-- 作者:看看資料
-- 发布时间:2007/6/13 0:45:00
-- XP 进程管理器用不了了
今天刚做的系统, 就连接宽待 米做什么. 一会就发现进程管理器用不了了, 提示任务管理器已被系统管理员停用,杀毒后依旧, 本来是可以打开的. 用了会就不行了
以下下用以下是HijackThis扫描结果 Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 0:39:06, on 2007-6-13 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\\WINDOWS\\System32\\smss.exe C:\\WINDOWS\\system32\\csrss.exe C:\\WINDOWS\\system32\\winlogon.exe C:\\WINDOWS\\system32\\services.exe C:\\WINDOWS\\system32\\lsass.exe C:\\WINDOWS\\system32\\svchost.exe C:\\WINDOWS\\system32\\svchost.exe C:\\WINDOWS\\System32\\svchost.exe C:\\WINDOWS\\system32\\svchost.exe C:\\WINDOWS\\system32\\svchost.exe C:\\WINDOWS\\system32\\spoolsv.exe C:\\WINDOWS\\SOUNDMAN.EXE C:\\WINDOWS\\VM303_STI.EXE C:\\Program Files\\Eset\\nod32kui.exe C:\\Program Files\\Rising\\AntiSpyware\\runiep.exe D:\\Program Files\\360safe\\safemon\\360Tray.exe C:\\WINDOWS\\system32\\ctfmon.exe C:\\Program Files\\Common Files\\Autodesk Shared\\Service\\AdskScSrv.exe d:\\Program Files\\3dsMax8\\mentalray\\satellite\\raysat_3dsmax8server.exe C:\\Program Files\\Eset\\nod32krn.exe C:\\WINDOWS\\System32\\svchost.exe C:\\WINDOWS\\system32\\svchost.exe C:\\WINDOWS\\System32\\svchost.exe C:\\WINDOWS\\system32\\wdfmgr.exe C:\\WINDOWS\\system32\\wbem\\SACH0ST.exe C:\\WINDOWS\\System32\\alg.exe D:\\Program Files\\Tencent\\QQ\\QQ.exe D:\\Program Files\\Tencent\\QQ\\TIMPlatform.exe D:\\Program Files\\360safe\\360safe.exe C:\\WINDOWS\\explorer.exe C:\\WINDOWS\\system32\\conime.exe C:\\DOCUME~1\\new\\LOCALS~1\\Temp\\Rar$EX00.266\\HiJackThis_v2_PConline.exe C:\\WINDOWS\\system32\\wbem\\wmiprvse.exe O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\\Program Files\\Thunder\\xunleibho_v14.dll O2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\\Program Files\\360safe\\safemon\\safemon.dll O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\\WINDOWS\\system32\\KakaTool.dll O4 - HKLM\\..\\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup O4 - HKLM\\..\\Run: [MPG4C32] MPG4C32.exe O4 - HKLM\\..\\Run: [BigDog303] C:\\WINDOWS\\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH) O4 - HKLM\\..\\Run: [nod32kui] "C:\\Program Files\\Eset\\nod32kui.exe" /WAITSERVICE O4 - HKLM\\..\\Run: [runeip] C:\\Program Files\\Rising\\AntiSpyware\\runiep.exe O4 - HKLM\\..\\Run: [360Safetray] D:\\Program Files\\360safe\\safemon\\360Tray.exe /start O4 - HKLM\\..\\RunOnce: [KKDelay] C:\\Program Files\\Rising\\AntiSpyware\\RunOnce.exe O4 - HKCU\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe O4 - HKUS\\S-1-5-19\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'LOCAL SERVICE\') O4 - HKUS\\S-1-5-20\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'NETWORK SERVICE\') O4 - HKUS\\S-1-5-18\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe (User \'SYSTEM\') O4 - HKUS\\S-1-5-18\\..\\RunOnce: [FlashPlayerUpdate] C:\\WINDOWS\\system32\\Macromed\\Flash\\GetFlash.exe (User \'SYSTEM\') O4 - HKUS\\.DEFAULT\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe (User \'Default user\') O4 - HKUS\\.DEFAULT\\..\\RunOnce: [FlashPlayerUpdate] C:\\WINDOWS\\system32\\Macromed\\Flash\\GetFlash.exe (User \'Default user\') O8 - Extra context menu item: 使用迅雷下载 - C:\\Program Files\\Thunder\\geturl.htm O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\\Program Files\\Thunder\\getallurl.htm O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\\PROGRA~1\\MICROS~2\\OFFICE11\\EXCEL.EXE/3000 O8 - Extra context menu item: 添加到QQ表情 - D:\\Program Files\\Tencent\\QQ\\AddEmotion.htm O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\\WINDOWS\\web\\related.htm (file missing) O9 - Extra \'Tools\' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\\WINDOWS\\web\\related.htm (file missing) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{51593A5F-77F6-44BE-95A3-06F7CBB15FDC}: NameServer = 202.101.107.54,202.101.98.55 O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{E2C6408B-5B7A-4884-A8B8-166F8D8E7515}: NameServer = 218.85.157.99 202.101.107.98 O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\\PROGRA~1\\WinKld\\WinKld.dll O22 - SharedTaskScheduler: Browseui 预加载程序 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\\WINDOWS\\system32\\browseui.dll O22 - SharedTaskScheduler: 组件类别缓存程序 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\\WINDOWS\\system32\\browseui.dll O23 - Service: Autodesk Licensing Service - Autodesk - C:\\Program Files\\Common Files\\Autodesk Shared\\Service\\AdskScSrv.exe O23 - Service: Help and Support (helpsvc) - 1 - C:\\WINDOWS\\system32\\inetres.exe O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - d:\\Program Files\\3dsMax8\\mentalray\\satellite\\raysat_3dsmax8server.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\\Program Files\\Eset\\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\\WINDOWS\\system32\\nvsvc32.exe -- End of file - 5016 bytes
有没有会的帮处理下
|