瑞星卡卡电脑诊断日志 v1.30 (2010-4-20 9:25:57) 北京瑞星信息技术有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
EPSON_PM_RPCV4_01
[AM] 1. c:\documents and settings\all users\application data\epson\epw!3 ssrp\e_s40rp7.exe
JTAGServer
[AM] 2. c:\altera\qprogrammer\bin\jtagserver.exe
ose
[A ] 3. c:\program files\common files\microsoft shared\source engine\ose.exe
RsRavMon
[AM] 4. c:\program files\rising\rav\ravmond.exe
RsRFWMon
[AM] 5. c:\program files\rising\rfw\ravmond.exe
TSUSVC
[A ] 6. c:\program files\tencent\qqsoftmgr\tencentupdatesvc.exe
UTSCSI
[AM] 7. c:\windows\system32\utscsi.exe
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ACPISYS
[A ] 8. c:\windows\system32\drivers\acpisys.sys
Alidevice
[A ] 9. c:\windows\system32\drivers\alidevice.sys
AlteraByteBlaster
[A ] 10. c:\windows\system32\drivers\pgdhdlc.sys
BaseTDI
[A ] 11. c:\windows\system32\drivers\basetdi.sys
CH341SER
[A ] 12. c:\windows\system32\drivers\ch341ser.sys
cmuda
[A ] 13. c:\windows\system32\drivers\cmuda.sys
CV2K1
[A ] 14. c:\windows\system32\drivers\cv2k1.sys
ferdr
[A ] 15. c:\windows\system32\drivers\ferdr.sys
FExxxISB
[A ] 16. c:\windows\system32\drivers\fexxx5b.sys
hookcont
[A ] 17. c:\windows\system32\drivers\hookcont.sys
hooksys
[A ] 18. c:\windows\system32\drivers\hooksys.sys
npkcrypt
[A ] 19. c:\program files\tencent\qq\npkcrypt.sys
NTSIM
[A ] 20. c:\windows\system32\ntsim.sys
qiqfqjp
[A ] 21. c:\windows\system32\drivers\qiqfqjp.sys
RFWARP
[A ] 22. c:\windows\system32\drivers\rfwarp.sys
RfwBase9
[A ] 23. c:\windows\system32\drivers\rfwbase.sys
rfwtdi
[A ] 24. c:\program files\rising\rfw\rfwtdi.sys
RsAntiSpyware
[A ] 25. c:\windows\system32\drivers\rsboot.sys
rsassist
[A ] 26. c:\windows\system32\drivers\rsassist.sys
rsfwdrv
[A ] 27. c:\program files\rising\rfw\rsfwdrv.sys
RsNTGDI
[A ] 28. c:\windows\system32\drivers\rsntgdi.sys
S3chipid
[A ] 29. c:\docume~1\sqian\locals~1\temp\{2b43252c-a1e3-4c47-927c-9f2c276d3515}\s3chipid.sys
Secdrv
[A ] 30. c:\windows\system32\drivers\secdrv.sys
Sentinel
[A ] 31. c:\windows\system32\drivers\sentinel.sys
Ser2pl
[A ] 32. c:\windows\system32\drivers\ser2pl.sys
Sntnlusb
[A ] 33. c:\windows\system32\drivers\sntnlusb.sys
SP5NT
[A ] 34. c:\windows\system32\drivers\sp5nt.sys
TSKSP
[A ] 35. c:\program files\tencent\qq\qqdoctor\tsksp.sys
viagfx
[A ] 36. c:\windows\system32\drivers\vtmini.sys
ZLGUSB
[A ] 37. c:\windows\system32\drivers\zlgusb.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
ADProt
[A ] 38. c:\windows\system32\drivers\adprot.sys
exFat
[A ] 39. c:\windows\system32\drivers\exfat.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[A ] 40. c:\program files\flashget\fgiebar.dll
{29CF293A-1E7D-4069-9E11-E39698D0AF95}
[A ] 41. c:\program files\tencent\qqtoolbar\iebar.dll
{EE5D279F-081B-4404-994D-C6B60AAEBA6D}
[AM] 42. c:\program files\epson\epson web-to-page\epson web-to-page.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 43. c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
{29CF293A-1E7D-4069-9E11-E39698D0AF95}
[A ] 41. c:\program files\tencent\qqtoolbar\iebar.dll
{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
[A ] 44. c:\program files\tencent\qq\qqdoctor\tswebmon.dat
{9030D464-4C02-4ABF-8ECC-5164760863C6}
[A ] 45. c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
[A ] 46. c:\windows\system32\urlfilter.dll
{A5366673-E8CA-11D3-9CD9-0090271D075B}
[AM] 47. c:\program files\flashget\jccatch.dll
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}
[AM] 42. c:\program files\epson\epson web-to-page\epson web-to-page.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[AM] 48. c:\program files\messenger\msmsgs.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 49. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
dic
[A ] 50. c:\program files\kingsoft\powerword 2003\xdictexb.dll
livecall
[A ] 51. c:\program files\windows live\messenger\msgrapp.14.0.8089.0726.dll
msnim
[A ] 51. c:\program files\windows live\messenger\msgrapp.14.0.8089.0726.dll
mso-offdap
[A ] 52. c:\program files\common files\microsoft shared\web components\10\owc10.dll
mso-offdap11
[A ] 53. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 54. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 55. c:\windows\system32\hticons.dll
WinRAR shell extension
[A ] 56. c:\program files\winrar\rarext.dll
PowerWord ExplorerBar
[A ] 50. c:\program files\kingsoft\powerword 2003\xdictexb.dll
Web Folders
[A ] 57. c:\program files\common files\microsoft shared\web folders\msonxxxt.dll
Microsoft Office HTML Icon Handler
[AM] 58. c:\program files\microsoft office\office11\msohev.dll
{506F4668-F13E-4AA1-BB04-B43203AB3CC0}
[A ] 59. c:\program files\microsoft office\visio11\visshe.dll
{D66DC78C-4F61-447F-942B-3FB6980118CF}
[A ] 59. c:\program files\microsoft office\visio11\visshe.dll
RISING
[AM] 60. c:\windows\system32\ravext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 60. c:\windows\system32\ravext.dll
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON ME 1
[A ] 61. c:\windows\system32\spool\drivers\w32x86\3\e_fati8wp.exe
msnmsgr
[A ] 62. c:\program files\windows live\messenger\msnmsgr.exe
aliim
[A ] 63. c:\program files\aliwangwang\aliim.exe
MSMSGS
[AM] 48. c:\program files\messenger\msmsgs.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VTTimer
[AM] 64. c:\windows\system32\vttimer.exe
RFWTray
[AM] 65. c:\program files\rising\rfw\rstray.exe
RavTray
[AM] 66. c:\program files\rising\rav\rstray.exe
runeip
[AM] 67. c:\program files\rising\antispyware\rstray.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 68. c:\program files\rising\antispyware\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 69. c:\windows\system32\bsmain.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 70. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 70. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 70. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 70. c:\program files\microsoft office\office11\msohtmed.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
CNAB4 Monitor
[AM] 71. c:\windows\system32\cnab4lmk.dll
EPSON ME 1 32MonitorBP
[AM] 72. c:\windows\system32\e_flb8wp.dll
Microsoft Document Imaging Writer Monitor
[AM] 73. c:\windows\system32\mdimon.dll
+ 其他自启动项目
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Reader Speed Launch.lnk
[A ] 74. c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
EPSON Online Register.lnk
[A ] 75. c:\program files\epson\online register\online register.exe
+ 正在运行的进程
+ 00000198(408) RsTray.exe
00400000[0002C000]
[AM] 65. c:\program files\rising\rfw\rstray.exe
10000000[00031000]
[ M] 76. c:\program files\rising\rfw\comserv.dll
23700000[00023000]
[ M] 77. c:\program files\rising\rfw\rslang.dll
00A80000[0002D000]
[ M] 78. c:\program files\rising\rfw\comx3.dll
00AB0000[00019000]
[ M] 79. c:\program files\rising\rfw\syslay.dll
00D20000[00019000]
[ M] 80. c:\program files\rising\rfw\proccomm.dll
23800000[00039000]
[ M] 81. c:\program files\rising\rfw\rsxml.dll
00F60000[00013000]
[ M] 82. c:\program files\rising\rfw\monstate.dll
00F90000[0000C000]
[ M] 83. c:\program files\rising\rfw\rfwrule.dll
7C3A0000[0007B000]
[ M] 84. c:\windows\system32\msvcp71.dll
7C340000[00056000]
[ M] 85. c:\windows\system32\msvcr71.dll
00FB0000[00017000]
[ M] 86. c:\program files\rising\rfw\rsconf.dll
00FE0000[00022000]
[ M] 87. c:\program files\rising\rfw\rspalvd.dll
26600000[00078000]
[ M] 88. c:\program files\rising\rfw\rsguilib.dll
33000000[00026000]
[ M] 89. c:\program files\rising\rfw\ravbintl.dll
01040000[0007E000]
[ M] 90. c:\program files\rising\rfw\rsnetsvr.dll
010E0000[0004C000]
[ M] 91. c:\program files\rising\rfw\rsmginfo.dll
01140000[00052000]
[ M] 92. c:\program files\rising\rfw\rfwtray.dll
32000000[00088000]
[ M] 93. c:\program files\rising\rfw\ravppops.dll
012D0000[0000E000]
[ M] 94. c:\program files\rising\rfw\rsappmgr.dll
012F0000[00044000]
[ M] 95. c:\program files\rising\rfw\cfgdll.dll
23900000[00040000]
[ M] 96. c:\program files\rising\rfw\pngdll.dll
01A60000[00082000]
[ M] 97. c:\program files\rising\rfw\rfwlog.dll
+ 000001d8(472) RsTray.exe
00400000[0002C000]
[AM] 66. c:\program files\rising\rav\rstray.exe
10000000[00031000]
[ M] 98. c:\program files\rising\rav\comserv.dll
23700000[00023000]
[ M] 99. c:\program files\rising\rav\rslang.dll
00A80000[0002D000]
[ M] 100. c:\program files\rising\rav\comx3.dll
00AB0000[00019000]
[ M] 101. c:\program files\rising\rav\syslay.dll
00D20000[00019000]
[ M] 102. c:\program files\rising\rav\proccomm.dll
23800000[00039000]
[ M] 103. c:\program files\rising\rav\rsxml.dll
00F60000[00013000]
[ M] 104. c:\program files\rising\rav\monstate.dll
00F90000[00016000]
[ M] 105. c:\program files\rising\rav\scanevnt.dll
26600000[00078000]
[ M] 106. c:\program files\rising\rav\rsguilib.dll
00FD0000[00017000]
[ M] 107. c:\program files\rising\rav\rsconf.dll
01000000[00022000]
[ M] 108. c:\program files\rising\rav\rspalvd.dll
33000000[00026000]
[ M] 109. c:\program files\rising\rav\ravbintl.dll
01050000[0007D000]
[ M] 110. c:\program files\rising\rav\mruleui.dll
010F0000[0007D000]
[ M] 111. c:\program files\rising\rav\montray.dll
34500000[00020000]
[ M] 112. c:\program files\rising\rav\ravitray.dll
01190000[0004C000]
[ M] 113. c:\program files\rising\rav\rsmginfo.dll
011F0000[00013000]
[ M] 114. c:\program files\rising\rav\scanleak.dll
32000000[00088000]
[ M] 115. c:\program files\rising\rav\ravppops.dll
01530000[0000E000]
[ M] 116. c:\program files\rising\rav\rsappmgr.dll
01550000[00044000]
[ M] 117. c:\program files\rising\rav\cfgdll.dll
23900000[00040000]
[ M] 118. c:\program files\rising\rav\pngdll.dll
01E00000[00080000]
[ M] 119. c:\program files\rising\rav\scanprxy.dll
+ 000001e8(488) rstray.exe
00400000[00034000]
[AM] 67. c:\program files\rising\antispyware\rstray.exe
10000000[0004C000]
[ M] 120. c:\program files\rising\antispyware\rsmginfo.dll
00CA0000[00014000]
[ M] 121. c:\program files\rising\antispyware\regcall.dll
23800000[00039000]
[ M] 122. c:\program files\rising\antispyware\rsxml.dll
00CE0000[00024000]
[ M] 123. c:\program files\rising\antispyware\comserv.dll
00D10000[00019000]
[ M] 124. c:\program files\rising\antispyware\syslay.dll
7C3A0000[0007B000]
[ M] 125. c:\program files\rising\antispyware\msvcp71.dll
7C340000[00056000]
[ M] 126. c:\program files\rising\antispyware\msvcr71.dll
23700000[00026000]
[ M] 127. c:\program files\rising\antispyware\rscommon.dll
00D60000[0002D000]
[ M] 128. c:\program files\rising\antispyware\comx3.dll
01280000[00022000]
[ M] 129. c:\program files\rising\antispyware\rsxml1.dll
23900000[00040000]
[ M] 130. c:\program files\rising\antispyware\pngdll.dll
012C0000[00074000]
[ M] 131. c:\program files\rising\antispyware\runiep.dll
01340000[00034000]
[ M] 132. c:\program files\rising\antispyware\ncomm.dll
013A0000[0001F000]
[ M] 133. c:\program files\rising\rav\proccom.dll
013C0000[00024000]
[ M] 134. c:\program files\rising\antispyware\rscommx2.dll
+ 000001f0(496) ctfmon.exe
10000000[00014000]
[ M] 121. c:\program files\rising\antispyware\regcall.dll
+ 00000230(560) UTSCSI.EXE
00400000[00010000]
[AM] 7. c:\windows\system32\utscsi.exe
+ 000002a0(672) smss.exe
+ 00000304(772) csrss.exe
+ 0000031c(796) winlogon.exe
72C80000[00008000]
[ M] 135. c:\windows\system32\msacm32.drv
+ 00000348(840) services.exe
+ 00000354(852) lsass.exe
+ 00000398(920) svchost.exe
+ 000003ec(1004) svchost.exe
+ 00000418(1048) svchost.exe
+ 0000046c(1132) RavMonD.exe
00400000[0002F000]
[AM] 4. c:\program files\rising\rav\ravmond.exe
10000000[00032000]
[ M] 136. c:\program files\rising\rav\combase.dll
01480000[00086000]
[ M] 137. c:\program files\rising\rav\cnt09.dll
01240000[00019000]
[ M] 138. c:\program files\rising\rav\moncomm.dll
01510000[0001D000]
[ M] 139. c:\program files\rising\rav\monbase.dll
01530000[00084000]
[ M] 140. c:\program files\rising\rav\rslog.dll
015E0000[00018000]
[ M] 141. c:\program files\rising\rav\mondrv.dll
01610000[0002E000]
[ M] 142. c:\program files\rising\rav\defmon.dll
01650000[00010000]
[ M] 143. c:\program files\rising\rav\moncom08.dll
01670000[0007E000]
[ M] 144. c:\program files\rising\rav\monrule.dll
01720000[00027000]
[ M] 145. c:\program files\rising\rav\filemon.dll
01760000[0002F000]
[ M] 146. c:\program files\rising\rav\mailmon.dll
017A0000[00015000]
[ M] 147. c:\program files\rising\rav\hookweb.dll
017E0000[0008C000]
[ M] 148. c:\program files\rising\rav\rsindent.dll
01870000[00019000]
[ M] 101. c:\program files\rising\rav\syslay.dll
018B0000[00018000]
[ M] 149. c:\program files\rising\rav\taskplug.dll
018E0000[00012000]
[ M] 150. c:\program files\rising\rav\scansrvp.dll
01D10000[0001D000]
[ M] 151. c:\program files\rising\rav\cnt08.dll
01E90000[00019000]
[ M] 102. c:\program files\rising\rav\proccomm.dll
01EC0000[0000E000]
[ M] 116. c:\program files\rising\rav\rsappmgr.dll
02300000[00044000]
[ M] 117. c:\program files\rising\rav\cfgdll.dll
02440000[0002D000]
[ M] 100. c:\program files\rising\rav\comx3.dll
025B0000[00020000]
[ M] 152. c:\program files\rising\rav\hooksys.dll
02660000[0001F000]
[ M] 133. c:\program files\rising\rav\proccom.dll
02680000[00024000]
[ M] 153. c:\program files\rising\rav\rscommx2.dll
028D0000[00013000]
[ M] 154. c:\program files\rising\rav\hookcont.dll
02A10000[00078000]
[ M] 155. c:\program files\rising\rav\bacore.dll
02BB0000[0003B000]
[ M] 156. c:\program files\rising\rav\recomp.dll
02C00000[00038000]
[ M] 157. c:\program files\rising\rav\refs.dll
02E60000[00030000]
[ M] 158. c:\program files\rising\rav\viruslib.dll
02FA0000[00029000]
[ M] 159. c:\program files\rising\rav\relibldr.dll
03220000[0007E000]
[ M] 160. c:\program files\rising\rav\rsnetsvr.dll
034E0000[00016000]
[ M] 161. c:\program files\rising\rav\bawhite.dll
03710000[0002B000]
[ M] 162. c:\program files\rising\rav\rsstore.dll
03610000[00043000]
[ M] 163. c:\program files\rising\rav\scanner.dll
036C0000[0001B000]
[ M] 164. c:\program files\rising\rav\scanadd.dll
045A0000[0001C000]
[ M] 165. c:\program files\rising\rav\ncomm2.dll
045D0000[00028000]
[ M] 166. c:\program files\rising\rav\rstask.dll
04610000[00018000]
[ M] 167. c:\program files\rising\rav\rsstub.dll
04BA0000[0001A000]
[ M] 168. c:\program files\rising\rav\scansrv.dll
04C10000[0002B000]
[ M] 169. c:\program files\rising\rav\scanpe.dll
06160000[00029000]
[ M] 170. c:\program files\rising\rav\pearc.dll
06550000[0001B000]
[ M] 171. c:\program files\rising\rav\ur000.dat
06580000[00035000]
[ M] 172. c:\program files\rising\rav\urutils.dll
065F0000[00032000]
[ M] 173. c:\program files\rising\rav\ffr.dll
06E70000[00022000]
[ M] 174. c:\program files\rising\rav\nvfile.dll
13AB0000[00045000]
[ M] 175. c:\program files\rising\rav\scanexec.dll
07710000[002DD000]
[ M] 176. c:\program files\rising\rav\unexe.dll
07A00000[000E2000]
[ M] 177. c:\program files\rising\rav\scanex.dll
07F40000[00011000]
[ M] 178. c:\program files\rising\rav\scantj.dll
0AB10000[00085000]
[ M] 179. c:\program files\rising\rav\methodex.dll
0DDD0000[000B9000]
[ M] 180. c:\program files\rising\rav\revm.dll
0B2E0000[0003F000]
[ M] 181. c:\program files\rising\rav\heurex.dll
0B330000[00022000]
[ M] 182. c:\program files\rising\rav\pecompd.dll
00E30000[00011000]
[ M] 183. c:\program files\rising\rav\ur001.dat
00E90000[00023000]
[ M] 184. c:\program files\rising\rav\scansct.dll
+ 00000490(1168) RavMonD.exe
00400000[0002F000]
[AM] 5. c:\program files\rising\rfw\ravmond.exe