|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
x
病毒还是木马????
电脑出现奇怪的现象,开机以后不使用任何程序,内存被一点一点的蚕食,就是说在windows任务管理器中,内存使用那一栏显示的数字自己不断的增长xxxxxx/629964K,前面的数字不断的长,直至弹出对话框提示系统虚拟内存空间不足,然后就无法运行任何程序了,因为没有内存空间了,这个蚕食的过程到实不快,如果什么都不用大概要用30分钟左右。进程已经调整到无法再减的地步了,还是搞不懂到底是怎么了,用的kapa一直正常,也没有报病毒。怀疑是木马,可是用HijackThis也没有找到。
求救,求救,高手帮帮忙!!
这里是我用HijackThis备份下来的进程目录。
Logfile of HijackThis v1.99.1
Scan saved at 03:14:19, on 07.06.2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\csrss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\system32\spoolsv.exe
E:\WINNT\System32\msdtc.exe
E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
E:\WINNT\SYSTEM32\RUNDLL32.EXE
E:\WINNT\Explorer.exe
E:\WINNT\system32\nvsvc32.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\system32\tcpsvcs.exe
E:\WINNT\System32\snmp.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\system32\MsPMSPSv.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\System32\dmadmin.exe
E:\WINNT\system32\RUNDLL32.EXE
E:\WINNT\LSASS.exe
E:\Program Files\NetLimiter\NetLimiter.exe
E:\WINNT\system32\ctfmon.exe
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
E:\WINNT\SMSS.EXE
E:\Program Files\Java\jre1.5.0\bin\jusched.exe
E:\Program Files\Java\jre1.5.0\bin\jucheck.exe
E:\WINNT\system32\taskmgr.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Documents and Settings\XuNa\桌面\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe 1
o2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar2.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdReg] E:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "E:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NetLimiter] E:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [winlass] E:\Program Files\Outlook Express\winlass.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAVPersonal50] "D:\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [ToP] E:\WINNT\LSASS.exe
O4 - HKLM\..\Run: [TProgram] E:\WINNT\SMSS.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用CyberArticle保存当前网页... - E:\Program Files\CyberArticle\script\save.htm
O8 - Extra context menu item: 使用CyberArticle保存更多内容... - E:\Program Files\CyberArticle\script\savex.htm
O8 - Extra context menu item: 使用CyberArticle保存网页选中部分... - E:\Program Files\CyberArticle\script\savesel.htm
O8 - Extra context menu item: 使用影音传送带下载 - E:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - E:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java ????ì¨ - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC8A2047-FA40-42D9-A404-302C7C350BE5}: NameServer = xxx.xx.xxx.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD159F58-1EC1-4EAE-9FD7-AFEB1E4D1135}: NameServer = xxx.xx.xxx.1,xxx.xxx.x.x
O18 - Protocol: Festoon - (no CLSID) - (no file)
O18 - Protocol: vskype - (no CLSID) - (no file)
O20 - Winlogon Notify: NavLogon - E:\WINNT\system32\NavLogon.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - D:\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - E:\WINNT\system32\nvsvc32.exe |
|