========Content========
请查看C:\WINNT\system32\是否同时存在svchost.exe和Svchost.exe,存在就中止掉后者,并删掉
修复
c:\winnt\system32\wbem\winlogon.exe我在C:\WINNT\system32\目录下只找到一个svchost.exe
但是在进程里有五个svchost.exe
我用process explorer发现有一个svchost.exe有问题,但是结束不了它
进程 PID CPU 描述 公司名
System Idle Process 0 100
中断 N/A 硬件中断
DPCs N/A 缓冲处理呼叫
System 8
smss.exe 148 Windows NT Session Manager Microsoft Corporation
csrss.exe 172
winlogon.exe 168 Windows NT Logon Application Microsoft Corporation
services.exe 220 Services and Controller app Microsoft Corporation
rfwsrv.exe 408 Rising Personal FireWall Service Beijing Rising Technology Co., Ltd.
RfwMain.exe 1416 Rising Personal FireWall Main Program Beijing Rising Technology Co., Ltd.
svchost.exe 420 Generic Host Process for Win32 Services Microsoft Corporation
iexplore.exe 1636
TIMPlatform.exe 1184 TIMPlatform tencent
CCenter.exe 500 CCenter Beijing Rising Technology Co., Ltd.
Ravmond.exe 516 RavMond Beijing Rising Technology Co., Ltd.
RavStub.exe 828 Rising RavStub Beijing Rising Technology Co., Ltd.
spoolsv.exe 560 Spooler SubSystem App Microsoft Corporation
zstatus.exe 1524 zstatus Zenographics
svchost.exe 596 Generic Host Process for Win32 Services Microsoft Corporation
rundll32.exe 1344 Run a DLL as an App Microsoft Corporation
ewidoctrl.exe 612 ewido control ewido networks
svchost.exe 672 Generic Host Process for Win32 Services Microsoft Corporation
RUNDLL.EXE 680 Run a DLL as an App Microsoft Corporation
svchost.exe 940 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1004 Generic Host Process for Win32 Services Microsoft Corporation
services.exe 1192 Generic Hosts for WinService Microsoft
iexplore.exe 1424 Internet Explorer Microsoft Corporation
iexplore.exe 280 Internet Explorer Microsoft Corporation
iexplore.exe 1576 Internet Explorer Microsoft Corporation
iexplore.exe 296 Internet Explorer Microsoft Corporation
iexplore.exe 1716 Internet Explorer Microsoft Corporation
iexplore.exe 1704 Internet Explorer Microsoft Corporation MSTask.exe 1024 Task Scheduler Engine Microsoft Corporation
WinMgmt.exe 1076 Windows Management Instrumentation Microsoft Corporation
svchost.exe 1088 Generic Host Process for Win32 Services Microsoft Corporation
lsass.exe 232 LSA Executable and Server DLL (Export Version) Microsoft Corporation
Explorer.EXE 1384 Windows Explorer Microsoft Corporation
RavTask.exe 1480 RavTimer Beijing Rising Technology Co., Ltd.
Ravmon.exe 1496 RavMon Beijing Rising Technology Co., Ltd.
ylive.exe 1548 YLive Yahoo! China
QQ.exe 572 QQ TENCENT
WinRAR.exe 312
wordpad.exe 1688 WordPad MFC Application Microsoft Corporation
procexp.exe 1680 Sysinternals Process Explorer Sysinternals
进程: PID:1424
类型 名称
用红色标注的肯定有问题,我发现c:\winnt\system32\wbem\services.exe很可疑
所以把它删了 还删了一些我觉得相关的注册表项 我把它删了之后好了几个小时 可是系统出了问题 看不到winnt下的东西只有用资源管理器才能看到网上邻居空白等等。而且过了一段时间又开始跳网页
那个可疑的svchost.exe 运行
C:\WINNT\System32\svchost.exe -k ReIISAdmin
它下面的几个ie连着几个网站 如 "C:\Program Files\Internet Explorer\iexplore.exe" http://cg.9e3.com/register3.html等等
正是跳出的几个网页。
现在我不知道要怎么去除它
