瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的CPU利用总是100%怎么办?好像什么病毒都查不出来啊?(有图)

1   1  /  1  页   跳转

我的CPU利用总是100%怎么办?好像什么病毒都查不出来啊?(有图)

我的CPU利用总是100%怎么办?好像什么病毒都查不出来啊?(有图)

谁能告诉我是什么原因啊?

附件附件:

下载次数:346
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-3 20:49:55
描述:



最后编辑2006-12-03 21:11:54
分享到:
gototop
 

看这个

附件附件:

下载次数:327
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-3 20:51:22
描述:



gototop
 

这个CSRSS怎么占这么多资源啊?他就没下过60,我机子被它拖死了,我该怎么办?
扫秒结果,高手帮我分析分析啊


2006-12-03,19:35:16

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <-650193><; C:\WINDOWS\system32\-650193.exe>  [N/A]
    <5076429><; C:\WINDOWS\system32\5076429.exe>  [N/A]
    <AGRSMMSG><; AGRSMMSG.exe>  [(Verified)Agere Systems]
    <BMMGAG><; RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor>  [IBM Corp.]
    <HotKeysCmds><; C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Intel Corporation]
    <IgfxTray><; C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Intel Corporation]
    <IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Corporation]
    <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
    <MS-4011 Memory Patch><; D:\RavSasser.exe -Patch>  [N/A]
    <MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <pdfFactory Pro 分配器 v2><; "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM>  [FinePrint Software, LLC]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <rkjefnh><; C:\WINDOWS\system32\rkjefnh.exe>  [N/A]
    <TP4EX><; tp4ex.exe>  [IBM Corporation]
    <TPHOTKEY><; C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe>  [N/A]
    <TrackPointSrv><; tp4serv.exe>  [(Verified)IBM Corporation]
    <vptray><; D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>  [Symantec Corporation]
    <wk><; C:\WINDOWS\system32\7faf361.exe>  [软告工作室]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\System32\REBUSI~1.SCR>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[DefWatch / DefWatch]
  <D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><Symantec Corporation>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IBM PM Service / IBMPMSVC]
  <C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[MATLAB Server / matlabserver]
  <d:\MATLAB6p5\webserver\bin\win32\matlabserver.exe><N/A>
[NOD32 Kernel Service / NOD32krn]
  <"C:\Program Files\Eset\nod32krn.exe"><Eset>
[Symantec AntiVirus Client / Norton AntiVirus Server]
  <D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><Symantec Corporation>
[pdfFactory Pro 分配器 v2 / pdfFactory Pro 分配器 v2]
  <"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /service><FinePrint Software, LLC>
[QCONSVC / QCONSVC]
  <System32\QCONSVC.EXE><N/A>
[Visual Studio Analyzer RPC bridge / Visual Studio Analyzer RPC bridge]
  <D:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe><Microsoft Corporation>
[WDelMgr20 / WDelMgr20]
  <C:\WINDOWS\system32\drivers\WDelMgr20.exe><N/A>

==================================
驱动程序
[aeaudio / aeaudio]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Agere Systems Soft Modem / AgereSoftModem]
  <System32\DRIVERS\AGRSM.sys><Agere Systems>
[AMON / AMON]
  <\??\C:\WINDOWS\system32\drivers\amon.sys><Eset>
[Intel(R) PRO Adapter Driver / E100B]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[IBM Access Support / EGATHDRV]
  <\??\C:\WINDOWS\System32\EGATHDRV.SYS><N/A>
[ialm / ialm]
  <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IBMPMDRV / IBMPMDRV]
  <System32\DRIVERS\ibmpmdrv.sys><IBM Corp.>
[IBMTPCHK / IBMTPCHK]
  <System32\drivers\IBMBLDID.SYS><N/A>
[NAVAP / NAVAP]
  <\??\D:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><Symantec Corporation>
[NAVAPEL / NAVAPEL]
  <\??\D:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><Symantec Corporation>
[NAVENG / NAVENG]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061129.017\NAVENG.sys><Symantec Corporation>
[NAVEX15 / NAVEX15]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061129.017\NAVEX15.sys><Symantec Corporation>
[npkcrypt / npkcrypt]
  <\??\D:\Program Files\Tencent\npkcrypt.sys><INCA Internet Co., Ltd.>
[NSC Infrared Device Driver / NSCIRDA]
  <System32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[NtFsLdf20 / NtFsLdf20]
  <C:\WINDOWS\SYSTEM32\DRIVERS\NtFsLdf20.SYS><Windows (R) 2000 DDK provider>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[Smapint / Smapint]
  <System32\drivers\Smapint.sys><Microsoft Corporation>
[smwdm / smwdm]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[SymEvent / SymEvent]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[TCP/IP Protocol Driver / Tcpip]
  <System32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TDSMAPI / TDSMAPI]
  <System32\drivers\TDSMAPI.SYS><N/A>
[IBM PS/2 TrackPoint Driver / Tp4Track]
  <System32\DRIVERS\tp4track.sys><IBM Corporation>
[TPHKDRV / TPHKDRV]
  <C:\WINDOWS\SYSTEM32\DRIVERS\TPHKDRV.SYS><IBM Corporation>
[TPPWR / TPPWR]
  <System32\drivers\Tppwr.sys><IBM Corp.>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
gototop
 

浏览器加载项
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>

==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 660][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 684][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NavLogon.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,1715]
    [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3,0,0,1715]
[PID: 732][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 744][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
[PID: 908][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1016][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
[PID: 1128][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
[PID: 1256][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
[PID: 1384][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1684][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\fppmon2.dll]  [FinePrint Software, LLC, 2.53]
    [C:\WINDOWS\system32\fppr232.dll]  [FinePrint Software, LLC, 2.53]
    [C:\WINDOWS\system32\prnmnt.dll]  [N/A, N/A]
[PID: 1780][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Eset\nodshex.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  [Symantec Corporation, 8.1.0.821]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 1, 5, 0, 0]
    [D:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3,0,0,1715]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,1715]
    [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3,0,0,1715]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,1715]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,1715]
[PID: 192][C:\Program Files\Eset\nod32kui.exe]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\nod32rui.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pu_dmon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_dmon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_emon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_emon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_mirr.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_mirr.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pu_upd.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_upd.dll]  [N/A, N/A]
[PID: 440][C:\Program Files\Eset\nod32krn.exe]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\nod32krr.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_dmon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_dmon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\ps_emon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_emon.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\ps_mirr.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_mirr.dll]  [N/A, N/A]
    [C:\Program Files\Eset\ps_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_upd.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_upd.dll]  [N/A, N/A]
[PID: 1884][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
[PID: 656][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1880][D:\Program Files\Tencent\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\Tencent\CoralAssist.DLL]  [Coral Team, 4.5.0 build 20060515]
    [D:\Program Files\Tencent\CoralQQ.DLL]  [Coral Team, 4.5.4 Build 20061001]
    [D:\Program Files\Tencent\ipsearcher.dll]  [N/A, 1.0.0.4]
    [D:\Program Files\Tencent\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [D:\Program Files\Tencent\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\Tencent\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\Program Files\Tencent\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\Program Files\Tencent\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQMainFrame.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\CQQApplication.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\GroupLive.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\QQSysMsgMng.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQPlugin.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QRingMng.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\Program Files\Tencent\VPortal.dll]  [, 1, 0, 0, 4]
    [D:\Program Files\Tencent\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\Program Files\Tencent\QQAvatar.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\Tencent\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\BQQApplication.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\Tencent\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [D:\Program Files\Tencent\QQAllInOne.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [D:\Program Files\Tencent\QQCustomFace.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
    [D:\Program Files\Tencent\QQSceneMng.dll]  [N/A, N/A]
    [D:\Program Files\Tencent\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [D:\Program Files\Tencent\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 1, 11]
    [D:\Program Files\Tencent\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [D:\Program Files\Tencent\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\Tencent\QQMsgFriendMng.dll]  [N/A, N/A]
gototop
 

[PID: 544][D:\Program Files\Tencent\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [D:\Program Files\Tencent\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1500][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 3228][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3536]
[PID: 3032][D:\Program Files\TheWorld 2.0\TheWorld.exe]  [Phoenix Studio, 2, 0, 0, 8]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 1, 5, 0, 0]
    [D:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_003.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[PID: 432][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2932][d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.3.0.220]
    [d:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [d:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 71]
    [d:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [d:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [d:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, N/A]
    [d:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [d:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [d:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [d:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 11]
    [d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  [ , 2, 3, 0, 37]
    [d:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 3, 8]
    [d:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 55]
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
[PID: 3020][C:\Documents and Settings\pl\桌面\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
NOD32 protected [MSAFD Tcpip [TCP/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [UDP/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [RAW/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP UDP Service Provider]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP TCP Service Provider]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)

==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\command.com

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

首先,那个文件属于系统正常文件,但是它下面的DLL是否有病毒,不得而知。
gototop
 

我查不出病毒啊?我该怎么办啊???????急死我了啊
谁帮帮我啊
gototop
 


运行SR,删除注册表项:

<-650193><; C:\WINDOWS\system32\-650193.exe> [N/A]
<5076429><; C:\WINDOWS\system32\5076429.exe> [N/A]
rkjefnh><; C:\WINDOWS\system32\rkjefnh.exe> [N/A]
删除相应文件

右键打开硬盘,删除:
Autorun.inf
D:\command.com

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT