安装过公司的诺顿客户端,里面有管理员管理模式,经卸载后,以前不能用的软件如迅雷等,现在还是不能用。简直比流氓软件还流氓。
瑞星卡卡电脑诊断日志 v1.30 (2008-9-7 20:16:25) 北京瑞星信息技术有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
NBService
[A ] 1. c:\program files\nero\nero 7\nero backitup\nbservice.exe
NVSvc
[AM] 2. c:\windows\system32\nvsvc32.exe
ose
[A ] 3. c:\program files\common files\microsoft shared\source engine\ose.exe
RsCCenter
[AM] 4. c:\program files\rising\rav\ccenter.exe
RsRavMon
[AM] 5. c:\program files\rising\rav\ravmond.exe
UMWdf
[A ] 6. c:\windows\system32\wdfmgr.exe
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
AmdK8
[A ] 7. c:\windows\system32\drivers\amdk8.sys
AmdLLD
[A ] 8. c:\windows\system32\drivers\amdlld.sys
COH_Mon
[A ] 9. c:\windows\system32\drivers\coh_mon.sys
HDAudBus
[A ] 10. c:\windows\system32\drivers\hdaudbus.sys
HookCont
[A ] 11. c:\windows\system32\drivers\hookcont.sys
HookNtos
[A ] 12. c:\windows\system32\drivers\hookntos.sys
HookReg
[A ] 13. c:\windows\system32\drivers\hookreg.sys
HookSys
[A ] 14. c:\windows\system32\drivers\hooksys.sys
hwmouser
[A ] 15. c:\windows\system32\drivers\hwpad_nt.sys
IntcAzAudAddService
[A ] 16. c:\windows\system32\drivers\rtkhdaud.sys
msiffei
[A ] 17. c:\windows\system32\drivers\msiffei.sys
PnpWmkDrv
[A ] 18. c:\windows\system32\drivers\pnpwmkdrv.sys
presafe
[A ] 19. c:\windows\system32\drivers\presafe.sys
RsNTGDI
[A ] 20. c:\windows\system32\drivers\rsntgdi.sys
RTLE8023xp
[A ] 21. c:\windows\system32\drivers\rtenicxp.sys
Secdrv
[A ] 22. c:\windows\system32\drivers\secdrv.sys
SiFilter
[A ] 23. c:\windows\system32\drivers\siwinacc.sys
SRTSPL
[A ] 24. c:\windows\system32\drivers\srtspl.sys
SRTSPX
[A ] 25. c:\windows\system32\drivers\srtspx.sys
SysPlant
[A ] 26. c:\windows\system32\drivers\sysplant.sys
Teefer2
[A ] 27. c:\windows\system32\drivers\teefer2.sys
TesSafe
[A ] 28. c:\windows\system32\tessafe.sys
WGX
[A ] 29. c:\windows\system32\drivers\wgx.sys
WPS
[A ] 30. c:\windows\system32\drivers\wpsdrvnt.sys
WpsHelper
[A ] 31. c:\windows\system32\drivers\wpshelper.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
SRTSP
[A ] 32. c:\windows\system32\drivers\srtsp.sys
+ IE浏览器加载模块
+ HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
{9F6E4456-7942-4AA7-9AD2-547C2BEA32B6}
[A ] 33. c:\windows\system32\flg32.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 34. c:\program files\thunder network\thunder\comdlls\tdatonce_now.dll
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 35. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
[A ] 36. c:\windows\system32\urlfilter.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
[AM] 37. c:\program files\360safe\safemon\safemon.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 38. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}
[AM] 39. c:\program files\common files\ahead\lib\nerodigitalext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 40. c:\windows\system32\hticons.dll
Portable Media Devices
[AM] 41. c:\windows\system32\audiodev.dll
Portable Media Devices Menu
[AM] 41. c:\windows\system32\audiodev.dll
WinRAR shell extension
[AM] 42. c:\program files\winrar\rarext.dll
Microsoft Office HTML Icon Handler
[A ] 43. c:\program files\microsoft office\office11\msohev.dll
Web Folders
[A ] 44. c:\program files\common files\microsoft shared\web folders\msonsext.dll
NvCpl DesktopContext Class
[A ] 45. c:\windows\system32\nvcpl.dll
Play on my TV helper
[A ] 45. c:\windows\system32\nvcpl.dll
NeroDigitalIconHandler
[AM] 39. c:\program files\common files\ahead\lib\nerodigitalext.dll
NeroDigitalPropSheetHandler
[AM] 39. c:\program files\common files\ahead\lib\nerodigitalext.dll
RISING
[AM] 46. c:\windows\system32\ravext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 46. c:\windows\system32\ravext.dll
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
[AM] 47. c:\program files\common files\ahead\lib\nmbgmonitor.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
amd_dc_opt
[A ] 48. c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
QuickTime Task
[A ] 49. c:\program files\quicktime\qttask.exe
Grid Service
[AM] 50. c:\program files\gridservice\peer.exe
NeroFilterCheck
[A ] 51. c:\program files\common files\ahead\lib\nerocheck.exe
RavTask
[AM] 52. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 53. c:\program files\rising\antispyware\rstray.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 54. c:\windows\system32\bsmain.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 55. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 55. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 55. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 55. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.mp3
NeroShowTime.Files7.mp3\play\Command
[A ] 56. c:\program files\nero\nero 7\nero showtime\showtime.exe
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 57. c:\windows\system32\kmon.dll
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 58. c:\windows\system32\mdimon.dll
+ 正在运行的进程
+ 000000ac(172) RavStub.exe
00400000[00021000]
[ M] 59. c:\program files\rising\rav\ravstub.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
10000000[0001F000]
[ M] 61. c:\program files\rising\rav\proccom.dll
00860000[00024000]
[ M] 62. c:\program files\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 63. c:\program files\rising\rav\rscommon.dll
+ 00000290(656) smss.exe
+ 000002bc(700) alg.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
60000000[00074000]
[AM] 57. c:\windows\system32\kmon.dll
+ 00000318(792) csrss.exe
+ 00000330(816) winlogon.exe
00B00000[0000D000]
[ M] 64. c:\windows\system32\hanwangp.ime
72C80000[00008000]
[ M] 65. c:\windows\system32\msacm32.drv
+ 00000360(864) services.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 0000036c(876) lsass.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 00000370(880) explorer.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
60000000[00074000]
[AM] 57. c:\windows\system32\kmon.dll
10000000[0002E000]
[ M] 66. c:\program files\rising\antispyware\comx3.dll
00B70000[00019000]
[ M] 67. c:\program files\rising\antispyware\syslay.dll
00D70000[00029000]
[AM] 37. c:\program files\360safe\safemon\safemon.dll
00DD0000[0000D000]
[ M] 64. c:\windows\system32\hanwangp.ime
018D0000[001B9000]
[AM] 39. c:\program files\common files\ahead\lib\nerodigitalext.dll
7C140000[00103000]
[ M] 68. c:\program files\common files\ahead\lib\mfc71.dll
7C340000[00056000]
[ M] 69. c:\program files\common files\ahead\lib\msvcr71.dll
7C3A0000[0007B000]
[ M] 70. c:\program files\common files\ahead\lib\msvcp71.dll
72C80000[00008000]
[ M] 65. c:\windows\system32\msacm32.drv
01810000[0001C000]
[AM] 46. c:\windows\system32\ravext.dll
01C90000[00014000]
[ M] 71. c:\program files\nero\nero 7\nero backitup\nbshell.dll
02190000[00102000]
[ M] 72. c:\program files\nero\nero 7\nero backitup\mfc71u.dll
020A0000[0002E000]
[AM] 42. c:\program files\winrar\rarext.dll
23700000[00028000]
[ M] 63. c:\program files\rising\rav\rscommon.dll
027A0000[0011A000]
[ M] 73. c:\program files\common files\ahead\lib\medialibrarynse.dll
096C0000[0007A000]
[AM] 41. c:\windows\system32\audiodev.dll
03860000[0002C000]
[AM] 34. c:\program files\thunder network\thunder\comdlls\tdatonce_now.dll
03890000[00031000]
[AM] 35. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll
240A0000[0000E000]
[ M] 74. c:\program files\thunder network\thunder\components\resworker\dsbho_01.dll
24050000[0001E000]
[ M] 75. c:\program files\thunder network\thunder\components\resworker\dataprocessor_01.dll
+ 000003c8(968) NMBgMonitor.exe
00400000[00022000]
[AM] 47. c:\program files\common files\ahead\lib\nmbgmonitor.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
7C3A0000[0007B000]
[ M] 70. c:\program files\common files\ahead\lib\msvcp71.dll
7C340000[00056000]
[ M] 69. c:\program files\common files\ahead\lib\msvcr71.dll
60000000[00074000]
[AM] 57. c:\windows\system32\kmon.dll
10000000[00029000]
[AM] 37. c:\program files\360safe\safemon\safemon.dll
01040000[002D5000]
[ M] 76. c:\program files\common files\ahead\lib\advrcntr2.dll
013A0000[0000D000]
[ M] 64. c:\windows\system32\hanwangp.ime
015C0000[00008000]
[ M] 77. c:\program files\common files\ahead\lib\nmindexstoresvrps.dll
015D0000[0013D000]
[ M] 78. c:\program files\common files\ahead\lib\nmdataservices.dll
+ 000003e4(996) knownsvr.exe
00400000[00072000]
[ M] 79. c:\program files\rising\antispyware\knownsvr.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
10000000[0002F000]
[ M] 80. c:\program files\rising\antispyware\ncomm.dll
60000000[00074000]
[AM] 57. c:\windows\system32\kmon.dll
00BE0000[0002E000]
[ M] 66. c:\program files\rising\antispyware\comx3.dll
00C10000[00019000]
[ M] 67. c:\program files\rising\antispyware\syslay.dll
+ 00000418(1048) svchost.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 00000458(1112) svchost.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 000004a8(1192) RavMon.exe
00400000[00067000]
[ M] 81. c:\program files\rising\rav\ravmon.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
7C140000[00106000]
[ M] 82. c:\windows\system32\mfc71.dll
7C360000[00056000]
[ M] 83. c:\windows\system32\msvcr71.dll
7C3C0000[0007C000]
[ M] 84. c:\windows\system32\msvcp71.dll
10000000[0001F000]
[ M] 61. c:\program files\rising\rav\proccom.dll
00C60000[00024000]
[ M] 62. c:\program files\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 63. c:\program files\rising\rav\rscommon.dll
00EB0000[00035000]
[ M] 85. c:\program files\rising\rav\recomp.dll
00F00000[00036000]
[ M] 86. c:\program files\rising\rav\refs.dll
01160000[0002F000]
[ M] 87. c:\program files\rising\rav\viruslib.dll
012A0000[00028000]
[ M] 88. c:\program files\rising\rav\relibldr.dll
01320000[0000E000]
[ M] 89. c:\program files\rising\rav\rsappmgr.dll
01340000[00030000]
[ M] 90. c:\program files\rising\rav\cfgdll.dll
01380000[00075000]
[ M] 91. c:\program files\rising\rav\monrule.dll
23900000[00040000]
[ M] 92. c:\program files\rising\rav\pngdll.dll
01560000[0000D000]
[ M] 64. c:\windows\system32\hanwangp.ime
26600000[000A8000]
[ M] 93. c:\program files\rising\rav\rsguilib.dll
23800000[00022000]
[ M] 94. c:\program files\rising\rav\rsxml.dll
+ 000004b4(1204) CCenter.exe
00400000[0002A000]
[AM] 4. c:\program files\rising\rav\ccenter.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 000004c4(1220) svchost.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 0000051c(1308) svchost.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
+ 00000574(1396) ravmond.exe
00400000[00069000]
[AM] 5. c:\program files\rising\rav\ravmond.exe
61740000[0006A000]
[ M] 60. c:\windows\system32\sysfer.dll
10000000[00042000]
[ M] 95. c:\program files\rising\rav\bwlist.dll
7C140000[00106000]
[ M] 82. c:\windows\system32\mfc71.dll
7C360000[00056000]
[ M] 83. c:\windows\system32\msvcr71.dll
7C3C0000[0007C000]
[ M] 84. c:\windows\system32\msvcp71.dll
00CA0000[0000E000]
[ M] 89. c:\program files\rising\rav\rsappmgr.dll
00CC0000[00030000]
[ M] 90. c:\program files\rising\rav\cfgdll.dll
00F30000[00067000]
[ M] 96. c:\program files\rising\rav\rslog.dll
00FA0000[0001F000]
[ M] 61. c:\program files\rising\rav\proccom.dll
00FC0000[00024000]
[ M] 62. c:\program files\rising\rav\rscommx2.dll
01010000[00075000]
[ M] 91. c:\program files\rising\rav\monrule.dll
010A0000[00013000]
[ M] 97. c:\program files\rising\rav\hooksys.dll
01200000[00013000]
[ M] 98. c:\program files\rising\rav\hookreg.dll
01260000[00013000]
[ M] 99. c:\program files\rising\rav\hookntos.dll
012C0000[0001D000]
[ M] 100. c:\program files\rising\rav\rswalmon.dll
02130000[00035000]
[ M] 85. c:\program files\rising\rav\recomp.dll
02170000[00036000]
[ M] 86. c:\program files\rising\rav\refs.dll
021B0000[00023000]
[ M] 101. c:\program files\rising\rav\ffr.dll
021E0000[00020000]
[ M] 102. c:\program files\rising\rav\rsstore.dll
02210000[00013000]
[ M] 103. c:\program files\rising\rav\hookcont.dll
02240000[00028000]
[ M] 104. c:\program files\rising\rav\fakescan.dll
027C0000[000DC000]
[ M] 105. c:\program files\rising\rav\extfile.dll
02290000[00022000]
[ M] 106. c:\program files\rising\rav\scanner.dll
028A0000[00027000]
[ M] 107. c:\program files\rising\rav\pearc.dll
029F0000[0002F000]
[ M] 87. c:\program files\rising\rav\viruslib.dll
02B30000[00028000]
[ M] 88. c:\program files\rising\rav\relibldr.dll
03000000[00012000]
[ M] 108. c:\program files\rising\rav\hookweb.dll
03150000[0000D000]
[ M] 64. c:\windows\system32\hanwangp.ime
040E0000[00021000]
[ M] 109. c:\program files\rising\rav\nvfile.dll
13AB0000[0004A000]
[ M] 110. c:\program files\rising\rav\scanexec.dll
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Maxthon)