瑞星卡卡电脑诊断日志 v1.20 (2007-7-10 14:8:59) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ Win32 Services
+ HKLM\System\CurrentControlSet\Services
NVSvc
[AM] 1. c:\windows\system32\nvsvc32.exe
NVIDIA Corporation
NVIDIA Driver Helper Service, Version 91.36
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 90 D5 41 00 68 A8 EF 40 00 64
ose
[A ] 2. c:\program files\common files\microsoft shared\source engine\ose.exe
Microsoft Corporation
Office Source Engine
.text,.data,.rsrc,
6A 74 68 60 2E 00 30 E8 23 04 00 00 33 DB 89 5D
WMPNetworkSvc
[A ] 3. c:\program files\windows media player\wmpnetwk.exe
Microsoft Corporation
Windows Media Player 网络共享服务
.text,.data,.rsrc,.reloc,
E8 6C FF FF FF 50 FF 15 F4 12 00 01 CC CC CC CC
WudfSvc
[A ] 4. c:\windows\system32\wudfsvc.dll
Microsoft Corporation
Windows Driver Foundation - User-mode Driver Framework Service
.text,.data,.rsrc,.reloc,
8B FF 55 8B EC 83 7D 0C 01 75 05 E8 D4 04 00 00
+ Kernel Drivers
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 5. c:\windows\system32\drivers\alcxwdm.sys
Realtek Semiconductor Corp.
Realtek AC'97 Audio Driver (WDM)
.text,CODE,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc,
A1 68 73 21 00 85 C0 B9 4E E6 40 BB 74 04 3B C1
AmdK8
[A ] 6. c:\windows\system32\drivers\amdk8.sys
Advanced Micro Devices
AMD Processor Driver
.text,.rdata,.data,PAGE,PAGELK,INIT,.rsrc,.reloc,
8B FF 55 8B EC A1 68 51 01 00 85 C0 B9 40 BB 00
npkcrypt
[A ] 7. d:\program files\qq2007\npkcrypt.sys
INCA Internet Co., Ltd.
nProtect KeyCrypt Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
51 53 56 E8 6F 2C 00 00 A3 28 46 01 00 E8 EC 2B
nvata
[A ] 8. c:\windows\system32\drivers\nvata.sys
NVIDIA Corporation
NVIDIA? nForce(TM) IDE Performance Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
8B 54 24 04 85 D2 75 0E FF 74 24 08 E8 99 0B 01
NVATABUS
[A ] 9. c:\windows\system32\drivers\nvatabus.sys
NVIDIA Corporation
NVIDIA? nForce(TM) IDE Performance Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
8B 54 24 04 85 D2 75 0E FF 74 24 08 E8 8B E7 00
RsAntiSpyware
[A ] 10. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
55 8B EC 83 EC 20 53 56 33 F6 57 89 75 F4 60 8D
RTLE8023xp
[A ] 11. c:\windows\system32\drivers\rtenicxp.sys
Realtek Semiconductor Corporation
Realtek 10/100/1000 NDIS 5.1 Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
8B FF 55 8B EC A1 00 42 02 00 85 C0 B9 40 BB 00
Secdrv
[A ] 12. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
55 8B EC 83 EC 10 53 56 57 E8 E4 A3 FF FF 89 45
WudfPf
[A ] 13. c:\windows\system32\drivers\wudfpf.sys
Microsoft Corporation
Windows Driver Foundation - User-mode Driver Framework Platform Driver
.text,.rdata,.data,PAGE,.edata,INIT,.rsrc,.reloc,
8B FF 55 8B EC A1 80 08 02 00 85 C0 B9 40 BB 00
WudfRd
[A ] 14. c:\windows\system32\drivers\wudfrd.sys
Microsoft Corporation
Windows Driver Foundation - User-mode Driver Framework Reflector
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
8B FF 55 8B EC A1 8C 11 02 00 85 C0 B9 40 BB 00
+ Internet Explorer
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 15. c:\program files\thunder\comdlls\tdatonce_now.dll
Thunder Networking Technologies,LTD
迅雷浏览器高级特性支持模块
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 56 8B 75 0C 83 FE 01 74 05 83 FE 02 75
{F08555AF-9CC3-11D2-AA8E-000000000000}
[AM] 16. c:\program files\thunder\comdlls\xunleibho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
6A 0C 68 80 0D 01 10 E8 2A F5 FF FF 33 C0 40 89
+ Explorer
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[AM] 17. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
Microsoft Corporation
Microsoft Office XML MIME Filter
.text,.data,.rsrc,.reloc,
6A 0C 68 70 22 40 00 E8 FD 01 00 00 33 C0 40 89
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
{2bf41073-b2b1-21c1-b5c1-0701f4155588}
[A ] 18. c:\program files\common files\services\svchost.exe
UPX0,UPX1,UPX2,
60 BE 00 E0 40 00 8D BE 00 30 FF FF 57 89 E5 8D
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 19. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[AM] 20. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
Shell Extensions for RealOne Player
[A ] 21. c:\program files\real\realplayer\rpshell.dll
RealNetworks, Inc.
RealPlayer Shell Extensions
.text,.rdata,.data,.rsrc,.reloc,
53 55 56 8B 74 24 14 85 F6 57 B8 01 00 00 00 75
Microsoft Office HTML Icon Handler
[AM] 22. c:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
6A 0C 68 A8 41 5C 32 E8 B5 00 00 00 33 C0 40 89
Web Folders
[A ] 23. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Corporation
Microsoft Web Folders
.text,.data,.rsrc,.reloc,
6A 0C 68 B0 AC 0A 49 E8 DA 00 00 00 33 C0 40 89
Portable Media Devices
[A ] 24. c:\windows\system32\audiodev.dll
Microsoft Corporation
Portable Media Devices Shell Extension
.text,.data,.rsrc,.reloc,
8B FF 55 8B EC 83 7D 0C 01 75 05 E8 E2 04 00 00
Portable Devices
[A ] 25. c:\windows\system32\wpdshext.dll
Microsoft Corporation
Portable Devices Shell Extension
.text,.data,.rsrc,.reloc,
8B FF 55 8B EC 83 7D 0C 01 75 05 E8 81 10 00 00