瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 ~!--> 日志扫描结果:我看不懂,大家帮看看!有病毒,系统很慢~!

1234   1  /  4  页   跳转

~!--> 日志扫描结果:我看不懂,大家帮看看!有病毒,系统很慢~!

~!--> 日志扫描结果:我看不懂,大家帮看看!有病毒,系统很慢~!

Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 06:48:46, on 2006-09-04
Platform: Microsoft Windows 2000 Service Pack 4 (Build 2195)
MSIE: Internet Explorer v6.00 SP1; (6.00.2800.1106)


Running processes:
[CTFMON.EXE]
CommandLine = "C:\WINNT\system32\ctfmon.exe"

[explorer.exe]
CommandLine = C:\WINNT\explorer.exe

[REGSVR32.EXE]
CommandLine = "C:\WINNT\system32\regsvr32.exe" /s /u "C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx (file missing)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKLM\..\Run: [MSConfig] C:\Documents and Settings\Administrator\My Documents\msconfig.exe /auto
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINNT\Java\classes\dajava.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147361392796
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\system32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\system32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINNT\system32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINNT\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx
O20 - Winlogon Notify: igfxcui
O20 - Winlogon Notify: NavLogon
O20 - Winlogon Notify: RunServices
O20 - Winlogon Notify: wzcnotif
O23 - Service: Command Service (cmdService) - - C:\WINNT\bWVuZ25pdS0xMjQ\command.exe
O23 - Service: DefWatch (DefWatch) - Symantec Corporation - C:\PROGRA~1\SAV\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe /com
O23 - Service: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
O23 - Service: Intel Alert Handler (Intel Alert Handler) - Intel? Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator (Intel Alert Originator) - Intel? Corporation - C:\WINNT\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer (Intel File Transfer) - Intel? Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS (Intel PDS) - Intel? Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Network Monitor (Network Monitor) - - C:\Program Files\Network Monitor\netmon.exe service
O23 - Service: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SAV\Rtvscan.exe
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
O23 - Service: Remote Reader Machine (Remote Reader Machine) - - C:\WINNT\system32\ssmc.exe"
O23 - Service: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Rhino Software, Inc. +1(262) 560-9627 - C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
O23 - Service: sqldps (sqldps) - - "C:\WINNT\sqldps.exe"
O23 - Service: sqlmanagement (sqlmanagement) - - "C:\WINNT\sqlmanagement.exe"
O23 - Service: sqldbmanager (xT?&t桯篈VEw) - - "C:\WINNT\sqldbmanager"

==========================================================

在C:\下面开机生成deskbar2.exe,dfndrff_15.exe,drsmartload.exe,drsmartload45a45k.exe,drsmartload46a46k.exe,drsmartload849a849k.exe,Installer3.exe,kybrdff_15.exe,MTE3NDI60DoxNg.exe,nwnmfl_15.exe,winde.exe.
开机之后出现“运行时76错误。”,打开Command.exe 服务,由于这个服务不是Microsoft
我将这个服务关了。
系统一会儿就自动打开一些国外网站,清也清不掉。
最后编辑2006-10-21 18:41:14
分享到:
gototop
 

先谢了,多多帮助呀~!
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      21:00:32, 日期 2006-9-4
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\PROGRA~1\SAV\DefWatch.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\System32\tcpsvcs.exe
C:\PROGRA~1\SAV\Rtvscan.exe
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINNT\system32\ntfrs.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
C:\WINNT\system32\ssmc.exe
C:\WINNT\system32\RsFsa.exe
C:\WINNT\system32\RsSub.exe
C:\WINNT\System32\locator.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\sqldps.exe
C:\WINNT\System32\lserver.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\ams_ii\hndlrsvc.exe
C:\WINNT\system32\ams_ii\iao.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\System32\mqsvc.exe
C:\WINNT\system32\RsEng.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\regsvr32.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\mdm.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINNT\system32\ssbezier.scr
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\Rar$EX02.500\HijackThis1991zww.exe

O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\RuunServices:[Crucial Runtime Services] rundlI32.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147361392796
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\\NavLogon.dll
O20 - Winlogon Notify: RunServices - C:\WINNT\system32\lvro0993e.dll
O23 - NT 服务: DefWatch - Symantec Corporation - C:\PROGRA~1\SAV\DefWatch.exe
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
O23 - NT 服务: Intel Alert Handler - Intel? Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - NT 服务: Intel Alert Originator - Intel? Corporation - C:\WINNT\system32\ams_ii\iao.exe
O23 - NT 服务: Intel File Transfer - Intel? Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - NT 服务: Intel PDS - Intel? Corporation - C:\WINNT\system32\cba\pds.exe
O23 - NT 服务: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - NT 服务: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SAV\Rtvscan.exe
O23 - NT 服务: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - NT 服务: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
O23 - NT 服务: Remote Reader Machine - Unknown owner - C:\WINNT\system32\ssmc.exe
O23 - NT 服务: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
O23 - NT 服务: Serv-U FTP Server (Serv-U) - Rhino Software, Inc. +1(262) 560-9627 - C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
O23 - NT 服务: sqldps - Unknown owner - C:\WINNT\sqldps.exe
O23 - NT 服务: sqlmanagement - Unknown owner - C:\WINNT\sqlmanagement.exe (file missing)
O23 - NT 服务: sqldbmanager (xT?&t桯篈VEw) - Unknown owner - C:\WINNT\sqldbmanager (file missing)

gototop
 

大哥,这是啥毛病啊~!
gototop
 

现在病毒是太厉害了~!
gototop
 

重装多麻烦,前两天升级中的标。不升级也就没事了~
gototop
 

自然是不会了,不会才要学的。
1、病毒乍清除?
2、系统咋维护?
gototop
 

ijackThis_815汉化版扫描日志 V1.99.1
保存于      14:49:24, 日期 2006-9-5
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\PROGRA~1\SAV\DefWatch.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\System32\tcpsvcs.exe
C:\Program Files\Network Monitor\netmon.exe
C:\PROGRA~1\SAV\Rtvscan.exe
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINNT\system32\ntfrs.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
C:\WINNT\system32\ssmc.exe
C:\WINNT\system32\RsFsa.exe
C:\WINNT\system32\RsSub.exe
C:\WINNT\System32\locator.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\sqldps.exe
C:\WINNT\System32\lserver.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\ams_ii\hndlrsvc.exe
C:\WINNT\system32\ams_ii\iao.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\System32\mqsvc.exe
C:\WINNT\system32\RsEng.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\explorer.exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\system32\WISPTIS.EXE
C:\WINNT\System32\mdm.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\conime.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\Rar$EX00.141\木马杀客\mmsk.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.687\木马杀客\mmsk.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\Rar$EX00.516\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147361392796
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{17304516-3D73-4161-8E22-9CCFBC316829}: NameServer = 192.168.100.124
O20 - Winlogon Notify: Control Panel - C:\WINNT\system32\gp2ol3f31.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: DefWatch - Symantec Corporation - C:\PROGRA~1\SAV\DefWatch.exe
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
O23 - NT 服务: Intel Alert Handler - Intel? Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - NT 服务: Intel Alert Originator - Intel? Corporation - C:\WINNT\system32\ams_ii\iao.exe
O23 - NT 服务: Intel File Transfer - Intel? Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - NT 服务: Intel PDS - Intel? Corporation - C:\WINNT\system32\cba\pds.exe
O23 - NT 服务: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - NT 服务: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SAV\Rtvscan.exe
O23 - NT 服务: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - NT 服务: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
O23 - NT 服务: Remote Reader Machine - Unknown owner - C:\WINNT\system32\ssmc.exe
O23 - NT 服务: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
O23 - NT 服务: Serv-U FTP Server (Serv-U) - Rhino Software, Inc. +1(262) 560-9627 - C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
O23 - NT 服务: sqldps - Unknown owner - C:\WINNT\sqldps.exe
O23 - NT 服务: sqlmanagement - Unknown owner - C:\WINNT\sqlmanagement.exe (file missing)
O23 - NT 服务: sqldbmanager (xT?&t桯篈VEw) - Unknown owner - C:\WINNT\sqldbmanager (file missing)

gototop
 

请教大家:
1、病毒乍清除?
2、系统咋维护?
gototop
 

请教,有没有这方面的学习资料啊~!
gototop
 
1234   1  /  4  页   跳转
页面顶部
Powered by Discuz!NT