瑞星卡卡电脑诊断日志 v1.30 (2007-9-7 20:30:6) 北京瑞星科技股份有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
ose
[A ] 1. c:\program files\common files\microsoft shared\source engine\ose.exe
RsCCenter
[A ] 2. c:\program files\rising\rav\ccenter.exe
RsRavMon
[A ] 3. c:\program files\rising\rav\ravmond.exe
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 4. c:\windows\system32\drivers\alcxwdm.sys
BaseTDI
[A ] 5. c:\windows\system32\drivers\basetdi.sys
EagleNT
[A ] 6. c:\windows\system32\drivers\eaglent.sys
ExpScaner
[A ] 7. c:\program files\rising\rav\expscan.sys
HookCont
[A ] 8. c:\program files\rising\rav\hookcont.sys
HookReg
[A ] 9. c:\program files\rising\rav\hookreg.sys
HookSys
[A ] 10. c:\program files\rising\rav\hooksys.sys
ialm
[A ] 11. c:\windows\system32\drivers\ialmnt5.sys
kgofqgna
[A ] 12. c:\windows\system32\drivers\kgofqgna.sys
MEMSCAN
[A ] 13. c:\program files\rising\rav\memscan.sys
R0A
[A ] 14. c:\windows\system32\a 21163.sys
R2A
[A ] 15. c:\windows\system32a2.sys
RsAntiSpyware
[A ] 16. c:\windows\system32\drivers\rsboot.sys
RsNTGDI
[A ] 17. c:\windows\system32\drivers\rsntgdi.sys
RSPPSYS
[A ] 18. c:\program files\rising\rav\rsppsys.sys
Secdrv
[A ] 19. c:\windows\system32\drivers\secdrv.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
ADProt
[A ] 20. c:\windows\system32\drivers\adprot.sys
CnsMinKP
[A ] 21. c:\windows\system32\drivers\cnsminkp.sys
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
igfxcui
[A ] 22. c:\windows\system32\igfxdev.dll
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[A ] 23. c:\program files\flashget\fgiebar.dll
{3F1ABCDB-A875-46c1-8345-B72A4567E486}
[A ] 24. c:\program files\bitcomet\bitcometbar\bitcometbar0.6.dll
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 25. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
[A ] 26. c:\program files\flashget\jccatch.dll
{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
[AM] 27. c:\windows\downloaded program files\cnshook.dll
{F156768E-81EF-470C-9057-481BA8380DBA}
[A ] 28. c:\program files\flashget\getflash.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 29. d:\herosoft\hero3000\mplayer.exe
Exec
[A ] 30. c:\program files\flashget\flashget.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 31. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
[A ] 32. c:\windows\system32\ieudinit.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 33. c:\windows\system32\hticons.dll
WinRAR shell extension
[AM] 34. c:\program files\winrar\rarext.dll
PicaView
[A ] 35. c:\program files\acdsee\picaview.dll
Web Folders
[A ] 36. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office Metadata Handler
[A ] 37. c:\program files\common files\microsoft shared\office12\msoshext.dll
Microsoft Office Thumbnail Handler
[A ] 37. c:\program files\common files\microsoft shared\office12\msoshext.dll
Microsoft Office HTML Icon Handler
[A ] 38. c:\program files\microsoft office\office11\msohev.dll
RISING
[AM] 39. c:\windows\system32\ravext.dll
Shell Extensions for RealOne Player
[A ] 40. c:\program files\real\realplayer\rpshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 39. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 41. c:\windows\system32\shlhook.dll
{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
[AM] 27. c:\windows\downloaded program files\cnshook.dll
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 42. c:\windows\system32\bgswitch.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
igfxtray
[AM] 43. c:\windows\system32\igfxtray.exe
igfxhkcmd
[AM] 44. c:\windows\system32\hkcmd.exe
igfxpers
[AM] 45. c:\windows\system32\igfxpers.exe
SoundMan
[AM] 46. c:\windows\soundman.exe
RavTask
[A ] 47. c:\program files\rising\rav\ravtask.exe
SysExplr
[AM] 48. d:\herosoft\hero3000\sysexplr.exe
runeip
[AM] 49. c:\program files\rising\antispyware\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub
[AM] 50. c:\program files\rising\rav\ravstub.exe
KKDelay
[A ] 51. c:\program files\rising\antispyware\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 52. c:\windows\system32\bsmain.exe
[A ] 53. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 54. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 54. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 54. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 54. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.vbs
超级解霸3000\open\Command
[A ] 55. d:\herosoft\hero3000\sthsdvd.exe
超级解霸3000\超级解霸3000\Command
[A ] 55. d:\herosoft\hero3000\sthsdvd.exe
+ HKCR\.mp3
音频解霸3000\open\Command
[A ] 56. d:\herosoft\hero3000\mmxado.exe
音频解霸3000\豪杰音频解霸3000\Command
[A ] 56. d:\herosoft\hero3000\mmxado.exe
[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)