火缨 - 2005-11-7 13:58:00
msmdsrv.exe是什么啊?我开机就占了100%的CPU……病毒?
各位大虾有没有人知道怎么解决啊?
可怜稻草人 - 2005-11-7 14:09:00
msmdsrv.e微软SQL 服务器分析服务
开机时占满CPU很正常
火缨 - 2005-11-7 14:10:00
在任务管理器里面把它关掉后,系统就能正常工作……关掉后我扫描了下系统……大家给我看看看到底哪儿出问题了啊?
HijackThis_815汉化版扫描日志 V1.99.1
保存于 14:09:50, 日期 2005-11-7
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
F:\tool\千千静听\TTPlayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\tool\QQ\TT\TTraveler.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F57} - C:\WINDOWS\system32\ThunderBHO_v07.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - F:\魔法兔子\MagicSet\HaokanBar.dll
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - F:\词霸\IEBand.dll
O3 - IE工具栏增项: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - F:\tool\BitComet\BitCometBar\BitCometBar0.2.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - F:\魔法兔子\MagicSet\HaokanBar.dll
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "F:\tool\StormCodec\Storm Codec\StormSet.exe" /S /opti
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - F:\tool\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - F:\tool\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: 迅雷 - {1FBA04EE-3024-11D2-8F1F-000019796948}} - (no file)
O9 - 浏览器额外的“工具”菜单项: 迅雷 - {1FBA04EE-3024-11D2-8F1F-000019796948}} - (no file)
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://cge.hn.chinavnet.com/plugin/PowerPlr.ocx
O16 - DPF: {2761225D-F0F2-44E8-A2C9-476FB6A3316A} (TRadio Control) - http://dl_dir.qq.com/qqtools/trsetuptr.exe
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125482893375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129166108687
O16 - DPF: {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (Qzone Media Tools) - http://219.133.62.248/QQPlayer.cab
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - NT 服务: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
火缨 - 2005-11-7 14:12:00
| 引用: |
【可怜稻草人的贴子】msmdsrv.e微软SQL 服务器分析服务 开机时占满CPU很正常 ........................... |
但是一直都是100%……什么都干不了……怎么才能让它停啊?
火缨 - 2005-11-7 14:20:00
| 引用: |
【神无的贴子】终止这个进程,能终止吗? ........................... |
反正我在任务管理器里面把它给卡了……但是重启又是100%……又要调管理器出来……
我是菜鸟……到底咋回事就不懂了……
神无 - 2005-11-7 14:23:00
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
这个是什么,楼主知道吗?
可怜稻草人 - 2005-11-7 14:25:00
可疑
火缨 - 2005-11-7 14:28:00
^……都说是菜鸟了……-_-!!
那木马怎么杀?
虚心请教……
火缨 - 2005-11-7 14:33:00
55555~~~~~
看不懂日志啊…………………………
神无 - 2005-11-7 14:44:00
你先终止msmdsrv.exe这个进程,再找到C:\WINDOWS\SYSTEM32\PCANotify.dll
这个文件删除试试。
火缨 - 2005-11-7 15:14:00
在安全模式下也删不掉…………
重启后进入一般模式,又是100%……
也许该把SQL 删了??…………
到底怎么回事啊………………!!
火缨 - 2005-11-7 15:39:00
用优化大师里的进程管理看了看,进程winlogon.exe有调用PCANotify.dll
优先级为高
有问题吗?
BlackStone - 2005-11-7 15:44:00
用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项
工具使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
BlackStone - 2005-11-7 16:12:00
太多了
保存日志时注意选择Options->Hide Microsoft Entries菜单项
火缨 - 2005-11-7 16:17:00
……我记得我明明选了的啊……
这个应该对了吧
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon
+ Local Group PolicyFile not found: C:\WINDOWS\System32\GroupPolicy\User\disshare.bat
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ATIPTAATI Desktop Control PanelATI Technologies, Inc.c:\program files\ati technologies\ati control panel\atiptaxx.exe
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe
+ StormCodec_Helperf:\tool\stormcodec\storm codec\stormset.exe
HKLM\System\CurrentControlSet\Services
+ Ati HotKey Pollerc:\windows\system32\ati2evxx.exe
+ ATI SmartATI Smartc:\windows\system32\ati2sgag.exe
+ Autodesk Licensing ServiceAnchor service for Autodesk products licensed with SafeCastAutodesk, Inc.c:\program files\common files\autodesk shared\service\adskscsrv.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ 好看123上网精灵超级兔子上网精灵超级兔子f:\魔法兔子\magicset\haokanbar.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ ThunderIEHelper ClassThunderBHO Modulec:\windows\system32\thunderbho_v07.dll
+ 超级兔子上网精灵超级兔子上网精灵超级兔子f:\魔法兔子\magicset\haokanbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ coolbar\
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ 超级兔子上网精灵超级兔子上网精灵超级兔子f:\魔法兔子\magicset\haokanbar.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ AtiExtEventc:\windows\system32\ati2evxx.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ pcAnywhere Remote PrintingpcAnywhere Monitor DLLSymantec Corporationc:\windows\system32\awmon.dll
BlackStone - 2005-11-7 16:24:00
未发现病毒或木马进程,
把这个+ MSSQLServerOLAPServiceMicrosoft SQL Server 2000 Analysis ServicesMicrosoft Corporationc:\program files\microsoft analysis services\bin\msmdsrv.exe
服务设置成手动启动方式.
火缨 - 2005-11-7 16:44:00
MSSQLServerOLAPService的后台服务改手动就可以了~~谢谢了哈
重启也没有问题了~~
不过要是又启动MSMDSRY应该又要100%了吧……是我机子的问题吗?
本来以前偶没问题的,安了Analysis Services打了SP4问题就来了……郁闷……
BlackStone - 2005-11-7 16:46:00
原因很多,不好说,得具体问题具体分析
© 2000 - 2026 Rising Corp. Ltd.