK Shell.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k ""C:\Users\19183\AppData\Local\Google\Cloud SDK\cloud_env.bat"" ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\9xbuddy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jbbdmogfiplichchhbjhlampmclfojal ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\Chrome 远程桌面.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\mas.to.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=igogikkndncglkaogojacfpippbclkdb ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\Podchaser.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jidghebejpknkjplakobfjaacfhgibhc ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\Spotify.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=pjibgclleladliembfgfagdaldikeohf ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\Twitch video & clip downloader.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=ckhokacgdhekfoifkkefjfpiicaafeao ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jgeocpdicgmkeemopbanhokmhcgcflmi ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome 应用\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml ShortcutWithArgument: C:\Users\19183\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\6902cd0f08afab92\Enhancer for YouTube™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=ponfpcnoihfmfllpaingbgckeeldkhle ==================== 加载模块 (将列入优先名单) ============= 0000-00-00 00:00 - 0000-00-00 00:00 - 000000000 _____ () [拒绝访问] C:\Program Files (x86)\Common Files\CoreDemo\NoolDatioa\nater_revP_168.dll 2021-09-18 15:36 - 2018-04-30 15:43 - 000256000 ____N (C-MEDIA Electronics INC.) [文件未签名] C:\Program Files\HECATE GAMING HEADSET\CPL\Driver\x64\vista\osConfLib.dll 2022-02-17 16:50 - 2022-02-17 16:51 - 000137168 _____ (Microsoft Windows -> Microsoft Corporation) [文件未签名] C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.95.0_x64__cw5n1h2txyewy\Dashboard\WebView2Loader.dll 2020-11-03 11:18 - 2019-12-30 22:01 - 000036352 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qdds.dll 2020-11-03 11:18 - 2019-12-30 22:00 - 000022016 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qgif.dll 2020-11-03 11:18 - 2019-12-30 22:01 - 000029184 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qicns.dll 2020-11-03 11:18 - 2019-12-30 22:00 - 000022528 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qico.dll 2020-11-03 11:18 - 2019-12-30 22:00 - 000206848 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qjpeg.dll 2020-11-03 11:18 - 2019-12-30 22:12 - 000016896 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qsvg.dll 2020-11-03 11:18 - 2019-12-30 22:01 - 000016384 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qtga.dll 2020-11-03 11:18 - 2019-12-30 22:02 - 000310272 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qtiff.dll 2020-11-03 11:18 - 2019-12-30 22:02 - 000015360 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qwbmp.dll 2020-11-03 11:18 - 2019-12-30 22:03 - 000287232 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\imageformats\qwebp.dll 2020-11-03 11:18 - 2019-12-30 22:00 - 000966144 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\platforms\qwindows.dll 2020-11-03 11:17 - 2019-12-31 13:35 - 004686848 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Core.dll 2020-11-03 11:17 - 2019-12-30 21:33 - 005035008 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Gui.dll 2020-11-03 11:17 - 2019-12-30 21:24 - 000674816 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Network.dll 2020-11-03 11:17 - 2019-12-30 22:12 - 000251392 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Svg.dll 2020-11-03 11:17 - 2019-12-30 21:49 - 004518912 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Widgets.dll 2020-11-03 11:17 - 2019-12-30 21:24 - 000151040 _____ (The Qt Company Ltd) [文件未签名] D:\Program Files (x86)\Pentablet\Qt5Xml.dll 2019-04-27 08:19 - 2016-10-11 13:52 - 002061824 _____ (TODO: <公司名稱>) [文件未签名] C:\Program Files (x86)\Hotkey\audio10ec.dll 2019-04-27 08:19 - 2007-12-03 11:33 - 000204800 _____ (TODO: <公司名稱>) [文件未签名] C:\Program Files (x86)\Hotkey\DataAddress.dll 2019-04-27 08:19 - 2016-10-11 20:01 - 002037248 _____ (TODO: <公司名稱>) [文件未签名] C:\Program Files (x86)\Hotkey\powerlife.dll ==================== Alternate Data Streams (将列入优先名单) ======== (如果条目包含在固定列表中,则只会删除ADS。) AlternateDataStreams: C:\Users\19183\Cookies:Vr05eQBMcUpE01AqKLAkkFrv3uY7 [2434] ==================== 安全模式 (将列入优先名单) ================== ==================== 社区 (将列入优先名单) ================= (如果条目包含在固定列表中,则注册表项目将恢复为默认或删除。) HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\Software\Classes\regfile: regedit.exe "%1" <==== 注意 ==================== Internet Explorer (将列入优先名单) ========== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001 -> DefaultScope {64AF4D11-6492-4C25-B014-B6C6CEE3B0C5} URL = hxxps://www.baidu.com/s?tn=80035161_2_dg&wd={searchTerms} SearchScopes: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001 -> {64AF4D11-6492-4C25-B014-B6C6CEE3B0C5} URL = hxxps://www.baidu.com/s?tn=80035161_2_dg&wd={searchTerms} BHO: 未命名 -> {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} -> 无文件 BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2022-02-04] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: AccountProtectBHO Class -> {DDD362CF-523B-4BC9-8FDC-58F93B6BC945} -> C:\Users\19183\AppData\Roaming\Tencent\QQ\QQAntiPhishing\AccountProtect.dll [2019-05-10] (Tencent Technology(Shenzhen) Company Limited -> Tencent) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-04] (Microsoft Corporation -> Microsoft Corporation) (如果一个条目包含在固定列表中,它将从注册表中删除。) IE trusted site: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\bankofchina.com -> hxxp://bankofchina.com IE trusted site: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\boc.cn -> hxxp://boc.cn IE trusted site: HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\boc.cn -> hxxps://boc.cn ==================== Hosts 内容: ========================= (如果需要的主机:指令可以包含在固定列表中以重置主机。) 2018-09-15 15:31 - 2022-02-23 19:17 - 000000000 _____ C:\WINDOWS\system32\drivers\etc\hosts 2020-05-10 16:22 - 2021-11-13 12:23 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics ==================== 其他区域 =========================== (目前本节没有自动修复功能。) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\NVIDIA GPU Computing Toolkit\CUDA\v10.2\bin;C:\Program Files\NVIDIA GPU Computing Toolkit\CUDA\v10.2\libnvvp;C:\Program Files\NVIDIA GPU Computing Toolkit\CUDA\v7.0\bin;C:\Program Files\NVIDIA GPU Computing Toolkit\CUDA\v7.0\libnvvp;C:\Program Files (x86)\Common Files\Intel\Shared Libraries\redist\intel64\compiler;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\dotnet\;C:\Program Files\NVIDIA Corporation\Nsight Compute 2019.5.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\Control Panel\Desktop\\Wallpaper -> D:\画\all eyes on me.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) 防火墙 已启用 ==================== MSCONFIG/TASK MANAGER 禁用项目 == (如果条目包含在固定列表中,它将被删除。) MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: autotimesvc => 3 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: BITCOMET_HELPER_SERVICE => 3 MSCONFIG\Services: HKClipSvc => 2 MSCONFIG\Services: HuaweiHiSuiteService64.exe => 2 MSCONFIG\Services: SwitchBoard => 3 HKLM\...\StartupApproved\Run: => "RtkAudUService" HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "cloudmusic" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "OpenVPN-GUI" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "QQ2009" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "BaiduYunDetect" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "CCXProcess" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "Dingtalk" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "Wechat" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "BCU" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "dwm" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "MSASCui" HKU\S-1-5-21-2099732615-3400469919-2622180112-1001\...\StartupApproved\Run: => "RegHost" ==================== 防火墙规则 (将列入优先名单) ================ (如果一个条目包含在固定列表中,它将从注册表中删除。 除非单独列出,否则文件将不会被移动。.) FirewallRules: [UDP Query User{65075851-DA17-481E-9FF0-4FE0055FE81F}F:\systemx64\dingding\main\current\dingtalk.exe] => (Allow) F:\systemx64\dingding\main\current\dingtalk.exe => 无文件 FirewallRules: [TCP Query User{63005900-67AB-4A6B-8D13-BA72C21EE1AA}F:\systemx64\dingding\main\current\dingtalk.exe] => (Allow) F:\systemx64\dingding\main\current\dingtalk.exe => 无文件 FirewallRules: [UDP Query User{561C08E6-8C94-48BC-8787-222A300B7C84}F:\systemx64\dingding\main\current_new\plugins\tblive\bin\32bit\tblive.exe] => (Allow) F:\systemx64\dingding\main\current_new\plugins\tblive\bin\32bit\tblive.exe => 无文件 FirewallRules: [TCP Query User{0C963873-6FAB-4AEE-B876-F65AACAE5D07}F:\systemx64\dingding\main\current_new\plugins\tblive\bin\32bit\tblive.exe] => (Allow) F:\systemx64\dingding\main\current_new\plugins\tblive\bin\32bit\tblive.exe => 无文件 FirewallRules: [UDP Query User{DBA5642B-8B6F-4D5C-937A-921746826872}F:\systemx64\dingding\main\current_new\dingtalk.exe] => (Allow) F:\systemx64\dingding\main\current_new\dingtalk.exe => 无文件 FirewallRules: [TCP Query User{455F8262-F7A2-4BD5-AFCB-205488E58E5A}F:\systemx64\dingding\main\current_new\dingtalk.exe] => (Allow) F:\systemx64\dingding\main\current_new\dingtalk.exe => 无文件 FirewallRules: [{5ABDFC7C-EC0E-4141-9583-F71834A8BA27}] => (Allow) G:\SteamLibrary\steamapps\common\Viridi\Viridi.exe => 无文件 FirewallRules: [{20AE6EE7-A804-47F7-A159-80622B2061EC}] => (Allow) G:\SteamLibrary\steamapps\common\Viridi\Viridi.exe => 无文件 FirewallRules: [{E1F02BB8-8C0C-470C-A6B8-CFA87E894F64}] => (Allow) G:\SteamLibrary\steamapps\common\MNIY\nw.exe => 无文件 FirewallRules: [{94CFA6C7-DB33-4CF8-BF7C-4B7623AA5CBE}] => (Allow) G:\SteamLibrary\steamapps\common\MNIY\nw.exe => 无文件 FirewallRules: [{D7448E7E-CD61-4497-A110-35D8B02B85E6}] => (Allow) G:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe => 无文件 FirewallRules: [{5A14D5C1-A30E-408C-8CCC-A2A74DBCE2CA}] => (Allow) G:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe => 无文件 FirewallRules: [{C172F1A1-E90C-4467-B371-29DFFDC61670}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => 无文件 FirewallRules: [{610380C0-ECE2-439F-8747-5A1A5E73CCCB}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\tencentdl.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [UDP Query User{3D56A287-9A69-4858-803B-F16F9D4E7AE4}E:\program files\bin\tim.exe] => (Allow) E:\program files\bin\tim.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [TCP Query User{CB9CBCC9-C388-4BD9-A90E-8DBD37AA8E6A}E:\program files\bin\tim.exe] => (Allow) E:\program files\bin\tim.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{521EAD1D-DA64-472B-9268-7D764E427178}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\tencentdl.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{5E169A7B-4BBC-4322-A641-F6CE1A271A4E}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => 无文件 FirewallRules: [{1E5743B7-9E8D-4BBB-8F50-792C3F451944}] => (Allow) E:\Program Files\Bin\maUpdat.exe => 无文件 FirewallRules: [{14B45316-4ADA-4C82-B623-4C7CCDDFD88D}] => (Allow) E:\Program Files\Bin\maLauncher.exe => 无文件 FirewallRules: [{66E93405-A6F8-4846-B805-2BCE0E53FEBC}] => (Allow) E:\Program Files\Bin\SetupEx\SetupEx.exe => 无文件 FirewallRules: [{BB1E99F3-3B68-4583-A388-D3B23800E2E0}] => (Allow) E:\Program Files\Bin\txupd.exe => 无文件 FirewallRules: [{1E4E5F6C-5D7C-419C-B381-687AB0192B83}] => (Allow) E:\Program Files\Bin\auclt.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{9BD39DA2-0CDE-46EE-A045-F6BD253C2FC7}] => (Allow) E:\Program Files\Bin\QQ.exe => 无文件 FirewallRules: [{0B33E82B-024A-4355-AFE3-CA6568856229}] => (Allow) C:\Users\19183\AppData\Roaming\Tencent\TIM\STemp\SetupEx0\QQSetupEx.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [UDP Query User{92ED51B0-FFC8-4270-B4AF-A91521E212B1}E:\sayo device\sayo_cli_windows.exe] => (Allow) E:\sayo device\sayo_cli_windows.exe => 无文件 FirewallRules: [TCP Query User{D0AE49DF-F484-4B64-9EBA-EA417F77BE85}E:\sayo device\sayo_cli_windows.exe] => (Allow) E:\sayo device\sayo_cli_windows.exe => 无文件 FirewallRules: [UDP Query User{4FC1672A-B9FB-4F04-8400-F4D1FD1FC9C0}E:5\sayo_control_cli.exe] => (Allow) E:5\sayo_control_cli.exe => 无文件 FirewallRules: [TCP Query User{531B1EC4-68F9-4354-974E-8C6665F643F2}E:5\sayo_control_cli.exe] => (Allow) E:5\sayo_control_cli.exe => 无文件 FirewallRules: [{93F4C8F0-9F29-4812-8C07-EAFD86A959E6}] => (Allow) E:\Program Files\ludashi\ComputerZTray.exe => 无文件 FirewallRules: [{807E9F1D-2DB3-444C-8E0E-4DFBE8D2CEDA}] => (Allow) E:\Program Files\ludashi\ComputerZTray.exe => 无文件 FirewallRules: [{AA53A2CA-5691-495B-9AFA-7507175E33E5}] => (Allow) G:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe => 无文件 FirewallRules: [{375210B2-DFB1-41B2-A828-5C2C83B70C2A}] => (Allow) G:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe => 无文件 FirewallRules: [UDP Query User{786D9CAB-E15D-4F9E-A656-9C6857DDEB6E}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase(Hangzhou) Network Co. Ltd. -> NetEase) FirewallRules: [TCP Query User{05F7AC33-878D-4B62-9D92-B32726763819}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase(Hangzhou) Network Co. Ltd. -> NetEase) FirewallRules: [UDP Query User{E3FFA8EA-A2AC-42DA-B75C-457EF33D01CA}D:\steamlibrary\steamapps\common\cyber hunter\bin\ccmini\ccmini.exe] => (Allow) D:\steamlibrary\steamapps\common\cyber hunter\bin\ccmini\ccmini.exe => 无文件 FirewallRules: [TCP Query User{5505BBB3-4916-4172-89FE-012A006160FF}D:\steamlibrary\steamapps\common\cyber hunter\bin\ccmini\ccmini.exe] => (Allow) D:\steamlibrary\steamapps\common\cyber hunter\bin\ccmini\ccmini.exe => 无文件 FirewallRules: [UDP Query User{886ECB1D-12D3-411E-95B0-6B41C0F18837}D:\steamlibrary\steamapps\common\cyber hunter\bin\client.exe] => (Allow) D:\steamlibrary\steamapps\common\cyber hunter\bin\client.exe => 无文件 FirewallRules: [TCP Query User{BC3F8EDC-4725-4EE7-A2C4-996EC0D4B232}D:\steamlibrary\steamapps\common\cyber hunter\bin\client.exe] => (Allow) D:\steamlibrary\steamapps\common\cyber hunter\bin\client.exe => 无文件 FirewallRules: [UDP Query User{CC38CC5C-0B7F-4EC1-A228-BD076D6B7E5D}D:\steamlibrary\steamapps\common\code vein\codevein\binaries\win64\codevein-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\code vein\codevein\binaries\win64\codevein-win64-shipping.exe => 无文件 FirewallRules: [TCP Query User{04231D23-038B-4F74-B6CA-DE7E9ED5C084}D:\steamlibrary\steamapps\common\code vein\codevein\binaries\win64\codevein-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\code vein\codevein\binaries\win64\codevein-win64-shipping.exe => 无文件 FirewallRules: [{A5FED1BE-9F93-4DBF-AEEE-79360F2C727C}] => (Allow) E:\SteamLibrary\steamapps\common\Virtual Cottage\Virtual Cottage_WINDOWS.exe => 无文件 FirewallRules: [{C8770F37-B260-4D52-A407-B7DFAA40F3C1}] => (Allow) E:\SteamLibrary\steamapps\common\Virtual Cottage\Virtual Cottage_WINDOWS.exe => 无文件 FirewallRules: [UDP Query User{E0B5ED4B-438D-4D0E-AE06-3EB497CA0248}E:0\systemx64\winmx\winmx.exe] => (Allow) E:0\systemx64\winmx\winmx.exe => 无文件 FirewallRules: [TCP Query User{0765A0B9-2E08-4733-A539-808D7A97A79D}E:0\systemx64\winmx\winmx.exe] => (Allow) E:0\systemx64\winmx\winmx.exe => 无文件 FirewallRules: [UDP Query User{7D88F9CA-DD24-4A44-A750-3748B273A885}C:\users\19183\downloads\arduino-1.8.13\java\bin\java.exe] => (Allow) C:\users\19183\downloads\arduino-1.8.13\java\bin\java.exe => 无文件 FirewallRules: [TCP Query User{EFAE43EF-151F-47DB-BB31-FD5EB576AD0D}C:\users\19183\downloads\arduino-1.8.13\java\bin\java.exe] => (Allow) C:\users\19183\downloads\arduino-1.8.13\java\bin\java.exe => 无文件 FirewallRules: [UDP Query User{B7313556-95F6-428A-8D78-E8AB17FE6449}C:\users\19183\downloads\arduino-1.8.13\java\bin\javaw.exe] => (Allow) C:\users\19183\downloads\arduino-1.8.13\java\bin\javaw.exe => 无文件 FirewallRules: [TCP Query User{1A275AA8-62CA-4ACB-A772-FC5EA53736A1}C:\users\19183\downloads\arduino-1.8.13\java\bin\javaw.exe] => (Allow) C:\users\19183\downloads\arduino-1.8.13\java\bin\javaw.exe => 无文件 FirewallRules: [UDP Query User{A73F05B7-CD65-4324-8D20-650E5E98672B}E:9\sayo_control_cli.exe] => (Allow) E:9\sayo_control_cli.exe => 无文件 FirewallRules: [TCP Query User{4D79C202-8561-445F-AC66-C97D93372D62}E:9\sayo_control_cli.exe] => (Allow) E:9\sayo_control_cli.exe => 无文件 FirewallRules: [TCP Query User{CBFE8E3F-DEC5-447D-8061-13E9523D14E4}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe (Xing Wang -> www.BitComet.com) FirewallRules: [UDP Query User{3FE8DC06-FEC7-40EB-AE9F-57A12006CC92}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe (Xing Wang -> www.BitComet.com) FirewallRules: [{283D3AF9-E39C-4B69-9DE1-53A34CA4ABA7}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{3F2D244D-86C1-419B-AAB8-0DA89944735B}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{D6052C0A-C075-48DD-B168-EB9753F722D9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{283E938A-60C5-431E-8E50-5FE2AF133991}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{46A12AED-A864-48C5-A998-B18CF8A94733}] => (Allow) D:\Program Files (x86)\Talesrunner\trgame.exe => 无文件 FirewallRules: [{7ACCA291-5CB6-4515-B7B9-9D81D0E689B3}] => (Allow) D:\Program Files (x86)\Talesrunner\trgame.exe => 无文件 FirewallRules: [{06EF3451-6D9F-4A2E-87B6-FED4458E3BCC}] => (Allow) D:\Program Files (x86)\Talesrunner\trgame.exe => 无文件 FirewallRules: [{8918F2BF-C2D0-4528-A637-8ABA33AFAACB}] => (Allow) D:\Program Files (x86)\Talesrunner\trgame.exe => 无文件 FirewallRules: [{63613545-F956-4AA8-A348-B6F2AC0B1368}] => (Allow) D:\Program Files (x86)\Talesrunner\upfile.exe => 无文件 FirewallRules: [{2E1B29F5-0A2E-4F55-8064-C3F2B2851FAA}] => (Allow) D:\Program Files (x86)\Talesrunner\upfile.exe => 无文件 FirewallRules: [{32E36BE4-D1AE-4398-AB7E-40E07CEDBE32}] => (Allow) D:\Program Files (x86)\Talesrunner\upfile.exe => 无文件 FirewallRules: [{0F256948-84B7-4ABA-895A-3353EC2283EA}] => (Allow) D:\Program Files (x86)\Talesrunner\upfile.exe => 无文件 FirewallRules: [{529653E9-357C-4B65-A73E-6D34E9224827}] => (Allow) D:\Program Files (x86)\Talesrunner\talesrunner.exe => 无文件 FirewallRules: [{F62C4889-EB2F-4405-8ED1-D6DD5A7713D2}] => (Allow) D:\Program Files (x86)\Talesrunner\talesrunner.exe => 无文件 FirewallRules: [{41C76C63-EBB9-4D17-81BD-B1A758243BBE}] => (Allow) D:\Program Files (x86)\Talesrunner\talesrunner.exe => 无文件 FirewallRules: [{28AD20E7-C10C-4552-80A9-9A6AAAA889E2}] => (Allow) D:\Program Files (x86)\Talesrunner\talesrunner.exe => 无文件 FirewallRules: [TCP Query User{53B278BB-7824-4404-A815-6AEBAFE4F557}C:\program files (x86)\pc remote receiver\monectserverservice.exe] => (Allow) C:\program files (x86)\pc remote receiver\monectserverservice.exe => 无文件 FirewallRules: [UDP Query User{430502AC-983C-4B12-90AD-97CE2336F7A1}C:\program files (x86)\pc remote receiver\monectserverservice.exe] => (Allow) C:\program files (x86)\pc remote receiver\monectserverservice.exe => 无文件 FirewallRules: [{45BFBCEA-18FC-4AE9-A9D0-3B901847A209}] => (Allow) C:\Users\19183\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{1D0BD540-6A5D-4BC2-ACC2-BD8389EF3473}] => (Allow) C:\Users\19183\AppData\Roaming\Zoom\bin\airhost.exe => 无文件 FirewallRules: [{733747B5-0894-4525-BC52-8FCBC1396003}] => (Allow) D:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe => 无文件 FirewallRules: [{F2BD2642-939E-4B60-9710-25A17BDF98B4}] => (Allow) D:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe => 无文件 FirewallRules: [TCP Query User{B310CBB2-546B-4826-BC63-E5132F22ADC7}D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => 无文件 FirewallRules: [UDP Query User{5B240A65-278A-48B1-AE52-E072658C916E}D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) D:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => 无文件 FirewallRules: [TCP Query User{EB107FE0-3A54-4CE4-9DF3-98BDACD611CF}C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) FirewallRules: [UDP Query User{28CBB89C-672D-44F3-806B-442CAEAA498F}C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) FirewallRules: [{B9ACF536-40C4-4933-A248-8CE8A5332544}] => (Allow) D:\SteamLibrary\steamapps\common\Blender\blender.exe => 无文件 FirewallRules: [{4E2FC5D5-9F4B-4D7E-8CD6-FD4E5493B7C3}] => (Allow) D:\SteamLibrary\steamapps\common\Blender\blender.exe => 无文件 FirewallRules: [{D8FC0311-7037-4AEF-8E72-F3A823F63F1D}] => (Allow) E:\SteamLibrary\steamapps\common\Rocksmith2014\Rocksmith2014.exe => 无文件 FirewallRules: [{8815B7BC-1A14-49FA-B293-B8D0608C2273}] => (Allow) E:\SteamLibrary\steamapps\common\Rocksmith2014\Rocksmith2014.exe => 无文件 FirewallRules: [{3972AD07-4068-43E6-93D4-1CF20A076F8F}] => (Allow) E:\SteamLibrary\steamapps\common\Nekojishi\Nekojishi.exe => 无文件 FirewallRules: [{5AB1C6AF-4B42-4E63-95C1-B2B39C4CC9E8}] => (Allow) E:\SteamLibrary\steamapps\common\Nekojishi\Nekojishi.exe => 无文件 FirewallRules: [TCP Query User{6CF37A89-0B00-4E06-BC9F-AC725AB3145D}E:\steamlibrary\ubi\hyper scape\hyperscape.exe] => (Allow) E:\steamlibrary\ubi\hyper scape\hyperscape.exe => 无文件 FirewallRules: [UDP Query User{72029FC8-245C-405A-9989-CD398EBB5CA3}E:\steamlibrary\ubi\hyper scape\hyperscape.exe] => (Allow) E:\steamlibrary\ubi\hyper scape\hyperscape.exe => 无文件 FirewallRules: [{23E23286-29A4-40AA-8A39-89E3D38E1B53}] => (Allow) E:\SteamLibrary\steamapps\common\McOsu\McEngine.exe => 无文件 FirewallRules: [{07950F3E-BCAA-4F35-BB93-F50145052E0A}] => (Allow) E:\SteamLibrary\steamapps\common\McOsu\McEngine.exe => 无文件 FirewallRules: [{F0AA5D51-C13F-43B8-9B6A-7E964B32F71D}] => (Allow) C:\Users\19183\WeChat\WeChat.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent) FirewallRules: [{E7CF947E-8602-48F8-982C-84D1E03509D5}] => (Allow) E:\SteamLibrary\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe => 无文件 FirewallRules: [{687E71E5-4047-4171-A01A-459884F0E41C}] => (Allow) E:\SteamLibrary\steamapps\common\Plants Vs Zombies\PlantsVsZombies.exe => 无文件 FirewallRules: [TCP Query User{3706D506-64F1-48DF-BBE7-E0125CB0C335}G:\e5mnq\e5mnqv1.0.1_free\program\main.exe] => (Allow) G:\e5mnq\e5mnqv1.0.1_free\program\main.exe => 无文件 FirewallRules: [UDP Query User{086EB685-5DFC-410C-8C4F-4DCE60FEC460}G:\e5mnq\e5mnqv1.0.1_free\program\main.exe] => (Allow) G:\e5mnq\e5mnqv1.0.1_free\program\main.exe => 无文件 FirewallRules: [{748D8F61-8F38-4CFA-A3A2-3795A16D4290}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe => 无文件 FirewallRules: [{6BEA5031-203B-4E85-A06D-83CF9DC56874}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\VideoEditor.exe => 无文件 FirewallRules: [{3D960277-E6E8-4ED5-A4AB-8243F91B0C0A}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\Activation.exe => 无文件 FirewallRules: [{230918CE-869F-464F-84F6-73AB28A43667}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\Activation.exe => 无文件 FirewallRules: [{63D8D5C0-0974-4AA5-BD72-5D51451F0C0A}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\Updater.exe => 无文件 FirewallRules: [{75A4FFA3-EA65-4EA4-9514-83F44DF49314}] => (Allow) C:\Program Files\FlashIntegro\VideoEditor\Updater.exe => 无文件 FirewallRules: [{17A70B65-78CE-4082-92CA-157123EC981E}] => (Allow) C:\Program Files (x86)\Feem 2018\Feem.exe => 无文件 FirewallRules: [{AD778EE4-42C6-4598-BCF7-9EB20782F587}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe => 无文件 FirewallRules: [{F54A6F45-2293-4761-880B-6B6700089BC7}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe => 无文件 FirewallRules: [{C04BA800-2E58-41E7-8CD0-82AEE8A4D73A}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe => 无文件 FirewallRules: [{C8203D82-813E-454F-B71A-2A8760472679}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe => 无文件 FirewallRules: [TCP Query User{470DC6F2-6BFE-45BA-ADD2-BD92F02B97AD}C:\users\19183\appdata\local\temp\netease-qnyh.exe] => (Allow) C:\users\19183\appdata\local\temp\netease-qnyh.exe => 无文件 FirewallRules: [UDP Query User{EF2DB6A2-4DB8-40A0-84BB-0280E1CC1DF8}C:\users\19183\appdata\local\temp\netease-qnyh.exe] => (Allow) C:\users\19183\appdata\local\temp\netease-qnyh.exe => 无文件 FirewallRules: [TCP Query User{36D60B04-96B4-4C9D-9000-DDB21790C2D7}C:\users\19183\appdata\local\temp\netease-qnyh_new.exe] => (Allow) C:\users\19183\appdata\local\temp\netease-qnyh_new.exe => 无文件 FirewallRules: [UDP Query User{482D63F7-EB19-4BCD-A199-A6B8C3337A92}C:\users\19183\appdata\local\temp\netease-qnyh_new.exe] => (Allow) C:\users\19183\appdata\local\temp\netease-qnyh_new.exe => 无文件 FirewallRules: [TCP Query User{580DC6E6-773C-419C-886C-C86807E1F59D}C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) FirewallRules: [UDP Query User{7F7F7B27-3CF6-41CE-AB5D-477BBE498A0A}C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\19183\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Baidu Netcom Science and Technology Co.,Ltd -> ) FirewallRules: [TCP Query User{6BD18053-F148-4970-9D2D-F4DDD9FD57F3}G:\逆水寒(ngp游戏平台)\out\release\cache\zr\clientrepair.exe] => (Allow) G:\逆水寒(ngp游戏平台)\out\release\cache\zr\clientrepair.exe => 无文件 FirewallRules: [UDP Query User{2B35A050-D8F3-4FA6-8BC1-C9727446BA6A}G:\逆水寒(ngp游戏平台)\out\release\cache\zr\clientrepair.exe] => (Allow) G:\逆水寒(ngp游戏平台)\out\release\cache\zr\clientrepair.exe => 无文件 FirewallRules: [TCP Query User{465B6441-B87D-4C34-904C-90DE4924C2B9}G:\逆水寒(ngp游戏平台)\out\release\cache\yj\clientrepair.exe] => (Allow) G:\逆水寒(ngp游戏平台)\out\release\cache\yj\clientrepair.exe => 无文件 FirewallRules: [UDP Query User{DD7A5A08-D982-4E5F-832E-285F24A6FF8E}G:\逆水寒(ngp游戏平台)\out\release\cache\yj\clientrepair.exe] => (Allow) G:\逆水寒(ngp游戏平台)\out\release\cache\yj\clientrepair.exe => 无文件 FirewallRules: [TCP Query User{84EA98D6-52E7-4BF3-BA9F-2CD941EB8467}E:0\sayo_control_cli.exe] => (Allow) E:0\sayo_control_cli.exe => 无文件 FirewallRules: [UDP Query User{A3C43D42-3A25-44FD-8E69-4B4936BB5ACD}E:0\sayo_control_cli.exe] => (Allow) E:0\sayo_control_cli.exe => 无文件 FirewallRules: [TCP Query User{DE4DB3EF-75A5-4D63-B297-C8BCDD02A169}E:3\sayo_control_cli.exe] => (Allow) E:3\sayo_control_cli.exe => 无文件 FirewallRules: [UDP Query User{66A60AED-B620-4E72-B2AF-3A2D7C4B2987}E:3\sayo_control_cli.exe] => (Allow) E:3\sayo_control_cli.exe => 无文件 FirewallRules: [{9D6593B8-4A14-4CAA-ACF9-D0EDE91B9D1F}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Bluestack Systems, Inc -> BlueStack Systems) FirewallRules: [{75269A69-0618-45D5-BA88-92600CE101BE}] => (Allow) G:\SteamLibrary\steamapps\common\Pilgrims\Pilgrims.exe => 无文件 FirewallRules: [{62BBAA92-031A-44B0-AB62-0486373773B1}] => (Allow) G:\SteamLibrary\steamapps\common\Pilgrims\Pilgrims.exe => 无文件 FirewallRules: [TCP Query User{51581F76-CA80-442E-8B8C-D51CAA6DABCA}C:\users\19183\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\19183\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [UDP Query User{BA0D1653-8D40-49B0-854C-D318FB56338D}C:\users\19183\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\19183\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [TCP Query User{88356AB5-0A3F-4A10-A365-FE2D85C452AF}C:\users\19183\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\19183\appdata\local\programs\rave-desktop\rave.exe (Rave Inc. -> Rave Inc.) FirewallRules: [UDP Query User{A65D2F47-8879-4DCF-A4E6-607D3EB3DE07}C:\users\19183\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\19183\appdata\local\programs\rave-desktop\rave.exe (Rave Inc. -> Rave Inc.) FirewallRules: [{47F9E7E8-B827-4704-B929-885D4E5DF0F1}] => (Allow) G:\SteamLibrary\steamapps\common\Oxenfree\OXENFREE.exe => 无文件 FirewallRules: [{007F3D76-F4D9-4B28-AAD9-3AF22B446B4A}] => (Allow) G:\SteamLibrary\steamapps\common\Oxenfree\OXENFREE.exe => 无文件 FirewallRules: [{F022A58E-BE2F-4B10-A474-94E45D67B7BA}] => (Allow) G:\SteamLibrary\steamapps\common\64.0\64.0.exe => 无文件 FirewallRules: [{456CCBA3-224E-44C0-A9EB-4FFCC3493809}] => (Allow) G:\SteamLibrary\steamapps\common\64.0\64.0.exe => 无文件 FirewallRules: [{3432C6A6-DBE1-41EB-85D1-8975B93D062C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F3398B08-18F5-4F40-8F63-239BA6BD7CEC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{78EA4E16-191F-4657-B078-8AB4CADCE0BE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\98.0.1108.56\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{6AA2E30A-06B2-4C56-891E-1FE729C5648E}] => (Allow) G:\SteamLibrary\steamapps\common\The Binding Of Isaac\Isaac.exe => 无文件 FirewallRules: [{AE2C0F80-2E6E-4DFD-B7E9-ECCC142B6ED2}] => (Allow) G:\SteamLibrary\steamapps\common\The Binding Of Isaac\Isaac.exe => 无文件 FirewallRules: [TCP Query User{416C0F66-82F1-4F9A-A7CB-46E8A2CFA18F}C:\users\19183\appdata\roaming\windows folder\addins\windowsfinder.exe] => (Allow) C:\users\19183\appdata\roaming\windows folder\addins\windowsfinder.exe => 无文件 FirewallRules: [UDP Query User{306E9860-1339-40DC-988C-C7530E550E2D}C:\users\19183\appdata\roaming\windows folder\addins\windowsfinder.exe] => (Allow) C:\users\19183\appdata\roaming\windows folder\addins\windowsfinder.exe => 无文件 FirewallRules: [TCP Query User{97FE1B10-F5C3-4FDB-9196-94E5C63FECB4}C:\windows\bfsvc.exe] => (Block) C:\windows\bfsvc.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{324B841E-0630-47A3-9FB1-5862A79B6514}C:\windows\bfsvc.exe] => (Block) C:\windows\bfsvc.exe (Microsoft Windows -> Microsoft Corporation) StandardProfile\AuthorizedApplications: [E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [E:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service StandardProfile\AuthorizedApplications: [E:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [E:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service ==================== 重启点 ========================= 注意: 系统恢复已禁用 (Total:118.35 GB) (Free:11.59 GB) (10%) ==================== 设备管理器故障 ============ ==================== 事件日志错误: ======================== 应用错误: ================== Error: (02/24/2022 12:24:22 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: hhctrl.ocx_unloaded,版本: 10.0.22000.1,时间戳: 0xfd09051e 异常代码: 0xc0000005 错误偏移量: 0x00026e4e 错误进程 ID: 0x14fc 错误应用程序启动时间: 0x01d82935e63682ad 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: hhctrl.ocx 报告 ID: fa10a284-285a-4ea7-9784-227dddd6f0df 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 12:20:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 异常代码: 0xc0000005 错误偏移量: 0x00005c92 错误进程 ID: 0x14fc 错误应用程序启动时间: 0x01d82935e63682ad 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 报告 ID: 09ec8f74-d5ca-4f4b-8908-bc4f27474a76 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 12:16:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: hhctrl.ocx_unloaded,版本: 10.0.22000.1,时间戳: 0xfd09051e 异常代码: 0xc0000005 错误偏移量: 0x00026e4e 错误进程 ID: 0x1d08 错误应用程序启动时间: 0x01d8293480941e2c 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: hhctrl.ocx 报告 ID: d1418a9b-5515-422c-9e77-44f8fb7679f5 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 12:10:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 异常代码: 0xc0000005 错误偏移量: 0x00005c92 错误进程 ID: 0x1d08 错误应用程序启动时间: 0x01d8293480941e2c 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 报告 ID: cfc2c880-8cc6-4e12-9bc4-10465aafa463 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 12:02:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: hhctrl.ocx_unloaded,版本: 10.0.22000.1,时间戳: 0xfd09051e 异常代码: 0xc0000005 错误偏移量: 0x00026e4e 错误进程 ID: 0x26c4 错误应用程序启动时间: 0x01d829331af942cd 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: hhctrl.ocx 报告 ID: 8e18c526-7aee-4386-9b08-9a6e12bdedbe 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 12:00:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 错误模块名称: SDUpdate.exe,版本: 2.8.68.100,时间戳: 0x5ea5e0d1 异常代码: 0xc0000005 错误偏移量: 0x00005c92 错误进程 ID: 0x26c4 错误应用程序启动时间: 0x01d829331af942cd 错误应用程序路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 错误模块路径: E:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe 报告 ID: d9a3ee1f-afb7-41d5-856d-44f0acce70d8 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 11:59:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: 错误应用程序名称: BlueStacksHelper.exe,版本: 1.80.0.0,时间戳: 0x6177b8f6 错误模块名称: KERNELBASE.dll,版本: 10.0.22000.434,时间戳: 0x72a6f702 异常代码: 0xe0434352 错误偏移量: 0x000000000004478c 错误进程 ID: 0x27ac 错误应用程序启动时间: 0x01d82932df26d323 错误应用程序路径: C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe 错误模块路径: C:\WINDOWS\System32\KERNELBASE.dll 报告 ID: 5bd404a1-a6a5-4706-bda1-3f3fbf26c24c 错误程序包全名: 错误程序包相对应用程序 ID: Error: (02/24/2022 11:59:09 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: 应用程序: BlueStacksHelper.exe Framework 版本: v4.0.30319 说明: 由于未经处理的异常,进程终止。 异常信息: System.UnauthorizedAccessException 在 System.IO.__Error.WinIOError(Int32, System.String) 在 System.IO.Directory.InternalCreateDirectory(System.String, System.String, System.Object, Boolean) 在 System.IO.Directory.InternalCreateDirectoryHelper(System.String, Boolean) 在 BlueStacks.Common.Logger.InitLogAtPath(System.String, System.String, Boolean) 在 BlueStacks.Helper.App.Init(System.String[]) 在 BlueStacks.Helper.App.Main(System.String[]) 系统错误: ============= Error: (02/24/2022 12:15:28 PM) (Source: Netwtw08) (EventID: 5005) (User: ) Description: Intel(R) Wireless-AC 9462 : 遇到内部错误,宣告失败。 5005 - Driver internal error Error: (02/24/2022 12:15:28 PM) (Source: Netwtw08) (EventID: 5002) (User: ) Description: Intel(R) Wireless-AC 9462 : 系统确定网络适配器的运行方式不恰当。 5002 - uCode SW error (SysAssert, NMI) Error: (02/24/2022 12:15:28 PM) (Source: Netwtw08) (EventID: 5005) (User: ) Description: Intel(R) Wireless-AC 9462 : 遇到内部错误,宣告失败。 5005 - Driver internal error Error: (02/24/2022 12:15:28 PM) (Source: Netwtw08) (EventID: 5002) (User: ) Description: Intel(R) Wireless-AC 9462 : 系统确定网络适配器的运行方式不恰当。 5002 - uCode SW error (SysAssert, NMI) Error: (02/24/2022 12:15:27 PM) (Source: Netwtw08) (EventID: 5005) (User: ) Description: Intel(R) Wireless-AC 9462 : 遇到内部错误,宣告失败。 5005 - Driver internal error Error: (02/24/2022 12:15:27 PM) (Source: Netwtw08) (EventID: 5005) (User: ) Description: Intel(R) Wireless-AC 9462 : 遇到内部错误,宣告失败。 5005 - Driver internal error Error: (02/24/2022 12:15:27 PM) (Source: Netwtw08) (EventID: 5002) (User: ) Description: Intel(R) Wireless-AC 9462 : 系统确定网络适配器的运行方式不恰当。 5002 - uCode SW error (SysAssert, NMI) Error: (02/24/2022 12:15:26 PM) (Source: Netwtw08) (EventID: 5005) (User: ) Description: Intel(R) Wireless-AC 9462 : 遇到内部错误,宣告失败。 5005 - Driver internal error Windows Defender: ================ Date: 2022-02-24 11:58:08 Description: Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。 有关详细信息,请参阅以下内容: https://go.microsoft.com/fwlink/?linkid=37020&name=Backdoor:MSIL/AsyncRat.AD!MTB&threatid=2147776186&enterprise=0 名称: Backdoor:MSIL/AsyncRat.AD!MTB 严重性: 严重 类别: 后门程序 路径: file:_C:\Users\19183\AppData\Roaming\1.exe 检测起源: 本地计算机 检测类型: 实际 检测源: 实时保护 用户: DESKTOP-7QJUT0M\19183 进程名称: C:\Windows\explorer.exe 安全智能版本: AV: 1.359.809.0, AS: 1.359.809.0, NIS: 1.359.809.0 引擎版本: AM: 1.1.18900.3, NIS: 1.1.18900.3 Date: 2022-02-24 11:58:07 Description: Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。 有关详细信息,请参阅以下内容: https://go.microsoft.com/fwlink/?linkid=37020&name=PWS:MSIL/ClipSteal.YA!MTB&threatid=2147740788&enterprise=0 名称: PWS:MSIL/ClipSteal.YA!MTB 严重性: 严重 类别: 密码窃取程序 路径: file:_C:\Users\19183\AppData\Roaming\NVIDIA\dllhost.exe 检测起源: 本地计算机 检测类型: 实际 检测源: 实时保护 用户: DESKTOP-7QJUT0M\19183 进程名称: C:\Windows\explorer.exe 安全智能版本: AV: 1.359.809.0, AS: 1.359.809.0, NIS: 1.359.809.0 引擎版本: AM: 1.1.18900.3, NIS: 1.1.18900.3 Date: 2022-02-24 11:54:46 Description: Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。 有关详细信息,请参阅以下内容: https://go.microsoft.com/fwlink/?linkid=37020&name=Ransom:Win32/StopCrypt!ml&threatid=2147788061&enterprise=0 名称: Ransom:Win32/StopCrypt!ml 严重性: 严重 类别: 勒索软件 路径: file:_C:\Users\19183\AppData\Roaming\wgteivv 检测起源: 本地计算机 检测类型: 快速路径 检测源: 系统 用户: NT AUTHORITY\SYSTEM 进程名称: Unknown 安全智能版本: AV: 1.359.770.0, AS: 1.359.770.0, NIS: 1.359.770.0 引擎版本: AM: 1.1.18900.3, NIS: 1.1.18900.3 Date: 2022-02-24 03:48:43 Description: Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。 有关详细信息,请参阅以下内容: https://go.microsoft.com/fwlink/?linkid=37020&name=Ransom:Win32/StopCrypt!ml&threatid=2147788061&enterprise=0 名称: Ransom:Win32/StopCrypt!ml 严重性: 严重 类别: 勒索软件 路径: file:_C:\Users\19183\AppData\Roaming\wgteivv 检测起源: 本地计算机 检测类型: 快速路径 检测源: 实时保护 用户: DESKTOP-7QJUT0M\19183 进程名称: C:\Users\19183\AppData\Roaming\wgteivv 安全智能版本: AV: 1.359.770.0, AS: 1.359.770.0, NIS: 1.359.770.0 引擎版本: AM: 1.1.18900.3, NIS: 1.1.18900.3 Date: 2022-02-24 03:25:30 Description: Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。 有关详细信息,请参阅以下内容: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Sabsik.FL.A!ml&threatid=2147780199&enterprise=0 名称: Trojan:Script/Sabsik.FL.A!ml 严重性: 严重 类别: 特洛伊木马 路径: file:_C:\Users\19183\AppData\Local\cache\libcurl.exe; process:_pid:9224,ProcessStart:132901176015581785 检测起源: 本地计算机 检测类型: 快速路径 检测源: 用户 用户: DESKTOP-7QJUT0M\19183 进程名称: C:\Users\19183\AppData\Local\cache\libcurl.exe 安全智能版本: AV: 1.359.770.0, AS: 1.359.770.0, NIS: 1.359.770.0 引擎版本: AM: 1.1.18900.3, NIS: 1.1.18900.3  CodeIntegrity: =============== Date: 2022-02-24 11:53:10 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe) attempted to load \Device\HarddiskVolume1\Program Files\Spybot - Search & Destroy 2\SDLicense.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== 内存信息 =========================== BIOS: American Megatrends Inc. 1.07.06RHAS2 09/21/2018 母板: HASEE Computer K650D 数据处理机: Intel(R) Pentium(R) Gold G5400 CPU @ 3.70GHz 内存使用百分比: 45% 总内存: 12168.34 MB 可用内存: 6594.78 MB 全虚拟: 28552.34 MB 可用的虚拟: 22096.93 MB ==================== 驱动程序 ================================ Drive c: (Windows) (Fixed) (Total:118.35 GB) (Free:11.59 GB) NTFS Drive d: (Games and Download) (Fixed) (Total:118.93 GB) (Free:44.3 GB) NTFS Drive e: (Atlantis) (Fixed) (Total:49.02 GB) (Free:38.89 GB) NTFS Drive f: (Games) (Fixed) (Total:50 GB) (Free:49.52 GB) NTFS Drive g: (Amazon) (Fixed) (Total:634.86 GB) (Free:249.21 GB) NTFS Drive i: (Audio) (Fixed) (Total:248.09 GB) (Free:199.96 GB) NTFS \\?\Volume{4f9cf4a8-6dfd-48d7-b92a-290c4ed6b31b}\ (Recovery) (Fixed) (Total:0.53 GB) (Free:0.52 GB) NTFS \\?\Volume{f2c6362d-0201-4b37-b1bc-946733ad828b}\ () (Fixed) (Total:0.58 GB) (Free:0.04 GB) NTFS \\?\Volume{e9b13052-d40d-4fcf-a5e6-6305d7ce1e97}\ (SYSTEM) (Fixed) (Total:0.06 GB) (Free:0.01 GB) FAT32 ==================== MBR & 分区表 ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 698.6 GB) (Disk ID: 25E74906) Partition 1: (Not Active) - (Size=49 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=634.9 GB) - (Type=0F Extended) ========================================================== Disk: 1 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 2 (MBR Code: Windows XP) (Size: 298.1 GB) (Disk ID: F2195342) Partition 1: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=248.1 GB) - (Type=07 NTFS) ==================== 结束 在 Addition.txt =======================