|
无法删除的病毒!请各位帮忙
Process list saved on 04:36:44, on 2006-10-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
[pid] [full path to filename] [file version] [company name]
428 C:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation
532 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 Microsoft Corporation
576 C:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation
588 C:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation
728 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
816 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1208 C:\WINDOWS\Explorer.EXE 6.0.2900.2180 Microsoft Corporation
1260 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.2696 Microsoft Corporation
1348 C:\WINDOWS\SOUNDMAN.EXE 5.1.0.24 Realtek Semiconductor Corp.
1356 C:\WINDOWS\VM_STI.EXE 4.2.610.4 VM.
1368 C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe 1.5.0.10 Sun Microsystems, Inc.
1408 C:\WINDOWS\system32\ctfmon.exe 5.1.2600.2180 Microsoft Corporation
1544 C:\WINDOWS\system32\nvsvc32.exe 6.14.10.6562 NVIDIA Corporation
1628 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1784 D:\Program Files\VMware\VMware Workstation\vmware-authd.exe 5.0.0.13124 VMware, Inc.
1796 C:\WINDOWS\system32\vmnat.exe 5.0.0.13124 VMware, Inc.
1860 C:\program files\internet explorer\IEXPLORE.EXE 6.0.2900.2180 Microsoft Corporation
1884 C:\WINDOWS\system32\vmnetdhcp.exe 5.0.0.13124 VMware, Inc.
1056 C:\Documents and Settings\Administrator\桌面\ha_hijackthis_1991\HijackThis.exe 1.99.0.1 Soeperman Enterprises Ltd.
DLLs loaded by process C:\program files\internet explorer\IEXPLORE.EXE:
[full path to filename] [file version] [company name]
C:\WINDOWS\system32\ntdll.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\kernel32.dll 5.1.2600.2945 Microsoft Corporation
C:\WINDOWS\system32\USER32.DLL 5.1.2600.2622 Microsoft Corporation
C:\WINDOWS\system32\GDI32.dll 5.1.2600.2818 Microsoft Corporation
C:\WINDOWS\system32\IMM32.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\LPK.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\USP10.dll 1.420.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\msvcrt.dll 7.0.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\OLEAUT32.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\ole32.dll 5.1.2600.2726 Microsoft Corporation
C:\WINDOWS\system32\MPR.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\VERSION.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\COMCTL32.DLL 5.82.2900.2180 Microsoft Corporation
C:\WINDOWS\system32\SHELL32.DLL 6.0.2900.2951 Microsoft Corporation
C:\WINDOWS\system32\SHLWAPI.dll 6.0.2900.2937 Microsoft Corporation
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll 6.0.2900.2180 Microsoft Corporation
C:\WINDOWS\system32\WININET.DLL 6.0.2900.2937 Microsoft Corporation
C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\MSASN1.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\WINMM.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\WSOCK32.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\WS2_32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\AVICAP32.DLL 5.1.2600.0 Microsoft Corporation
C:\WINDOWS\system32\MSVFW32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\URLMON.DLL 6.0.2900.2960 Microsoft Corporation
C:\WINDOWS\system32\NETAPI32.DLL 5.1.2600.2952 Microsoft Corporation
C:\WINDOWS\system32\uxtheme.dll 6.0.2900.2180 Microsoft Corporation
C:\WINDOWS\system32\msctfime.ime 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\Secur32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\RASAPI32.DLL 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\rasman.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\TAPI32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\rtutils.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\sensapi.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\System32\mswsock.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\DNSAPI.dll 5.1.2600.2938 Microsoft Corporation
C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.2912 Microsoft Corporation
C:\WINDOWS\system32\rasadhlp.dll 5.1.2600.2938 Microsoft Corporation
C:\WINDOWS\System32\winrnr.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.2180 Microsoft Corporation
C:\WINDOWS\system32\msv1_0.dll 5.1.2600.2180 Microsoft Corporation
用HijackThis.exe查出来导出的,麻烦各位帮忙额!
现在每一次系统启动都会以SYSTEM用户名起的IEXPLORE.EXE |
|