1   1  /  1  页   跳转

机器现在这两天老是自己读硬盘

机器现在这两天老是自己读硬盘

不知道是怎么搞的,开机后老是出现强烈的读硬盘,以致系统盘没有空间
还有一点就是开机的时候会出现硬盘检测,但有时不(当然我说的是正常关机的时候会出现自检,而且是只检查F盘)

自己读取硬盘会致使系统速度性能严重降低,本来C盘有一个多G的空间,现在是一点都没有,虚拟内存不在这个盘符,大家有没有碰到过种问题。

不像是木马吧,我安装了木马查杀工具,下面是我用hijackthis的扫描结果:
最后编辑2005-11-24 11:28:08
分享到:
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      10:33:14, 日期 2005-11-24
操作系统:  Windows 2003  (WinNT 5.02.3790)
浏览器:    Internet Explorer v6.00 (6.00.3790.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\PROGRA~1\RISING\RAV\RAVMON.EXE
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\Java\j2re1.4.2_09\bin\jusched.exe
E:\download\ftcsetup\ftcsetup\木马清道夫6.6\Trojanwall.exe
D:\Program Files\SkyNet\FireWall\PFW.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SSREADER36\ssreader.exe
D:\Program Files\SSREADER36\ssreader.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\广电嘉和\济南广电嘉和认证客户端\广电认证.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
D:\Program Files\GOSURF2\gsfbwsr.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.578\HijackThis1991zww.exe

gototop
 

R3 - URLSearchHook: (no name) - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - (no file)
R3 - URLSearchHook: QQ Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\AddrPlus\IEHelp2.dll (file missing)
R3 - URLSearchHook: SrchHook Class - {EED92A43-CFCE-4548-BD73-B0A405470ED5} - C:\PROGRA~1\CNNIC\Cdn\iesrch.dll (file missing)
O1 - Hosts: 218.246.32.208 www.luosoft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - (no file)
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: EyeOnIE Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - D:\Program Files\IS\BhoPlugin.dll (file missing)
O2 - BHO: CPub Object - {6F6D1BD2-9270-4e9e-B491-0287F418B5AB} - D:\Program Files\AspStudio\AspDebugerBHO.dll
O2 - BHO: ShowBarObject Class - {850B69E4-90DB-4F45-8621-891BF35A5B53} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (no file)
O2 - BHO: bho Class - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll (file missing)
O3 - IE工具栏增项: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - d:\Program Files\CyberArticle\CyberArticleExpress.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - IE工具栏增项: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - d:\Program Files\Zend\ZendStudioClient-4.0.0\bin\ZendIEToolbar.dll
O3 - IE工具栏增项: CopySo拷贝搜 - {40987A5C-6AB8-4977-8BE9-A8889DE2EDCC} - C:\Program Files\Copyso\CopysoIE.dll (file missing)
O3 - IE工具栏增项: (no name) - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - (no file)
O3 - IE工具栏增项: (no name) - {2E7D3330-EB94-4518-B0FE-E05379A5C1DA} - (no file)
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_09\bin\jusched.exe
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [Windows木马防火墙] E:\download\ftcsetup\ftcsetup\木马清道夫6.6\Trojanwall.exe
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] D:\Program Files\SkyNet\FireWall\PFW.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用CyberArticle保存 - d:\Program Files\CyberArticle\script\savex.htm
O8 - IE右键菜单中的新增项目: 使用CyberArticle保存当前网页 - d:\Program Files\CyberArticle\script\save.htm
O8 - IE右键菜单中的新增项目: 使用CyberArticle保存网页选中部分 - d:\Program Files\CyberArticle\script\savesel.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导入当前页到超星阅览器(&A) - d:\Program Files\SSREADER36\ss_all.htm
O8 - IE右键菜单中的新增项目: 导入选中部分到超星阅览器(&S) - d:\Program Files\SSREADER36\ss_select.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: (no name) - {0713E8D2-850A-101B-AFC0-4210122A8DA9} - (no file)
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O15 - “受信任的站点”中添加项: http://ny.contentmatch.net (HKLM)
O16 - DPF: _{1C960AA3-FAEE-11D0-9262-00A0243D2412} - http://web.77169.com/ActiveX/TegoLoad.cab
O16 - DPF: _{28E0FA88-ABA8-4937-A247-3031F1A11165} - http://dl.51.net/download/diybar2.cab
O16 - DPF: _{56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: _{C50341E9-CDC1-4377-AB88-3486CCD0FDA1} - http://ms1.cyworld.com.cn/music/package/cycnset.cab
O16 - DPF: _{C6760A07-A574-4705-B113-7856315922C3} - http://akamai.downloadv3.com/binaries/IA/sysnetsvc32_EN.cab
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vod.ruyi.com/plugin/PowerPlr.ocx
O16 - DPF: {3359C0B1-2363-40B3-AFCA-1ABC799AC486} (SSReaderPlug Control) - http://reg.ssreader.com/ssreaderplug.ocx
O16 - DPF: {339C1EE2-1029-46B8-81F1-360217F26FC4} (VGAPlayer Control) - http://219.144.186.220/glx/1/VGAPlayer.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {8135EF31-FE8C-4C6E-A18A-F59944C3A488} - http://ddddl.dudu.com/ddd/update/plugin/dddspocx.cab
O16 - DPF: {8D73F890-B627-428B-BFBA-D7467B00E6E2} (RLTestFormX Control) - http://www.reallink.cn/search/RLTestX.ocx
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/180solutions/ie/bridge-c15.cab
O16 - DPF: {B2900CC6-9736-4AF5-8B98-FFFCBBDD46D8} (dgsxcgfss.UserControl1) - http://110dj.com/sz/RealPlayer.ocx
O16 - DPF: {C298F7C6-958F-47AE-B811-C730070B5BD2} (EzWebView Control) - http://www.i-view.com.tw/cab/Webview.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F381FC65-D92D-4410-B865-E4E9713994E8} - http://61.55.138.4/sso/ccitpay.CAB
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61C7FCE9-8CF2-4B76-8199-E2B40E7F5849}: NameServer = 210.77.192.88
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - (no file)
O18 - 列举现有的协议: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - NT 服务: Apache2 - Unknown owner - E:\Apache\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - NT 服务: Microsoft Search (MSSEARCH) - Unknown owner - C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe (file missing)
O23 - NT 服务: MSSQLSERVER - Unknown owner - d:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe (file missing)
O23 - NT 服务: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - d:\oracle\ora90\bin\xsolap.exe
O23 - NT 服务: Oracle OLAP Agent - Unknown owner - d:\oracle\ora90\bin\xsaagent.exe
O23 - NT 服务: OracleOraHome90Agent - Oracle Corporation - d:\oracle\ora90\bin\agntsrvc.exe
O23 - NT 服务: OracleOraHome90ClientCache - Unknown owner - d:\oracle\ora90\BIN\ONRSD.EXE
O23 - NT 服务: OracleOraHome90HTTPServer - Unknown owner - d:\oracle\ora90\Apache\Apache\Apache.exe
O23 - NT 服务: OracleOraHome90ManagementServer - Unknown owner - D:\oracle\ora90\BIN\OMSNTsrv.exe
O23 - NT 服务: OracleOraHome90PagingServer - Unknown owner - d:\oracle\ora90/bin/pagntsrv.exe
O23 - NT 服务: OracleOraHome90SNMPPeerEncapsulator - Unknown owner - d:\oracle\ora90\BIN\ENCSVC.EXE
O23 - NT 服务: OracleOraHome90SNMPPeerMasterAgent - Unknown owner - d:\oracle\ora90\BIN\AGNTSVC.EXE
O23 - NT 服务: OracleOraHome90TNSListener - Unknown owner - d:\oracle\ora90\BIN\TNSLSNR.exe
O23 - NT 服务: OracleServiceMYORACLE - Oracle Corporation - d:\oracle\ora90\bin\ORACLE.EXE
O23 - NT 服务: OracleServiceOEMREP - Oracle Corporation - d:\oracle\ora90\bin\ORACLE.EXE
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: SQLSERVERAGENT - Unknown owner - d:\PROGRA~1\MICROS~1\MSSQL\binn\sqlagent.exe (file missing)
O23 - NT 服务: Sybase BCKServer _ OS586_BS (SYBBCK_OS586_BS) - Unknown owner - D:\Sybase\bin\bcksrvr.exe (file missing)
O23 - NT 服务: Sybase HISServer_OS586_HS (SYBHIS_OS586_HS) - Unknown owner - D:\Sybase\bin\histsrvr.exe (file missing)
O23 - NT 服务: Sybase MONServer _ OS586_MS (SYBMON_OS586_MS) - Unknown owner - D:\Sybase\bin\monsrvr.exe (file missing)
O23 - NT 服务: Sybase SQLServer _ OS586 (SYBSQL_OS586) - Unknown owner - D:\Sybase\bin\sqlsrvr.exe (file missing)
O23 - NT 服务: Sybase XPServer _ OS586_XP (SYBXPS_OS586_XP) - Unknown owner - D:\Sybase\bin\xpserver.exe (file missing)
O23 - NT 服务: Visibroker Smart Agent (xsSmartAgent) - Unknown owner - d:\oracle\ora90\bin\osagent.exe

gototop
 

还有没有啊?
我感觉到这些是不够的吧,呵呵

不过有一点我发现机子自己就在输入法当中安装微软拼音啊,我从来不用的,删除了后再加上,怪事?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT