瑞星卡卡电脑诊断日志 v1.30 (2007-8-2 14:49:25) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
ACS
[AM] 1. c:\windows\system32\acs.exe
aspnet_state
[A ] 2. c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe
Ati HotKey Poller
[AM] 3. c:\windows\system32\ati2evxx.exe
ccEvtMgr
[AM] 4. c:\program files\common files\symantec shared\ccevtmgr.exe
ccPwdSvc
[A ] 5. c:\program files\common files\symantec shared\ccpwdsvc.exe
ccSetMgr
[AM] 6. c:\program files\common files\symantec shared\ccsetmgr.exe
CeEPwrSvc
[AM] 7. c:\program files\toshiba\power management\ceepwrsvc.exe
CFSvcs
[AM] 8. c:\program files\toshiba\configfree\cfsvcs.exe
DVD-RAM_Service
[AM] 9. c:\windows\system32\dvdramsv.exe
kdtd
[AM] 10. c:\program files\fyoy\piyi.dll
navapsvc
[AM] 11. c:\program files\norton antivirus\navapsvc.exe
ose
[A ] 12. c:\program files\common files\microsoft shared\source engine\ose.exe
SAVScan
[AM] 13. c:\program files\norton antivirus\savscan.exe
SBService
[A ] 14. c:\program files\common files\symantec shared\script blocking\sbserv.exe
SNDSrvc
[A ] 15. c:\program files\common files\symantec shared\sndsrvc.exe
SymWSC
[AM] 16. c:\program files\common files\symantec shared\security center\symwsc.exe
ttvf
[AM] 17. c:\program files\ooqa\yyak.dll
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
AgereSoftModem
[A ] 18. c:\windows\system32\drivers\agrsm.sys
ALCXSENS
[A ] 19. c:\windows\system32\drivers\alcxsens.sys
ALCXWDM
[A ] 20. c:\windows\system32\drivers\alcxwdm.sys
ApfiltrService
[A ] 21. c:\windows\system32\drivers\apfiltr.sys
AR5211
[A ] 22. c:\windows\system32\drivers\ar5211.sys
atiide
[A ] 23. c:\windows\system32\drivers\atiide.sys
caboagp
[A ] 24. c:\windows\system32\drivers\atisgkaf.sys
DKbFltr
[A ] 25. c:\windows\system32\drivers\dkbfltr.sys
drvmcdb
[A ] 26. c:\windows\system32\drivers\drvmcdb.sys
EMSCR
[A ] 27. c:\windows\system32\drivers\ems7sk.sys
EPOWER
[A ] 28. c:\windows\system32\drivers\hkdrv.sys
ESDCR
[A ] 29. c:\windows\system32\drivers\esd7sk.sys
ESMCR
[A ] 30. c:\windows\system32\drivers\esm7sk.sys
InCDPass
[A ] 31. c:\windows\system32\drivers\incdpass.sys
InCDRm
[A ] 32. c:\windows\system32\drivers\incdrm.sys
MDC8021X
[A ] 33. c:\windows\system32\drivers\mdc8021x.sys
NAVENG
[A ] 34. c:\progra~1\common~1\symant~1\virusd~1\20070725.023\naveng.sys
NAVEX15
[A ] 35. c:\progra~1\common~1\symant~1\virusd~1\20070725.023\navex15.sys
Netdevio
[A ] 36. c:\windows\system32\drivers\netdevio.sys
npkcrypt
[A ] 37. d:\program files\tencent\npkcrypt.sys
ojpfjep
[A ] 38. c:\windows\system32\drivers\ojpfjep.sys
Pfc
[A ] 39. c:\windows\system32\drivers\pfc.sys
PxHelp20
[A ] 40. c:\windows\system32\drivers\pxhelp20.sys
QKeyService
[A ] 41. c:\windows\system32\keycrypt.sys
RsAntiSpyware
[A ] 42. c:\windows\system32\drivers\rsboot.sys
RTL8023
[A ] 43. c:\windows\system32\drivers\rtlnic51.sys
SAVRT
[A ] 44. c:\program files\norton antivirus\savrt.sys
SAVRTPEL
[A ] 45. c:\program files\norton antivirus\savrtpel.sys
Secdrv
[A ] 46. c:\windows\system32\drivers\secdrv.sys
SrvcEKIOMngr
[A ] 47. c:\windows\system32\drivers\ekiomngr.sys
SrvcEPECioctl
[A ] 48. c:\windows\system32\drivers\ecioctl.sys
SrvcEPIOMngr
[A ] 49. c:\windows\system32\drivers\epiomngr.sys
SrvcSSIOMngr
[A ] 50. c:\windows\system32\drivers\ssiomngr.sys
SrvcTPIOMngr
[A ] 51. c:\windows\system32\drivers\tpiomngr.sys
SymEvent
[A ] 52. c:\program files\symantec\symevent.sys
SYMREDRV
[A ] 53. c:\windows\system32\drivers\symredrv.sys
SYMTDI
[A ] 54. c:\windows\system32\drivers\symtdi.sys
TBiosDrv
[A ] 55. c:\windows\system32\drivers\tbiosdrv.sys
TesSafe
[A ] 56. c:\windows\system32\tessafe.sys
ZSMC301b
[A ] 57. c:\windows\system32\drivers\usbvm31b.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
drvnddm
[A ] 58. c:\windows\system32\drivers\drvnddm.sys
InCDFs
[A ] 59. c:\windows\system32\drivers\incdfs.sys
meiudf
[A ] 60. c:\windows\system32\drivers\meiudf.sys
sscdbhk5
[A ] 61. c:\windows\system32\drivers\sscdbhk5.sys
ssrtln
[A ] 62. c:\windows\system32\drivers\ssrtln.sys
tfsnboio
[A ] 63. c:\windows\system32\dla\tfsnboio.sys
tfsncofs
[A ] 64. c:\windows\system32\dla\tfsncofs.sys
tfsndrct
[A ] 65. c:\windows\system32\dla\tfsndrct.sys
tfsndres
[A ] 66. c:\windows\system32\dla\tfsndres.sys
tfsnifs
[A ] 67. c:\windows\system32\dla\tfsnifs.sys
tfsnopio
[A ] 68. c:\windows\system32\dla\tfsnopio.sys
tfsnpool
[A ] 69. c:\windows\system32\dla\tfsnpool.sys
tfsnudf
[A ] 70. c:\windows\system32\dla\tfsnudf.sys
tfsnudfa
[A ] 71. c:\windows\system32\dla\tfsnudfa.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
[A ] 72. c:\program files\norton antivirus\navshext.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[A ] 73. c:\program files\yahoo!\companion\installs\cpn\yt.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 74. d:\program files\thunder network\thunder\comdlls\tdatonce_now.dll
{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 75. d:\program files\thunder network\thunder\comdlls\xunleibho_now.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 76. c:\program files\adobe\acrobat 5.0\reader\activex\acroiehelper.ocx
{54EBD53A-9BC1-480B-966A-843A333CA162}
[A ] 77. d:\program files\tencent\qqiehelper.dll
{5CA3D70E-1895-11CF-8E15-001234567890}
[AM] 78. c:\windows\system32\dla\tfswshx.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[AM] 79. c:\windows\system32\mscoree.dll
application/x-complus
[AM] 79. c:\windows\system32\mscoree.dll
application/x-msdownload
[AM] 79. c:\windows\system32\mscoree.dll
text/xml
[A ] 80. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
KuGoo3
[A ] 81. c:\program files\kugoo3\inextend\kugoo3downxcontrol.ocx
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
{4b218e3e-bc98-4770-93d3-2731b9329278}
[A ] 82. c:\windows\inf\ie.inf
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}
[AM] 83. c:\program files\common files\ahead\lib\nerodigitalext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 84. c:\windows\system32\hticons.dll
CePMTab Property Sheet
[A ] 85. c:\windows\system32\cepmtab.dll
TouchPad Property Sheet
[A ] 86. c:\windows\system32\tpprop.dll
RecordNow! SendToExt
[A ] 87. c:\program files\sonic\recordnow!\shlext.dll
DriveLetterAccess
[AM] 78. c:\windows\system32\dla\tfswshx.dll
Web Folders
[A ] 88. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office HTML Icon Handler
[A ] 89. c:\program files\microsoft office\office11\msohev.dll
Fusion Cache
[AM] 79. c:\windows\system32\mscoree.dll
WinRAR shell extension
[A ] 90. c:\program files\winrar\rarext.dll
Yahoo Trojan Cleanner
[A ] 91. d:\program files\3721\ske\contmenu.dll
NeroDigitalIconHandler
[AM] 83. c:\program files\common files\ahead\lib\nerodigitalext.dll
NeroDigitalPropSheetHandler
[AM] 83. c:\program files\common files\ahead\lib\nerodigitalext.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
runeip
[AM] 92. d:\program files\rising\antispyware\runiep.exe
TkBellExe
[AM] 93. c:\program files\common files\real\update_ob\realsched.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 94. d:\program files\rising\antispyware\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 95. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 96. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\open\Command
[AM] 97. d:\program files\tencent\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 96. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 97. d:\program files\tencent\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 96. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\open\Command
[AM] 97. d:\program files\tencent\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 96. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 97. d:\program files\tencent\tt\ttraveler.exe
+ HKCR\.mp3
NeroShowTime.Files7.mp3\play\Command
[A ] 98. c:\program files\nero\nero 7\nero showtime\showtime.exe
+ 其他自启动项目
+ C:\WINDOWS\Tasks
Norton AntiVirus - Scan my computer - jaleo.job
[A ] 99. c:\program files\norton antivirus\navw32.exe
Symantec NetDetect.job
[A ] 100. c:\program files\symantec\liveupdate\ndetect.exe
+ 正在运行的进程
+ 00000108(264) spoolsv.exe
+ 00000190(400) Ras.exe
00400000[0013F000]
[ M] 101. d:\program files\rising\antispyware\ras.exe
10000000[0002F000]
[ M] 102. c:\program files\fyoy\slbl.dll
00EE0000[0003B000]
[ M] 103. c:\program files\fyoy\xqgq.dll
00F30000[000A3000]
[ M] 104. d:\program files\rising\antispyware\rasgui.dll
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler ; .NET CLR 1.1.4322)