机器关机的时候需要3分多钟
尤其到WINDOWS那还有开始程序里无缘无故多了个rsautorunsdisabled上网查有说是病毒有说是自动程序帮我看看啊 谢谢各位了 瑞星卡卡电脑诊断日志 v1.30 (2008-10-5 0:42:59) 北京瑞星信息技术有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
Apple Mobile Device
[AM] 1. c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
Bonjour Service
[A ] 2. c:\program files\bonjour\mdnsresponder.exe
iPod Service
[A ] 3. c:\program files\ipod\bin\ipodservice.exe
NBService
[A ] 4. c:\program files\nero\nero 7\nero backitup\nbservice.exe
NMIndexingService
[A ] 5. c:\program files\common files\ahead\lib\nmindexingservice.exe
NVSvc
[AM] 6. c:\windows\system32\nvsvc32.exe
ose
[A ] 7. c:\program files\common files\microsoft shared\source engine\ose.exe
RfwProxySrv
[AM] 8. c:\program files\rising\rfw\rfwproxy.exe
RfwService
[AM] 9. c:\program files\rising\rfw\rfwsrv.exe
RsCCenter
[AM] 10. c:\program files\rising\rav\ccenter.exe
RsRavMon
[AM] 11. c:\program files\rising\rav\ravmond.exe
Sysbak_hotkey_Server
[AM] 12. c:\program files\thunis\emergency center\hotkey.exe
WMPNetworkSvc
[A ] 13. c:\program files\windows media player\wmpnetwk.exe
WudfSvc
[A ] 14. c:\windows\system32\wudfsvc.dll
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
CA561
[A ] 15. c:\windows\system32\drivers\spca561.sys
GEARAspiWDM
[A ] 16. c:\windows\system32\drivers\gearaspiwdm.sys
HDAudBus
[A ] 17. c:\windows\system32\drivers\hdaudbus.sys
HookCont
[A ] 18. c:\windows\system32\drivers\hookcont.sys
HookNtos
[A ] 19. c:\windows\system32\drivers\hookntos.sys
HookReg
[A ] 20. c:\windows\system32\drivers\hookreg.sys
HookSys
[A ] 21. c:\windows\system32\drivers\hooksys.sys
HookUrl
[A ] 22. c:\program files\rising\rfw\hookurl.sys
IntcAzAudAddService
[A ] 23. c:\windows\system32\drivers\rtkhdaud.sys
k750bus
[A ] 24. c:\windows\system32\drivers\k750bus.sys
npkcrypt
[A ] 25. c:\windows\system32\npkcrypt.sys
npkycryp
[A ] 26. c:\windows\system32\npkycryp.sys
PauseDrv
[A ] 27. c:\windows\system32\drivers\pausedrv.sys
PxHelp20
[A ] 28. c:\windows\system32\drivers\pxhelp20.sys
QKeyService
[A ] 29. c:\windows\system32\keycrypt.sys
RfwBase
[A ] 30. c:\windows\system32\drivers\rfwbase.sys
RsFwDrv
[A ] 31. c:\program files\rising\rfw\rsfwdrv.sys
RsNTGDI
[A ] 32. c:\windows\system32\drivers\rsntgdi.sys
RTLE8023xp
[A ] 33. c:\windows\system32\drivers\rtenicxp.sys
SafeBoxKrnl
[A ] 34. c:\program files\360safebox\safeboxkrnl.sys
Secdrv
[A ] 35. c:\windows\system32\drivers\secdrv.sys
TesSafe
[A ] 36. c:\windows\system32\tessafe.sys
USBAAPL
[A ] 37. c:\windows\system32\drivers\usbaapl.sys
VHDISK
[A ] 38. c:\windows\system32\drivers\vhdisk.sys
VolFlter
[A ] 39. c:\windows\system32\drivers\volflter.sys
WoptiHWDetect
[A ] 40. c:\program files\wopti\woptihwdetect.sys
WudfPf
[A ] 41. c:\windows\system32\drivers\wudfpf.sys
WudfRd
[A ] 42. c:\windows\system32\drivers\wudfrd.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
Mulsys
[A ] 43. c:\windows\system32\drivers\mulsys.sys
yshield
[A ] 44. c:\windows\system32\drivers\yshield.sys
+ IE浏览器加载模块
+ HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
[AM] 45. c:\windows\system32\ieframe.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[A ] 46. c:\program files\thunder\comdlls\tdatonce_now.dll
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 47. c:\program files\thunder\comdlls\xunleibho_now.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
[AM] 48. c:\program files\360safe\safemon\safemon.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[AM] 49. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
mso-offdap11
[A ] 50. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
[A ] 51. c:\windows\system32\ieudinit.exe
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{0561EC90-CE54-4f0c-9C55-E226110A740C}
[AM] 52. c:\program files\haali\matroskasplitter\mmfinfo.dll
{7D4D6379-F301-4311-BEBA-E26EB0561882}
[AM] 53. c:\program files\common files\ahead\lib\nerodigitalext.dll
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 54. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 55. c:\windows\system32\hticons.dll
IE Search Band
[AM] 45. c:\windows\system32\ieframe.dll
IE AutoComplete
[AM] 45. c:\windows\system32\ieframe.dll
Shell DocObject Viewer
[AM] 45. c:\windows\system32\ieframe.dll
InternetShortcut
[AM] 45. c:\windows\system32\ieframe.dll
Microsoft Url History Service
[AM] 45. c:\windows\system32\ieframe.dll
History
[AM] 45. c:\windows\system32\ieframe.dll
Temporary Internet Files
[AM] 45. c:\windows\system32\ieframe.dll
Temporary Internet Files
[AM] 45. c:\windows\system32\ieframe.dll
Microsoft Url Search Hook
[AM] 45. c:\windows\system32\ieframe.dll
The Internet
[AM] 45. c:\windows\system32\ieframe.dll
Internet Name Space
[AM] 45. c:\windows\system32\ieframe.dll
NvCpl DesktopContext Class
[AM] 56. c:\windows\system32\nvcpl.dll
Play on my TV helper
[AM] 56. c:\windows\system32\nvcpl.dll
Desktop Explorer
[AM] 57. c:\windows\system32\nvshell.dll
Desktop Explorer Menu
[AM] 57. c:\windows\system32\nvshell.dll
nView Desktop Context Menu
[AM] 57. c:\windows\system32\nvshell.dll
NeroDigitalIconHandler
[AM] 53. c:\program files\common files\ahead\lib\nerodigitalext.dll
NeroDigitalPropSheetHandler
[AM] 53. c:\program files\common files\ahead\lib\nerodigitalext.dll
Web Folders
[A ] 58. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office HTML Icon Handler
[AM] 59. c:\program files\microsoft office\office11\msohev.dll
WinRAR shell extension
[AM] 60. c:\program files\winrar\rarext.dll
IE Microsoft BrowserBand
[AM] 45. c:\windows\system32\ieframe.dll
IE Fade Task
[AM] 45. c:\windows\system32\ieframe.dll
IE Menu Desk Bar
[AM] 45. c:\windows\system32\ieframe.dll
IE Navigation Bar
[AM] 45. c:\windows\system32\ieframe.dll
IE Menu Site
[AM] 45. c:\windows\system32\ieframe.dll
IE Menu Band
[AM] 45. c:\windows\system32\ieframe.dll
IE Microsoft History AutoComplete List
[AM] 45. c:\windows\system32\ieframe.dll
IE Tracking Shell Menu
[AM] 45. c:\windows\system32\ieframe.dll
IE IShellFolderBand
[AM] 45. c:\windows\system32\ieframe.dll
IE BandProxy
[AM] 45. c:\windows\system32\ieframe.dll
IE MRU AutoComplete List
[AM] 45. c:\windows\system32\ieframe.dll
IE RSS Feeder Folder
[AM] 45. c:\windows\system32\ieframe.dll
IE Microsoft Shell Folder AutoComplete List
[AM] 45. c:\windows\system32\ieframe.dll
IE Microsoft Multiple AutoComplete List Container
[AM] 45. c:\windows\system32\ieframe.dll
Microsoft Browser Architecture
[AM] 45. c:\windows\system32\ieframe.dll
IE Shell Rebar BandSite
[AM] 45. c:\windows\system32\ieframe.dll
IE Shell Band Site Menu
[AM] 45. c:\windows\system32\ieframe.dll
&Links
[AM] 45. c:\windows\system32\ieframe.dll
IE Registry Tree Options Utility
[AM] 45. c:\windows\system32\ieframe.dll
IE User Assist
[AM] 45. c:\windows\system32\ieframe.dll
IE Custom MRU AutoCompleted List
[AM] 45. c:\windows\system32\ieframe.dll
Haali Column Provider
[AM] 52. c:\program files\haali\matroskasplitter\mmfinfo.dll
RISING
[A ] 61. c:\windows\system32\ravext.dll
Portable Media Devices
[AM] 62. c:\windows\system32\audiodev.dll
Portable Devices
[AM] 63. c:\windows\system32\wpdshext.dll
Portable Devices Menu
[AM] 63. c:\windows\system32\wpdshext.dll
iTunes
[A ] 64. e:\itunes\itunesminiplayer.dll
EncryptFile
[A ] 65. c:\program files\wopti\woptiencryptmodule.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RfwMain
[AM] 66. c:\program files\rising\rfw\rfwmain.exe
RavTask
[AM] 67. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 68. c:\program files\rising\antispyware\rstray.exe
360Safebox
[A ] 69. c:\program files\360safebox\safeboxtray.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 70. c:\windows\system32\bsmain.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 71. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\open\Command
[AM] 72. c:\program files\theworld 2.0\theworld.exe
htmlfile\Print\Command
[A ] 71. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TheWorld\Command
[AM] 72. c:\program files\theworld 2.0\theworld.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 71. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\open\Command
[AM] 72. c:\program files\theworld 2.0\theworld.exe
htmlfile\Print\Command
[A ] 71. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TheWorld\Command
[AM] 72. c:\program files\theworld 2.0\theworld.exe
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 73. c:\windows\system32\kmon.dll
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 74. c:\windows\system32\mdimon.dll
+ 其他自启动项目
+ C:\WINDOWS\Tasks
AppleSoftwareUpdate.job
[A ] 75. c:\program files\apple software update\softwareupdate.exe
+ 正在运行的进程
+ 0000009c(156) RfwMain.exe
00400000[00092000]
[AM] 66. c:\program files\rising\rfw\rfwmain.exe
7C140000[00103000]
[ M] 76. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 77. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 78. c:\windows\system32\msvcp71.dll
26600000[000A8000]
[ M] 79. c:\program files\rising\rfw\rsguilib.dll
5D360000[0000A000]
[ M] 80. c:\windows\system32\mfc71chs.dll
10000000[0001F000]
[ M] 81. c:\program files\rising\rfw\proccom.dll
00B10000[00024000]
[ M] 82. c:\program files\rising\rfw\rscommx2.dll
00C50000[0000E000]
[ M] 83. c:\program files\rising\rfw\rsappmgr.dll
00C70000[00030000]
[ M] 84. c:\program files\rising\rfw\cfgdll.dll
23700000[00028000]
[ M] 85. c:\program files\rising\rfw\rscommon.dll
00EC0000[00014000]
[ M] 86. c:\program files\rising\rfw\rfwctrl.dll
23800000[00022000]
[ M] 87. c:\program files\rising\rfw\rsxml.dll
23900000[00040000]
[ M] 88. c:\program files\rising\rfw\pngdll.dll
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
013F0000[0000F000]
[ M] 91. c:\program files\rising\rfw\rfwrule.dll
02C90000[005CF000]
[ M] 92. c:\windows\system32\gamelink.dll
16080000[00025000]
[ M] 93. c:\program files\bonjour\mdnsnsp.dll
+ 000000f4(244) spoolsv.exe
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
00B00000[00008000]
[AM] 74. c:\windows\system32\mdimon.dll
00B10000[00008000]
[ M] 94. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
16080000[00025000]
[ M] 93. c:\program files\bonjour\mdnsnsp.dll
+ 0000026c(620) smss.exe
+ 00000294(660) TheWorld.exe
00400000[0029D000]
[AM] 72. c:\program files\theworld 2.0\theworld.exe
00390000[00009000]
[ M] 95. c:\windows\system32\normaliz.dll
41D50000[00045000]
[ M] 96. c:\windows\system32\iertutil.dll
60000000[00074000]
[AM] 73. c:\windows\system32\kmon.dll
10000000[0002E000]
[ M] 97. c:\program files\rising\antispyware\comx3.dll
00FB0000[00019000]
[ M] 98. c:\program files\rising\antispyware\syslay.dll
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
01090000[00029000]
[AM] 48. c:\program files\360safe\safemon\safemon.dll
01250000[0014F000]
[ M] 99. c:\windows\system32\sogoupy.ime
027E0000[0002F000]
[ M] 100. c:\program files\theworld 2.0\languages\chs.dll
422B0000[005CD000]
[AM] 45. c:\windows\system32\ieframe.dll
04280000[0000D000]
[AM] 49. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
325C0000[00012000]
[AM] 59. c:\program files\microsoft office\office11\msohev.dll
042B0000[00012000]
[ M] 101. c:\program files\thunis\emergency center\sbhotkey.dll
05D50000[005CF000]
[ M] 92. c:\windows\system32\gamelink.dll
16080000[00025000]
[ M] 93. c:\program files\bonjour\mdnsnsp.dll
06A50000[00028000]
[ M] 102. c:\program files\rising\rav\ravscrch.dll
30000000[003AF000]
[ M] 103. c:\windows\system32\macromed\flash\flash9f.ocx
72C80000[00008000]
[ M] 104. c:\windows\system32\msacm32.drv
61930000[0004A000]
[ M] 105. c:\program files\internet explorer\ieproxy.dll
+ 000002a4(676) csrss.exe
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
+ 000002bc(700) winlogon.exe
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
10000000[0014F000]
[ M] 99. c:\windows\system32\sogoupy.ime
72C80000[00008000]
[ M] 104. c:\windows\system32\msacm32.drv
+ 000002e8(744) services.exe
47260000[0000F000]
[ M] 106. c:\windows\apppatch\acadproc.dll
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
+ 000002f4(756) lsass.exe
70000000[00019000]
[ M] 89. c:\program files\rising\rfw\ijt_base.dll
75000000[0000F000]
[ M] 90. c:\program files\rising\rfw\olemon.dll
10000000[005CF000]
[ M] 92. c:\windows\system32\gamelink.dll
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) )