有哪位大虾或高手能指教一二?下面是日志:
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 12:40:10, on 2006-08-16
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP1; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "D:\Program Files\Rising\Rav\CCenter.exe"
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "D:\Program Files\Rising\Rav\Ravmond.exe"
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = "D:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[Apache.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice
[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"
[nTrayFw.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
[hpwuSchd2.exe]
CommandLine = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
[WebThunder.exe]
CommandLine = "C:\Program Files\Thunder Network\WebThunder\WebThunder.exe"
[RavTask.exe]
CommandLine = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "D:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[msmsgs.exe]
CommandLine = "C:\Program Files\Messenger\msmsgs.exe" /background
[MsnMsgr.Exe]
CommandLine = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[nSvcIp.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe"
[wcescomm.exe]
CommandLine = "C:\PROGRA~1\MICROS~3\wcescomm.exe"
[Apache.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -d "C:/Program Files/NVIDIA Corporation/NetworkAccessManager/Apache Group/Apache2" -D SSL
[hpqtra08.exe]
CommandLine = "C:\Program Files\HP\digital imaging\bin\hpqtra08.exe"
[TabUserW.exe]
CommandLine = "C:\WINDOWS\system32\WTablet\TabUserW.exe"
[nSvcLog.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe"
[NVSVC32.EXE]
CommandLine = C:\WINDOWS\system32\nvsvc32.exe
[NkvMon.exe]
CommandLine = "C:\Program Files\Nikon\NkView6\NkvMon.exe"
[rapimgr.exe]
CommandLine = C:\PROGRA~1\MICROS~3\rapimgr.exe -Embedding
[HPZipm12.exe]
CommandLine = C:\WINDOWS\system32\HPZipm12.exe
[Tablet.exe]
CommandLine = C:\WINDOWS\system32\Tablet.exe
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[nSvcAppFlt.exe]
CommandLine = "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe"
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[VirusKiller.com]
CommandLine = "C:\Downloads\软件\VirusKiller.com"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[NOTEPAD.EXE]
CommandLine = "notepad.exe" C:\Documents and Settings\Owner\桌面\流氓软件查杀问题.txt
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.sina.com.cn/
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - (file missing)
O2 - BHO: C:\WINDOWS\system32\NBBHO.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] ; C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb13.exe
O4 - HKLM\..\Run: [HPHUPD06] ; C:\Program Files\HP\{BA2D9411-DBB4-43e4-9421-780413650A67}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon06] ; C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HPHped06] ; C:\PROGRA~1\HP\{BA2D9~1\pexpress\hphPED06.exe
O4 - HKLM\..\Run: [NvMediaCenter] ; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunOnce: [RavStub] "D:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - Startup: desktop.ini =
O4 - Startup: office文件检索.exe =
O4 - Global Startup: desktop.ini =
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {3E8B7E3C-6DD0-4580-91C5-3398C5EEAFDB} (UpFile Control) - http://vod.lz160.net/UpFile.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C8F9227-47F1-4665-8E9E-41903101756A}: NameServer = 202.98.160.68,202.96.134.133