这是我的日志扫描
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 21:52:42, on 2006-08-09
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[WINLOGON.EXE]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[KWatch.EXE]
CommandLine = C:\KAV2006\KWatch.EXE
[SPOOLSV.EXE]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k AutoUpgrade
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k BITS32
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k RpcSs32
[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[Network.exe]
CommandLine = "C:\Program Files\Common Files\COMM\Network.exe"
[ALG.EXE]
CommandLine = C:\WINDOWS\System32\alg.exe
[hkcmd.exe]
CommandLine = "C:\WINDOWS\system32\hkcmd.exe"
[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"
[KAVStart.EXE]
CommandLine = "C:\KAV2006\kavstart.exe" -startup
[VM305_STI.EXE]
CommandLine = "C:\WINDOWS\VM305_STI.EXE" BigDog305
[CTFMON.EXE]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[KPFW32.EXE]
CommandLine = "C:\KAV2006\KPFW32.EXE"
[KMailMon.EXE]
CommandLine = KMailMon.EXE
[QQ.exe]
CommandLine = "D:\Program Files\qq\QQ.exe"
[TIMPlatform.exe]
CommandLine = "D:\Program Files\qq\TIMPlatform.exe" -Embedding
[wuauclt.exe]
CommandLine = "C:\WINDOWS\system32\wuauclt.exe"
[conime.exe]
CommandLine = C:\WINDOWS\system32\conime.exe
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "C:\Documents and Settings\Administrator\My Documents\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://toolsbar.kuaiso.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://toolsbar.kuaiso.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.265.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.powernum123.com
O1 - Hosts: 127.0.0.1 www.powernum123.com.cn
O1 - Hosts: 127.0.0.1 powernum123.com
O1 - Hosts: 127.0.0.1 powernum123.com.cn
O1 - Hosts: 127.0.0.1 www.chebl.com
O1 - Hosts: 127.0.0.1 www.chebl.cn
O1 - Hosts: 127.0.0.1 www.chebl.com.cn
O1 - Hosts: 127.0.0.1 chebl.com
O1 - Hosts: 127.0.0.1 chebl.com.cn
O1 - Hosts: 127.0.0.1 chebl.cn
O1 - Hosts: 127.0.0.1 www.chebuluo.com.cn
O1 - Hosts: 127.0.0.1 www.chebuluo.com
O1 - Hosts: 127.0.0.1 www.chebuluo.cn
O1 - Hosts: 127.0.0.1 chebuluo.com.cn
O1 - Hosts: 127.0.0.1 chebuluo.com
O1 - Hosts: 127.0.0.1 chebuluo.cn
O1 - Hosts: 127.0.0.1 www.17sp.com
O1 - Hosts: 127.0.0.1 www.17sp.com.cn
O1 - Hosts: 127.0.0.1 17sp.com
O1 - Hosts: 127.0.0.1 17sp.com.cn
O1 - Hosts: 127.0.0.1 www.feikong.com
O1 - Hosts: 127.0.0.1 www.feikong.com.cn
O1 - Hosts: 127.0.0.1 www.feikong.cn
O1 - Hosts: 127.0.0.1 feikong.com
O1 - Hosts: 127.0.0.1 feikong.com.cn
O1 - Hosts: 127.0.0.1 feikong.cn
O1 - Hosts: 127.0.0.1 www.hacong.com
O1 - Hosts: 127.0.0.1 hacong.com
O1 - Hosts: 127.0.0.1 www.xbxb*****com
O1 - Hosts: 127.0.0.1 www.sobt.com
O1 - Hosts: 127.0.0.1 www.sobt.com.cn
O1 - Hosts: 127.0.0.1 www.sobt.cn
O1 - Hosts: 127.0.0.1 www.sobt.net
O1 - Hosts: 127.0.0.1 sobt.com
O1 - Hosts: 127.0.0.1 sobt.com.cn
O1 - Hosts: 127.0.0.1 sobt.cn
O1 - Hosts: 127.0.0.1 sobt.net
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: Shockwave Flash
Object - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Flash 8 ocx - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\flash8.dll
O2 - BHO: shdocvwhlp Class - {BE442802-3911-46E0-B227-076B15A4EAD3} - C:\WINDOWS\system32\shdocvw2.dll
O2 - BHO: (file missing)
O3 - Toolbar: (file missing)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KavStart] "C:\KAV2006\KAVStart.exe" -startup
O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [MSService_v1.0] C:\WINDOWS\system\realsched.exe
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\RunOnce: [CnsMinEx.dll] regsvr32.exe /s
O4 - HKLM\..\RunOnce: [3721C:\PROGRA~1\3721\alrex.dll2029156] regsvr32 /s C:\PROGRA~1\3721\alrex.dll
O4 - HKLM\..\RunOnce: [CnsMinKP] rundll32.exe C:\WINDOWS\DOWNLO~1\KEEPMAIN.DLL,ReInstallKP
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\qq\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\qq\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\qq\SendMMS.htm
O9 - Extra Button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra Button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra Button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816 (file missing)
O9 - Extra Button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/?source=Cns (file missing)
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra Button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\qq\QQ.EXE
O9 - Extra Button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra Button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra Button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\msplus2.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\msplus2.dll
O11 - Options group: [!CNS] 网络实名
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O17 - HKLM\System\CCS\Services\Tcpip\..\{C81F88F7-C3FA-4EAF-9901-6164C7A08858}: NameServer = 61.134.1.4 218.30.19.40