瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有好像IE进程,中毒了怎么解决呢?

1   1  /  1  页   跳转

有好像IE进程,中毒了怎么解决呢?

有好像IE进程,中毒了怎么解决呢?

打开进程管理器,时不时的会多出好多IE进程,用瑞星杀了毒也没用,这是怎么回事啊?请高手指点!

附件附件:

下载次数:238
文件类型:image/pjpeg
文件大小:
上传时间:2007-1-7 15:13:30
描述:



最后编辑2007-01-07 15:23:40
分享到:
gototop
 

【回复“强化毛毛虫”的帖子】
http://www.KZTechs.com/
下载System Repair Engineer
导出全部日志
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 15:06:49, on 2007-1-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\mgabg.exe
C:\WINDOWS\system32\PDesk\PDesk.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
G:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\program files\Tencent\TT\TTraveler.exe
F:\program files\Tencent\TT\TCPlus.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.922\HijackThis.exe

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: &Download by NetAnts - D:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: Download &All by NetAnts - D:\PROGRA~1\NETANTS\NAGetAll.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\program files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网文快捕保存 - d:\Program Files\WebCatcher\script\savex.htm
O8 - Extra context menu item: 使用网文快捕保存当前网页 - d:\Program Files\WebCatcher\script\save.htm
O8 - Extra context menu item: 使用网文快捕保存选中部分 - d:\Program Files\WebCatcher\script\savesel.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\program files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\program files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\program files\Tencent\QQ\SendMMS.htm
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\PROGRA~1\NETANTS\NetAnts.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - f:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - f:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: 使用网文快捕保存当前网页 - {0246d4c7-57d6-41eb-ae55-cc9a883929da} - D:\Program Files\WebCatcher\script\save.htm (HKCU)
O9 - Extra button: 使用网文快捕保存 - {0246d4c7-57d6-41eb-ae55-cc9a883929db} - D:\Program Files\WebCatcher\script\savex.htm (HKCU)
O9 - Extra button: (no name) - {0246d4c7-57d6-41eb-ae55-cc9a883929dc} - d:\Program Files\WebCatcher\script\save.htm (HKCU)
O9 - Extra 'Tools' menuitem: 使用网文快捕保存当前网页 - {0246d4c7-57d6-41eb-ae55-cc9a883929dc} - d:\Program Files\WebCatcher\script\save.htm (HKCU)
O9 - Extra button: (no name) - {0246d4c7-57d6-41eb-ae55-cc9a883929dd} - d:\Program Files\WebCatcher\script\savex.htm (HKCU)
O9 - Extra 'Tools' menuitem: 使用网文快捕保存 - {0246d4c7-57d6-41eb-ae55-cc9a883929dd} - d:\Program Files\WebCatcher\script\savex.htm (HKCU)
O9 - Extra button: (no name) - {0246d4c7-57d6-41eb-ae55-cc9a883929de} - d:\Program Files\WebCatcher\WebCatcher.exe (HKCU)
O9 - Extra 'Tools' menuitem: 运行网文快捕 - {0246d4c7-57d6-41eb-ae55-cc9a883929de} - d:\Program Files\WebCatcher\WebCatcher.exe (HKCU)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\system32\mgabg.exe
O23 - Service: PDEngine - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

gototop
 

是正常地~
gototop
 

请高手看看吧。
gototop
 

???正常???不会吧,有时还会出来内存地址不能为READ的情况 哦55555555555555555
gototop
 

引用:
【强化毛毛虫的贴子】???正常???不会吧,有时还会出来内存地址不能为READ的情况 哦55555555555555555
………………

参考
http://forum.ikaka.com/topic.asp?board=3&artid=7350632
gototop
 

唉。反正有多个IE在,总觉得怪怪的。不过多谢楼上的GG帮忙了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT