瑞星卡卡安全论坛技术交流区系统软件 【求助】希望大家都看看!有好处的!!!

1   1  /  1  页   跳转

【求助】希望大家都看看!有好处的!!!

【求助】希望大家都看看!有好处的!!!

这是我用卡卡安全助手里面的日志扫表功能扫描的!
麻烦大家给看看,正常或是不正常?谢谢!
Logfile of Kaka v1. 0. 0. 33 Scan Module v1. 0. 0. 3
Scan saved at 15:14:07, on 2005-11-25
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[rfwsrv.exe]
CommandLine = "C:\Program Files\Rising\Rfw\rfwsrv.exe"

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[nvsvc32.exe]
CommandLine = C:\WINDOWS\system32\nvsvc32.exe

[CCenter.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"

[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[Explorer.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE

[RfwMain.exe]
CommandLine =  -StartUp

[RavTimer.exe]
CommandLine = "C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE"

[ghostfiles.exe]
CommandLine = "C:\Program Files\Lowrie Associates Ltd\Ghostfiles\ghostfiles.exe"

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k HTTPFilter

[QQ.exe]
CommandLine = "E:\qq2005\QQ.exe"

[Maxthon.exe]
CommandLine = "C:\Program Files\Maxthon\Maxthon.exe"  "http://forum.ikaka.com/"

[msnmsgr.exe]
CommandLine = "C:\Program Files\MSN Messenger\msnmsgr.exe"

[RavMonD.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"

[RavStub.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RavStub.exe" /RAVMOND

[RavMon.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE"

[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://g.msn.com/0SEZHCN/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://g.msn.com/0SEZHCN/SAOS01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Startup: desktop.ini =
O4 - Startup: Ghostfiles.lnk = C:\Program Files\Lowrie Associates Ltd\Ghostfiles\ghostfiles.exe
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\qq2005\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\qq2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\qq2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\qq2005\SendMMS.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O17 - HKLM\System\CCS\Services\Tcpip\..\{679304E4-FA86-4EA7-85E1-4A532117FCE9}: NameServer = 202.102.152.3,202.102.168.68
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

附送给好心人一张桌面,不回帖的别下哦!

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-11-25 15:21:21
描述:



最后编辑2005-11-25 17:33:09
分享到:
gototop
 

没有看懂的吗?
我再自己顶顶!!
gototop
 

再顶顶!!!!!
gototop
 

这项应该修复一下.O1 - Hosts: 127.0.0.1 localhost


其他似乎没异常了。.
gototop
 

真是太谢谢你的回复了!

可是我不知道怎么样修复啊?

卡卡安全助手只能扫描,不能修复!!!
gototop
 

http://forum.ikaka.com/topic.asp?board=67&artid=5188931
楼主还在啊
点上面这个链接去下个HJ汉化版
使用前要先看明白那个帖子中的说明、注意事项等
下载后扫个LOG发到反病毒版请高手看下,安全版的访客似乎专注于研究被动防御
你的LOG中018动态链接库中现有协议怎么和我的一样多:21项
据高手说有问题,我自己查了几天,还没找到答案
gototop
 

谢谢了!!我去看看
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT