瑞星卡卡电脑诊断日志 v1.20 (2007-10-26 9:51:19) 北京瑞星科技股份有限公司
注释:[A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ Win32 Services
+ HKLM\System\CurrentControlSet\Services
PGPserv
[AM] 1. c:\windows\system32\pgpserv.exe
RsCCenter
[AM] 2. c:\program files\rising\rav\ccenter.exe
VMAuthdService
[AM] 3. c:\program files\vmware\vmware workstation\vmware-authd.exe
VMnetDHCP
[AM] 4. c:\windows\system32\vmnetdhcp.exe
VMware NAT Service
[AM] 5. c:\windows\system32\vmnat.exe
+ Kernel Drivers
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 6. c:\windows\system32\drivers\alcxwdm.sys
FOIMLPE
[A ] 7. c:\windows\system32\drivers\mahaha.sys
hcmon
[A ] 8. c:\windows\system32\drivers\hcmon.sys
MegaIDE
[A ] 9. c:\windows\system32\drivers\megaide.sys
NPF
[A ] 10. c:\windows\system32\drivers\npf.sys
PGPdisk
[A ] 11. c:\windows\system32\drivers\pgpdisk.sys
PGPsdkDriver
[A ] 12. c:\windows\system32\drivers\pgpsdk.sys
PQNTDrv
[A ] 13. c:\windows\system32\drivers\pqntdrv.sys
ROEMGP
[A ] 14. c:\windows\system32\drivers\maxixi.sys
RsAntiSpyware
[A ] 15. c:\windows\system32\drivers\rsboot.sys
RsNTGDI
[A ] 16. c:\windows\system32\drivers\rsntgdi.sys
RTL8023
[A ] 17. c:\windows\system32\drivers\rtlnic51.sys
Secdrv
[A ] 18. c:\windows\system32\drivers\secdrv.sys
VMnetAdapter
[A ] 19. c:\windows\system32\drivers\vmnetadapter.sys
VMnetBridge
[A ] 20. c:\windows\system32\drivers\vmnetbridge.sys
VMnetuserif
[A ] 21. c:\windows\system32\drivers\vmnetuserif.sys
VMparport
[A ] 22. c:\windows\system32\drivers\vmparport.sys
vmx86
[A ] 23. c:\windows\system32\drivers\vmx86.sys
+ Winlogon
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
UIHost
[A ] 24. c:\program files\logonui\royale.exe
+ Internet Explorer
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[A ] 25. c:\program files\flashget\fgiebar.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
[AM] 26. c:\program files\flashget\jccatch.dll
{F156768E-81EF-470C-9057-481BA8380DBA}
[AM] 27. c:\program files\flashget\getflash.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 28. c:\program files\flashget\flashget.exe
+ Explorer
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 29. c:\windows\system32\hticons.dll
WinRAR shell extension
[AM] 30. c:\program files\winrar\rarext.dll
PicaView
[AM] 31. c:\program files\acdsee\picaview.dll
Shell Extension
[AM] 32. c:\windows\system32\pgpmn.dll
RISING
[AM] 33. c:\windows\system32\ravext.dll
RTX Shell Menu
[AM] 34. c:\program files\tencent\rtxc\rtxshl.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 33. c:\windows\system32\ravext.dll
+ Logon
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr
[AM] 35. c:\program files\msn messenger\msnmsgr.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SoundMan
[AM] 36. c:\windows\soundman.exe
RavTask
[AM] 37. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 38. c:\program files\rising\antispyware\runiep.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
twin
[A ] 39. c:\windows\system32\ctfnom.exe
文件名和"ctfmon.exe"类似
+ Boot Execute
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 40. c:\windows\system32\bsmain.exe
+ Image Hijacks
+ HKCR\.html
htmlfile\Edit\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
+ HKCR\.log
UltraEdit.log\open\Command
[A ] 42. c:\program files\idm computer solutions\ultraedit-32\uedit32.exe
UltraEdit.log\print\Command
[A ] 42. c:\program files\idm computer solutions\ultraedit-32\uedit32.exe
+ AppInit Dlls & Known Dlls
+ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
PGPsdk
[AM] 43. c:\windows\system32\pgpsdk.dll
PGPsdkNL
[AM] 44. c:\windows\system32\pgpsdknl.dll
PGPsdkUI
[AM] 45. c:\windows\system32\pgpsdkui.dll
PGPclientlib
[AM] 46. c:\windows\system32\pgpclientlib.dll
PGPhk
[AM] 47. c:\windows\system32\pgphk.dll
PGPsc
[AM] 48. c:\windows\system32\pgpsc.dll
+ 其他自启动项目
+ C:\Documents and Settings\user\「开始」菜单\程序\启动
腾讯通RTX.lnk
[AM] 49. c:\program files\tencent\rtxc\rtx.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
PGPtray.lnk
[AM] 50. c:\program files\pgp corporation\pgp for windows xp\pgptray.exe
Ti
»Bvîbbs.ikaka.comhbP¼¨ûÐòá