Logfile of Kaka v2. 0. 3. 0 Scan Module v1. 0. 6. 1
Scan saved at 04:20:01, on 2007-06-01
Platform: Personal (Build 6000)
MSIE: Internet Explorer v7.00 0 (7.00.6000.16386 (vista_rtm.061101-2205))
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\Windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,default_page_url=http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 127.0.0.1 localhost
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [runeip] C:\Program Files\Rising\AntiSpyware\runiep.exe
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O11 - Options group: [INTERNATIONAL] International*
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
以上是在VISTA下面用不知道被什么关掉IE防漏墙的卡卡复制出来的机器信息,希望可以给反病毒工程师一点帮助.因为我家附近的那个比我多学了几年(也可能是十几年)计算机的找我N年麻烦的邻居黑客已经可以在我打瞌睡的时候不知不觉就对我那没做过多少防范的机器做点手脚了.
顺带一提他已经改了我的BIOS,通过控制系统和硬件的交互来控制我的机器了(我是不是换个电脑还比较快一点?就怕换了也是一个下场)
之前已经通过官方报告递交了一些异常表现和一些可疑文件了,不过感觉不用任何病毒,只通过漏洞入侵并且更改你的系统达到控制目的的家伙,周旋了五六年我已经拿他没有任何办法了.
说不定这帖子就在他眼皮底下写着
先发一下待会补