日志如下:
Logfile of Kaka v2. 0. 0. 7 Scan Module v2. 0. 0. 1
Scan saved at 06:33:18, on 2006-02-15
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[SMSS.EXE]
CommandLine =
[CSRSS.EXE]
CommandLine = F:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = F:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = F:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\system32\svchost -k DcomLaunch
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "F:\Program Files\Rising\Rav\CCenter.exe"
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\system32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\system32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "F:\Program Files\Rising\Rav\Ravmond.exe"
[EXPLORER.EXE]
CommandLine = F:\WINDOWS\Explorer.EXE
[RavStub.exe]
CommandLine = "F:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[RavMon.exe]
CommandLine = "F:\PROGRA~1\RISING\RAV\RAVMON.EXE" -SYSTEM
[RavTask.exe]
CommandLine = "F:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[VDTask.exe]
CommandLine = "F:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
[RUNDLL32.EXE]
CommandLine = "F:\WINDOWS\system32\RUNDLL32.exe" F:\WINDOWS\system32\msibm\cfsys.dll,cfs
[RUNDLL32.EXE]
CommandLine = F:\WINDOWS\SYSTEM32\RUNDLL32.EXE F:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087
[inetinfo.exe]
CommandLine = F:\WINDOWS\system32\inetsrv\inetinfo.exe
[SVCHOST.EXE]
CommandLine = F:\WINDOWS\system32\svchost.exe -k imgsvc
[Network.exe]
CommandLine = "F:\Program Files\Common Files\COMM\Network.exe"
[RUNDLL32.EXE]
CommandLine = F:\WINDOWS\system32\RunDLL32.exe "F:\WINDOWS\system32\wint\wint.dll",Run -r
[alg.exe]
CommandLine = F:\WINDOWS\System32\alg.exe
[QQ.exe]
CommandLine = "F:\Program Files\Tencent\qq\QQ.exe"
[Repair.exe]
CommandLine = "F:\Program Files\Rising\KakaToolBar\Repair.exe"
[RsAgent.exe]
CommandLine = "F:\Program Files\Rising\Rav\RsAgent.exe"
[AgentSvr.exe]
CommandLine = F:\WINDOWS\msagent\AgentSvr.exe -Embedding
[iexplore.exe]
CommandLine = "F:\Program Files\Internet Explorer\iexplore.exe" -Embedding
[CTFMON.EXE]
CommandLine = ctfmon.exe
[spoolsv.exe]
CommandLine = F:\WINDOWS\system32\spoolsv.exe
[conime.exe]
CommandLine = F:\WINDOWS\system32\conime.exe
[msmsgs.exe]
CommandLine = "F:\Program Files\Messenger\msmsgs.exe" -Embedding
[KkScan.exe]
CommandLine = "F:\Program Files\Rising\KakaToolBar\KkScan.exe"
R3 - URLSearchHook: SrchHook Class - {EED92A43-CFCE-4548-BD73-B0A405470ED5} - F:\PROGRA~1\CNNIC\Cdn\iesrch.dll
O1 - Hosts: 127.0.0.1 tol24.com
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - F:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - F:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_8191.dll
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - F:\Program Files\CoolWebsite\QuickLink.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - F:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: (file missing)
O2 - BHO: CBHelper
Object - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - F:\WINDOWS\system32\msibm\cfsbho.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL (file missing)
O2 - BHO: - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - F:\PROGRA~1\KuGoo2\KUGOO3~1.OCX
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - F:\WINDOWS\system32\microapmddt.dll
O2 - BHO: IEHlprObj Class - {C5E5DB7E-46B1-47E6-8447-2E517F269925} - F:\Program Files\Xplus\GETIE.dll (file missing)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - F:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - F:\WINDOWS\system32\KakaTool.dll
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [PHIME2002ASync] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RavTimer] F:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] F:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [RavTask] "F:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [IMSCMig] F:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [000] F:\Program Files\wordman\WordMonitor.exe
O4 - HKLM\..\Run: [VirtualDrive] "F:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [mscfs] RUNDLL32 F:\WINDOWS\system32\msibm\cfsys.dll,cfs
O4 - HKLM\..\Run: [spoolsv] F:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [pobres] F:\WINDOWS\system32\pob2res.exe
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - F:\Program Files\KuGoo2\KuGoo3DownX.htm
O8 - Extra context menu item: 使用网际快车下载 - F:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - F:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Program Files\Tianya\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Program Files\Tianya\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Program Files\Tianya\qq\SendMMS.htm
O9 - Extra Button: 实用网址导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - F:\Program Files\CoolWebsite\QuickLink.dll