星卡卡电脑诊断日志 v1.20 (2007-7-12 20:54:15) 北京瑞星科技股份有限公司
注释:[A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ Win32 Services
+ HKLM\System\CurrentControlSet\Services
82485F4E
[A ] 1. c:\windows\system32\d81e5dba.exe
IDriverT
[A ] 2. c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
iPodService
[AM] 3. c:\program files\ipod\bin\ipodservice.exe
ose
[A ] 4. c:\program files\common files\microsoft shared\source engine\ose.exe
P4P Service
[AM] 5. c:\program files\common files\sogou pxp\p2psvr.exe
RfwProxySrv
[A ] 6. c:\program files\rising\rfw\rfwproxy.exe
RfwService
[A ] 7. c:\program files\rising\rfw\rfwsrv.exe
RsCCenter
[A ] 8. c:\program files\rising\rav\ccenter.exe
RsRavMon
[A ] 9. c:\program files\rising\rav\ravmond.exe
ServiceLayer
[AM] 10. c:\program files\common files\pcsuite\services\servicelayer.exe
usnjsvc
[A ] 11. c:\program files\msn messenger\usnsvc.exe
+ Kernel Drivers
+ HKLM\System\CurrentControlSet\Services
BaseTDI
[A ] 12. c:\windows\system32\drivers\basetdi.sys
EagleNT
[A ] 13. c:\windows\system32\drivers\eaglent.sys
ExpScaner
[A ] 14. c:\program files\rising\rav\expscan.sys
GEARAspiWDM
[A ] 15. c:\windows\system32\drivers\gearaspiwdm.sys
GMSIPCI
[A ] 16. g:\install\gmsipci.sys
HOOKAPI
[A ] 17. c:\program files\rising\rav\hookapi.sys
HookCont
[A ] 18. c:\program files\rising\rav\hookcont.sys
HookReg
[A ] 19. c:\program files\rising\rav\hookreg.sys
HookSys
[A ] 20. c:\program files\rising\rav\hooksys.sys
HookUrl
[A ] 21. c:\program files\rising\rfw\hookurl.sys
kikhlfsd
[A ] 22. c:\windows\system32\drivers\kikhlfsd.sys
kmsinput
[A ] 23. c:\windows\system32\drivers\kmsinput.sys
MEMSCAN
[A ] 24. c:\program files\rising\rav\memscan.sys
mProcRs
[A ] 25. c:\program files\rising\rfw\mprocrs.sys
Nokia USB Generic
[A ] 26. c:\windows\system32\drivers\nmwcdc.sys
Nokia USB Modem
[A ] 27. c:\windows\system32\drivers\nmwcdcm.sys
Nokia USB Phone Parent
[A ] 28. c:\windows\system32\drivers\nmwcd.sys
Nokia USB Port
[A ] 29. c:\windows\system32\drivers\nmwcdcj.sys
NPF
[A ] 30. c:\windows\system32\drivers\npf.sys
npkcrypt
[A ] 31. d:\游戏\qq2005\npkcrypt.sys
npkycryp
[A ] 32. d:\游戏\qq2005\npkycryp.sys
prodrv06
[A ] 33. c:\windows\system32\drivers\prodrv06.sys
prohlp02
[A ] 34. c:\windows\system32\drivers\prohlp02.sys
prosync1
[A ] 35. c:\windows\system32\drivers\prosync1.sys
RsAntiSpyware
[A ] 36. c:\windows\system32\drivers\rsboot.sys
RsFwDrv
[A ] 37. c:\program files\rising\rfw\rsfwdrv.sys
RsNTGDI
[A ] 38. c:\windows\system32\drivers\rsntgdi.sys
RSPPSYS
[A ] 39. c:\program files\rising\rav\rsppsys.sys
Secdrv
[A ] 40. c:\windows\system32\drivers\secdrv.sys
sfdrv01
[A ] 41. c:\windows\system32\drivers\sfdrv01.sys
sfhlp01
[A ] 42. c:\windows\system32\drivers\sfhlp01.sys
sfhlp02
[A ] 43. c:\windows\system32\drivers\sfhlp02.sys
sfsync02
[A ] 44. c:\windows\system32\drivers\sfsync02.sys
sfsync04
[A ] 45. c:\windows\system32\drivers\sfsync04.sys
ssm_bus
[A ] 46. c:\windows\system32\drivers\ssm_bus.sys
ssm_mdfl
[A ] 47. c:\windows\system32\drivers\ssm_mdfl.sys
ssm_mdm
[A ] 48. c:\windows\system32\drivers\ssm_mdm.sys
viaagp1
[A ] 49. c:\windows\system32\drivers\viaagp1.sys
VIAudio
[A ] 50. c:\windows\system32\drivers\vinyl97.sys
+ File System Drivers
+ HKLM\System\CurrentControlSet\Services
ADProt
[A ] 51. c:\windows\system32\drivers\adprot.sys
+ Winlogon
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
WgaLogon
[AM] 52. c:\windows\system32\wgalogon.dll
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 53. c:\windows\fish.scr
+ Internet Explorer
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{BA440AED-8A58-46A3-B8E5-6AEE4D03A7D8}
[A ] 54. d:\软件\biget\bntoolbar.dll
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 55. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 56. c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
[AM] 57. c:\program files\flashget\jccatch.dll
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
[AM] 58. c:\program files\msn apps\st\01.02.3000.1001\en-xu\stmain.dll
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
[AM] 59. c:\program files\msn apps\msn toolbar\01.02.5000.1021\zh-cn\msntb.dll
{F156768E-81EF-470C-9057-481BA8380DBA}
[AM] 60. c:\program files\flashget\getflash.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 61. c:\program files\thunder network\thunder\thunder.exe
Exec
[A ] 62. d:\游戏\浩方对战平台\gameclient.exe
Exec
[A ] 63. c:\program files\herosoft\hero 9\sthsdvd.exe
Exec
[A ] 64. d:\游戏\qq2005\qq.exe
Exec
[A ] 65. c:\program files\flashget\flashget.exe
Exec
[A ] 66. c:\program files\messenger\msmsgs.exe
+ Explorer
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[AM] 67. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
livecall
[A ] 68. c:\program files\msn messenger\msgrapp.8.1.0178.00.dll
msnim
[A ] 68. c:\program files\msn messenger\msgrapp.8.1.0178.00.dll
mso-offdap
[A ] 69. c:\program files\common files\microsoft shared\web components\10\owc10.dll
mso-offdap11
[A ] 70. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
{81716107-A10D-11cf-64CD-11115FE1CF41}
[A ] 71. c:\windows\system32\nwizzhuxians.exe
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 72. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 73. c:\windows\system32\hticons.dll
Web Folders
[A ] 74. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office Outlook Desktop Icon Handler
[A ] 75. d:\软件\office2000\office11\mlshext.dll
Microsoft Office Outlook Custom Icon Handler
[A ] 76. d:\软件\office2000\office11\olkfstub.dll
Microsoft Office HTML Icon Handler
[AM] 77. d:\软件\office2000\office11\msohev.dll
RISING
[AM] 78. c:\windows\system32\ravext.dll
百纳搜索
[A ] 54. d:\软件\biget\bntoolbar.dll
WinRAR shell extension
[AM] 79. d:\软件\winrar\rarext.dll
iTunes
[A ] 80. c:\program files\itunes\itunesminiplayer.dll
Messenger Sharing Folders
[A ] 81. c:\program files\msn messenger\fsshext.8.1.0178.00.dll
PhoneBrowser
[AM] 82. c:\program files\nokia\nokia pc suite 6\phonebrowser.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 78. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 83. c:\windows\system32\shlhook.dll
+ Logon
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr
[A ] 84. c:\program files\msn messenger\msnmsgr.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RfwMain
[AM] 85. c:\program files\rising\rfw\rfwmain.exe
TkBellExe
[A ] 86. c:\program files\common files\real\update_ob\realsched.exe
IMSCMig
[A ] 87. c:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
RavTask
[A ] 88. c:\program files\rising\rav\ravtask.exe
iTunesHelper
[AM] 89. c:\program files\itunes\ituneshelper.exe
runeip
[A ] 90. c:\program files\rising\antispyware\runiep.exe
miniqqlive
[A ] 91. c:\program files\tencent\qqlive\miniqqlive.exe
cmdbcs
[A ] 92. c:\windows\cmdbcs.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub
[AM] 93. c:\program files\rising\rav\ravstub.exe
KKDelay
[A ] 94. c:\program files\rising\antispyware\runonce.exe
+ Boot Execute
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 95. c:\windows\system32\bsmain.exe
[A ] 96. c:\windows\system32\kknative.exe
+ Image Hijacks
+ HKCR\.html
htmlfile\Edit\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\open\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\open\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
+ HKCR\.mp3
Winamp.File\Enqueue\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\ListBookmark\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\open\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\Play\Command
[A ] 99. c:\program files\winamp\winamp.exe
+ Print Monitor
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 100. c:\windows\system32\mdimon.dll