瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】有个进程占用资源相当大???

1   1  /  1  页   跳转

【原创】有个进程占用资源相当大???

【原创】有个进程占用资源相当大???

新装系统两周左右,启动到桌面时,等好久,启动后,反应很慢,有个PID为1116的进程,占用CPU 99%,内存160M,持续5-10分钟后,机子恢复正常,但该进程始终占用内存在52M左右,用nod32查杀没有病毒,现扫描帖出如下,请各位帮忙看下!
--------------
[CODE]
2007-02-23,10:59:46
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Advanced Server Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
    <NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  [N/A]
    <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
    <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Visual Studio Debugger Proxy Service / DbgProxy][Stopped/Manual Start]
  <C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Packages\Debugger\dbgproxy.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[Microsoft Search / MSSEARCH][Running/Auto Start]
  <"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Stopped/Manual Start]
  <C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[NOD32 Kernel Service / NOD32krn][Running/Auto Start]
  <"C:\Program Files\Eset\nod32krn.exe"><Eset>
[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  <C:\WINNT\system32\nvsvc32.exe><NVIDIA Corporation>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  <C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>

==================================
驱动程序
[AMON / AMON][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\amon.sys><Eset>
[CMBProtector / CMBProtector][Running/Auto Start]
  <\??\C:\WINNT\system32\Drivers\CMBProtector.dat><N/A>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  <system32\drivers\cmuda.sys><C-Media Inc>
[d346bus / d346bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d346bus.sys><>
[d346prt / d346prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d346prt.sys><>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[IdeBusDr / IdeBusDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start]
  <system32\DRIVERS\Rtlnic.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>

==================================
浏览器加载项
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[PowerBand]
  {6DD4D4B2-79D0-4073-B8CA-C87273AEC114} <D:\Web_资料\JavaScript\powerband205_JS工具\PowerBand.dll, AWater>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINNT\system32\muweb.dll, Microsoft Corporation>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
最后编辑2007-02-23 11:56:37
分享到:
gototop
 

接上面
==================================
正在运行的进程
[PID: 184][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 208][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 228][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6714]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
[PID: 256][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.6700]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
[PID: 268][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.6695]
[PID: 456][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 488][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
    [C:\WINNT\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINNT\system32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINNT\system32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 516][C:\WINNT\system32\msdtc.exe]  [Microsoft Corporation, 1999.9.3421.3]
[PID: 640][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 664][C:\WINNT\System32\llssrv.exe]  [Microsoft Corporation, 5.00.2195.6697]
[PID: 756][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  [Microsoft Corporation, 7.10.3077]
    [C:\Program Files\Common Files\Microsoft Shared\VS7Debug\2052\mdmui.dll]  [Microsoft Corporation, 7.10.3077]
    [C:\Program Files\Common Files\Microsoft Shared\VS7Debug\csm.dll]  [Microsoft Corporation, 7.10.3077]
    [C:\WINNT\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Microsoft Shared\VS7Debug\msdbg2.dll]  [Microsoft Corporation, 7.10.3077]
[PID: 784][C:\Program Files\Eset\nod32krn.exe]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\nod32krr.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_dmon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_dmon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\ps_emon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_emon.dll]  [N/A, N/A]
    [C:\WINNT\system32\imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\ps_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\ps_upd.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_upd.dll]  [N/A, N/A]
[PID: 716][C:\WINNT\system32\WINDOW~1\Server\nspmon.exe]  [Microsoft Corporation, 4.1.00.3934]
gototop
 

接上面
---------

[PID: 840][C:\WINNT\system32\WINDOW~1\Server\nscm.exe]  [Microsoft Corporation, 4.1.00.3934]
[PID: 932][C:\WINNT\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.13.10.2742]
[PID: 984][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
[PID: 1000][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6704]
[PID: 1020][C:\WINNT\System32\snmp.exe]  [Microsoft Corporation, 5.00.2195.7112]
    [C:\Program Files\Microsoft SQL Server\MSSQL\BINN\sqlsnmp.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINNT\System32\odbcint.dll]  [Microsoft Corporation, 3.520.6526.0]
[PID: 1052][C:\WINNT\system32\stisvc.exe]  [Microsoft Corporation, 5.00.2195.6656]
[PID: 1104][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
[PID: 1116][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 1136][C:\WINNT\system32\Dfssvc.exe]  [Microsoft Corporation, 5.00.2195.6664]
[PID: 1164][C:\WINNT\system32\inetsrv\inetinfo.exe]  [Microsoft Corporation, 5.00.0984]
    [C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINNT\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1188][C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe]  [Microsoft Corporation, 9.107.5512.0]
    [C:\Program Files\Common Files\System\MSSearch\Bin\mssws.dll]  [Microsoft Corporation, 9.107.5512.0]
    [C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\mssrch.dll]  [Microsoft Corporation, 9.107.5512.0]
    [C:\Program Files\Common Files\System\MSSearch\Bin\tquery.dll]  [Microsoft Corporation, 9.107.5512.0]
    [C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\propdefs.dll]  [Microsoft Corporation, 9.107.5512.0]
    [C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\srchidx.dll]  [Microsoft Corporation, 9.107.5512.0]
[PID: 1236][C:\WINNT\system32\WINDOW~1\Server\nspm.exe]  [Microsoft Corporation, 4.1.00.3917]
    [C:\WINNT\system32\odbcint.dll]  [Microsoft Corporation, 3.520.6526.0]
    [C:\WINNT\system32\odbccp32.dll]  [Microsoft Corporation, 3.520.6526.0]
    [C:\WINNT\system32\tssoft32.acm]  [DSP GROUP, INC., 1.01]
    [C:\WINNT\system32\tsd32.dll]  [N/A, N/A]
    [C:\WINNT\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINNT\system32\iac25_32.ax]  [Intel Corporation, 2.05.53]
    [C:\WINNT\system32\vorbis.acm]  [HMS http://hp.vector.co.jp/authors/VA012897/, 0, 0, 3, 6]
    [C:\WINNT\system32\vct3216.acm]  [Voxware, Inc., 1.6.0.17]
    [C:\WINNT\system32\vct3216.dll]  [Voxware, Inc., 1.6.0.12]
    [C:\WINNT\system32\msms001.vwp]  [Voxware, Inc., 2.0.2.61]
    [C:\WINNT\system32\mvoice.vwp]  [Voxware, Inc., 2.0.0.12.01]
    [C:\WINNT\system32\msaud32.acm]  [Microsoft Corporation, 7.01.00.3055]
    [C:\WINNT\system32\sl_anet.acm]  [Sipro Lab Telecom Inc., 3.02]
[PID: 1328][C:\WINNT\system32\WINDOW~1\Server\nsum.exe]  [Microsoft Corporation, 4.1.00.3930]
[PID: 1512][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll]  [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Eset\nodshex.dll]  [N/A, N/A]
[PID: 1860][C:\Program Files\Eset\nod32kui.exe]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\nod32rui.dll]  [N/A, N/A]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Eset\pu_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pu_dmon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_dmon.dll]  [N/A, N/A]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\Program Files\Eset\pu_emon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_emon.dll]  [N/A, N/A]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\Eset\pu_imon.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_imon.dll]  [N/A, N/A]
    [C:\Program Files\Eset\pu_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pu_upd.dll]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\pr_upd.dll]  [N/A, N/A]
[PID: 1944][C:\WINNT\system32\ctfmon.exe]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\MSUTB.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\mui\fallback\0804\msutb.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1916][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 2136][C:\WINNT\system32\taskmgr.exe]  [Microsoft Corporation, 5.00.2195.6620]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 2068][C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE]  [Microsoft Corporation, 11.0.5515]
[PID: 656][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 1200][C:\Program Files\Tencent\TT\TTraveler.exe]  [腾讯公司, 3.2.200.275]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\Tencent\TT\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL]  [Microsoft Corporation, 5.00.2916.0]
[PID: 1176][C:\Program Files\Tencent\TM\TMDlls\TM.exe]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\BasicCtrlDll.dll]  [Tencent, 0, 3, 3, 9]
    [C:\Program Files\Tencent\TM\TMDlls\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\Program Files\Tencent\TM\TMDlls\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\TM\TMDlls\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Tencent\TM\TMDlls\BaseUIClass.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\Program Files\Tencent\TM\TMDlls\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Tencent\TM\TMDlls\RICHED20.DLL]  [Microsoft Corporation, 5.31.23.1218]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\Tencent\TM\TMDlls\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\TM\TMDlls\QQRes.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\npkcntc.dll]  [INCA Internet Co., Ltd., 2005, 9, 1, 1]
    [C:\Program Files\Tencent\TM\TMDlls\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
gototop
 

接上面
---------
[C:\Program Files\Tencent\TM\TMDlls\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\Tencent\TM\TMDlls\WizardCtrl.dll]  [Tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQMainFrame.dll]  [TENCENT, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\CQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\FrameBar.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\UserRelationWeight.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQAllInOne.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\MiscCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\TM\TMDlls\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Program Files\Tencent\TM\TMDlls\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 0, 3, 0, 43]
    [C:\Program Files\Tencent\TM\TMDlls\LongConnection.dll]  [tencent, 0, 3, 3, 8]
    [C:\Program Files\Tencent\TM\TMDlls\ShareFiles.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\TM\TMDlls\QQMMSender.dll]  [N/A, N/A]
[PID: 308][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1284][C:\Program Files\Eset\nod32.exe]  [Eset , 2, 51, 26 ]
    [C:\Program Files\Eset\nod32r.dll]  [N/A, N/A]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 444][C:\Program Files\Thunder Network\WebThunder\WebThunder.exe]  [深圳市迅雷网络技术有限公司, 1, 6, 0, 87]
    [C:\Program Files\Thunder Network\WebThunder\taskmanage.dll]  [Thunder Networking Technologies,LTD, 1, 6, 0, 87]
    [C:\Program Files\Thunder Network\WebThunder\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 12, 3, 46]
    [C:\Program Files\Thunder Network\WebThunder\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 12, 3, 46]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\Program Files\Thunder Network\WebThunder\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 43]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\Thunder Network\WebThunder\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 3, 0, 228]
    [C:\Program Files\Thunder Network\WebThunder\iEmbedShell.dll]  [ , 1, 0, 0, 14]
    [C:\Program Files\Thunder Network\WebThunder\iEmbed07.dll]  [ , 3, 1, 0, 58]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 1544][D:\SoftWare_保留\Tools\网络安全\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
    [C:\WINNT\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [D:\SoftWare_保留\Tools\网络安全\sreng2\Plugins\SRECXTMG.SRE]  [Smallfrogs Studio, 1, 5, 0, 55]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

新装系统两周左右,启动到桌面时,等好久,启动后,反应很慢,有个PID为1116的进程,占用CPU 99%,内存160M,持续5-10分钟后,机子恢复正常
是什么进程?
gototop
 

PID为1116的进程 是什么进程? 这得问你 每个机器都不同的 PID都不是固定的
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT