Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 13:07:52, on 2006-08-22
Platform: Microsoft Windows XP Personal Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[EvtEng.exe]
CommandLine = "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe"
[S24EvMon.exe]
CommandLine = "C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE
[rundll32.exe]
CommandLine = Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
[nvsvc32.exe]
CommandLine = C:\WINDOWS\system32\nvsvc32.exe
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[RegSrvc.exe]
CommandLine = "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[VESMgr.exe]
CommandLine = "C:\Program Files\Sony\VAIO Event Service\VESMgr.exe"
[VCSW.exe]
CommandLine = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe" -RunBySCM
[VzCdbSvc.exe]
CommandLine = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"
[VzFw.exe]
CommandLine = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe"
[VzRs.exe]
CommandLine = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe"
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[Apoint.exe]
CommandLine = "C:\Program Files\Apoint\Apoint.exe"
[SPMgr.exe]
CommandLine = "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
[ISBMgr.exe]
CommandLine = "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
[Switcher.exe]
CommandLine = "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
[VCUServe.exe]
CommandLine = "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
[ApntEx.exe]
CommandLine = "Apntex.exe"
[menusw.exe]
CommandLine = "C:\Program Files\Protector Suite QL\menusw.exe"
[conime.exe]
CommandLine = C:\WINDOWS\system32\conime.exe
[iTunesHelper.exe]
CommandLine = "D:\IPOD\iTunesHelper.exe"
[SSAAD.exe]
CommandLine = "C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe"
[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[iPodService.exe]
CommandLine = D:\IPOD\bin\iPodService.exe
[Pvv.exe]
CommandLine = "C:\Program Files\systems\pvv.exe"
[call.exe]
CommandLine = "C:\Program Files\systems\Call.exe"
[ctfmon.exe]
CommandLine = ctfmon.exe
[rundll32.exe]
CommandLine = "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\3721\helper.dll,Rundll32
[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[wuauclt.exe]
CommandLine = "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[628]SUSDS7285076a3b81804a914a18f68181a664
[yassistse.exe]
CommandLine = "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[TosBtMng.exe]
CommandLine = "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
[TosA2dp.exe]
CommandLine = "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
[wscntfy.exe]
CommandLine = C:\WINDOWS\system32\wscntfy.exe
[TosBtHid.exe]
CommandLine = "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
[TosBtHSP.exe]
CommandLine = "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
[HNMainUI.exe]
CommandLine = "C:\Program Files\HelloNet\HNMainUI.exe"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "D:\tian zhi\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\kugoo\KuGoo3DownXControl.ocx
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (file missing)
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Biomenu] "C:\Program Files\Protector Suite QL\menusw.exe"
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [iTunesHelper] D:\IPOD\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-2052] "C:\Program Files\D-Tools\daemon.exe" -lang 2052
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [3721] C:\Program Files\systems\pvv.exe
O4 - HKLM\..\Run: [baidu] C:\Program Files\systems\Call.exe
O4 - HKLM\..\Run: [Str3] hongqt
O4 - HKLM\..\Run: [LongData] 焼
O4 - HKLM\..\Run: [BinaryData] "3D梯
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [WebThunder] D:\hu\WebThunder.exe
O4 - HKLM\..\Run: [KnightIII] ?
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [Knight V] 0?
O4 - HKLM\..\Run: [KuGoo3] D:\kugoo\KuGoo.exe
O4 - HKLM\..\Run: [zt] C:\Program Files\Intel\svhost32.exe
O4 - HKLM\..\Run: [svchost] C:\DOCUME~1\sony\LOCALS~1\Temp\RarSFX1\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup