求助:Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 13:25:01, on 2006-05-24
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
Running processes:
[SMSS.EXE]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[CCenter.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[rfwsrv.exe]
CommandLine = "d:\program files\rfw\rfwsrv.exe"
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[CDAC11BA.EXE]
CommandLine = C:\WINDOWS\system32\drivers\CDAC11BA.EXE
[lmgrd.exe]
CommandLine = G:\EDS\bin\lmgrd.exe
[lmgrd.exe]
CommandLine = "C:\flexlm\SolidWorks SolidNetWork License Manager\lmgrd.exe"
[lmgrd.exe]
CommandLine = "G:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe"
[iwlmd.exe]
CommandLine = iwlmd.exe -T fordeary-cctv 8.1 -1 -c "G:\EDS\Licenses\Imageware12.lic" --lmgrd_start 4473dd81 -l "+G:\EDS\Log Files\ImagewareLicenseLog.txt"
[uglmd.exe]
CommandLine = uglmd.exe -T fordeary-cctv 9.2 -1 -c "G:\Program Files\UGS\License Servers\UGNXFLEXlm\ugnx3.lic" --lmgrd_start 4473dd83 -l "G:\Program Files\UGS\License Servers\UGNXFLEXlm\ugflexlm.log"
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[wscntfy.exe]
CommandLine = C:\WINDOWS\system32\wscntfy.exe
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[RFWMAIN.EXE]
CommandLine = -StartUp
[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[Rav.exe]
CommandLine = "C:\Program Files\Rising\Rav\Rav.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[HijackThis.exe]
CommandLine = "H:\Program Files\HijackThis.exe"
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://verycd.265.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://VeryCD.265.com
R3 - URLSearchHook: CopySo拷贝搜 - {40987A5C-6AB8-4977-8BE9-A8889DE2EDCC} - C:\Program Files\Copyso\CopysoIE.dll
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - H:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: bho Class - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - H:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - H:\Program Files\CyberArticle\CAExp.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: CopySo拷贝搜 - {40987A5C-6AB8-4977-8BE9-A8889DE2EDCC} - C:\Program Files\Copyso\CopysoIE.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBCLIENT\hbast.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\microOffice\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Program Files\Adobe Reader7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download by NetAnts - H:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: Download &All by NetAnts - H:\PROGRA~1\NETANTS\NAGetAll.htm
O8 - Extra context menu item: Open PDF in Word (PDF Converter 2.0) - res://H:\Program Files\PDF2Word\IEShellExt.dll /100
O8 - Extra context menu item: 使用影音传送带下载 -
O8 - Extra context menu item: 使用影音传送带下载全部链接 -
O8 - Extra context menu item: 使用网际快车下载 - H:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - H:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 保存: 完整网页... - H:\Program Files\CyberArticle\script\Save.htm
O8 - Extra context menu item: 保存: 更多保存内容... - H:\Program Files\CyberArticle\script\SaveAuto.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\MICROO~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - h:\Program Files\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - h:\Program Files\SSREADER36\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - H:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - H:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - H:\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度--MP3搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度--图片搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度--新闻搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度--歌词搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度--网页搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度--词典搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 百度--贴吧搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O9 - Extra Button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - H:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - H:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL (file missing)
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL (file missing)
附件:
6612702006524133651.JPG