Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 18:15:38, on 2006-02-23
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
WENDOWSXP
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[rfwsrv.exe]
CommandLine = "c:\program files\rising\rfw\rfwsrv.exe"
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[RFWMAIN.EXE]
CommandLine = -StartUp
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[hkcmd.exe]
CommandLine = "C:\WINDOWS\system32\hkcmd.exe"
[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"
[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[QQ.exe]
CommandLine = "D:\Program Files\QQ.exe"
[TIMPlatform.exe]
CommandLine = "D:\Program Files\TIMPlatform.exe" -Embedding
[EXCEL.EXE]
CommandLine = "C:\Program Files\Microsoft Office\Office\EXCEL.EXE" -Embedding
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KuGoo.exe]
CommandLine = "E:\Program Files\KuGoo3\KuGoo.exe"
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[KkScan.exe]
CommandLine = "D:\Program Files\KkScan.exe"
[PYINTAU.EXE]
CommandLine = PYINTAU.EXE
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: (no name) - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - (no file)
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: PPGou BHO - {00000000-0000-0000-0000-C4CA9A05F1E2} - E:\PROGRA~1\PPGou\PPGIEC~1.DLL (file missing)
O2 - BHO: - {01A7A372-71E8-4022-9D76-B66BECF71A2E} - C:\WINDOWS\system32\IEBHOGET.dll
O2 - BHO: CSaveTarget
Object - {0654EACE-5660-4ca2-B673-04B7FC9FE45A} - C:\Program Files\MiniTuoTu\MiniTuoTu.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\