某SRE报告,请分析下,症状:CPU经常到100%,IEMC.exe等进程是否有问题,另卡巴、AVG、windows清理助手等扫描无毒
- 2007-09-29,12:22:30
- System Repair Engineer 2.3.13.690
- Smallfrogs (http://www.KZTechs.com)
- Windows 2000 Professional Service Pack 4 (Build 2195)
- - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- [(Verified)Microsoft Corporation]
- [(Verified)Google Inc.]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- [(Verified)Microsoft Corporation]
- <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"> [Kaspersky Lab]
- [N/A]
- [深圳市三代科技开发有限公司]
- <"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
- <!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [(Verified)GRISOFT s.r.o.]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- [(Verified)Microsoft Corporation]
- [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
- [Kaspersky Lab]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\noitfy]
- [N/A]
- [HKEY_CURRENT_USER\Control Panel\Desktop]
- [(Verified)Microsoft Corporation]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
-
- [卡巴斯基互联网安全套装 6.0 / AVP][Running/Auto Start]
- <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r>
- [C-DillaSrv / C-DillaSrv][Running/Auto Start]
-
- [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
-
- [Google Updater Service / gusvc][Stopped/Manual Start]
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">
- [IEMC / IEMC][Running/Auto Start]
- <"C:\WINNT\system32\Iemc.exe" -service>
- [卡巴斯基网络代理 / klnagent][Running/Auto Start]
- <"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe">
- [Messenger / Messenger][Stopped/Boot Start]
- <\SystemRoot\C:\WINNT\system32\services.exe>
- [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
-
- [RemoteService / RemoteService][Stopped/Manual Start]
- <>
- [scsvc / scsvc][Running/Auto Start]
- <>
- [Svcam / Svcam][Running/Auto Start]
- <>
- [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
- C:\WINNT\system32\mspmsnsv.dll>
- ==================================
- 驱动程序
- [2067187 / 2067187][Stopped/Boot Start]
- <\SystemRoot\System32\drivers\2067187.sys>
- [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
- <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys>
- [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
-
- [C-Dilla / C-Dilla][Stopped/Manual Start]
- <\??\C:\WINNT\system32\drivers\CDANT.SYS>
- [c12969609 / c12969609][Stopped/Boot Start]
- <\SystemRoot\System32\drivers\c12969609.sys>
- [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
-
- [dmboot / dmboot][Stopped/Disabled]
-
- [Logical Disk Manager Driver / dmio][Running/Boot Start]
- <\SystemRoot\System32\drivers\dmio.sys>
- [dmload / dmload][Running/Boot Start]
- <\SystemRoot\System32\drivers\dmload.sys>
- [Smart card reader 2000 service / ft2k][Running/Manual Start]
-
- [gaiddabj / gaiddabj][Stopped/Boot Start]
- <\SystemRoot\system32\drivers\gaiddabj.sys>
- [kl1 / kl1][Running/Boot Start]
- <\SystemRoot\system32\drivers\kl1.sys>
- [klif / klif][Running/System Start]
- <\??\C:\WINNT\system32\drivers\klif.sys>
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys>
- [nv / nv][Running/Manual Start]
-
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
-
- [Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
-
- [ScFilter / ScFilter][Stopped/Manual Start]
- <\??\C:\WINNT\system32\ScFilter.sys>
- [SiS AGP Filter / SISAGP][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\SISAGPx.sys>
- [sjhpakd / sjhpakd][Stopped/Manual Start]
- <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sjhpakdlxj>
- ==================================
- 浏览器加载项
- [IEHelpObj Class]
- {2D585C2F-24E6-4A88-A986-EE402F1A8EBF}
- [Google Toolbar Helper]
- {AA58ED58-01DD-4d91-8333-CF10577473F7}
- [Google Toolbar Notifier BHO]
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
- [Web反病毒保护]
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}
- [QQ]
- {c95fe080-8f5d-11d2-a20b-00aa003c157b}
- [FlashGet]
- {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <, N/A>
- [QQIEFloatBarCfgCmd Class]
- {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <, N/A>
- [@msdxmLC.dll,-1@2052,电台(&R)]
- {8E718888-423F-11D2-876E-00A0C9082467}
- [&Google]
- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
- [InstaFred]
- {1F831FA1-42FC-11D4-95A6-0080AD30DCE1}
- [AcDcToday 控件]
- {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}
- [NOXLATE-BANR]
- {AE563722-B4F5-11D4-A415-00108302FDFD}
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000}
- [AcPreview 控件]
- {F281A59C-7B65-11D3-8617-0010830243BD}
- [&使用暴风下载器下载]
-
- [上传到QQ网络硬盘]
-
- [使用网际快车下载]
- <, N/A>
- [使用网际快车下载全部链接]
- <, N/A>
- [添加到QQ自定义面板]
-
- [添加到QQ表情]
-
- [用QQ彩信发送该图片]
-
- [豪杰超级解霸V8实时播放]
-
- ==================================
- 正在运行的进程
- [PID: 176][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
- [PID: 200][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
- [PID: 220][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997]
- [C:\WINNT\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\LogonNotify.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 248][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.7035]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
- [PID: 260][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.7011]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 396][C:\WINNT\System32\SCardSvr.exe] [Microsoft Corporation, 5.00.2195.6609]
- [PID: 472][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 520][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.7059]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\adimon.dll] [Autodesk, Inc., 3,0,14,176]
- [C:\WINNT\system32\heidi3.dll] [Autodesk, Inc., 3,0,14,176]
- [C:\WINNT\system32\KMPJLMN.DLL] [KYOCERA MITA Corporation, 0, 3, 259, 6]
- [C:\WINNT\system32\FXZSMLHI.DLL] [Fuji Xerox Co., Ltd., 1.000.703.21]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [PID: 552][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe] [GRISOFT s.r.o., 7, 5, 1, 22]
- [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 584][C:\WINNT\system32\DRIVERS\CDANTSRV.EXE] [C-Dilla Ltd, 3.24.010]
- [PID: 604][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 644][C:\WINNT\system32\Iemc.exe] [N/A, N/A]
- [C:\WINNT\FExcep.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [PID: 656][C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe] [Kaspersky Lab, 5.0.0474.0]
- [C:\Program Files\Kaspersky Lab\NetworkAgent\klstfix.dll] [Kaspersky Lab, 5.0.0474.0]
- [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsn.dll] [Kaspersky Lab, 5.0.0474.0]
- [C:\Program Files\Kaspersky Lab\NetworkAgent\kltrace.dll] [Kaspersky Lab, 5.0.0474.0]
- [C:\Program Files\Kaspersky Lab\NetworkAgent\FSSync.dll] [Kaspersky Lab, 5.0.0474.0]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\NetworkAgent\klsecur2.dll] [Kaspersky Lab, 5.0.0474.0]
- [PID: 756][C:\WINNT\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.4403]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [PID: 828][C:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2195.6701]
- [PID: 772][C:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6972]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [PID: 1056][C:\WINNT\system32\scsvc.exe] [, 3, 1, 0, 0]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\WINNT\FExcep.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\procinfo.dll] [N/A, N/A]
- [C:\WINNT\system32\PMDLL5.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\ForbidModem.dll] [N/A, N/A]
- [PID: 1168][C:\WINNT\system32\Svcam.exe] [, 1]
- [C:\WINNT\FExcep.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [PID: 1204][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
- [PID: 1256][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1304][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\IEHlpCom.dll] [, 1, 0, 0, 1]
- [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
- [PID: 1428][C:\WINNT\system32\WinShell.exe] [N/A, N/A]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [PID: 1448][C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe] [深圳市三代科技开发有限公司, 1, 1, 0, 4]
- [C:\Program Files\Ringz Studio\Storm Downloader\boost_thread-vc6-mt-1_31.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [PID: 1484][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [GRISOFT s.r.o., 7, 5, 1, 43]
- [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL] [N/A, N/A]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [PID: 1492][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [PID: 1500][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [PID: 860][C:\Program Files\Ringz Studio\Storm Downloader\TDUpdate.exe] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 688][C:\WINNT\system32\taskmgr.exe] [Microsoft Corporation, 5.00.2195.6620]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [PID: 1068][D:\常用工具\杀毒\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
- [C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
- [C:\WINNT\system32\FDHook3.dll] [N/A, N/A]
- [C:\WINNT\system32\dllhook.dll] [N/A, N/A]
- [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINNT\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- 警告!System Repair Engineer 提醒
- 你下面的函数内容与预期值不符,他
- 们可能被一些恶意的软件所修改:
- RVA 错误: LoadLibraryA
- RVA 错误: LoadLibraryExA
- RVA 错误: LoadLibraryExW
- RVA 错误: LoadLibraryW
- ==================================
复制代码
[ 本帖最后由 兔斯基 于 2007-9-29 12:49 编辑 ] |