瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】系统变慢,时不时弹出IE保护程序(有图)

12   2  /  2  页   跳转

【求助】系统变慢,时不时弹出IE保护程序(有图)

Process    PID    CPU    Description    Company Name    Verified Signer
System Idle Process    0    93.27           
Interrupts    n/a    0.96    Hardware Interrupts       
DPCs    n/a    0.96    Deferred Procedure Calls       
System    4               
  smss.exe    384        Windows NT Session Manager    Microsoft Corporation    (Verified) Microsoft Windows Publisher
  csrss.exe    468        Client Server Runtime Process    Microsoft Corporation    (Verified) Microsoft Windows Publisher
  winlogon.exe    504        Windows NT Logon Application    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    services.exe    548    1.92    Services and Controller app    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    764        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
      wmiprvse.exe    1460        WMI    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    828        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    CCenter.exe    872        CCenter    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
    svchost.exe    888        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    964        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    1008        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    RavMonD.exe    1036    0.96    RavMond    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
      RavStub.exe    1400        Rising RavStub    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
    svchost.exe    1052        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    rfwsrv.exe    1132        Rising Personal FireWall Service    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
      rfwmain.exe    360        Rising Personal FireWall Main Program    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
    spoolsv.exe    1716        Spooler SubSystem App    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    msdtc.exe    1744        MS DTCconsole program    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    1884        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    MDM.EXE    1920        Machine Debug Manager    Microsoft Corporation    (Verified) Microsoft Corporation
    svchost.exe    1992        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    232        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    svchost.exe    2648        Generic Host Process for Win32 Services    Microsoft Corporation    (Verified) Microsoft Windows Publisher
    lsass.exe    560        LSA Shell    Microsoft Corporation    (Verified) Microsoft Windows Publisher
explorer.exe    2028    0.96    Windows Explorer    Microsoft Corporation    (Verified) Microsoft Windows Publisher
pctspk.exe    2164        pctvoice MFC Application        (Verified) Microsoft Windows Hardware Compatibility Publisher
soundman.exe    2228        Realtek Sound Manager    Realtek Semiconductor Corp.    (Verified) Microsoft Windows Hardware Compatibility Publisher
RavTask.exe    2248        RavTimer    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
  RavMon.exe    2324        RavMon    Beijing Rising Technology Co., Ltd.    (Unable to verify) Beijing Rising Technology Co., Ltd.
ctfmon.exe    2292        CTF Loader    Microsoft Corporation    (Verified) Microsoft Windows Publisher
jiajiasr.exe    2348        加加输入法 4.01 作者:孙百川    加加工作组    (Unable to verify) 加加工作组
procexp.exe    2252    0.96    Sysinternals Process Explorer    Sysinternals    (Verified) Microsoft Corporation

Process:  Pid: 2348

Name    Description    Company Name    Version    Path    Verified Signer
advapi32.dll    Advanced Windows 32 Base API    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\advapi32.dll    (Verified) Microsoft Windows Publisher
apphelp.dll    Application Compatibility Client Library    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\apphelp.dll    (Verified) Microsoft Windows Publisher
comdlg32.dll    Common Dialogs DLL    Microsoft Corporation    6.00.3790.1830    C:\WINDOWS\system32\comdlg32.dll    (Verified) Microsoft Windows Publisher
ctype.nls                C:\WINDOWS\system32\ctype.nls   
dnsapi.dll    DNS Client API DLL    Microsoft Corporation    5.02.3790.2745    C:\WINDOWS\system32\dnsapi.dll    (Verified) Microsoft Windows Component Publisher
gdi32.dll    GDI Client DLL    Microsoft Corporation    5.02.3790.2606    C:\WINDOWS\system32\gdi32.dll    (Verified) Microsoft Windows Component Publisher
hnetcfg.dll    Home Networking Configuration Manager    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\hnetcfg.dll    (Verified) Microsoft Windows Publisher
imm32.dll    Windows IMM32 API Client DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\imm32.dll    (Verified) Microsoft Windows Publisher
kernel32.dll    Windows NT BASE API Client DLL    Microsoft Corporation    5.02.3790.2756    C:\WINDOWS\system32\kernel32.dll    (Verified) Microsoft Windows Component Publisher
locale.nls                C:\WINDOWS\system32\locale.nls   
lpk.dll    Language Pack    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\lpk.dll    (Verified) Microsoft Windows Publisher
MSCTF.dll    MSCTF Server DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\MSCTF.dll    (Verified) Microsoft Windows Publisher
MSCTFIME.IME    Microsoft Text Frame Work Service IME    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\MSCTFIME.IME    (Verified) Microsoft Windows Publisher
msvcrt.dll    Windows NT CRT DLL    Microsoft Corporation    7.00.3790.1830    C:\WINDOWS\system32\msvcrt.dll    (Verified) Microsoft Windows Publisher
mswsock.dll    Microsoft Windows Sockets 2.0 Service Provider    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\mswsock.dll    (Verified) Microsoft Windows Publisher
ntdll.dll    NT Layer DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\ntdll.dll    (Verified) Microsoft Windows Publisher
ole32.dll    Microsoft OLE for Windows    Microsoft Corporation    5.02.3790.2492    C:\WINDOWS\system32\ole32.dll    (Verified) Microsoft Windows Publisher
oleaut32.dll        Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\oleaut32.dll    (Verified) Microsoft Windows Publisher
rasadhlp.dll    Remote Access AutoDial Helper    Microsoft Corporation    5.02.3790.2745    C:\WINDOWS\system32\rasadhlp.dll    (Verified) Microsoft Windows Component Publisher
rpcrt4.dll    Remote Procedure Call Runtime    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\rpcrt4.dll    (Verified) Microsoft Windows Publisher
secur32.dll    Security Support Provider Interface    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\secur32.dll    (Verified) Microsoft Windows Publisher
sensapi.dll    SENS Connectivity API DLL    Microsoft Corporation    5.02.3790.0000    C:\WINDOWS\system32\sensapi.dll    (Verified) Microsoft Windows Publisher
shell32.dll    Windows Shell Common Dll    Microsoft Corporation    6.00.3790.2746    C:\WINDOWS\system32\shell32.dll    (Verified) Microsoft Windows Component Publisher
shlwapi.dll    Shell Light-weight Utility Library    Microsoft Corporation    6.00.3790.2795    C:\WINDOWS\system32\shlwapi.dll    (Verified) Microsoft Windows Component Publisher
sortkey.nls                C:\WINDOWS\system32\sortkey.nls   
sorttbls.nls                C:\WINDOWS\system32\sorttbls.nls   
unicode.nls                C:\WINDOWS\system32\unicode.nls   
user32.dll    Windows USER API Client DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\user32.dll    (Verified) Microsoft Windows Publisher
usp10.dll    Uniscribe Unicode script processor    Microsoft Corporation    1.422.3790.1830    C:\WINDOWS\system32\usp10.dll    (Verified) Microsoft Windows Publisher
uxtheme.dll    Microsoft UxTheme Library    Microsoft Corporation    6.00.3790.1830    C:\WINDOWS\system32\uxtheme.dll    (Unable to verify) Microsoft Corporation
winrnr.dll    LDAP RnR Provider DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\winrnr.dll    (Verified) Microsoft Windows Publisher
wldap32.dll    Win32 LDAP API DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\wldap32.dll    (Verified) Microsoft Windows Publisher
ws2_32.dll    Windows Socket 2.0 32-Bit DLL    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\ws2_32.dll    (Verified) Microsoft Windows Publisher
ws2help.dll    Windows Socket 2.0 Helper for Windows NT    Microsoft Corporation    5.02.3790.1830    C:\WINDOWS\system32\ws2help.dll    (Verified) Microsoft Windows Publisher
wshtcpip.dll    Windows Sockets Helper DLL    Microsoft Corporation    5.02.3790.0000    C:\WINDOWS\system32\wshtcpip.dll    (Verified) Microsoft Windows Publisher
comctl32.dll    Common Controls Library    Microsoft Corporation    5.82.3790.2778    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.3790.2778_x-ww_497C098C\comctl32.dll    (Verified) Microsoft Windows Component Publisher
comctl32.dll    User Experience Controls Library    Microsoft Corporation    6.00.3790.2778    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.2778_x-ww_A8F04F11\comctl32.dll    (Verified) Microsoft Windows Component Publisher
jiajiasr.exe    加加输入法 4.01 作者:孙百川    加加工作组    4.00.0001.0033    D:\Program Files\jj4\jiajiasr.exe    (Unable to verify) 加加工作组
gototop
 

【回复“轻轻地来”的帖子】
[c:\windows\system32\microservice\svchost.dll] [N/A, N/A]
[c:\windows\system32\microservice\MsoService.dll] [N/A, N/A]
发那么多东西,看到头痛
gototop
 

清理临时文件
gototop
 

【回复“轻轻地来”的帖子】
什么意思?
gototop
 

【回复“帅的被贼砍”的帖子】
已经清理过但没什么用?
gototop
 

尊敬的客户,您好!
    您的邮件已经收到,感谢您对瑞星的支持。

    我们已经详细分析过您的问题和文件,以下是您上传的文件的分析结果:
    1.文件名:MsoService.dll
    病毒名:Trojan.DL.Agent.zyb

    2.文件名:Register.exe
    不是病毒

    3.文件名:svchost.dll
    不是病毒

    4.文件名:unregist.dll
    不是病毒

    我们将在较新的18.55.22版本中处理解决,请您届时将您的瑞星软件升级到18.55.22版本并且打开监控中心全盘杀毒。如果我们在测试过程中发现问题的话,我们会推迟一到两版本后升级。

瑞星升到18.55.22无法杀死,请求帮助。


gototop
 

现在能杀了,但系统启动时报错,在日志中查到MicroMsgServices 服务因下列错误而停止:
找不到指定的模块。
怎么解决??
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT