1   1  /  1  页   跳转

C盘空间越变越少.

C盘空间越变越少.

机子配置:P4.2.4.联想品牌机,系统为WINXP SP2 系统装在C盘

问题:C盘所在的空间越来越少,以至于不断弹出要清理磁盘空间的提示.

偿试过的解决办法:
1.用瑞星和卡吧斯基,木马克星在安全和非安全模式下杀过毒,但一无所过
2.重启过机子并转移C盘我的文档和桌面文件,当时转移之前C盘有100M,转移大概500M文件左右后,重启后只有90M.
3.查看过C盘隐藏文件,发现正常,没有出现过大文件的现象

曾出现过的情况:
1.机子于下午3:00时出现问题,C盘空间应有至少4G以上的空间
2.机子出现问题之前,曾装过软件木马清道夫,现以现载
3.机子出现问题之前,磁盘整理和碎片整理以清理过,并还使用过系统文件清理的软件清理过.

希望各位大哥大姐能帮帮小弟,在此先谢过各过了.
另附扫描日志一份.
Logfile of HijackThis v1.99.1
Scan saved at 15:56:33, on 2006-3-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\hpzipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\COMM\Network.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
G:\Program Files\Rising\Rav\CCenter.exe
G:\Program Files\Rising\Rav\RavTask.exe
G:\Program Files\Rising\Rav\Ravmond.exe
G:\Program Files\Rising\Rav\RavMon.exe
G:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Tencent\TT\TTraveler.exe
G:\Program Files\Rising\Rav\Rav.exe
E:\备份\备份\程序备份\HijackThis.exe

O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] rem "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [WindowsUpdate] rem C:\WINDOWS\system32\WindowsUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [KDTEnterprise] e:\Program Files\快递通企业版客户端\kdtmain.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [Windows木马防火墙] G:\Program Files\ftc\Trojanwall.exe
O4 - HKLM\..\Run: [RavTask] "G:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - g:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - g:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - g:\Program Files\sina\UC\uc.exe (file missing)
O9 - Extra button: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra 'Tools' menuitem: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra button: 寻论网--中学作业解答 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra 'Tools' menuitem: 中学作业 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://61.129.90.99:1995/VTrans.cab
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://61.129.90.93:1995/talk.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} (Ppinstall Control) - http://popo.163.com/install/ppinstall2.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11A9E1F0-B3F9-44E3-969B-7F3A179DC9A9}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C06EE9D-DC60-4354-82E3-7DC3DB2A1365}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{11A9E1F0-B3F9-44E3-969B-7F3A179DC9A9}: NameServer = 192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{11A9E1F0-B3F9-44E3-969B-7F3A179DC9A9}: NameServer = 192.168.0.1
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - G:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - G:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Network System (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe
Ë⽎‚Y®&dotÜpbbs.ikaka.com|S`”¦Aâ¯Ð
最后编辑2006-03-29 10:24:51
分享到:
gototop
 

哪位大大给回复一下...自己顶上去.Ë⽎‚Y®&dotÜpbbs.ikaka.com|S`”¦Aâ¯Ð
gototop
 

【回复“清舞飞扬”的帖子】
结束C:\Program Files\Common Files\COMM\Network.exe进程

修复
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O23 - Service: Network System (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe

卸载
C:\Program Files\LtUcx\

删除
C:\Program Files\LtUcx\
C:\Program Files\Common Files\COMM\
C:\WINDOWS\SYSTEM32\stdup.dll

stdup.dll无法删除请参考http://forum.ikaka.com/topic.asp?board=67&artid=7423269

另外
是否开启了系统还原?Ë⽎‚Y®&dotÜpbbs.ikaka.com|S`”¦Aâ¯Ð
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT