Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 08:43:16, on 2006-11-09
Platform: Microsoft Windows 2000 Professional Service Pack 4 (Build 2195)
MSIE: Internet Explorer v6.00 SP1; (6.00.2800.1106)
Running processes:
[SMSS.EXE]
CommandLine =
[CSRSS.EXE]
CommandLine = C:\WINNT\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINNT\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINNT\system32\lsass.exe
[CCenter.exe]
CommandLine = "C:\Program Files\rising\rav\CCenter.exe"
[rfwsrv.exe]
CommandLine = "e:\program files\rising\rfw\rfwsrv.exe"
[svchost.exe]
CommandLine = C:\WINNT\system32\svchost -k rpcss
[spoolsv.exe]
CommandLine = C:\WINNT\system32\spoolsv.exe
[svchost.exe]
CommandLine = C:\WINNT\System32\svchost.exe -k netsvcs
[nvsvc32.exe]
CommandLine = C:\WINNT\System32\nvsvc32.exe
[regsvc.exe]
CommandLine = C:\WINNT\system32\regsvc.exe
[mstask.exe]
CommandLine = C:\WINNT\system32\MSTask.exe
[stisvc.exe]
CommandLine = C:\WINNT\system32\stisvc.exe
[WinMgmt.exe]
CommandLine = C:\WINNT\System32\WBEM\WinMgmt.exe
[svchost.exe]
CommandLine = C:\WINNT\system32\svchost.exe -k wugroup
[explorer.exe]
CommandLine = C:\WINNT\Explorer.EXE
[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
[SOUNDMAN.EXE]
CommandLine = "C:\WINNT\SOUNDMAN.EXE"
[RavTimer.exe]
CommandLine = "C:\Program Files\rising\rav\RavTimer.exe"
[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[internat.exe]
CommandLine = "C:\WINNT\system32\internat.exe"
[HNMainUI.exe]
CommandLine = "E:\Program Files\ADSL拨号王\HNMainUI.exe"
[realplay.exe]
CommandLine = "e:\Program Files\Real\RealPlayer\RealPlay.exe" /runevent "C:\Program Files\Common Files\Real\Update_OB\rnms3270.dll" RNMsgAutoCheck
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "F:\Program Files\Rising\KakaToolBar\KkScan.exe"
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RavTimer] C:\Program Files\rising\rav\RavTimer.exe
O4 - HKLM\..\Run: [RavMon] C:\Program Files\rising\rav\RavMon.exe
O4 - HKLM\..\Run: [ccenter] C:\Program Files\rising\Rav\CCenter.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RfwMain] "e:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\System32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes -
file://C:\WINNT\Java\classes\dajava.cab
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158304381875
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://qz-photo.qq.com/qzone3/QzoneMediaTools.cab
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O20 - Winlogon Notify: wzcnotif
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe /com
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
018那个怎么也弄不掉...不知道是什么东西啊!~