1   1  /  1  页   跳转

syshost.exe是个什么东东?

syshost.exe是个什么东东?

以前没见过,昨天换杀软为NOD32,发现系统进程里有这个东西。请看日志:
日志文件: 趋势科技 HijackThis v2.0.0 (BETA)
保存时间: 13:40:14, on 2007-6-18
操作系统: Windows XP SP2 (WinNT 5.01.2600)
启动模式: 正常

正在运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\syshost.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\conime.exe
D:\Program Files\Tencent\QQ2007 psgl精简版\QQ.exe
D:\Program Files\foobar2000\foobar2000.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Opera9\Opera.exe
C:\Documents and Settings\大梦先觉\桌面\ha_hijackthisv2_pp\HA_HijackThisv2_PP\HiJackThis_v2.exe

O2 - BHO: ThunderAtOnce Class - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder.v5.6.3.307.NoAD-Ayu\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Thunder.v5.6.3.307.NoAD-Ayu\ComDlls\xunleiBHO_Now.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (未命名) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (没有文件)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - d:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - 工具栏: (未命名) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (没有文件)
O3 - 工具栏: (未命名) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (没有文件)
O3 - 工具栏: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - D:\Program Files\VSP\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [FXCalendar] D:\Program Files\FXCalendar\FXCalendar.EXE
O4 - HKLM\..\Run: [Vistadrv] D:\Program Files\VSP\VistaDrv\vsdrv.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [syshost] C:\WINDOWS\syshost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [1] C:\WINDOWS\TomatoSoft\XPLODE.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [1] C:\WINDOWS\TomatoSoft\XPLODE.EXE (User 'NETWORK SERVICE')
O8 - 扩展右键菜单项: &使用快车(FlashGet)下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - 扩展右键菜单项: &使用快车(FlashGet)下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - 扩展右键菜单项: 使用迅雷下载 - D:\Program Files\Thunder.v5.6.3.307.NoAD-Ayu\Program\geturl.htm
O8 - 扩展右键菜单项: 使用迅雷下载全部链接 - D:\Program Files\Thunder.v5.6.3.307.NoAD-Ayu\Program\getallurl.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{87B2C2A1-6DE0-4275-8508-539AED9471A8}: NameServer = 192.168.1.1
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - E:\娱乐工具\KuGoo3\KuGoo3\InExtend\KuGoo3DownXControl.ocx
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Altera JTAG Server (JTAGServer) - Unknown owner - d:\altera\quartus60\win\JTAGServer.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - H:\MATLAB6p5p1\webserver\bin\win32\matlabserver.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
文件结束 - 4175 字节
最后编辑2007-06-21 11:22:31
分享到:
gototop
 

老大啊,怎么清除啊?我的NOD32和AVG都查不出来啊
gototop
 

谢谢  搞定了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT