瑞星卡卡电脑诊断日志 v1.30 (2007-7-17 17:7:19) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
KAVSvc
[AM] 1. c:\kav5\kavsvc.exe
kingsoft Antivirus
KAVSvc
.text,.rdata,.data,.rsrc,
NVSvc
[AM] 2. c:\windows\system32\nvsvc32.exe
NVIDIA Corporation
NVIDIA Driver Helper Service, Version 66.93
.text,.rdata,.data,.rsrc,
UMWdf
[AM] 3. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
KWatch2
[A ] 4. c:\windows\system32\drivers\kwatch2.sys
Kingsoft Antivirus
KWatch2
.text,.data,INIT,.rsrc,.reloc,
mdmxsdk
[A ] 5. c:\windows\system32\drivers\mdmxsdk.sys
Conexant
Diagnostic Interface DRIVER
.text,.rdata,.data,INIT,.rsrc,.reloc,
RsAntiSpyware
[A ] 6. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Secdrv
[A ] 7. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
VIAudio
[A ] 8. c:\windows\system32\drivers\viaudios.sys
VIA Technologies, Inc.
Vinyl AC'97 Codec Combo WDM Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{A9BE2902-C447-420A-BB7F-A5DE921E6138}
[A ] 9. c:\kav5\kaieplus.dll
KAIEPlus Module
.text,.rdata,.data,.rsrc,.reloc,
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[A ] 10. c:\program files\flashget\fgiebar.dll
Amaze Soft
FlashGet IE Bar
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{A5366673-E8CA-11D3-9CD9-0090271D075B}
[A ] 11. c:\program files\flashget\jccatch.dll
Amaze Soft
jccatch Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 12. c:\program files\flashget\flashget.exe
Amaze Soft
FlashGet
.text,.rdata,.data,.rsrc,
Exec
[A ] 13. c:\kav5\kavie.htm
Exec
[A ] 14. c:\program files\messenger\msmsgs.exe
Microsoft Corporation
Windows Messenger
.text,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 15. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
NvCpl DesktopContext Class
[A ] 16. c:\windows\system32\nvcpl.dll
NVIDIA Corporation
NVIDIA Display Properties Extension
.text,.rdata,.data,.rsrc,.reloc,
Play on my TV helper
[A ] 16. c:\windows\system32\nvcpl.dll
NVIDIA Corporation
NVIDIA Display Properties Extension
.text,.rdata,.data,.rsrc,.reloc,
Desktop Explorer
[A ] 17. c:\windows\system32\nvshell.dll
NVIDIA Corporation
NVIDIA Desktop Explorer, Version 66.93
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
Desktop Explorer Menu
[A ] 17. c:\windows\system32\nvshell.dll
NVIDIA Corporation
NVIDIA Desktop Explorer, Version 66.93
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
nView Desktop Context Menu
[A ] 17. c:\windows\system32\nvshell.dll
NVIDIA Corporation
NVIDIA Desktop Explorer, Version 66.93
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
WinRAR shell extension
[AM] 18. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
Shell Extensions for RealOne Player
[A ] 19. c:\program files\real\realplayer\rpshell.dll
RealNetworks, Inc.
RealPlayer Shell Extensions
.text,.rdata,.data,.rsrc,.reloc,
Portable Media Devices
[A ] 20. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Portable Media Devices Menu
[A ] 20. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
金山毒霸 V OEM版
[AM] 21. c:\kav5\kavext.dll
Kingsoft Corp.
金山毒霸右键菜单支持程序
DiDUBA,TiDUBA,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 22. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
nwiz
[A ] 23. c:\windows\system32\nwiz.exe
NVIDIA Corporation
NVIDIA nView Wizard, Version 66.93
.text,.rdata,.data,.rsrc,
RemoteControl
[AM] 24. c:\program files\cyberlink\powerdvd\pdvdserv.exe
Cyberlink Corp.
PowerDVD RC Service
.text,.rdata,.data,.rsrc,
TkBellExe
[AM] 25. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
KAVRun
[A ] 26. c:\kav5\kavrun.exe
kingsoft
KAVRun
.text,.rdata,.data,.rsrc,
runeip
[A ] 27. c:\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
+ 其他自启动项目
+ C:\Documents and Settings\able\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 28. d:\tencent\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,