查看: 3545|回复: 10
收起左侧

[已解决] SRE报告,症状:CPU经常到100%

 关闭 [复制链接]
兔斯基
发表于 2007-9-29 12:33:50 | 显示全部楼层 |阅读模式
某SRE报告,请分析下,症状:CPU经常到100%,IEMC.exe等进程是否有问题,另卡巴、AVG、windows清理助手等扫描无毒
  1. 2007-09-29,12:22:30

  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows 2000 Professional Service Pack 4 (Build 2195)
  5. - 管理权限用户 - 完整功能

  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Corporation]
  18.       [(Verified)Google Inc.]
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  20.     <>  [N/A]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  22.       [(Verified)Microsoft Corporation]
  23.     <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe">  [Kaspersky Lab]
  24.       [N/A]
  25.       [深圳市三代科技开发有限公司]
  26.     <"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
  27.     <!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [(Verified)GRISOFT s.r.o.]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.       [(Verified)Microsoft Corporation]
  30.       [(Verified)Microsoft Corporation]
  31. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  32.     <>  [N/A]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  34.       [N/A]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  36.       [Kaspersky Lab]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\noitfy]
  38.       [N/A]
  39. [HKEY_CURRENT_USER\Control Panel\Desktop]
  40.       [(Verified)Microsoft Corporation]

  41. ==================================
  42. 启动文件夹
  43. N/A

  44. ==================================
  45. 服务
  46. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  47.   
  48. [卡巴斯基互联网安全套装 6.0 / AVP][Running/Auto Start]
  49.   <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r>
  50. [C-DillaSrv / C-DillaSrv][Running/Auto Start]
  51.   
  52. [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  53.   
  54. [Google Updater Service / gusvc][Stopped/Manual Start]
  55.   <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">
  56. [IEMC / IEMC][Running/Auto Start]
  57.   <"C:\WINNT\system32\Iemc.exe" -service>
  58. [卡巴斯基网络代理 / klnagent][Running/Auto Start]
  59.   <"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe">
  60. [Messenger / Messenger][Stopped/Boot Start]
  61.   <\SystemRoot\C:\WINNT\system32\services.exe>
  62. [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  63.   
  64. [RemoteService / RemoteService][Stopped/Manual Start]
  65.   <>
  66. [scsvc / scsvc][Running/Auto Start]
  67.   <>
  68. [Svcam / Svcam][Running/Auto Start]
  69.   <>
  70. [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  71.   C:\WINNT\system32\mspmsnsv.dll>

  72. ==================================
  73. 驱动程序
  74. [2067187 / 2067187][Stopped/Boot Start]
  75.   <\SystemRoot\System32\drivers\2067187.sys>
  76. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  77.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys>
  78. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  79.   
  80. [C-Dilla / C-Dilla][Stopped/Manual Start]
  81.   <\??\C:\WINNT\system32\drivers\CDANT.SYS>
  82. [c12969609 / c12969609][Stopped/Boot Start]
  83.   <\SystemRoot\System32\drivers\c12969609.sys>
  84. [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  85.   
  86. [dmboot / dmboot][Stopped/Disabled]
  87.   
  88. [Logical Disk Manager Driver / dmio][Running/Boot Start]
  89.   <\SystemRoot\System32\drivers\dmio.sys>
  90. [dmload / dmload][Running/Boot Start]
  91.   <\SystemRoot\System32\drivers\dmload.sys>
  92. [Smart card reader 2000 service / ft2k][Running/Manual Start]
  93.   
  94. [gaiddabj / gaiddabj][Stopped/Boot Start]
  95.   <\SystemRoot\system32\drivers\gaiddabj.sys>
  96. [kl1 / kl1][Running/Boot Start]
  97.   <\SystemRoot\system32\drivers\kl1.sys>
  98. [klif / klif][Running/System Start]
  99.   <\??\C:\WINNT\system32\drivers\klif.sys>
  100. [npkcrypt / npkcrypt][Running/Auto Start]
  101.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys>
  102. [nv / nv][Running/Manual Start]
  103.   
  104. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  105.   
  106. [Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  107.   
  108. [ScFilter / ScFilter][Stopped/Manual Start]
  109.   <\??\C:\WINNT\system32\ScFilter.sys>
  110. [SiS AGP Filter / SISAGP][Running/Boot Start]
  111.   <\SystemRoot\system32\DRIVERS\SISAGPx.sys>
  112. [sjhpakd / sjhpakd][Stopped/Manual Start]
  113.   <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sjhpakdlxj>

  114. ==================================
  115. 浏览器加载项
  116. [IEHelpObj Class]
  117.   {2D585C2F-24E6-4A88-A986-EE402F1A8EBF}
  118. [Google Toolbar Helper]
  119.   {AA58ED58-01DD-4d91-8333-CF10577473F7}
  120. [Google Toolbar Notifier BHO]
  121.   {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
  122. [Web反病毒保护]
  123.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}
  124. [QQ]
  125.   {c95fe080-8f5d-11d2-a20b-00aa003c157b}
  126. [FlashGet]
  127.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <, N/A>
  128. [QQIEFloatBarCfgCmd Class]
  129.   {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <, N/A>
  130. [@msdxmLC.dll,-1@2052,电台(&R)]
  131.   {8E718888-423F-11D2-876E-00A0C9082467}
  132. [&Google]
  133.   {2318C2B1-4965-11d4-9B18-009027A5CD4F}
  134. [InstaFred]
  135.   {1F831FA1-42FC-11D4-95A6-0080AD30DCE1}
  136. [AcDcToday 控件]
  137.   {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}
  138. [NOXLATE-BANR]
  139.   {AE563722-B4F5-11D4-A415-00108302FDFD}
  140. [Shockwave Flash Object]
  141.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  142. [AcPreview 控件]
  143.   {F281A59C-7B65-11D3-8617-0010830243BD}
  144. [&使用暴风下载器下载]
  145.   
  146. [上传到QQ网络硬盘]
  147.   
  148. [使用网际快车下载]
  149.   <, N/A>
  150. [使用网际快车下载全部链接]
  151.   <, N/A>
  152. [添加到QQ自定义面板]
  153.   
  154. [添加到QQ表情]
  155.   
  156. [用QQ彩信发送该图片]
  157.   
  158. [豪杰超级解霸V8实时播放]
  159.   

  160. ==================================
  161. 正在运行的进程
  162. [PID: 176][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  163. [PID: 200][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  164. [PID: 220][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6997]
  165.     [C:\WINNT\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  166.     [C:\WINNT\system32\LogonNotify.dll]  [N/A, N/A]
  167.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  168.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  169.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  170. [PID: 248][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.7035]
  171.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  172.     [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
  173. [PID: 260][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.7011]
  174.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  175. [PID: 396][C:\WINNT\System32\SCardSvr.exe]  [Microsoft Corporation, 5.00.2195.6609]
  176. [PID: 472][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  177.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  178. [PID: 520][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
  179.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  180.     [C:\WINNT\system32\adimon.dll]  [Autodesk, Inc., 3,0,14,176]
  181.     [C:\WINNT\system32\heidi3.dll]  [Autodesk, Inc., 3,0,14,176]
  182.     [C:\WINNT\system32\KMPJLMN.DLL]  [KYOCERA MITA Corporation, 0, 3, 259, 6]
  183.     [C:\WINNT\system32\FXZSMLHI.DLL]  [Fuji Xerox Co., Ltd., 1.000.703.21]
  184.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  185.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  186. [PID: 552][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe]  [GRISOFT s.r.o., 7, 5, 1, 22]
  187.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
  188.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  189. [PID: 584][C:\WINNT\system32\DRIVERS\CDANTSRV.EXE]  [C-Dilla Ltd, 3.24.010]
  190. [PID: 604][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  191.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  192. [PID: 644][C:\WINNT\system32\Iemc.exe]  [N/A, N/A]
  193.     [C:\WINNT\FExcep.dll]  [N/A, N/A]
  194.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  195.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  196.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  197. [PID: 656][C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe]  [Kaspersky Lab, 5.0.0474.0]
  198.     [C:\Program Files\Kaspersky Lab\NetworkAgent\klstfix.dll]  [Kaspersky Lab, 5.0.0474.0]
  199.     [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsn.dll]  [Kaspersky Lab, 5.0.0474.0]
  200.     [C:\Program Files\Kaspersky Lab\NetworkAgent\kltrace.dll]  [Kaspersky Lab, 5.0.0474.0]
  201.     [C:\Program Files\Kaspersky Lab\NetworkAgent\FSSync.dll]  [Kaspersky Lab, 5.0.0474.0]
  202.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  203.     [C:\Program Files\Kaspersky Lab\NetworkAgent\klsecur2.dll]  [Kaspersky Lab, 5.0.0474.0]
  204. [PID: 756][C:\WINNT\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.4403]
  205.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  206.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  207. [PID: 828][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
  208. [PID: 772][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6972]
  209.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  210.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  211.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  212. [PID: 1056][C:\WINNT\system32\scsvc.exe]  [, 3, 1, 0, 0]
  213.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  214.     [C:\WINNT\FExcep.dll]  [N/A, N/A]
  215.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  216.     [C:\WINNT\system32\procinfo.dll]  [N/A, N/A]
  217.     [C:\WINNT\system32\PMDLL5.dll]  [N/A, N/A]
  218.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  219.     [C:\WINNT\system32\ForbidModem.dll]  [N/A, N/A]
  220. [PID: 1168][C:\WINNT\system32\Svcam.exe]  [, 1]
  221.     [C:\WINNT\FExcep.dll]  [N/A, N/A]
  222.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  223.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  224. [PID: 1204][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
  225. [PID: 1256][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  226. [PID: 1304][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
  227.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  228.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  229.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  230.     [C:\WINNT\system32\IEHlpCom.dll]  [, 1, 0, 0, 1]
  231.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
  232.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  233.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  234.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  235. [PID: 1428][C:\WINNT\system32\WinShell.exe]  [N/A, N/A]
  236.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  237.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  238.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  239. [PID: 1448][C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe]  [深圳市三代科技开发有限公司, 1, 1, 0, 4]
  240.     [C:\Program Files\Ringz Studio\Storm Downloader\boost_thread-vc6-mt-1_31.dll]  [N/A, N/A]
  241.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  242.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  243.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  244.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  245. [PID: 1484][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe]  [GRISOFT s.r.o., 7, 5, 1, 43]
  246.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
  247.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  248.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  249.     [C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL]  [N/A, N/A]
  250.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  251. [PID: 1492][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
  252.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  253.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  254.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  255. [PID: 1500][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe]  [Google Inc., 2, 0, 301, 1654]
  256.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll]  [Google Inc., 2, 0, 301, 7164]
  257.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  258.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  259.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  260.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll]  [Google Inc., 2, 0, 301, 7164]
  261.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll]  [Google Inc., 2, 0, 301, 7164]
  262.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  263. [PID: 860][C:\Program Files\Ringz Studio\Storm Downloader\TDUpdate.exe]  [N/A, N/A]
  264.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  265. [PID: 688][C:\WINNT\system32\taskmgr.exe]  [Microsoft Corporation, 5.00.2195.6620]
  266.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  267.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  268.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  269. [PID: 1068][D:\常用工具\杀毒\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  270.     [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
  271.     [C:\WINNT\system32\FDHook3.dll]  [N/A, N/A]
  272.     [C:\WINNT\system32\dllhook.dll]  [N/A, N/A]
  273.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]

  274. ==================================
  275. 文件关联
  276. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  277. .EXE  OK. ["%1" %*]
  278. .COM  OK. ["%1" %*]
  279. .PIF  OK. ["%1" %*]
  280. .REG  OK. [regedit.exe "%1"]
  281. .BAT  OK. ["%1" %*]
  282. .SCR  OK. ["%1" /S]
  283. .CHM  OK. ["C:\WINNT\hh.exe" %1]
  284. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  285. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  286. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  287. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  288. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  289. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  290. ==================================
  291. Winsock 提供者
  292. N/A

  293. ==================================
  294. Autorun.inf
  295. N/A

  296. ==================================
  297. HOSTS 文件
  298. 127.0.0.1       localhost

  299. ==================================
  300. API HOOK
  301. 警告!System Repair Engineer 提醒
  302. 你下面的函数内容与预期值不符,他
  303. 们可能被一些恶意的软件所修改:
  304. RVA  错误: LoadLibraryA
  305. RVA  错误: LoadLibraryExA
  306. RVA  错误: LoadLibraryExW
  307. RVA  错误: LoadLibraryW

  308. ==================================
复制代码

[ 本帖最后由 兔斯基 于 2007-9-29 12:49 编辑 ]
雪茄烟
发表于 2007-9-29 13:13:40 | 显示全部楼层
看不懂报告耶,肯定是中毒了.你进安全模式下杀下
风雪
发表于 2007-9-29 15:00:52 | 显示全部楼层
System Repair Engineer2.5(SREng)或者System Repair Engineer2.5(SREng)下载System Repair Engineer2.5扫描日志上来.
如果不能运行将下载的SREngPS.EXE重命名为SREngPS.com(SREngPS.scr\SREngPS.bat\SREngPS.pif)或者改名为11BD.abc等等自己随便改运行.
sreng——智能扫描——扫描——保存日志——打开日志记事本SREngLOG——Ctrl+A——Ctrl+C——到论坛回复——Ctrl+V。
使用新版本扫描日志上来。
石油工业
发表于 2007-9-29 15:43:03 | 显示全部楼层
不怎么看得懂
随风飘扬
发表于 2007-9-29 17:26:42 | 显示全部楼层
楼主进任务管理器看下是哪些程序占CPU那么高啊?
兔斯基
 楼主| 发表于 2007-9-29 19:34:25 | 显示全部楼层
谢谢楼上的各位
今天发现进程里IEMC.EXE 占CPU较高,用UNlocker发现其与SCSVC.EXE SVCAM.EXE两个文件关联,解锁后可删除,但SCSVC.EXE SVCAM.EXE这两个无法删除,重启后这三个进程仍然存在;后进入安全模式下,发现有SCSVC.EXE SVCAM.EXE这两个进程,用冰刃无法结束,且冰刃未在相应文件夹中找到这两个文件;UNlocker无法删除。后进入纯dos模式,删除IEMC.EXE,另两个提示文件不存在。重启后三个进程仍然存在。
现在还没试删2067187.sys这个驱动文件
风雪
发表于 2007-9-29 22:45:17 | 显示全部楼层
楼主不肯使用新版本扫描日志。
下面给一个参考。
用xdelbox(http://www.i170.com/attach/97670969-F47C-4A8B-9529-F0F602EFA902下载)删除下面文件(按住鼠标左键向下拖动,用鼠标从第一行拖动从上往下到最后一行,右键复制,或者(添入“文件路径”点击“添加”路径),在xdelbox窗口空白处点右键-从剪贴板导入,在抑制再生前打钩,在要删除文件上点击右键,选择立刻重启删除,运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等))。
C:\WINNT\system32\ScFilter.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sjhpakdlxj
C:\WINNT\system32\drivers\gaiddabj.sys
C:\WINNT\System32\drivers\dmload.sys
C:\WINNT\System32\drivers\c12969609.sys
C:\WINNT\System32\drivers\2067187.sys
C:\WINNT\system32\Svcam.exe
C:\WINNT\system32\scsvc.exe
C:\WINNT\system32\Iemc.exe
C:\WINNT\system32\WinShell.exe
C:\WINNT\system32\IEHlpCom.dll
(C:\WINNT\FExcep.dll
C:\WINNT\system32\FDHook3.dll
C:\WINNT\system32\ForbidModem.dll
C:\WINNT\system32\procinfo.dll
C:\WINNT\system32\PMDLL5.dll
C:\WINNT\system32\dllhook.dll)括号中的发到样本区测试。或者http://www.virscan.org测试一下。

运行 System Repair Engineer在"启动项目->服务->"Win32服务应用程序"选中"隐藏微软服务" 然后将下面名称的服务
"删除服务"->"设置"->"否" (注意: 按"否"是确认删除服务,按"是"为取消操作)
[IEMC / IEMC][Running/Auto Start]
  <"C:\WINNT\system32\Iemc.exe" -service>

运行 System Repair Engineer在"启动项目->服务->"驱动程序"选中"隐藏微软服务" 然后将下面名称的服务
"删除服务"->"设置"->"否" (注意: 按"否"是确认删除服务,按"是"为取消操作)
[2067187 / 2067187][Stopped/Boot Start]
  <\SystemRoot\System32\drivers\2067187.sys>
[c12969609 / c12969609][Stopped/Boot Start]
  <\SystemRoot\System32\drivers\c12969609.sys>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys>
[gaiddabj / gaiddabj][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\gaiddabj.sys>
[sjhpakd / sjhpakd][Stopped/Manual Start]
  <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sjhpakdlxj>
[ScFilter / ScFilter][Stopped/Manual Start]
  <\??\C:\WINNT\system32\ScFilter.sys>

Windows清理助手升级查一下:
http://www.arswp.com/download/arswp2/arswp2.zip
兔斯基
 楼主| 发表于 2007-10-7 10:34:27 | 显示全部楼层

回复 undefined 的帖子

谢谢风雪,解决了
风雪
发表于 2007-10-7 10:40:55 | 显示全部楼层
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys>
不要删除,我的失误。
兔斯基
 楼主| 发表于 2007-10-7 10:49:54 | 显示全部楼层

回复 undefined 的帖子

再次感谢风雪,不过偶因为另一台正常的机器里也有dmload.sys,所以没删,不过这个不知道正常不
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-23 07:08 , Processed in 0.124336 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表