瑞星卡卡电脑诊断日志 v1.30 (2007-8-6 12:16:5) 北京瑞星科技股份有限公司
注释:[A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
RsCCenter
[A ] 1. e:\rising\rising\rav\ccenter.exe
Beijing Rising Technology Co., Ltd.
CCenter
.text,.rdata,.data,.rsrc,
RsRavMon
[A ] 2. e:\rising\rising\rav\ravmond.exe
Beijing Rising Technology Co., Ltd.
RavMond
.text,.rdata,.data,.rsrc,
VnetSecurityService
[AM] 3. c:\program files\vnetcomp\vnetsecsvc.exe
中国电信股份有限公司
vnetsecsvc 互联星空安全服务程序
.text,.rsrc,
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
6fkgdlyuj
[A ] 4. c:\windows\system32\drivers\6fkgdlyuj.sys
.text,.data,INIT,.reloc,
aeaudio
[A ] 5. c:\windows\system32\drivers\aeaudio.sys
Andrea Electronics Corporation
Andrea Audio Noise Cancellation Driver
.text,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc,
BaseTDI
[A ] 6. c:\windows\system32\drivers\basetdi.sys
Beijing Rising Technology Co., Ltd.
basetdi
.text,.rdata,.data,INIT,.rsrc,.reloc,
EagleNT
[A ] 7. c:\windows\system32\drivers\eaglent.sys
ExpScaner
[A ] 8. e:\rising\rising\rav\expscan.sys
ExpScan.sys
.text,.rdata,.data,INIT,.rsrc,.reloc,
HookCont
[A ] 9. e:\rising\rising\rav\hookcont.sys
Rising
HookCont
.text,.rdata,.data,INIT,.rsrc,.reloc,
HookReg
[A ] 10. e:\rising\rising\rav\hookreg.sys
.text,.rdata,.data,INIT,.rsrc,.reloc,
HookSys
[A ] 11. e:\rising\rising\rav\hooksys.sys
Rising
Hooksys
.text,.rdata,.data,INIT,.rsrc,.reloc,
hwinterface
[A ] 12. c:\windows\system32\drivers\hwinterface.sys
Logix4u
hwinterface.sys
.text,.rdata,INIT,.rsrc,.reloc,
kmsinput
[A ] 13. c:\windows\system32\drivers\kmsinput.sys
.text,.data,INIT,.reloc,
mchInjDrv
[A ] 14. c:\docume~1\admini~1.a45\locals~1\temp\mc25.tmp
mdmxsdk
[A ] 15. c:\windows\system32\drivers\mdmxsdk.sys
Conexant
Diagnostic Interface DRIVER
.text,.rdata,.data,INIT,.rsrc,.reloc,
MEMSCAN
[A ] 16. e:\rising\rising\rav\memscan.sys
Beijing Rising Technology Co., Ltd.
MemScan Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
npkcrypt
[A ] 17. d:\qq\npkcrypt.sys
INCA Internet Co., Ltd.
nProtect KeyCrypt Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
oreans32
[A ] 18. c:\windows\system32\drivers\oreans32.sys
RsAntiSpyware
[A ] 19. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
RsNTGDI
[A ] 20. c:\windows\system32\drivers\rsntgdi.sys
Beijing Rising Technology Co., Ltd.
RsNTGDI
.text,.rdata,INIT,.rsrc,.reloc,
RSPPSYS
[A ] 21. e:\rising\rising\rav\rsppsys.sys
Rising
RSPPSYS.SYS
.text,.rdata,.data,INIT,.rsrc,.reloc,
Secdrv
[A ] 22. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
smwdm
[A ] 23. c:\windows\system32\drivers\smwdm.sys
Analog Devices, Inc.
SoundMAX Integrated Digital Audio
.text,_LTEXT,_PTEXT,.rdata,.data,_LDATA,_PDATA,.data1,.CRT,PAGE,PAGED,INIT,.rsrc,.reloc,
wlbl#01
[A ] 24. c:\windows\system32\ttyufzplusdtwlbl.sys
y7h1bfe
[A ] 25. c:\windows\system32\drivers\y7h1bfe.sys
.text,.data,INIT,.reloc,
+ 系统登陆自运行
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 26. c:\windows\system32\年韵 2006.scr
Microsoft Corp.
Microsoft Chinese New Year Pack 2006
.text,.rdata,.data,.rsrc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{889D2FEB-5411-4565-8998-1DD2C5261283}
[A ] 27. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 28. c:\program files\thunder network\thunder\thunder.exe
Thunder Networking Technologies,LTD
.text,.rdata,.data,.rsrc,
Exec
[A ] 29. d:\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
KuGoo3
[A ] 30. f:\program files\kugoo3\inextend\kugoo3downxcontrol.ocx
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 31. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[AM] 32. e:\新建文件夹\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
RISING
[AM] 33. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 34. c:\windows\system32\bgswitch.exe
.text,.data,.rsrc,
Super Rabbit IEPro
[A ] 35. e:\兔子\magicset\magicset\sriecli.exe
Super Rabbit Soft
http://www.superrsoft.com
,,.rsrc,.data,.adata,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
runeip
[AM] 36. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
HPDJ Taskbar Utility
[A ] 37. c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe
HP
.text,.rdata,.data,.rsrc,
HP Software Update
[AM] 38. c:\program files\hewlett-packard\hp software update\hpwuschd.exe
.text,.rdata,.data,.rsrc,
DeviceDiscovery
[AM] 39. c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
Hewlett-Packard
hpotdd01
.text,.rdata,.data,.rsrc,
TkBellExe
[AM] 40. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
StormCodec_Helper
[A ] 41. e:\爆风影象\storm codec\stormset.exe
.text,.rdata,.data,.ndata,.rsrc,
RavTask
[A ] 42. e:\rising\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
VnetComp
[AM] 43. c:\program files\vnetcomp\vccli.exe
中国电信股份有限公司
vccli.exe 互联星空安全伴侣客户端
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 44. c:\program files\rising\antispyware\runonce.exe
Beijing Rising Technology Co., Ltd.
RunOnce Application
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 45. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,