skyzx - 2007-4-22 17:46:00
没有中毒 ,为什么 cpu100%,一启动就死机 ,我都启动好就回了 ,安全模式下杀毒也没有读阿,只有个什么svchost.exe刚开始一直是100%,我一关这个进程,就好点,但是具体怎么回事,请帮我看下日志,分析下,说一具体解决办法谢谢~~~~~~~~~~
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><; C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><; C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<PmProxy><; C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe> [adi]
<00THotkey><; C:\WINDOWS\System32\00THotkey.exe> [东芝公司]
<000StTHK><; 000StTHK.exe> [N/A]
<LTSMMSG><; LTSMMSG.exe> [LT]
<Tpwrtray><; TPWRTRAY.EXE> [东芝公司]
<TFNF5><; TFNF5.exe> [Toshiba Corp.]
<NDSTray.exe><; "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"> [TOSHIBA CORPORATION]
<Apoint><; C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe> [东芝公司]
<ezShieldProtector for Px><C:\WINDOWS\System32\ezSP_Px.exe> [Easy Systems Japan Ltd.]
<Drag'n Drop CD+DVD><; C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp> [N/A]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [Microsoft Corporation]
<MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> [N/A]
<RavTask><"D:\瑞星杀毒\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><D:\瑞星卡卡\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<StormCodec_Helper><; "D:\暴风影音\Storm Codec\StormSet.exe" /S /opti> [N/A]
<WangWang><; "D:\汪汪\淘宝旺旺\WangWang.EXE"> [淘宝(中国)软件有限公司]
<BigDogPath><; C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><D:\瑞星卡卡\RunOnce.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[RAMASST]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\RAMASST.lnk --> C:\WINDOWS\system32\RAMASST.exe [Matsushita Electric Industrial Co., Ltd.]><H>
[腾讯QQ]
<C:\Documents and Settings\zx\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\QQ\QQ.exe [TENCENT]><H>
==================================
服务
[IPv6 Helper Service / 6to4][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\6to4svc.dll><Microsoft Corporation>
[Alerter / Alerter][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k LocalService-->%SystemRoot%\system32\alrsvc.dll><Microsoft Corporation>
[Application Layer Gateway Service / ALG][Stopped/Manual Start]
<C:\WINDOWS\System32\alg.exe><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[DVD-RAM_Service / DVD-RAM_Service][Stopped/Disabled]
<C:\WINDOWS\System32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\瑞星杀毒\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"D:\瑞星杀毒\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
<System32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
skyzx - 2007-4-22 17:47:00
<\??\D:\瑞星杀毒\RISING\RAV\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\D:\瑞星杀毒\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\D:\瑞星杀毒\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\D:\瑞星杀毒\RISING\RAV\HookSys.sys><Rising>
[ialm / ialm][Running/Manual Start]
<System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[meiudf / meiudf][Running/System Start]
<System32\Drivers\meiudf.sys><Matsushita Electric Industrial Co.,Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\D:\瑞星杀毒\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\PxHelp20.sys><VERITAS Software, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\D:\瑞星杀毒\RISING\RAV\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[TOSHIBA Software Modem / TOSHIBASoftModem][Stopped/Manual Start]
<System32\DRIVERS\LTSM.sys><LT>
[Toshiba ACPI-Based Value Added Logical Device Driver / TVALD][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\TVALD.SYS><Toshiba Corporation>
[Toshiba Value Added Logical and General Purpose Device Driver / TVALG][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\TVALG.SYS><TOSHIBA Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[xinstall / xinstall][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\xinstall.sys><N/A>
[VIMICRO USB PC Camera 301x / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
[AIM 3.0 Part 01 Codec Driver CH-7009-A/CH-7011 / {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
<system32\drivers\wA301a.sys><Intel Corporation>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[PhotoDraw Class]
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\WINDOWS\System32\QQPhotoDraw.dll, TENCENT>
[MofileUploadX Control]
{7260569F-1D40-4E7F-B95B-2E68D35668B9} <C:\WINDOWS\DOWNLO~1\MoUpload.ocx, N/A>
[163Uploader Control]
{8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\System32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 692][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
[PID: 736][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 748][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 900][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1032][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1224][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1300][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1452][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.1699 (xpsp2.050610-1533)]
[PID: 1620][D:\瑞星杀毒\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[D:\瑞星杀毒\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\瑞星杀毒\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1992][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[PID: 272][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\System32\igfxpph.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[D:\Winrar\rarext.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\瑞星杀毒\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\System32\DVDMenu.dll] [Matsushita Electric Industrial Co., Ltd., 4. 0. 8. 0]
[PID: 368][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 400][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 672][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1152][C:\WINDOWS\System32\ezSP_Px.exe] [Easy Systems Japan Ltd., 1, 0, 0, 0]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1264][D:\瑞星卡卡\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[D:\瑞星卡卡\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1628][C:\WINDOWS\System32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2004][D:\魔法兔子\MagicSet\SRCK.EXE] [Super Rabbit Soft, 7.98]
[D:\魔法兔子\MagicSet\shlobj71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[D:\魔法兔子\MagicSet\fldrvw71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 232][C:\Documents and Settings\zx\桌面\常用软件\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[D:\瑞星卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
© 2000 - 2026 Rising Corp. Ltd.