瑞星卡卡电脑诊断日志 v1.30 (2008-1-28 0:20:39) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
NVSvc
[AM] 1. c:\windows\system32\nvsvc32.exe
RsCCenter
[AM] 2. e:\program files\rising\rav\ccenter.exe
RsRavMon
[AM] 3. e:\program files\rising\rav\ravmond.exe
spupdsvc
[A ] 4. c:\windows\system32\spupdsvc.exe
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ADIHdAudAddService
[A ] 5. c:\windows\system32\drivers\adihdaud.sys
AEAudioService
[A ] 6. c:\windows\system32\drivers\aeaudio.sys
AmdK8
[A ] 7. c:\windows\system32\drivers\amdk8.sys
CnsStd
[A ] 8. c:\windows\system32\drivers\cnsstd.sys
HdAudAddService
[A ] 9. c:\windows\system32\drivers\hdaudio.sys
HDAudBus
[A ] 10. c:\windows\system32\drivers\hdaudbus.sys
HookCont
[A ] 11. c:\windows\system32\drivers\hookcont.sys
HookNtos
[A ] 12. c:\windows\system32\drivers\hookntos.sys
HookReg
[A ] 13. c:\windows\system32\drivers\hookreg.sys
HookSys
[A ] 14. c:\windows\system32\drivers\hooksys.sys
KSysCall
[A ] 15. c:\docume~1\user\locals~1\temp\ksyscall.sys
lfoakf
[A ] 16. c:\windows\system32\drivers\lfoakf.sys
MTsensor
[A ] 17. c:\windows\system32\drivers\asacpi.sys
npkcrypt
[A ] 18. c:\program files\tencent\qq\npkcrypt.sys
nvata
[A ] 19. c:\windows\system32\drivers\nvata.sys
NVENETFD
[A ] 20. c:\windows\system32\drivers\nvenetfd.sys
nvnetbus
[A ] 21. c:\windows\system32\drivers\nvnetbus.sys
RsAntiSpyware
[A ] 22. c:\windows\system32\drivers\rsboot.sys
RsNTGDI
[A ] 23. c:\windows\system32\drivers\rsntgdi.sys
Secdrv
[A ] 24. c:\windows\system32\drivers\secdrv.sys
SenFiltService
[A ] 25. c:\windows\system32\drivers\senfilt.sys
TesSafe
[A ] 26. c:\windows\system32\tessafe.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{0005A87C-D626-4B3A-84F9-1D9571695F55}
[A ] 27. c:\program files\thunder network\thunder\comdlls\xunleibho_007.dll
{0005A87D-D626-4B3A-84F9-1D9571695F55}
[A ] 28. c:\windows\system32\xunleibho_v6.dll
{54EBD53A-9BC1-480B-966A-843A333CA162}
[A ] 29. c:\program files\tencent\qq\qqiehelper.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 30. c:\program files\thunder network\thunder\thunder.exe
Exec
[A ] 31. c:\herosoft\herov8\sthsdvd.exe
Exec
[A ] 32. c:\program files\messenger\msmsgs.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 33. c:\windows\system32\hticons.dll
NvCpl DesktopContext Class
[A ] 34. c:\windows\system32\nvcpl.dll
Play on my TV helper
[A ] 34. c:\windows\system32\nvcpl.dll
Desktop Explorer
[A ] 35. c:\windows\system32\nvshell.dll
Desktop Explorer Menu
[A ] 35. c:\windows\system32\nvshell.dll
nView Desktop Context Menu
[A ] 35. c:\windows\system32\nvshell.dll
WinRAR shell extension
[A ] 36. c:\program files\winrar\rarext.dll
Shell Extensions for RealOne Player
[A ] 37. c:\program files\real\realplayer\rpshell.dll
RISING
[A ] 38. c:\windows\system32\ravext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[A ] 38. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[A ] 39. c:\windows\system32\shlhook.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RavTask
[AM] 40. e:\program files\rising\rav\ravtask.exe
Thunder
[A ] 30. c:\program files\thunder network\thunder\thunder.exe
runeip
[AM] 41. c:\program files\rising\antispyware\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 42. c:\program files\rising\antispyware\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 43. c:\windows\system32\bsmain.exe
[A ] 44. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 45. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 45. c:\program files\microsoft office\office\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 45. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 45. c:\program files\microsoft office\office\msohtmed.exe
+ HKCR\.mp3
豪杰超级解霸V8_MP3\open\Command
[A ] 31. c:\herosoft\herov8\sthsdvd.exe
豪杰超级解霸V8_MP3\豪杰超级解霸\Command
[A ] 31. c:\herosoft\herov8\sthsdvd.exe
+ 正在运行的进程
+ 000001a0(416) runiep.exe
00400000[0001F000]
[AM] 41. c:\program files\rising\antispyware\runiep.exe
7C140000[00103000]
[ M] 46. c:\program files\rising\antispyware\mfc71.dll
7C340000[00056000]
[ M] 47. c:\program files\rising\antispyware\msvcr71.dll
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
00DF0000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 00000254(596) smss.exe
+ 00000298(664) smax4pnp.exe
00400000[000E3000]
[ M] 50. c:\program files\analog devices\core\smax4pnp.exe
10000000[00057000]
[ M] 51. c:\program files\analog devices\core\smwdmif.dll
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
72C80000[00008000]
[ M] 52. c:\windows\system32\msacm32.drv
00E60000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 0000029c(668) csrss.exe
+ 000002b4(692) winlogon.exe
72C80000[00008000]
[ M] 52. c:\windows\system32\msacm32.drv
+ 000002e0(736) services.exe
+ 000002e4(740) RavTask.exe
00400000[00034000]
[AM] 40. e:\program files\rising\rav\ravtask.exe
10000000[0001F000]
[ M] 53. e:\program files\rising\rav\proccom.dll
00A20000[00024000]
[ M] 54. e:\program files\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 55. e:\program files\rising\rav\rscommon.dll
00C80000[0000E000]
[ M] 56. e:\program files\rising\rav\rsappmgr.dll
08CA0000[00030000]
[ M] 57. e:\program files\rising\rav\cfgdll.dll
08F90000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 000002ec(748) lsass.exe
+ 00000378(888) svchost.exe
+ 000003bc(956) svchost.exe
+ 000003f0(1008) YDownloader.exe
00400000[000BF000]
[ M] 58. c:\program files\3721\dlaccel\ydownloader.exe
10000000[0000C000]
[ M] 59. c:\program files\3721\dlaccel\boost_thread-vc6-mt-1_31.dll
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
01050000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 000003f8(1016) rundll32.exe
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
10000000[00021000]
[ M] 60. c:\program files\3721\autolive.dll
00B90000[00018000]
[ M] 61. c:\program files\3721\notifier.dll
00BB0000[0002D000]
[ M] 62. c:\program files\3721\alliveex.dll
00CF0000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 00000400(1024) realsched.exe
00400000[0002F000]
[ M] 63. c:\program files\common files\real\update_ob\realsched.exe
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
10000000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 00000404(1028) ctfmon.exe
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
10000000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 00000414(1044) CCenter.exe
00400000[00029000]
[AM] 2. e:\program files\rising\rav\ccenter.exe
+ 00000424(1060) svchost.exe
+ 00000450(1104) svchost.exe
+ 00000478(1144) RavMon.exe
00400000[00057000]
[ M] 64. e:\program files\rising\rav\ravmon.exe
7C140000[00103000]
[ M] 65. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 66. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 67. c:\windows\system32\msvcp71.dll
10000000[0001F000]
[ M] 53. e:\program files\rising\rav\proccom.dll
00B10000[00024000]
[ M] 54. e:\program files\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 55. e:\program files\rising\rav\rscommon.dll
00D60000[00029000]
[ M] 68. e:\program files\rising\rav\recomp.dll
00EA0000[00030000]
[ M] 69. e:\program files\rising\rav\refs.dll
00EE0000[0002C000]
[ M] 70. e:\program files\rising\rav\viruslib.dll
01020000[00027000]
[ M] 71. e:\program files\rising\rav\relibldr.dll
010A0000[0000E000]
[ M] 56. e:\program files\rising\rav\rsappmgr.dll
010C0000[00030000]
[ M] 57. e:\program files\rising\rav\cfgdll.dll
01220000[00075000]
[ M] 72. e:\program files\rising\rav\monrule.dll
23900000[00040000]
[ M] 73. e:\program files\rising\rav\pngdll.dll
26600000[000B5000]
[ M] 74. e:\program files\rising\rav\rsguilib.dll
23800000[00018000]
[ M] 75. e:\program files\rising\rav\rsxml.dll
02C70000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 00000490(1168) svchost.exe
+ 000004b0(1200) RiGaGa.exe
00400000[0012A000]
[ M] 76. f:\瑞星升级助手 v7.06_绿色版_可以免序列号及id升级瑞星杀毒产品\rigagav7\rigaga.exe
73390000[00154000]
[ M] 77. c:\windows\system32\msvbvm60.dll
58000000[0000E000]
[ M] 48. c:\program files\3721\helper.dll
10000000[0001B000]
[ M] 49. c:\program files\rising\antispyware\ieprot.dll
+ 000004b8(1208) Ravmond.exe
00400000[0006C000]
[AM] 3. e:\program files\rising\rav\ravmond.exe
10000000[00042000]
[ M] 78. e:\program files\rising\rav\bwlist.dll
7C140000[00103000]
[ M] 65. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 66. c:\windows\system32\msvcr71.dll
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)