您的位置:程序门 -> windows专区 -> windows nt/2000/xp/2003



怪事,怎么解决?


[收藏此页] [打印本页]选择字色:背景色:字体:[][][]


怪事,怎么解决?[已结贴,结贴人:wenzifeifei]
发表于:2007-02-27 08:50:39 楼主
xp操作系统,当没有接上宽带时一切正常,当一旦可以上网,电脑反应速度便迟钝,打开资源管理器要几十秒,运行软件也是一样,但又不像是病毒,因为在反应慢的这段时间里,cpu使用率只有2%左右,也就是很正常的水平,系统中运行的进程也被我降到十几个了,能结束的都结束了,杀毒软件也扫过几次了没有结果,咋回事,有除了重装以外的办法吗?(不可以重装的)
发表于:2007-02-27 09:21:461楼 得分:10
一般说来,你这种情况中病毒的可能很大,不知道你使用的什么杀毒软件,但推荐你使用恶意软件清除助理或者安全卫士也不错,先检查清除一下,对付木马可以试试木马杀客或者avg   (ewido)看看。并在微软网站上打好补丁可能会好一些。
发表于:2007-02-27 09:48:082楼 得分:10
hijackthis把进程列表和注册表相关日志发个上来看看
发表于:2007-02-27 11:14:493楼 得分:10
确实奇怪,是否是公司的电脑?若是,则用带网络连接的安全模式试试,看还是否是这样子?
是否换个网卡试过了?
发表于:2007-02-27 17:15:114楼 得分:10
临时关掉杀软和防火墙试试。
发表于:2007-02-27 17:44:275楼 得分:10
應該與你的ip和dns有關..
发表于:2007-02-27 21:36:336楼 得分:10
帮顶…………
应该是防火墙的事情
发表于:2007-02-27 21:57:107楼 得分:5
如果是,只慢1,2分钟的话,那是你的网卡没有配置固定ip地址的原因
发表于:2007-02-28 09:59:088楼 得分:0
以下是扫描的结果(...是公司网站,省掉了,应该不要紧)

logfile   of   hijackthis   v1.99.1
scan   saved   at   9:55:37   am,   on   2/28/2007
platform:   windows   xp   sp1   (winnt   5.01.2600)
msie:   internet   explorer   v6.00   sp1   (6.00.2800.1106)

running   processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program   files\intel\wireless\bin\evteng.exe
c:\program   files\intel\wireless\bin\s24evmon.exe
c:\program   files\intel\wireless\bin\wlkeeper.exe
c:\windows\system32\spoolsv.exe
c:\program   files\kaspersky   lab\kaspersky   anti-virus   6.0\avp.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program   files\common   files\microsoft   shared\vs7debug\mdm.exe
c:\progra~1\mi6841~1\mssql\binn\sqlservr.exe
c:\program   files\intel\wireless\bin\regsrvc.exe
c:\program   files\intel\wireless\bin\zcfgsvc.exe
c:\windows\explorer.exe
c:\program   files\kaspersky   lab\kaspersky   anti-virus   6.0\avp.exe
c:\windows\system32\ctfmon.exe
c:\windows\system32\conime.exe
c:\program   files\internet   explorer\iexplore.exe
c:\progra~1\micros~4\common\msdev98\bin\msdev.exe
c:\program   files\internet   explorer\iexplore.exe
c:\windows\system32\wuauclt.exe
e:\smartsw\hijackthis.exe

o2   -   bho:   acroiehlprobj   class   -   {06849e9f-c8d7-4d59-b87d-784b7d6be0b3}   -   c:\program   files\adobe\acrobat   7.0\activex\acroiehelper.dll
o3   -   toolbar:   &radio   -   {8e718888-423f-11d2-876e-00a0c9082467}   -   c:\windows\system32\msdxm.ocx
o4   -   hklm\..\run:   [kav]   "c:\program   files\kaspersky   lab\kaspersky   anti-virus   6.0\avp.exe "
o4   -   hklm\..\run:   [imjpmig8.1]   "c:\windows\ime\imjp8_1\imjpmig.exe "   /spoil   /remadvdef   /migration32
o4   -   hklm\..\run:   [imekrmig6.1]   c:\windows\ime\imkr6_1\imekrmig.exe
o4   -   hklm\..\run:   [mspy2002]   c:\windows\system32\ime\pintlgnt\imscinst.exe   /sync
o4   -   hklm\..\run:   [phime2002async]   c:\windows\system32\ime\tintlgnt\tintsetp.exe   /sync
o4   -   hklm\..\run:   [phime2002a]   c:\windows\system32\ime\tintlgnt\tintsetp.exe   /imename
o4   -   hkcu\..\run:   [ctfmon.exe]   c:\windows\system32\ctfmon.exe
o8   -   extra   context   menu   item:   e&xport   to   microsoft   excel   -   res://c:\progra~1\micros~2\office11\excel.exe/3000
o9   -   extra   button:   web?¤??2????à?ê??è   -   {1f460357-8a94-4d71-9ca3-aa4acf32ed8e}   -   c:\program   files\kaspersky   lab\kaspersky   anti-virus   6.0\scieplugin.dll
o9   -   extra   button:   research   -   {92780b25-18cc-41c8-b9be-3c9c571a8263}   -   c:\progra~1\micros~2\office11\refiebar.dll
o9   -   extra   button:   related   -   {c95fe080-8f5d-11d2-a20b-00aa003c157a}   -   c:\windows\web\related.htm
o9   -   extra   'tools '   menuitem:   show   &related   links   -   {c95fe080-8f5d-11d2-a20b-00aa003c157a}   -   c:\windows\web\related.htm
o9   -   extra   button:   messenger   -   {fb5f1910-f110-11d2-bb9e-00c04f795683}   -   c:\program   files\messenger\msmsgs.exe
o9   -   extra   'tools '   menuitem:   messenger   -   {fb5f1910-f110-11d2-bb9e-00c04f795683}   -   c:\program   files\messenger\msmsgs.exe
o16   -   dpf:   {6414512b-b978-451d-a0d8-fcfdf33e833c}   (wuwebcontrol   class)   -   http://v5.windowsupdate.microsoft.com/v5consumer/v5controls/en/x86/client/wuweb_site.cab?1115927755281
o16   -   dpf:   {f2a84794-ee6d-447b-8c21-3ba1dc77c5b4}   (sdkinstall   class)   -   file://z:\english\platsdk\controls\sdkinst.cab
o17   -   hklm\system\ccs\services\tcpip\parameters:   domain   =   ...
o17   -   hklm\software\..\telephony:   domainname   =   ...
o17   -   hklm\system\ccs\services\tcpip\..\{bef64314-ea25-4b45-9545-7c0596f9af81}:   nameserver   =   10.1.0.20,10.1.16.20
o17   -   hklm\system\cs1\services\tcpip\parameters:   domain   =   ...
o18   -   protocol:   ms-help   -   {314111c7-a502-11d2-bbca-00c04f8ec294}   -   c:\program   files\common   files\microsoft   shared\help\hxds.dll
o20   -   winlogon   notify:   igfxcui   -   c:\windows\system32\igfxdev.dll
o20   -   winlogon   notify:   intelwireless   -   c:\program   files\intel\wireless\bin\lgnotify.dll
o20   -   winlogon   notify:   klogon   -   c:\windows\system32\klogon.dll
o23   -   service:   ati   hotkey   poller   -   ati   technologies   inc.   -   c:\windows\system32\ati2evxx.exe
o23   -   service:   ?¨°í?1?ù·′2???6.0   (avp)   -   unknown   owner   -   c:\program   files\kaspersky   lab\kaspersky   anti-virus   6.0\avp.exe "   -r   (file   missing)
o23   -   service:   evteng   -   intel   corporation   -   c:\program   files\intel\wireless\bin\evteng.exe
o23   -   service:   contivity   vpn   service   (extranetaccess)   -   nortel   networks   na,   inc.   -   c:\program   files\equant   ipsec   client\extranet_serv.exe
o23   -   service:   installdriver   table   manager   (idrivert)   -   macrovision   corporation   -   c:\program   files\common   files\installshield\driver\1050\intel   32\idrivert.exe
o23   -   service:   regsrvc   -   intel   corporation   -   c:\program   files\intel\wireless\bin\regsrvc.exe
o23   -   service:   spectrum24   event   monitor   (s24eventmonitor)   -   intel   corporation     -   c:\program   files\intel\wireless\bin\s24evmon.exe
o23   -   service:   wlankeeper   -   intel?   corporation   -   c:\program   files\intel\wireless\bin\wlkeeper.exe

发表于:2007-02-28 12:15:009楼 得分:5
不知道帮你顶一下
发表于:2007-03-15 14:44:2810楼 得分:0
没有人明白怎么回事吗?简单地说就是不上网没事,一上网机器发应慢,但cpu   和   内存使用一直正常!系统并非装的而是从把别人硬盘做了个镜像,然后装在自己电脑上.我把网卡驱动装好几次了一直都是这样.
发表于:2007-03-15 14:50:1611楼 得分:5
看下原来的网卡的插槽和现在的位置一样不!
网卡换插槽试试!
感觉应该是网卡的事.
发表于:2007-03-20 09:17:5412楼 得分:0
呵呵,应该是网卡的问题,可是我的是笔记本电脑啊,怎么换插槽?做镜像的电脑型号和我的不一样,但是只要不上网就没什么问题啊!这又是怎么回事呢!
发表于:2007-03-20 09:51:1713楼 得分:5
不同网卡驱动的关系吧,更新一下你的网卡的驱动试试。
发表于:2007-03-20 12:46:0014楼 得分:5
//我把网卡驱动装好几次了一直都是这样

到驱动之家重新下载一个驱动
发表于:2007-03-20 13:08:0315楼 得分:5
o16   -   dpf:   {f2a84794-ee6d-447b-8c21-3ba1dc77c5b4}   (sdkinstall   class)   -   file://z:\english\platsdk\controls\sdkinst.cab
关注一下这个
另,尝试关掉iis看有没有效果
发表于:2007-03-20 13:19:4516楼 得分:0
o20   -   winlogon   notify:   klogon   -   c:\windows\system32\klogon.dll这个是什么东西?还有就是把ati的hotkey服务关了吧
发表于:2007-03-21 09:46:0217楼 得分:0
反正就是很奇怪,只要上网,不管是用网卡,还是用usb转换的网卡或者是用无线网卡,只要一能上网,电脑反应就会很慢,有时候运行一个程序会莫名奇妙地出现人个对话框:
the   ??   can 't   be   completed   because   the   server   is   busy   now,什么什么的由于出现时间短所以没能记下来,但是出现过不少的次数了.我现在升级了操作系统,ie   也升了,重新扫描一份给大家过目吧!
以下是启动列表:

//----------------------------------------------------------------------------------
startuplist   report,   3/21/2007,   9:40:11   am
startuplist   version:   1.52.2
started   from   :   e:\smartsw\hijackthis.exe
detected:   windows   xp   sp2   (winnt   5.01.2600)
detected:   internet   explorer   v7.00   (7.00.6000.16414)
*   using   default   options
==================================================

running   processes:

c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program   files\common   files\microsoft   shared\vs7debug\mdm.exe
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
c:\windows\system32\conime.exe
c:\program   files\internet   explorer\iexplore.exe
c:\windows\system32\cmd.exe
c:\progra~1\micros~4\common\msdev98\bin\msdev.exe
c:\program   files\microsoft   visual   studio   6\common\msdev98\bin\msdev.exe
e:\smartsw\hijackthis.exe

--------------------------------------------------

checking   windows   nt   userinit:

[hklm\software\microsoft\windows   nt\currentversion\winlogon]
userinit   =   c:\windows\system32\userinit.exe,

--------------------------------------------------

autorun   entries   from   registry:
hkcu\software\microsoft\windows\currentversion\run

ctfmon.exe   =   c:\windows\system32\ctfmon.exe

--------------------------------------------------

shell   &   screensaver   key   from   c:\windows\system.ini:

shell=*ini   section   not   found*
scrnsave.exe=*ini   section   not   found*
drivers=*ini   section   not   found*

shell   &   screensaver   key   from   registry:

shell=explorer.exe
scrnsave.exe=c:\windows\system32\logon.scr
drivers=*registry   value   not   found*

policies   shell   key:

hkcu\..\policies:   shell=*registry   key   not   found*
hklm\..\policies:   shell=*registry   value   not   found*

--------------------------------------------------


enumerating   task   scheduler   jobs:

applesoftwareupdate.job
defrag-c.job
defrag-d.job

--------------------------------------------------

enumerating   download   program   files:

[windows   genuine   advantage   validation   tool]
inprocserver32   =   c:\windows\system32\legitcheckcontrol.dll
codebase   =   http://go.microsoft.com/fwlink/?linkid=39204

[wuwebcontrol   class]
inprocserver32   =   c:\windows\system32\wuweb.dll
codebase   =   http://v5.windowsupdate.microsoft.com/v5consumer/v5controls/en/x86/client/wuweb_site.cab?1115927755281

[shockwave   flash   object]
inprocserver32   =   c:\windows\system32\macromed\flash\flash9b.ocx
codebase   =   http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

enumerating   windows   nt   logon/logoff   scripts:
*no   scripts   set   to   run*

windows   nt   checkdisk   command:
bootEXECute   =   autocheck   autochk   *

windows   nt   'wininit.ini ':
pendingfilerenameoperations:   c:\windows\system32\drivers\230921.sys ¦ ¦c:\docume~1\admini~1\locals~1\temp\230828.exe ¦ ¦c:\windows\system32\setb.tmp   =>   c:\windows\system32\mlang.dll ¦ ¦\

--------------------------------------------------

enumerating   shellserviceobjectdelayload   items:

postbootreminder:   c:\windows\system32\shell32.dll
cdburn:   c:\windows\system32\shell32.dll
webcheck:   c:\windows\system32\webcheck.dll
systray:   c:\windows\system32\stobject.dll

--------------------------------------------------
end   of   report,   3,918   bytes
report   generated   in   0.031   seconds

command   line   options:
      /verbose     -   to   add   additional   info   on   each   section
      /complete   -   to   include   empty   sections   and   unsuspicious   data
      /full           -   to   include   several   rarely-important   sections
      /force9x     -   to   include   win9x-only   startups   even   if   running   on   winnt
      /forcent     -   to   include   winnt-only   startups   even   if   running   on   win9x
      /forceall   -   to   include   all   win9x   and   winnt   startups,   regardless   of   platform
      /history     -   to   list   version   history   only

//----------------------------------------------------------------------------------
以下是扫描的日志:

logfile   of   hijackthis   v1.99.1
scan   saved   at   9:43:34   am,   on   3/21/2007
platform:   windows   xp   sp2   (winnt   5.01.2600)
msie:   internet   explorer   v7.00   (7.00.6000.16414)

running   processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program   files\common   files\microsoft   shared\vs7debug\mdm.exe
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
c:\windows\system32\conime.exe
c:\program   files\internet   explorer\iexplore.exe
c:\windows\system32\cmd.exe
c:\progra~1\micros~4\common\msdev98\bin\msdev.exe
c:\program   files\microsoft   visual   studio   6\common\msdev98\bin\msdev.exe
c:\windows\system32\notepad.exe
e:\smartsw\hijackthis.exe

o4   -   hkcu\..\run:   [ctfmon.exe]   c:\windows\system32\ctfmon.exe
o8   -   extra   context   menu   item:   e&xport   to   microsoft   excel   -   res://c:\progra~1\micros~2\office11\excel.exe/3000
o8   -   extra   context   menu   item:   上传到qq网络硬盘   -   e:\smartsw\tencent\qq\addtonetdisk.htm
o9   -   extra   button:   research   -   {92780b25-18cc-41c8-b9be-3c9c571a8263}   -   c:\progra~1\micros~2\office11\refiebar.dll
o9   -   extra   button:   (no   name)   -   {e2e2dd38-d088-4134-82b7-f2ba38496583}   -   %windir%\network   diagnostic\xpnetdiag.exe   (file   missing)
o9   -   extra   'tools '   menuitem:   @xpsp3res.dll,-20001   -   {e2e2dd38-d088-4134-82b7-f2ba38496583}   -   %windir%\network   diagnostic\xpnetdiag.exe   (file   missing)
o9   -   extra   button:   messenger   -   {fb5f1910-f110-11d2-bb9e-00c04f795683}   -   c:\program   files\messenger\msmsgs.exe
o9   -   extra   'tools '   menuitem:   windows   messenger   -   {fb5f1910-f110-11d2-bb9e-00c04f795683}   -   c:\program   files\messenger\msmsgs.exe
o11   -   options   group:   [international]   international*
o16   -   dpf:   {17492023-c23a-453e-a040-c7c580bbf700}   (windows   genuine   advantage   validation   tool)   -   http://go.microsoft.com/fwlink/?linkid=39204
o16   -   dpf:   {6414512b-b978-451d-a0d8-fcfdf33e833c}   (wuwebcontrol   class)   -   http://v5.windowsupdate.microsoft.com/v5consumer/v5controls/en/x86/client/wuweb_site.cab?1115927755281
o18   -   protocol:   ms-help   -   {314111c7-a502-11d2-bbca-00c04f8ec294}   -   c:\program   files\common   files\microsoft   shared\help\hxds.dll
o20   -   winlogon   notify:   igfxcui   -   c:\windows\system32\igfxdev.dll
o20   -   winlogon   notify:   wgalogon   -   c:\windows\system32\wgalogon.dll
o23   -   service:   contivity   vpn   service   (extranetaccess)   -   nortel   networks   na,   inc.   -   c:\program   files\equant   ipsec   client\extranet_serv.exe
o23   -   service:   installdriver   table   manager   (idrivert)   -   macrovision   corporation   -   c:\program   files\common   files\installshield\driver\1050\intel   32\idrivert.exe
o23   -   service:   iviregmgr   -   intervideo   -   c:\program   files\common   files\intervideo\regmgr\iviregmgr.exe


大家帮忙看看有什么不正常的米.
发表于:2007-03-21 09:54:5618楼 得分:5
e:\smartsw\hijackthis.exe?
c:\windows\system32\conime.exe\
发表于:2007-03-21 11:01:5619楼 得分:5
你的启动项内   清除下


快速检索

最新资讯
热门点击