12   1  /  2  页   跳转

多了几个陌生进程?

多了几个陌生进程?

我的WIN2000操作系统这几天多出了几个陌生的进程分别为winrav.exe/winmodel.exe/dllhost.exe
,现在一用IE,没过几下内存占用率很高,有时候CPU使用也很高,不知道各位大虾知道这些是什么吗, 我该怎么做?

最后编辑2005-08-28 12:54:48
分享到:
gototop
 

查杀过病毒了吗?
gototop
 

用瑞星杀过,没病毒啊
gototop
 

你说的这个我也有
gototop
 

这几个是比较可疑.把这几个文件打包上传
gototop
 

有没有好的解决办法啊?
gototop
 

HJ扫描日志贴上来。
gototop
 

什么叫HJ扫描日志啊,我不懂啊告诉我啊大哥
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6202404
一楼
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 12:29:29, on 2005-8-28
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\Explorer.EXE
D:\WINNT\System32\winrav.exe
D:\PROGRA~1\RISING\RAV\RAVMON.EXE
D:\WINNT\System32\ctfmon.exe
E:\常用软件\155847200541134207\HijackThis.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE

R3 - URLSearchHook: 虎翼DIY吧! - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - D:\WINNT\System32\diybar2\diybar2.dll
O2 - BHO: Link Filter - {4022F902-ABC7-4C79-924F-BB26F1D355A2} - D:\WINNT\System32\diybar2\diybar2.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - D:\WINNT\Downloaded Program Files\CONFLICT.4\barhelp22.0.dll
O2 - BHO: SFP Class - {F236CC5A-F6E4-4011-9EED-C52FDF51CE3D} - D:\WINNT\system32\Sbhoplin.dll
O4 - HKLM\..\Run: [msbfsvr] D:\WINNT\System32\msbfsvr.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [msbfsvr] D:\WINNT\System32\msbfsvr.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\常用软件\腾讯QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\常用软件\腾讯QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\常用软件\腾讯QQ\SendMMS.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://202.101.62.195:1995/VTrans.cab
O16 - DPF: {09F59435-7814-48ED-A73A-96FF861A91EB} - http://download.china.alibaba.com/search/alibaba/2/bar.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://D:est.mht!http://yanliangbbs.com/Skins/Default/_notes/test.chm::/test.exe
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vod.ruyi.com/plugin/PowerPlr.ocx
O16 - DPF: {28E0FA88-ABA8-4937-A247-3031F1A11165} (Installer Class) - http://pi.51.net/download/diybar2.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://rick.viewnetcam.com/kxhcm10.ocx
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {3C38FB11-C9DF-4AF2-ACCC-9E682A1CC365} (Print Control) - http://www.zform.net/Offline/Print/ZFMPrint.CAB
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {5CD211FE-6EC8-4ED2-B116-0872A9D87BBA} (VTPlug2 Class) - http://s1.88813.com:1995/VTrans.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://202.101.62.195:1995/talk.cab
O16 - DPF: {6EC14D77-72E0-436D-8C04-3BEE5D75B2F1} (VideoOcx Control) - http://www.hualiao.net/room/roomui/videoocx.ocx
O16 - DPF: {7253A666-8D4A-11D7-A4DC-00E04C504779} (BDC Control) - http://www.liao119.com/BDC.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/normalbank/AxSafeControls.cab
O16 - DPF: {8135EF31-FE8C-4C6E-A18A-F59944C3A488} (Spocx Class) - http://ddddl.dudu.com/ddd/channel/spockx-channel.cab
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} - http://scan.kingsoft.com/scan/oscan/kavclean.cab
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} (Ppinstall Control) - http://popo.163.com/install/ppinstall.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {DDA166FA-B3EA-4A3B-8EE2-4F552CDEEE81} - http://scan.kingsoft.com/scan/KatNewVerHtml/KATScan.CAB
O16 - DPF: {FA463B6E-93D5-4E02-B7F2-E0BA98DA73FC} (SHLaunch Control) - http://61.155.9.9/SHLaunch_0935.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2715C7C7-6C8F-4E8F-A658-205824D88B85}: NameServer = 202.96.107.29,202.96.107.28
O17 - HKLM\System\CS2\Services\Tcpip\..\{2715C7C7-6C8F-4E8F-A658-205824D88B85}: NameServer = 202.96.107.29,202.96.107.28
O17 - HKLM\System\CS3\Services\Tcpip\..\{2715C7C7-6C8F-4E8F-A658-205824D88B85}: NameServer = 202.96.107.29,202.96.107.28
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - (no file)
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINNT\System32\mbprot.dll
O20 - Winlogon Notify: nwprovau - D:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: Smart Card Client (SCardClnt) - Unknown owner - D:\WINNT\System32\SCardClnt.exe (file missing)
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT