![]() |
電腦不定時出現一排錯誤訊息又迅速消失?
電腦不定時出現一排錯誤訊息又迅速消失?
用趨勢掃過還是未發現病毒。 最近頻率愈來愈密集。求助各位先進。 我把事件檢視器清空,出錯後去看也是無相關資訊。 "msconfig"停用一些相關啟動還是一樣發生。 懇請相助。謝謝 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 上午 11:20:15, on 2009/2/13 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\helpme.exe C:\WINDOWS\system32\conime.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\cmd.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe C:\WINDOWS\TEMP\YO8E1D.EXE C:\Program Files\Panasonic\Panasonic-DMS\Port Controller\mfpscdl.exe C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe C:\Program Files\Trend Micro\OfficeScan Client\tmproxy.exe C:\Program Files\Microsoft Office\OFFICE11\outlook.exe C:\Documents and Settings\All Users\桌面\vnc\winvnc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\S.F.Yu\桌面\HiJackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - C:\Program Files\Inventec\Dreye\DreyeMT\DreyeIEBar.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user') O8 - Extra context menu item: 匯出至 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - ESC Trusted Zone: http://runonce.msn.com O15 - ESC Trusted Zone: http://runonce.msn.com (HKLM) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1230603791889 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趨勢科技線上掃毒程式) - http://dcs.qisda.qcorp.com/housecall/xscan53.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Qisda.Qcorp.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Qisda.Qcorp.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Qisda.Qcorp.com O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe -- End of file - 5487 bytes <a target='_blank' title='ImageShack - Image And Video Hosting' href='http://img8.imageshack.us/my.php?image=2222vp6.jpg'><img src='http://img8.imageshack.us/img8/7112/2222vp6.jpg' border='0'/></a><br/><a href="http://g.imageshack.us/img8/2222vp6.jpg/1/"><img src="http://img8.imageshack.us/img8/2222vp6.jpg/1/w950.png" border="0"></a> ![]() |
這應該是某個程式出錯的訊息吧
你可以把你所安裝的軟體一一列出來嗎? 另外交待一些電腦組態,是否是筆記型電腦? |
|
去下一套 Process Explorer
在 Process欄位上右鍵 select Columns,將 Windows Title 打勾 接著就可輕易找到Error視窗的債主 知道債主是哪一個程式後 就比較方便作接下來的處理 |
有二個奇怪的工作程式:helpme.exe & YO8E1D.EXE
引用:
1. 將下面代碼用計事本儲存到 C:\Clean.bat (放在 C: 根目錄,比較好找) 語法:
@echo 結束目前奇怪程序: 當它出現 "請按任意鍵繼續 . . ." 隨便按一個鍵隨即關閉視窗。 3. 執行 HijackThis 修復下面項目: 語法:
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM') |
目前使用5樓大哥方法,因為訊息為不定時出現。我再觀察一下。非常感謝。
|
所有時間均為台北時間。現在的時間是 09:35 AM。 |
Powered by vBulletin® 版本 3.6.8
版權所有 ©2000 - 2025, Jelsoft Enterprises Ltd.
『服務條款』
* 有問題不知道該怎麼解決嗎?請聯絡本站的系統管理員 *