瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 求助,关于本本的两个问题!!!!!先谢过.....
taoyecc - 2005-7-1 21:53:00
1.出现蓝屏的英文代码如下:

A problem has been detected and windows has been shut down to prevent
damage to your computer.
DRIVER-POWER-STATE-FAILURE
If this is the first time you’ve seen this stop error screen.
Vestart your computer if this screen appears again,follow these steps.
Check to make sure any new hardware or software is properly installed.
If this is a new installation,ask your.
Hardware or software manufacturer for any windows updates you might need.
If problems continue disable or vemove any newly installed hardwareor software,
Disable biso memory options such as caching or shadowing. if you need to use saft mode to remove or disable components,testart your computer, peess F8 to select.Adcanced start up options,
And then select safe mode
Technical information:
***STOP:0×0000009F (0×00000500,0×00000002,0×813B2C10,0×81B59F18)


请教各位大侠出现这样的问题是软件还是硬件有问题,先谢了!



taoyecc - 2005-7-1 21:55:00
求助!!东芝本本开机后提示:MSASP32.exe-损坏的图像 具体如下.....
"应用程序或DLL C:\WINDOWS\System32\fltmgr.dll 为无效的windows映象.请检查一遍您的安装盘.


另外在桌面上有这样几行文字:
security warning
A fatal error in IE has occured at 0028:c0011e36 in vxd vmm<01> +0010e36.Error was caused by trojan-spy.HTML.Smitfraud.c.............................

请问大家如何处理!!!!

操作系统是xp Home 型号是satellite A10
taoyecc - 2005-7-1 21:56:00
hijackthis扫描日志
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 18:37:05, 日期 2005-7-1
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
C:\Herosoft\HeroV8\SYSEXPLR.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\taskbars.exe
C:\WINDOWS\System32\phqghum.EXE
C:\WINDOWS\System32\MSASP32.exe
C:\program files\180searchassistant\sac.exe
C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
C:\WINDOWS\System32\r7d75q0d.exe
C:\WINDOWS\System32\combo.exe
C:\WINDOWS\System32\combop.exe
C:\WINDOWS\System32\intel32.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\MSASP32.exe
C:\WINDOWS\system32\RAMASST.exe
c:\windows\system32\asnbxm.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\program files\internet explorer\iexplore.exe
C:\WINDOWS\System32\dhcpclient.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\cdapp\ykpuugvxps.exe
C:\Documents and Settings\user\桌面\新建文件夹 (2)\HijackThis1991汉化版\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\system32\webdlg32.dll
R3 - URLSearchHook: BDSrchHook Class - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\DOWNLO~1\BDSrHook.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: CDownCom Class - {031B6D43-CBC4-46A5-8E46-CF8B407C1A33} - C:\WINDOWS\DOWNLO~1\ipreg32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {07BB2646-52D7-E7F0-BD87-7A2DB05D5B1E} - C:\WINDOWS\System32\cdapp\ykpuugvxps.dll
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\WINDOWS\Downlo~1\ddtinit.dll
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\sachook.dll
O2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\system32\webdlg32.dll
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - C:\WINDOWS\Downlo~1\ddtkillw.ocx
O2 - BHO: Pop Class - {A9AEE0DD-89E1-40EE-8749-A18650CC2175} - C:\WINDOWS\winsx.dll
O2 - BHO: BDSrchHook Class - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\DOWNLO~1\BDSrHook.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\WINDOWS\Downlo~1\DDTONG~1.DLL
O3 - IE工具栏增项: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O3 - IE工具栏增项: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\webdlg32.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - 启动项HKLM\\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - 启动项HKLM\\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - 启动项HKLM\\Run: [000StTHK] 000StTHK.exe
O4 - 启动项HKLM\\Run: [LTSMMSG] LTSMMSG.exe
O4 - 启动项HKLM\\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - 启动项HKLM\\Run: [TFNF5] TFNF5.exe
O4 - 启动项HKLM\\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - 启动项HKLM\\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - 启动项HKLM\\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - 启动项HKLM\\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - 启动项HKLM\\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [SysExplr] C:\Herosoft\HeroV8\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [BIE] Rundll32.exe C:\WINDOWS\DOWNLO~1\BDSrHook.dll,Rundll32
O4 - 启动项HKLM\\Run: [SysTray] C:\WINDOWS\System32\Systray.exe
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe nmgamex.dll,LiveProcess /aa
O4 - 启动项HKLM\\Run: [MS taskbar] taskbars.exe
O4 - 启动项HKLM\\Run: [KYM Control Settings] phqghum.EXE
O4 - 启动项HKLM\\Run: [MS Auto-IPSec Protection] MSASP32.exe
O4 - 启动项HKLM\\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - 启动项HKLM\\Run: [sac] c:\program files\180searchassistant\sac.exe
O4 - 启动项HKLM\\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - 启动项HKLM\\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - 启动项HKLM\\Run: [msxct] msxct.exe
O4 - 启动项HKLM\\Run: [r7d75q0d] C:\WINDOWS\System32\r7d75q0d.exe
O4 - 启动项HKLM\\Run: [stgdaxod] C:\WINDOWS\stgdaxod.exe
O4 - 启动项HKLM\\Run: [combo.exe] combo.exe
O4 - 启动项HKLM\\Run: [combop.exe] combop.exe
O4 - 启动项HKLM\\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe
O4 - 启动项HKLM\\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - 启动项HKLM\\Run: [xhlydu] c:\windows\system32\asnbxm.exe r
O4 - 启动项HKLM\\RunServices: [MS taskbar] taskbars.exe
O4 - 启动项HKLM\\RunServices: [KYM Control Settings] phqghum.EXE
O4 - 启动项HKLM\\RunServices: [MS Auto-IPSec Protection] MSASP32.exe
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - 启动项HKCU\\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - 启动项HKCU\\Run: [MS taskbar] taskbars.exe
O4 - 启动项HKCU\\Run: [KYM Control Settings] phqghum.EXE
O4 - 启动项HKCU\\Run: [MS Auto-IPSec Protection] MSASP32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - IE右键菜单中的新增项目: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - IE右键菜单中的新增项目: 使用新浪下载助手下载 - C:\WINDOWS\Downlo~1\sinadl.htm
O8 - IE右键菜单中的新增项目: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=20000001
O8 - IE右键菜单中的新增项目: 收藏此页到ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - IE右键菜单中的新增项目: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - IE右键菜单中的新增项目: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - 浏览器额外的按钮: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的“工具”菜单项: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的按钮: 百度搜索伴侣 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\DOWNLO~1\BDSrHook.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\fltmgr.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\fltmgr.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\fltmgr.dll
O11 - Options group: [!IESearch] !IESearch
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccessVerisign/ie/bridge-c18.cab
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vod.wx.js.cn/plugin/PowerPlr.ocx
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/website.ocx
O16 - DPF: {99888952-AC62-437C-AFC6-7B5CF05A7F2F} (IEDown Class) - http://download.ourgame.com/IEDown.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} (BDSrchHook Class) - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildAppNonUS.cab
O18 - 列举现有的协议: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\DOWNLO~1\BDSrHook.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - NT 服务: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe
O23 - NT 服务: Handling the DHCP requests (DHCP Client) - Unknown owner - C:\WINDOWS\System32\dhcpclient.exe
O23 - NT 服务: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - NT 服务: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
taoyecc - 2005-7-1 22:26:00
急!!自己顶一下
1
查看完整版本: 求助,关于本本的两个问题!!!!!先谢过.....