瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 出现很多个SVCHOST.EXE进程,其中一个占CPU90%以上

12   2  /  2  页   跳转

出现很多个SVCHOST.EXE进程,其中一个占CPU90%以上

浏览器加载项
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <F:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[PowerList Control]
  {20C2C286-BDE8-441B-B73D-AFA22D914DA5} <C:\WINDOWS\DOWNLO~1\POWERL~1.OCX, EaseSo, Inc.>
[PowerPlr Control]
  {2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[EmoWebInstallerCtl Class]
  {7FC751A9-492D-41B1-9F8D-D2C8809D8907} <C:\WINDOWS\Downloaded Program Files\EmoWebInstaller.dll, MotinOne Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[PowerPlr Control]
  {2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <F:\PROGRA~1\KuGoo2\KUGOO3~1.OCX, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <F:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[&Google Search]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <F:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <F:\PROGRA~1\FLASHGET\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <F:\PROGRA~1\FLASHGET\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <F:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <F:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <F:\Program Files\Tencent\qq\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 556][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 612][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 636][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 692][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 848][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 912][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1020][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1080][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1120][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1356][e:\KAV2005\KWatch.EXE]  <Kingsoft Corporation><2005, 4, 24, 48>
    [e:\KAV2005\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [e:\KAV2005\KAEPlat.DLL]  <Kingsoft Corp.><2004, 11, 26, 53>
    [e:\KAV2005\KAEMem.DAT]  <Kingsoft><2004, 11, 9, 11>
[PID: 1540][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\igfxpph.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,1918>
    [f:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [e:\KAV2005\KAVEXT.DLL]  <Kingsoft Corporation><2005, 2, 21, 13>
[PID: 1536][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1804][C:\WINDOWS\system32\igfxtray.exe]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxress.dll]  <Intel Corporation><3,0,0,1918>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1824][C:\WINDOWS\system32\hkcmd.exe]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxhk.dll]  <Intel Corporation><3,0,0,1918>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,1918>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1956][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.00>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1964][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1972][C:\WINDOWS\VM_STI.EXE]  <VM.><4.2.610.4>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 1984][E:\KAV2005\KAVStart.exe]  <Kingsoft Corporation><2005, 11, 30, 188>
    [E:\KAV2005\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [E:\KAV2005\KAVPassp.dll]  <Kingsoft Corporation><2005, 11, 22, 221>
    [E:\KAV2005\PopSprt3.dll]  <Kingsoft Corporation><2005, 11, 8, 28>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 328][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 456][E:\KAV2005\KMailMon.EXE]  <Kingsoft Corporation><2005, 10, 8, 85>
    [E:\KAV2005\KAntiSpm.dll]  <N/A><1, 0, 0, 2>
    [E:\KAV2005\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [E:\KAV2005\KAECall2.DLL]  <Kingsoft Corporation><2004, 12, 28, 7>
    [E:\KAV2005\KAEPlat.DLL]  <Kingsoft Corp.><2004, 11, 26, 53>
    [E:\KAV2005\KAEMem.DAT]  <Kingsoft><2004, 11, 9, 11>
    [E:\KAV2005\KAConfig.DLL]  <Kingsoft Corporation><2005, 3, 23, 30>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1332][e:\KAV2005\KPfwSvc.EXE]  <Kingsoft Corporation><2004, 12, 19, 24>
[PID: 1296][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 124][C:\WINDOWS\system32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1888][F:\Program Files\Super Rabbit\MagicSet\srsi.exe]  <Super Rabbit Soft><4.72>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\vbalIml6.ocx]  <vbAccelerator><2.00.0001>
    [C:\WINDOWS\system32\vbalExpBar6.ocx]  <vbAccelerator><1.00.0009>
    [C:\WINDOWS\system32\SSubTmr6.dll]  <vbAccelerator><1.01.0003>
[PID: 3672][F:\Program Files\Tencent\TT\TTraveler.exe]  <腾讯公司><2, 2, 0, 224>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [F:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [F:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 2680][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2692][E:\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [E:\KAV2005\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

魔法学徒....
快来看哦...
gototop
 

魔法学徒....
帮我看下
gototop
 

打开注册表,搜索Rising Process Communication Center

删除相关键值
gototop
 

不行删除哦
显示"无法删除所以指定的值"
怎么回事哦
相关键值是DEVICEDESC
怎么办哦
而且机子时好时坏的
都不能开BT的
帮帮我哦
怎么一个暑假回来就坏了啊
gototop
 

不行删除哦
怎么办
gototop
 

麻烦了
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT