【回复“我无邪”的帖子】
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 23:10:18, on 2006-10-10
Platform: Microsoft Windows XP Professional (Build 2600)
MSIE: Internet Explorer v6.00 SP1; (6.00.2600.0000 (xpclient.010817-1148))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
[rfwsrv.exe]
CommandLine = "C:\Program Files\Rising\Rfw\rfwsrv.exe"
[Explorer.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[RfwMain.exe]
CommandLine = -StartUp
[MDM.EXE]
CommandLine = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
[WebThunder.exe]
CommandLine = "D:\Program Files\Thunder Network\WebThunder\WebThunder.exe"
[ctfmon.exe]
CommandLine = "C:\WINDOWS\System32\ctfmon.exe"
[SRSB.EXE]
CommandLine = "E:\Program Files\Super Rabbit\MagicSet\SRSB.EXE" /Load
[DesktopSprite.exe]
CommandLine = "D:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe"
[nvsvc32.exe]
CommandLine = C:\WINDOWS\System32\nvsvc32.exe
[ULCDRSvr.exe]
CommandLine = "C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
[wdfmgr.exe]
CommandLine = C:\WINDOWS\System32\wdfmgr.exe
[QQ.exe]
CommandLine = "d:\Program Files\Tencent\QQ\QQ.exe"
[TIMPlatform.exe]
CommandLine = "d:\Program Files\Tencent\QQ\TIMPlatform.exe" -Embedding
[Maxthon.exe]
CommandLine = "C:\Program Files\Maxthon\Maxthon.exe"
[QQGame.exe]
CommandLine = "D:\Program Files\tencent\QQGame\QQGame.exe" /START QQUIN:20008977 PWDHASH:8nNDqJCJ6ZOxn61SWVKBDg==
[QQ.exe]
CommandLine = "D:\Program Files\tencent\QQ\QQ.exe"
[QQPet.exe]
CommandLine = "D:\Program Files\tencent\QQ\qqpet\qqpet.exe" 514401010600041200BDA8B9B2BD8C9F8C80B2899AA58C8389818804000000E6060400040F00A0B5A4AFA09182919DAF9487A5999E04000000619F8004061100BEABBAB1BE8F9C8F83B19D9A9CA0878D850C0000005255495D495D16097FBB563D061000BFAABBB0BF8E9D8E82B09C9B9DA48A9640000000FC8AF98C8C8FFA8C8A878E8C8B8AFC8E8A8E8EFC8C878C8686FAFC8A88F988FA8F8EF9F9FEFB8A8989898CFEFDFD8BFD8AFD868A8AF9F9FD8B878DFDFBFA8F8F040100AE04000000B5B62B45021400BBAEBFB4BB8A998A86B488BB99849392BF929B8E0100000000
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
O2 - BHO: QQBrowserHelper
Object Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit Start Button] E:\Program Files\Super Rabbit\MagicSet\SRSB.EXE /Load
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [PCSuiteTrayApplication] ; D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [WebThunder] d:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - d:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - d:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\tencent\QQ\SendMMS.htm
O9 - Extra Button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra Button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra Button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra Button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra Button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)