【求助】System进程
我的爱机这几天,system进程老是点用cpu 70%~~100%,搞到卡死了,用最新卡巴,瑞星,NOD32,ewido查毒,无发现毒。
请高手解救下。
以下是卡卡日志
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 10:45:35, on 2006-08-23
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE
[nod32kui.exe]
CommandLine = "D:\Tools\Eset\nod32kui.exe" /WAITSERVICE
[KAVPF.exe]
CommandLine = "D:\Tools\Kaspersky Anti-Hacker\kavpf.exe" /silence
[cfosspeed.exe]
CommandLine = "C:\Program Files\cFosSpeed\cFosSpeed.exe"
[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[PcBoost.exe]
CommandLine = "D:\Tools\pcboost\pcboost.exe"
[ram.exe]
CommandLine = "D:\Program Files\SYSTOOLS\Ram\ram.exe"
[spd.exe]
CommandLine = "C:\Program Files\cFosSpeed\spd.exe" -service
[nod32krn.exe]
CommandLine = D:\Tools\Eset\nod32krn.exe
[oodag.exe]
CommandLine = "D:\Program Files\O&O_Defrag\oodag.exe"
[conime.exe]
CommandLine = C:\WINDOWS\system32\conime.exe
[taskmgr.exe]
CommandLine = taskmgr.exe
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
[cmd.exe]
CommandLine = cmd /c ""F:\My Documents\工具\192.bat" "
[ping.exe]
CommandLine = ping -t 202.96.128.68
[cmd.exe]
CommandLine = cmd /c ""F:\My Documents\工具\182.bat" "
[ping.exe]
CommandLine = ping -t 192.168.0.1
[WangWang.exe]
CommandLine = "D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe"
[QQ.exe]
CommandLine = "C:\Program Files\Tencent\QQ\QQ.exe"
[TIMPlatform.exe]
CommandLine = "C:\Program Files\Tencent\QQ\TIMPlatform.exe" -Embedding
[KkScan.exe]
CommandLine = "d:\Program Files\Rising\KakaToolBar\KkScan.exe"
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R3 - Default URLSearchHook is missing
O1 - Hosts: 219.238.233.252 forum.ikaka.com
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Tools\Internet Download Manager\IDMIECC.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pcboost] D:\Tools\pcboost\pcboost.exe
O4 - HKCU\..\Run: [ram] D:\Program Files\SYSTOOLS\Ram\ram.exe
O4 - HKLM\..\Run: [nod32kui] "D:\Tools\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Kaspersky Anti-Hacker] D:\Tools\Kaspersky Anti-Hacker\kavpf.exe /silence
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: Download All Links with IDM - D:\Tools\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Tools\Internet Download Manager\IEExt.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.baidu.com
O15 - Trusted Zone: www3721com.cnnic.net.cn
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150171169013
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{379EC941-7831-4CAC-A983-869B0C94335B}: NameServer = 61.144.56.100,202.96.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{7C30E592-137A-4224-A41E-0FFAF65F21B4}: NameServer = 61.144.56.100,202.96.128.68
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - AppInit_DLLs: wbsys.dll
O20 - Winlogon Notify: WBSrv
O23 - Service: Adobe LM Service (Adobe LM Service) - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - "C:\Program Files\cFosSpeed\spd.exe" -service
O23 - Service: ewido anti-spyware 4.0 guard (ewido anti-spyware 4.0 guard) - Anti-Malware Development a.s. - D:\Tools\ewido anti-spyware 4.0\guard.exe
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: kavsvc (kavsvc) - Kaspersky Lab - "D:\Tools\KAV\kavsvc.exe"
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Tools\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag (O&O Defrag) - O&O Software GmbH - D:\Program Files\O&O_Defrag\oodag.exe