打开IE有时会弹出http://www.11670.com/pring/website/y/60.php?a=5&b=535721&c=1240&d=1477&e=60&g=null&k=null&exs_1=&x=,http://www.1860cl.com,http://ad.31148.com这些网站,还会弹出一些窗口:豪杰网卡和MSN。
Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 14:54:43, on 2006-03-07
Platform: Microsoft Windows 2000 Professional Service Pack 4 (Build 2195)
MSIE: Internet Explorer v6.00 SP1;Q823353; (6.00.2800.1106)
Running processes:
[SMSS.EXE]
CommandLine =
[CSRSS.EXE]
CommandLine = C:\WINNT\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINNT\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINNT\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINNT\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINNT\System32\svchost.exe -k netsvcs
[rfwsrv.exe]
CommandLine = "c:\program files\rising\rfw\rfwsrv.exe"
[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[spoolsv.exe]
CommandLine = C:\WINNT\system32\spoolsv.exe
[ati2evxx.exe]
CommandLine = C:\WINNT\system32\Ati2evxx.exe
[CDAC11BA.EXE]
CommandLine = C:\WINNT\system32\drivers\CDAC11BA.EXE
[mstask.exe]
CommandLine = C:\WINNT\system32\MSTask.exe
[SMAgent.exe]
CommandLine = "C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe"
[WinMgmt.exe]
CommandLine = C:\WINNT\System32\WBEM\WinMgmt.exe
[WLTRYSVC.EXE]
CommandLine = C:\WINNT\System32\wltrysvc.exe C:\WINNT\System32\bcmwltry.exe
[svchost.exe]
CommandLine = C:\WINNT\system32\svchost.exe -k wugroup
[BCMWLTRY.EXE]
CommandLine = C:\WINNT\System32\bcmwltry.exe
[svchost.exe]
CommandLine = C:\WINNT\System32\svchost.exe -k BITSgroup
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[explorer.exe]
CommandLine = C:\WINNT\Explorer.EXE
[rfwmain.exe]
CommandLine = -StartUp
[prpcui.exe]
CommandLine = "C:\WINNT\system32\PRPCUI.exe"
[atiptaxx.exe]
CommandLine = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
[eabservr.exe]
CommandLine = "C:\Program Files\Compaq\EAB\EABSERVR.EXE" /Start
[bcmntray.EXE]
CommandLine = "C:\WINNT\system32\bcmntray.exe"
[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[daemon.exe]
CommandLine = "C:\Program Files\D-Tools\daemon.exe" -lang 1033
[acrotray.exe]
CommandLine = "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[DevDetect.exe]
CommandLine = "C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun
[CTFMON.EXE]
CommandLine = "C:\WINNT\system32\ctfmon.exe"
[ACDSee8.exe]
CommandLine = "C:\Program Files\ACD Systems\ACDSee\8.0\ACDSee8.exe" "C:\Documents and Settings\power-notbook\My Documents\我接收到的文件\PICT0684.JPG"
[msnmsgr.exe]
CommandLine = "C:\Program Files\MSN Messenger\msnmsgr.exe"
[AliTalk.exe]
CommandLine = "C:\Program Files\阿里巴巴\贸易通\AliTalk.exe"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINNT\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.google.com/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.labpower.com.cn/
O1 - Hosts: # Copyright (c) 1993-1999 Microsoft Corp.
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll (file missing)
O2 - BHO: QQBrowserHelper
Object Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\q06\QQIEHelper.dll
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: CpapView Class - {77962960-536E-47EC-9DDB-52651519705F} - C:\WINNT\system32\cacb.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\bcmntray
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = C:\WINNT\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe