85991168 - 2007-7-17 14:39:00
瑞星卡卡电脑诊断日志 v1.30 (2007-7-17 13:52:21) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
AVP
[A ] 1. d:\系统工具\卡巴斯基\avp.exe
Kaspersky Lab
Kaspersky Anti-Virus
.text,.rdata,.data,.rsrc,.reloc,
UMWdf
[A ] 2. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 3. c:\windows\system32\drivers\alcxwdm.sys
Realtek Semiconductor Corp.
Realtek AC'97 Audio Driver (WDM)
.text,CODE,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc,
DCN530
[A ] 4. c:\windows\system32\drivers\dcn530n5.sys
Digitalchina Networks Limited.
DigitalChina DCN-530TX Fast Ethernet Adapter NDIS5 Driver
.text,.rdata,.data,PAGE,INIT,.rsrc,.reloc,
kl1
[A ] 5. c:\windows\system32\drivers\kl1.sys
Kaspersky Lab
Kaspersky Unified Driver
.text,.data,INIT,.rsrc,.reloc,
klif
[A ] 6. c:\windows\system32\drivers\klif.sys
Kaspersky Lab
spuper-ptor
.text,.data,.user,INIT,.rsrc,.reloc,
RsAntiSpyware
[A ] 7. c:\windows\system32\drivers\rsboot.sys
Beijing Rising Technology Co., Ltd.
Anti-RootKit Driver
.text,.rdata,.data,INIT,.rsrc,.reloc,
Secdrv
[A ] 8. c:\windows\system32\drivers\secdrv.sys
.text,.data,INIT,.reloc,
TSP
[A ] 6. c:\windows\system32\drivers\klif.sys
Kaspersky Lab
spuper-ptor
.text,.data,.user,INIT,.rsrc,.reloc,
ZSMC303
[A ] 9. c:\windows\system32\drivers\usbvm303.sys
Vimicro Corporation
Video streaming and Capture Device Driver
.text,.data,.data1,PAGECONS,INIT,.rsrc,.reloc,
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
klogon
[AM] 10. c:\windows\system32\klogon.dll
Kaspersky Lab
Logon Visualizer
.text,.rdata,.data,.rsrc,.reloc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 11. d:\系统工具\迅雷\comdlls\tdatonce_now.dll
Thunder Networking Technologies,LTD
迅雷浏览器高级特性支持模块
.text,.rdata,.data,.rsrc,.reloc,
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 12. d:\系统工具\迅雷\comdlls\xunleibho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 14. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
Portable Media Devices
[AM] 15. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Portable Media Devices Menu
[AM] 15. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Web反病毒统计
[A ] 16. d:\系统工具\卡巴斯基\scieplugin.dll
Kaspersky Lab
Script Monitor Internet Explorer plugin
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 17. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 18. c:\windows\system32\bgswitch.exe
.text,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303
[AM] 19. c:\windows\vm303_sti.exe
Vimicro
Vimicro
.text,.rdata,.data,.rsrc,
360Safetray
[AM] 20. d:\系统工具\360safe\safemon\360tray.exe
奇虎网
360安全卫士实时保护模块
.text,.rdata,.data,.rsrc,
AVP
[A ] 1. d:\系统工具\卡巴斯基\avp.exe
Kaspersky Lab
Kaspersky Anti-Virus
.text,.rdata,.data,.rsrc,.reloc,
runeip
[AM] 21. d:\系统工具\瑞星卡卡\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
QQ游戏启动加速程序.lnk
[A ] 22. d:\qqgame\accel.exe
深圳市腾讯计算机系统有限公司
QQ游戏
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 000001e4(484) smss.exe
+ 00000224(548) csrss.exe
+ 0000023c(572) winlogon.exe
10000000[00033000]
[AM] 10. c:\windows\system32\klogon.dll
Kaspersky Lab
Logon Visualizer
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 23. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 00000268(616) services.exe
+ 00000274(628) lsass.exe
+ 000002d8(728) Ras.exe
00400000[0013F000]
[ M] 24. d:\系统工具\瑞星卡卡\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
10000000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
00E70000[000A3000]
[ M] 25. d:\系统工具\瑞星卡卡\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
01780000[00011000]
[AM] 17. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
01810000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
85991168 - 2007-7-17 14:39:00
01A40000[00025000]
[ M] 27. d:\系统工具\卡巴斯基\scrchpg.dll
Kaspersky Lab
Script Checker
.text,.rdata,.data,.rsrc,.reloc,
026D0000[0000B000]
[ M] 28. d:\系统工具\卡巴斯基\klscav.dll
Kaspersky Lab
Script Checker AV Plugin
.text,.rdata,.data,.rsrc,.reloc,
78130000[0009B000]
[ M] 29. d:\系统工具\卡巴斯基\msvcr80.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
66600000[00017000]
[ M] 30. d:\系统工具\卡巴斯基\prremote.dll
Kaspersky Lab
PR_REMOTE
.text,.rdata,.data,.rsrc,.reloc,
7C420000[00087000]
[ M] 31. d:\系统工具\卡巴斯基\msvcp80.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
02720000[00048000]
[ M] 32. d:\系统工具\卡巴斯基\prloader.dll
Kaspersky Lab
Prague Loader
.text,.rdata,.data,.rsrc,.reloc,
64A00000[00030000]
[ M] 33. d:\系统工具\卡巴斯基\prkernel.ppl
Kaspersky Lab
Prague kernel
.text,.rdata,.data,.rsrc,.reloc,
036E0000[00061000]
[ M] 34. d:\系统工具\卡巴斯基\params.ppl
Kaspersky Lab
Structure Serializer
.text,.rdata,.data,.rsrc,.reloc,
03750000[00009000]
[ M] 35. d:\系统工具\卡巴斯基\pxstub.ppl
Kaspersky Lab
Proxy Stubs
.text,.rdata,.data,.rsrc,.reloc,
67F00000[00007000]
[ M] 36. d:\系统工具\卡巴斯基\tempfile.ppl
Kaspersky Lab
Temporary IO
.text,.rdata,.data,.rsrc,.reloc,
+ 000002fc(764) runiep.exe
00400000[00012000]
[AM] 21. d:\系统工具\瑞星卡卡\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
10000000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
00C60000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000310(784) svchost.exe
+ 0000033c(828) svchost.exe
+ 00000388(904) svchost.exe
50E60000[0000C000]
[ M] 37. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
+ 000003c0(960) svchost.exe
+ 000003e4(996) svchost.exe
+ 00000488(1160) alg.exe
+ 000004e4(1252) wuauclt.exe
50E60000[0000C000]
[ M] 37. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
+ 0000051c(1308) Explorer.EXE
10000000[00025000]
[ M] 27. d:\系统工具\卡巴斯基\scrchpg.dll
Kaspersky Lab
Script Checker
.text,.rdata,.data,.rsrc,.reloc,
014D0000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
72C80000[00008000]
[ M] 23. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
01490000[00021000]
[AM] 11. d:\系统工具\迅雷\comdlls\tdatonce_now.dll
Thunder Networking Technologies,LTD
迅雷浏览器高级特性支持模块
.text,.rdata,.data,.rsrc,.reloc,
017A0000[0001A000]
[AM] 12. d:\系统工具\迅雷\comdlls\xunleibho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
22110000[00009000]
[ M] 38. d:\系统工具\迅雷\components\resworker\dsbho_00.dll
DsBho
.text,.rdata,.data,.rsrc,.reloc,
220F0000[0000C000]
[ M] 39. d:\系统工具\迅雷\components\resworker\dataprocessor_00.dll
Thunder Networking Technologies,LTD
DataProcessor
.text,.rdata,.data,.rsrc,.reloc,
096C0000[0007A000]
[AM] 15. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
023E0000[0000C000]
[ M] 40. d:\系统工具\卡巴斯基\shellex.dll
Kaspersky Lab
Windows Shell Extension
.text,.rdata,.data,.rsrc,.reloc,
78130000[0009B000]
[ M] 29. d:\系统工具\卡巴斯基\msvcr80.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C420000[00087000]
[ M] 31. d:\系统工具\卡巴斯基\msvcp80.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
02190000[00011000]
[AM] 17. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
02490000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000055c(1372) spoolsv.exe
+ 000005b8(1464) notepad.exe
10000000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
00BC0000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000618(1560) VM303_STI.EXE
00400000[0000F000]
[AM] 19. c:\windows\vm303_sti.exe
Vimicro
Vimicro
.text,.rdata,.data,.rsrc,
10000000[00042000]
[ M] 41. c:\windows\system32\vm303prp.ax
Vimicro
DirectShow Extension Page
.text,.rdata,.data,.idata,.CRT,.rsrc,.reloc,
01000000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000620(1568) 360Tray.exe
00400000[00029000]
[AM] 20. d:\系统工具\360safe\safemon\360tray.exe
奇虎网
360安全卫士实时保护模块
.text,.rdata,.data,.rsrc,
10000000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
00A10000[0000C000]
[ M] 42. d:\系统工具\360safe\safemon\safekrnl.dll
奇虎网
360安全卫士实时保护模块
.text,.rdata,.data,.rsrc,.reloc,
00B00000[00022000]
[ M] 43. d:\系统工具\360safe\antiadwa.dll
360Safe.com
360安全卫士检测模块
.text,.rdata,.data,.rsrc,.reloc,
01530000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000063c(1596) ctfmon.exe
10000000[0001B000]
[ M] 26. d:\系统工具\瑞星卡卡\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000690(1680) svchost.exe
+ 00000708(1800) svchost.exe
+ 000007a4(1956) wuauclt.exe
10000000[0001C000]
[AM] 13. d:\系统工具\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
50E60000[0000C000]
[ M] 37. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
© 2000 - 2026 Rising Corp. Ltd.