瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 svchost.exe和IEXPLORE.EXE怎么删啊(日志)

1   1  /  1  页   跳转

svchost.exe和IEXPLORE.EXE怎么删啊(日志)

svchost.exe和IEXPLORE.EXE怎么删啊(日志)

电脑每次开机都会有svchost.exe和IEXPLORE.EXE,怎么也杀不掉,怎么办?
[CODE]

2007-05-22,17:49:39

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><G:\WINDOWS\system32\ctfmon.exe>  [(Verified)]
    <rundll32><G:\Program Files\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE>  []
    <wfz6xh3c6bews87><G:\DOCUME~1\Drudine\LOCALS~1\Temp\iexpl0re.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <fy><G:\WINDOWS\Sysfy4\svchost.exe>  [N/A]
    <wl><G:\WINDOWS\Syswl3\svchost.exe>  [N/A]
    <wm><G:\WINDOWS\Syswm7\svchost.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><G:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)]
    <PHIME2002A><G:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)]
    <桌面图标文字自动透明><C:\Program Files\Wom\WinMem.exe XP>  [N/A]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [N/A]
    <RfwMain><"G:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <MsIMMs32><G:\WINDOWS\MsIMMs32.exe>  []
    <cmdbcs><G:\WINDOWS\cmdbcs.exe>  []
    <Kvsc3><G:\WINDOWS\Kvsc3.exe>  []
    <msccrt><G:\WINDOWS\msccrt.exe>  []
    <upxdnd><G:\WINDOWS\upxdnd.exe>  []
    <mppds><G:\WINDOWS\mppds.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)]
    <Userinit><G:\WINDOWS\system32\userinit.exe,>  [(Verified)]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)]

==================================
启动文件夹
[快捷方式 到 WKeyKill]
  <G:\Documents and Settings\Drudine\「开始」菜单\程序\启动\快捷方式 到 WKeyKill.lnk --> E:\游戏安装\WIN键~1\WKeyKill.exe [Brad Jackson]><N>
[腾讯QQ]
  <G:\Documents and Settings\Drudine\「开始」菜单\程序\启动\腾讯QQ.lnk --> G:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <G:\WINDOWS\system32\Ati2evxx.exe><>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <G:\WINDOWS\system32\ati2sgag.exe><>
[局域网通讯协议 / Hello World][Stopped/Auto Start]
  <G:\Program Files\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <G:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[P4P Service / P4P Service][Running/Auto Start]
  <G:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <g:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <g:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
  <G:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Windows User Mode Driver Framework / UMWdf][Running/Auto Start]
  <G:\WINDOWS\system32\wdfmgr.exe><Microsoft Corporation>

==================================
驱动程序
[aeaudio / aeaudio][Running/Manual Start]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ASUSTeK/Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
  <system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation>
[EIO / EIO][Running/Auto Start]
  <\??\G:\WINDOWS\system32\drivers\EIO.sys><ASUSTeK Computer Inc.>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\G:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[IdeBusDr / IdeBusDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\g:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\G:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\G:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>

==================================
最后编辑2007-05-22 19:55:37
分享到:
gototop
 

浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <G:\WINDOWS\system32\xunleibho_v5.dll, >
[浩方对战平台]
  {0A155D3C-68E2-4215-A47A-E800A446447A} <C:\浩方对战平台\GameClient.exe, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <G:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <G:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Radio]
  {8E718888-423F-11D2-876E-00A0C9082467} <G:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <G:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <G:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <G:\WINDOWS\system32\xunleibho_v5.dll, >
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <G:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <G:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
  <G:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <G:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
  <G:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <G:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <G:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <G:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 552][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 608][\??\G:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][\??\G:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [G:\WINDOWS\system32\Ati2evxx.dll]  [, ]
    [G:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 688][G:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
[PID: 700][G:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
[PID: 856][G:\WINDOWS\system32\Ati2evxx.exe]  [, ]
[PID: 3564][G:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 1372][G:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\DOCUME~1\Drudine\LOCALS~1\Temp\LgSy0.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [G:\WINDOWS\system32\xunleibho_v5.dll]  [, 4, 3, 3, 30]
[PID: 1516][g:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
    [g:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [g:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [g:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 2296][G:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 444][G:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\xunleibho_v5.dll]  [, 4, 3, 3, 30]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 2348][E:\游戏安装\win键杀手\WKeyKill.exe]  [Brad Jackson, 1.7]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 3460][G:\program files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\xunleibho_v5.dll]  [, 4, 3, 3, 30]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 1644][G:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 2540][G:\WINDOWS\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
[PID: 2700][E:\游戏安装\sreng2(1)\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [G:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.2]
    [G:\WINDOWS\system32\msccrt.dll]  [N/A, ]
    [G:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
    [G:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [G:\WINDOWS\system32\Kvsc3.dll]  [N/A, ]
    [G:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [G:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [E:\游戏安装\win键杀手\WKeyKill.dll]  [N/A, ]
    [G:\DOCUME~1\Drudine\LOCALS~1\Temp\LgSy0.dll]  [N/A, ]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["G:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1      mmm.caifu18.net
127.0.0.1      www.18dmm.com
127.0.0.1      d.qbbd.com
127.0.0.1      www.5117music.com
127.0.0.1      www.union123.com
127.0.0.1      www.wu7x.cn
127.0.0.1      www.54699.com
127.0.0.1      www1.6tan.com
127.0.0.1      www2.6tan.com
127.0.0.1      www.97725.com
127.0.0.1      down.97725.com
127.0.0.1      ip.315hack.com
127.0.0.1      ip.54liumang.com
127.0.0.1      www.41ip.com
127.0.0.1      xulao.com
127.0.0.1      www.heixiou.com
127.0.0.1      www.9cyy.com
127.0.0.1      www.hunll.com
127.0.0.1      www.down.hunll.com
127.0.0.1      do.77276.com
127.0.0.1      www.baidulink.com
127.0.0.1      adnx.yygou.cn
127.0.0.1      222.73.220.45
127.0.0.1      www.f5game.com
127.0.0.1      www.guazhan.cn
127.0.0.1      wm,103715.com
127.0.0.1      www.my6688.cn
127.0.0.1      i.96981.com
127.0.0.1      d.77276.com
127.0.0.1      www1.cw988.cn
127.0.0.1      cool.47555.com
127.0.0.1      www.asdwc.com
127.0.0.1      55880.cn
127.0.0.1      61.152.169.234
127.0.0.1      cc.wzxqy.com
127.0.0.1      www.54699.com
127.0.0.1      t.gcuj.com
127.0.0.1      www.puma163.com
127.0.0.1      ceoww.com
127.0.0.1      boolom.com
127.0.0.1      adult-novel.cn
127.0.0.1      ll.chinasese.net
127.0.0.1      www.tellumore.com
127.0.0.1      www.o1wg.com
127.0.0.1      www.qq756.com
127.0.0.1      ll.chinasese.net

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

<MsIMMs32><G:\WINDOWS\MsIMMs32.exe> []
<cmdbcs><G:\WINDOWS\cmdbcs.exe> []
<Kvsc3><G:\WINDOWS\Kvsc3.exe> []
<msccrt><G:\WINDOWS\msccrt.exe> []
<upxdnd><G:\WINDOWS\upxdnd.exe> []
<mppds><G:\WINDOWS\mppds.exe> []
很明显这些是木马,而且我的svchost.exe和IEXPLORE.EXE都是以我的用户名存在的,但是我明明没有开IE
另外,我把svchost.exe和IEXPLORE.EXE进程结束后,双击任何一个应用程序它们都会再生,我的优化大师和超级兔子连打都打不开,我把木马都杀掉以后,每次开机svchost.exe和IEXPLORE.EXE都存在。怎么也杀不干净,我找不到它们的主程序在哪
gototop
 

有人能帮忙吗
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT