*----> 系统信息 <----*
计算机名: 大狗狗
用户名: Richard
终端会话 Id: 0
处理器数量: 2
处理器类型: x86 Family 15 Model 4 Stepping 4
Windows 版本: 5.1
当前内部版本号: 2600
Service Pack: 2
当前类型: Multiprocessor Free
注册的单位:
注册的所有者: USER
eax=00000000 ebx=00000003 ecx=7ffdf000 edx=7c92eb94 esi=00111af8 edi=00000000
eip=7c92eb94 esp=0007fef0 ebp=0007ff08 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
函数: ntdll!KiFastSystemCallRet
7c92eb89 90 nop
7c92eb8a 90 nop
ntdll!KiFastSystemCall:
7c92eb8b 8bd4 mov edx,esp
7c92eb8d 0f34 sysenter
7c92eb8f 90 nop
7c92eb90 90 nop
7c92eb91 90 nop
7c92eb92 90 nop
7c92eb93 90 nop
ntdll!KiFastSystemCallRet:
7c92eb94 c3 ret
7c92eb95 8da42400000000 lea esp,[esp]
7c92eb9c 8d642400 lea esp,[esp]
7c92eba0 90 nop
7c92eba1 90 nop
7c92eba2 90 nop
7c92eba3 90 nop
7c92eba4 90 nop
ntdll!KiIntSystemCall:
7c92eba5 8d542408 lea edx,[esp+0x8]
7c92eba9 cd2e int 2e
*----> 堆栈反向跟踪 <---*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHELL32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\explorer.exe
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0007ff08 7d5dbe9c 00000000 0007ff5c 01016e95 ntdll!KiFastSystemCallRet
0007ff14 01016e95 00111af8 7ffdd000 0007ffc0 SHELL32!Ordinal201+0x28
0007ff5c 0101e2b6 00000000 00000000 0002064a explorer+0x16e95
0007ffc0 7c816fd7 0007f730 0006e890 7ffdd000 explorer+0x1e2b6
0007fff0 00000000 0101e24e 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
*----> 堆栈反向跟踪 <---*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
008dff44 77dc9b26 00000002 008dff6c 00000000 ntdll!KiFastSystemCallRet
008dffb4 7c80b683 00000000 7c9340bb 00000000 ADVAPI32!RegDeleteKeyW+0x2a2
008dffec 00000000 77dc9981 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
eax=00000102 ebx=15012758 ecx=00f5fc2c edx=7c92eb94 esi=00000110 edi=00000000
eip=7c92eb94 esp=00f5fc2c ebp=00f5fc90 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
*----> 堆栈反向跟踪 <---*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** WARNING: Unable to verify checksum for C:\Program Files\AntiVirus\Micropoint\mp110031.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\AntiVirus\Micropoint\mp110031.dll -
ChildEBP RetAddr Args to Child
00f5fc90 7c802532 00000110 00001388 00000000 ntdll!KiFastSystemCallRet
00f5fca4 15001248 00000110 00001388 02480248 kernel32!WaitForSingleObject+0x12
00f5ffb4 7c80b683 15012758 02480248 02480248 mp110031+0x1248
00f5ffec 00000000 150011a9 15012758 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> 堆栈反向跟踪 <---*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
0113ff78 7c802451 0000ea60 00000000 0113ffb4 ntdll!KiFastSystemCallRet
0113ff88 769ae31d 0000ea60 000bf1b0 769ae3dc kernel32!Sleep+0xf
0113ffb4 7c80b683 000bf1b0 00000000 7c93094e ole32!StringFromGUID2+0x51b
0113ffec 00000000 769ae429 000bf1b0 00000000 kernel32!GetModuleFileNameA+0x1b4
Originally posted by Legend at 2007-7-10 19:47:
请楼主将 C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log 文件和mp6文件压缩后发送到support@micropoint.com.cn我们帮您分析一下
请在来信中附上这个帖 ...
[ Last edited by Legend on 2007-7-13 at 10:48 ]作者: 大狗狗 时间: 2007-7-16 01:00
Quote:
Originally posted by Legend at 2007-7-13 10:32:
请楼主打开微点主界面--【进程综合信息】--【应用软件】--【安全软件】下选中mpsvc2进程,将这个进程调用的其他模块信息(下边的模块信息,右键选择"隐藏已知的模块信息“)抓个图或者记录具体的程序文件和其 ...