完整的日志在附件里
瑞星卡卡电脑诊断日志 v1.30 (2007-7-25 23:1:50) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
aspnet_state
[A ] 1. c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe
Microsoft Corporation
aspnet_state.exe
.text,.data,.rsrc,
Rasautol
[A ] 2. c:\windows\system32\ntsokele.exe
CODE,.rsrc,.llydd,
入口点在最后一个节;
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 3. c:\windows\system32\drivers\alcxwdm.sys
Realtek Semiconductor Corp.
Realtek AC'97 Audio Driver (WDM)
.text,_LTEXT,_PTEXT,.rdata,.data,.CRT,_LDATA,_PDATA,.data1,PAGE,INIT,.rsrc,.reloc,
ialm
[A ] 4. c:\windows\system32\drivers\ialmnt5.sys
Intel Corporation
Controller Hub for Intel Graphics Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
NPF
[A ] 5. c:\windows\system32\drivers\npf.sys
CACE Technologies
npf
.text,.rdata,.data,INIT,.rsrc,.reloc,
RsAntiSpyware
[A ] 6. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Secdrv
[A ] 7. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
ss_bus
[A ] 8. c:\windows\system32\drivers\ss_bus.sys
MCCI
Samsung Mobile USB Device 1.0 Driver
.text,.data,INIT,.rsrc,.reloc,
ss_mdfl
[A ] 9. c:\windows\system32\drivers\ss_mdfl.sys
MCCI
SAMSUNG Mobile USB Modem 1.0 Filter Driver
.text,.rdata,INIT,.rsrc,.reloc,
ss_mdm
[A ] 10. c:\windows\system32\drivers\ss_mdm.sys
MCCI
SAMSUNG Mobile USB Modem 1.0 Driver
.text,.data,INIT,.rsrc,.reloc,
{6080A529-897E-4629-A488-ABA0C29B635E}
[A ] 11. c:\windows\system32\drivers\ialmsbw.sys
Intel Corporation
Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
{D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
[A ] 12. c:\windows\system32\drivers\ialmkchw.sys
Intel Corporation
Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
igfxcui
[AM] 13. c:\windows\system32\igfxsrvc.dll
Intel Corporation
igfxsrvc Module
.text,.rdata,.data,.rsrc,.reloc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 14. c:\program files\tencent\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
Exec
[A ] 15. c:\program files\messenger\msmsgs.exe
Microsoft Corporation
Windows Messenger
.text,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[A ] 16. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-complus
[A ] 16. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-msdownload
[A ] 16. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 17. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
Fusion Cache
[A ] 16. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[AM] 18. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{40117B96-998D-4D80-8F89-5E9DBD9F3460}
[AM] 19. c:\program files\internet explorer\plugins\syswin64.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
{2562452F-FA36-BA4F-892A-FF5FBBAC5312}
[AM] 20. c:\windows\system32\mybpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
{22311A42-AC1B-158F-FD32-5674345F23A2}
[AM] 21. c:\windows\system32\dhbpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
{2F12545B-1212-1314-5679-4512ACEF8902}
[AM] 22. c:\windows\system32\wdbpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
{D8E0E3BA-D55F-4A08-8EE4-0A59E0284124}
[AM] 23. c:\windows\system32\agent.dll
.Upack,.rsrc,
入口点在最后一个节;
{559AFD5B-159F-ACD8-954C-ACD545FA6585}
[AM] 24. c:\windows\system32\jzepri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
{5A65498A-7653-9801-1647-987114AB7F45}
[AM] 25. c:\windows\system32\zxepri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 26. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched
[AM] 27. c:\program files\java\jre1.5.0_04\bin\jusched.exe
Sun Microsystems, Inc.
Java(TM) 2 Platform Standard Edition binary
.text,.rdata,.data,.rsrc,
load
[AM] 28. c:\windows\uninstall\rundl132.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
文件名和"rundll32.exe"类似;
SoundMan
[AM] 29. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.rsrc,
IgfxTray
[AM] 30. c:\windows\system32\igfxtray.exe
Intel Corporation
igfxTray Module
.text,.rdata,.data,.rsrc,
HotKeysCmds
[AM] 31. c:\windows\system32\hkcmd.exe
Intel Corporation
hkcmd Module
.text,.rdata,.data,.rsrc,
cmdbcs
[A ] 32. c:\windows\cmdbcs.exe
UPX0,UPX1,.rsrc,
qjsa
[A ] 33. c:\documents and settings\administrator\local settings\temp\qjso.exe
.text,.rsrc,
upxdnd
[A ] 34. c:\windows\upxdnd.exe
.text,.rdata,.data,.rsrc,
Microsoft Autorun3
[A ] 35. c:\windows\system32\nwizhx2.exe
VL橸谚?_Y??G,QV?褤瑒,
mppds
[A ] 36. c:\windows\mppds.exe
.text,.rdata,.data,.rsrc,
TIMHost
[A ] 37. c:\windows\timhost.exe
.text,.rdata,.data,.rsrc,
runeip
[AM] 38. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
MSDEG32
[A ] 39. c:\windows\system32\lyloader.exe
VL橸谚?_Y??G,QV?褤瑒,
visin
[A ] 40. c:\windows\system32\visin.exe
Microsoft Corporation
Microsoft Wisin Control
,,,
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 21. c:\windows\system32\dhbpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 14. c:\program files\tencent\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 0000013c(316) svchost.exe
10060000[00010000]
[ M] 41. c:\windows\system32\netsrvcs.dll
.text,.rsrc,.reloc,
+ 000001b4(436) smss.exe
+ 000001ec(492) csrss.exe
+ 00000204(516) winlogon.exe
004D0000[0000A000]
[AM] 20. c:\windows\system32\mybpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
72C80000[00008000]
[ M] 42. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 00000234(564) services.exe
003C0000[0000A000]
[AM] 20. c:\windows\system32\mybpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10000000[0000F000]
[ M] 43. c:\windows\system32\lymangr.dll
.Upack,.rsrc,
入口点在最后一个节;
+ 00000240(576) lsass.exe
003C0000[0000A000]
[AM] 20. c:\windows\system32\mybpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 000002d0(720) alg.exe
10000000[00015000]
[ M] 44. c:\windows\system32\msipfilter.dll
.text,.rdata,.data,Shared,.reloc,
+ 000002d8(728) svchost.exe
003C0000[0000A000]
[AM] 20. c:\windows\system32\mybpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
00A30000[00011000]
[AM] 19. c:\program files\internet explorer\plugins\syswin64.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00A50000[0001F000]
[ M] 45. c:\windows\system32\zeqax.dll
.Upack,.rsrc,
入口点在最后一个节;
00A70000[0001F000]
[ M] 46. c:\windows\system32\wiytd.dll
.Upack,.rsrc,
入口点在最后一个节;
00EB0000[0001F000]
[ M] 47. c:\windows\system32\wljhj.dll
.Upack,.rsrc,
入口点在最后一个节;