1   1  /  1  页   跳转

explorer.exe 进程占用100%CPU

explorer.exe 进程占用100%CPU

如题,一开机就是这样,根本不能干别的。是在一次打开陌生人的邮件后就这样了,这是啥病毒,如何搞定他。
最后编辑2006-09-21 06:17:34
分享到:
gototop
 

掃描日記上來。看看
gototop
 

桌面上有一可疑的文件“message.elm"删除不了。下面是扫描报告:
2006-09-21,04:32:29

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Zone Labs Client><"C:\Program Files\Zone Labs\Integrity Client\iclient.exe">  [Check Point Inc.]
    <C4EBReg><"C:\progra~1\c4ebreg\c4ebreg.exe" /q>  [IBM Global Services]
    <Isamtray><"C:\progra~1\c4ebreg\isamtray.exe">  [IBM Global Services]
    <ISSI EZUpdate Service><"c:\sdwork\issimsvc.exe">  [IBM Global Services]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    <WinlogonNotify: NavLogon><C:\WINNT\system32\NavLogon.dll>  [Symantec Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <AEIWLSTA.EXE><; AEIWLSTA.EXE>  [Actiontec Electronics, Inc]
    <AGRSMMSG><; AGRSMMSG.exe>  [Agere Systems]
    <C4EBReg><; "C:\progra~1\c4ebreg\c4ebreg.exe" /q>  [IBM Global Services]
    <ccApp><; "C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [Symantec Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><; ctfmon.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <HotKeysCmds><; C:\WINNT\system32\hkcmd.exe>  [Intel Corporation]
    <IgfxTray><; C:\WINNT\system32\igfxtray.exe>  [Intel Corporation]
    <ISAMTray><; "C:\progra~1\c4ebreg\isamtray.exe">  [IBM Global Services]
    <ISSI EZUpdate Service><; "c:\sdwork\issimsvc.exe">  [IBM Global Services]
    <Mysee Alert><; "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray>  []
    <NMGameX_AutoRun><; C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa>  [NMGameX]
    <qcsszjcz><; c:\chenhu2\chenqxms.exe>  []
    <Synchronization Manager><; mobsync.exe /logon>  [Microsoft Corporation]
    <SynTPEnh><; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [Synaptics, Inc.]
    <SynTPLpr><; C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [Synaptics, Inc.]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  []
    <TpShocks><; TpShocks.exe>  [IBM Corp.]
    <TrackPointSrv><; tp4serv.exe>  [IBM Corporation]
    <vptray><; C:\PROGRA~1\SYMANT~1\VPTray.exe>  [Symantec Corporation]
    <WangWang><; "d:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">  []

==================================
启动文件夹
服务
[Indexing Data / BNESS]
  <C:\WINNT\SYSTEM32\RUNDLL32.EXE C:\WINNT\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Symantec Event Manager / ccEvtMgr]
  <C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
  <C:\Program Files\Symantec AntiVirus\DefWatch.exe><Symantec Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[IBM PM Service / IBMPMSVC]
  <C:\WINNT\system32\ibmpmsvc.exe><N/A>
[IBM Standard Asset Manager Service / ISAMSvc]
  <C:\progra~1\c4ebreg\c4ebreg.exe><IBM Global Services>
[ISSI EZUpdate / ISSIMon]
  <c:\sdwork\issimsvc.exe><IBM Global Services>
[Pml Driver HPZ12 / Pml Driver HPZ12]
  <C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPZipm12.exe><HP>
[SavRoam / SavRoam]
  <C:\Program Files\Symantec AntiVirus\SavRoam.exe><symantec>
[Symantec Network Drivers Service / SNDSrvc]
  <C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
  <C:\Program Files\Symantec AntiVirus\Rtvscan.exe><Symantec Corporation>
[TrueVector Internet Monitor / vsmon]
  <C:\WINNT\system32\ZoneLabs\vsmon.exe -service><Check Point Inc.>

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[LinkFilter Class]
  {4022F902-ABC7-4C79-924F-BB26F1D355A2} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, N/A>
[T2BHO Class]
  {B1D147E7-873E-4909-8127-695D9BB78728} <C:\WINNT\Downloaded Program Files\CONFLICT.1\barhelp24.0.dll, HDT, Inc.>
[IEHlprObj Class]
  {CE7C3CF0-4B15-11D1-ABED-709549C10000} <C:\WINNT\system32\IEHelper.dll, >
[QuickBtn]
  {D1BB7CF4-4463-4e91-88D7-ECC3CE0A13B7} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[bho Class]
  {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} <C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll, 深圳世强软件开发部>
[金山词霸]
  {9A687CA6-D585-4947-9ED9-BE96071F5CD9} <C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[虎翼DIY吧!]
  {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINNT\system32\CMBEdit.dll, >
[Installer Class]
  {28E0FA88-ABA8-4937-A247-3031F1A11165} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
[Downloader Class]
  {5932517A-3326-4439-A708-1C98EDB5C549} <C:\WINNT\system32\iMopDl.dll, >
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINNT\DOWNLO~1\PHOTO_~1.OCX, N/A>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[Google 搜索(&G)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[反向链接]
  <res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A>
[类似网页]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A>
[缓存的网页快照]
  <res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A>

gototop
 

==================================
正在运行的进程
[PID: 156][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 180][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 176][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6997>
    [C:\WINNT\system32\NavLogon.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\WINNT\system32\igfxsrvc.dll]  <Intel Corporation><3.0.0.2249>
    [C:\WINNT\system32\hccutils.DLL]  <Intel Corporation><3.0.0.2249>
[PID: 228][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.7035>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
[PID: 240][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.7011>
[PID: 364][C:\WINNT\system32\ibmpmsvc.exe]  <N/A><N/A>
[PID: 388][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 440][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\Program Files\Zone Labs\Integrity Client\zlxeap.dll]  <Check Point Inc.><6.0.202.000>
[PID: 492][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.7059>
    [C:\WINNT\system32\HPBMMON.DLL]  <Hewlett-Packard><10.00.16>
    [C:\WINNT\system32\hpdomon.dll]  <Hewlett-Packard><03.42.00>
    [C:\WINNT\system32\HPBHealr.dll]  <N/A><N/A>
[PID: 540][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  <Symantec Corporation><2.2.2.008>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><2.2.2.008>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  <Symantec Corporation><2.2.2.008>
[PID: 596][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe]  <Symantec Corporation><2.2.2.008>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><2.2.2.008>
[PID: 612][C:\Program Files\Symantec AntiVirus\DefWatch.exe]  <Symantec Corporation><9.0.3.1000>
[PID: 676][C:\progra~1\c4ebreg\c4ebreg.exe]  <IBM Global Services><6.11>
    [C:\progra~1\c4ebreg\osprules.dll]  <IBM Global Services><1.8>
    [C:\progra~1\c4ebreg\python23.dll]  <Python Software Foundation><2.3.4>
    [C:\progra~1\c4ebreg\pmemw.dll]  <N/A><N/A>
[PID: 736][c:\sdwork\issimsvc.exe]  <IBM Global Services><2.09>
[PID: 768][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  <Microsoft Corporation><7.00.9064.9150>
[PID: 872][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.6701>
[PID: 888][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6972>
[PID: 964][C:\Program Files\Symantec AntiVirus\Rtvscan.exe]  <Symantec Corporation><9.0.3.1000>
    [C:\WINNT\system32\CBA.DLL]  <Intel? Corporation><6.12.0.130 E>
    [C:\WINNT\system32\MsgSys.dll]  <Intel? Corporation><6.12.0.130 E>
    [C:\WINNT\system32\NTS.dll]  <Intel? Corporation><6.12.0.130 E>
    [C:\WINNT\system32\PDS.DLL]  <Intel? Corporation><6.12.0.130 E>
    [C:\Program Files\Symantec AntiVirus\NAVLU.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\Program Files\Symantec AntiVirus\I2ldvp3.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\Program Files\Symantec AntiVirus\ecmldr32.DLL]  <Symantec Corp.><1.1.0.3>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.3.0.28>
    [C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL]  <Symantec Corporation><9.0.3.1000>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\ecmsvr32.dll]  <Symantec Corporation><61.2.1.10>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\NAVEX32a.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\NAVENG32.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\Program Files\Symantec AntiVirus\IMail.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\Program Files\Symantec AntiVirus\NotesExt.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\Program Files\Symantec AntiVirus\vpmsece2.dll]  <Symantec Corporation><9.0.3.1000>
    [C:\Program Files\Symantec AntiVirus\DecSDK.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ID.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2SS.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2CAB.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2LHA.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2LZ.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2AMG.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2TAR.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2RTF.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2Text.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll]  <Symantec Corporation><9.0.3.1000>
[PID: 1044][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
[PID: 1064][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 1076][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 1380][C:\WINNT\Explorer.exe]  <Microsoft Corporation><5.00.3700.6690>
    [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.1.2003110300>
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  <Symantec Corporation><9.0.3.1000>
[PID: 1432][D:\ISH1 KT共享文件夹\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
[PID: 460][D:\ISH1 KT共享文件夹\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.JS  Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

顶起
gototop
 

启动项目--注册表
删除
<NMGameX_AutoRun><; C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX

修复
.VBS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.JS Error. [C:\WINNT\system32\WScript.exe "%1" %*]

删除文件
NMGameX.dll
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT