用卡卡助手扫描的日志如下:
Running processes:
[SMSS.EXE]
CommandLine =
[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService
[CCenter.exe]
CommandLine = C:\RISING\RAV\CCENTER.EXE
[RFWSRV.EXE]
CommandLine = c:\rising\rfw\rfwsrv.exe
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[RavMonD.exe]
CommandLine = "C:\rising\Rav\Ravmond.exe"
[RUNDLL32.EXE]
CommandLine = Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
[LEXBCES.EXE]
CommandLine = C:\WINDOWS\system32\LEXBCES.EXE
[LEXPPS.EXE]
CommandLine = LEXPPS.EXE
[SPOOLSV.EXE]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = C:\rising\Rav\RavStub.exe /RAVMOND
[RFWMAIN.EXE]
CommandLine = -StartUp
[Crypserv.exe]
CommandLine = crypserv.exe
[INETINFO.EXE]
CommandLine = C:\WINDOWS\System32\inetsrv\inetinfo.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc
[WDFMGR.EXE]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[ALG.EXE]
CommandLine = C:\WINDOWS\System32\alg.exe
[RavTask.exe]
CommandLine = "C:\RISING\RAV\RAVTASK.EXE" -SYSTEM
[YLIVE.EXE]
CommandLine = "C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe"
[RavMon.exe]
CommandLine = "C:\rising\Rav\Ravmon.exe" -SYSTEM
[CTFMON.EXE]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[VnetClient.exe]
CommandLine = "C:\Program Files\ChinaNet\VnetClient.exe"
[Thunder.exe]
CommandLine = "C:\迅雷\Thunder.exe"
[TTraveler.exe]
CommandLine = "C:\Tencent\TT\TTraveler.exe" "http://jump.qq.com/tturl_2"
[QQ.EXE]
CommandLine = "C:\Tencent\QQ\QQ.exe"
[TIMPlatform.exe]
CommandLine = C:\Tencent\QQ\TIMPlatform.exe -Embedding
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
[KillProc.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KillProc.exe"
R3 - Default URLSearchHook is missing
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: CPub
Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4666.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: (file missing)
O2 - BHO: QQBrowserHelper
Object Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Tencent\QQ\QQIEHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (file missing)
O2 - BHO: (file missing)
O2 - BHO: (file missing)
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\cnshook.dll
O2 - BHO: (file missing)
O2 - BHO: (file missing)
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [RfwMain] "C:\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKLM\..\RunOnce: [RavStub] "C:\rising\Rav\ravstub.exe" /RUNONCE
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Tencent\QQ\SendMMS.htm
O9 - Extra Button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra Button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)