1   1  /  1  页   跳转

求助:系统资源问题

求助:系统资源问题

干别的什么问题都没有,只要一开IE,所有的系统资源都被explorer占用了,cpu使用率从百分之几急速上升到100%。然后把这个进程关掉,桌面没了,再开启IE,系统又慢的很了。这时是被rundll32占用了所有的资源,把这个进程关掉,IE的内容马上显示出来,再开启IE窗口,rundll32又重新出现,占去所有的资源,请问各位大侠,是不是病毒的缘故?还是系统本身出了问题?多谢啦!
有时候是使用IE,系统资源直接被rundll32占用!
最后编辑2006-05-03 16:38:41
分享到:
gototop
 

你扫个日志上来吧
gototop
 

不好意思大侠,日志怎么扫啊?
gototop
 

http://forum.ikaka.com/topic.asp?board=67&artid=5188931
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 16:07:53, on 2006-5-3
Platform: Windows XP SP2 (WinNT

5.01.2600)
MSIE: Internet Explorer v6.00 SP2

(6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\PROGRAM

FILES\RISING\RAV\CCENTER.EXE
d:\program

files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
d:\program

files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32

\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Sogou

PXP\p2psvr.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program

Files\Rising\Rav\RavTask.exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet

Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program

Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program

Files\Rising\Rav\Ravmond.exe
d:\Program

Files\Rising\Rav\RAVMON.EXE
D:\Program

Files\Rising\Rav\RavStub.exe
D:\Program Files\Tencent\QQ\QQ.exe
C:\Documents and

Settings\Administrator\桌面

\248783200522382732\HijackThis.exe

R3 - URLSearchHook: MyURLSearchHook

Class - {982CB676-38F0-4D9A-BB72-

D9371ABE876E} - d:\Program

Files\P4P\ToolBar.dll
R3 - URLSearchHook: SgUrlSearHook

Class - {BAB1AC41-6FF7-4F2E-A04E-

5C592CCFEA7D} -

C:\WINDOWS\system32\socul.dll
F2 - REG:system.ini:

UserInit=userinit.exe,
O2 - BHO: SohuDAIEHelper -

{0CA51D02-7739-43EA-8D9A-

1E8AD4327B03} - d:\Program

Files\P4P\sodaie.dll
O2 - BHO: Yahoo!Photo - {33BBE430-

0E42-4f12-B075-8D21ACB10DCB} -

C:\PROGRA~1\Yahoo!\ASSIST~1

\Assist\yphtb.dll
O2 - BHO: Vision - {6671A431-5C3D-

463d-A7CF-5587F9B7E191} -

C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7

-EC78-4e8d-9841-6C02E8FA9838} -

C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: IE - {D157330A-9EF3-49F8

-9A67-4141AC41ADD4} -

C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: 超级兔子上网精灵 -

{FEDF637B-F631-4583-A210-

33CC828D42DB} - D:\PROGRA~1

\SUPERR~1\MagicSet\HAOKAN~1.DLL
O3 - Toolbar: 捜狗直通车 -

{DBBB7978-AF21-4EF4-9AD1-

B2F4BC75696C} - d:\Program

Files\P4P\ToolBar.dll
O3 - Toolbar: 超级兔子上网精灵 -

{FEDF637B-F631-4583-A210-

33CC828D42DB} - D:\PROGRA~1

\SUPERR~1\MagicSet\HAOKAN~1.DLL
O4 - HKLM\..\Run: [RavTask]

"d:\Program

Files\Rising\Rav\RavTask.exe" -

system
O4 - HKLM\..\Run: [CnsMin]

Rundll32.exe C:\WINDOWS\downlo~1

\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [IMJPMIG8.1]

"C:\WINDOWS\IME\imjp8_1

\IMJPMIG.EXE" /Spoil /RemAdvDef

/Migration32
O4 - HKLM\..\Run: [TkBellExe]

"C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\RunOnce: [RavStub]

"D:\Program

Files\Rising\Rav\ravstub.exe"

/RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: >>彩

信发送<< - res://C:\PROGRA~1

\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传

到QQ网络硬盘 - D:\Program

Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加

到QQ自定义面板 - D:\Program

Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加

到QQ表情 - D:\Program

Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ

彩信发送该图片 - D:\Program

Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Yahoo 1G电邮 -

{507F9113-CD77-4866-BA92-

0E86DA3D0B97} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=yahoomail (file

missing)
O9 - Extra button: 寻宝乐趣多 -

{59BC54A2-56B3-44a0-93E5-

432D58746E26} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=taobao (file

missing)
O9 - Extra button: 雅虎助手 -

{5D73EE86-05F1-49ed-B850-

E423120EC338} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=yassist (file

missing)
O9 - Extra button: (no name) -

{6671A433-5C3D-463d-A7CF-

5587F9B7E191} - C:\PROGRA~1

\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精

灵设置 - {6671A433-5C3D-463d-A7CF-

5587F9B7E191} - C:\PROGRA~1

\MMSASS~1\Mmsass~1.dll
O9 - Extra button: 我的订阅 -

{8755CE6E-0BF7-4441-8751-

FB728941B0B4} - d:\Program

Files\P4P\rss.dll
O9 - Extra button: 情景聊天 -

{E5D12C4E-7B4F-11D3-B5C9-

0050045C3C96} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=yahoomsg (file

missing)
O9 - Extra button: (no name) -

{ECF2E268-F28C-48d2-9AB7-

8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=repair (file

missing)
O9 - Extra 'Tools' menuitem: 修复浏

览器 - {ECF2E268-F28C-48d2-9AB7-

8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=repair (file

missing)
O9 - Extra button: (no name) -

{FD00D911-7529-4084-9946-

A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=clean (file

missing)
O9 - Extra 'Tools' menuitem: 清理上

网记录 - {FD00D911-7529-4084-9946-

A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.ht

m?source=cns&btn=clean (file

missing)
O11 - Options group: [!CNS]  网络实


O17 -

HKLM\System\CCS\Services\Tcpip\..\{

A1D3B76B-2022-4F2A-A8B2-

60577CE657B2}: NameServer =

202.106.0.20
O20 - AppInit_DLLs:

C:\WINDOWS\system32\SoDAHK.DLL
O21 - SSODL: Vision - {6671A431-

5C3D-463d-A7CF-5587F9B7E191} -

C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O23 - Service: C-DillaCdaC11BA -

Macrovision - C:\WINDOWS\system32

\drivers\CDAC11BA.EXE
O23 - Service: P4P Service -

Sohu.com Inc. - C:\Program

Files\Common Files\Sogou

PXP\p2psvr.exe
O23 - Service: Rising Personal

Firewall Service (RfwService) -

Beijing Rising Technology Co., Ltd.

- d:\program

files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process

Communication Center (RsCCenter) -

Beijing Rising Technology Co., Ltd.

- D:\PROGRAM

FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service

(RsRavMon) - Beijing Rising

Technology Co., Ltd. - D:\Program

Files\Rising\Rav\Ravmond.exe
O23 - Service: Epson Printer Status

Agent4 (StatusAgent4) - SEIKO EPSON

CORPORATION - C:\WINDOWS\system32

\SAgent4.exe

gototop
 

拜托大侠给分析分析,看是哪出问题了!
gototop
 

日志不全啊
gototop
 

啊?不会把?扫描出来的东西我全部都拷上了啊!
我再传一遍看看!
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 16:15:05, on 2006-5-3
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Rising\Rav\Ravmond.exe
d:\Program Files\Rising\Rav\RAVMON.EXE
D:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Tencent\QQ\QQ.exe
C:\Documents and Settings\Administrator\桌面\248783200522382732\HijackThis.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - d:\Program Files\P4P\ToolBar.dll
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - d:\Program Files\P4P\sodaie.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O3 - Toolbar: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - d:\Program Files\P4P\ToolBar.dll
O3 - Toolbar: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\RunOnce: [RavStub] "D:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra button: 我的订阅 - {8755CE6E-0BF7-4441-8751-FB728941B0B4} - d:\Program Files\P4P\rss.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  网络实名
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1D3B76B-2022-4F2A-A8B2-60577CE657B2}: NameServer = 202.106.0.20
O20 - AppInit_DLLs: C:\WINDOWS\system32\SoDAHK.DLL
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT