启动时自动加载ie进程,奇怪的是这个进程在C:\Program Files\Internet Explorer文件夹下,是正常的ie主程序
但在自启动项目里也没找到这个进程,此外这个ie进程加载一个musichack.3322.org.dll的文件,正常ie则没有,连带启动musichack.3322.org.exe进程,此进程加载3秒后消失
在system32文件夹下,这两个文件都是隐藏的且新建的,谁知道这是什么程序???
杀软(avast!+avg7.5)扫描未果...........
帮忙啊..

我晕超过字数,日志分两部分吧
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\windows\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<NvMediaCenter><; RUNDLL32.EXE C:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit> [(Verified)NVIDIA Corporation]
<PSwitch><; D:\Proxy Switcher Standard\ProxySwitcher.exe> [Proxy Switcher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<Vistadrv><C:\Program Files\Vista\systool\Vistadrive\vsdrv.exe> [N/A]
<avast!><C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe> [(Verified)N/A]
<nwiz><; nwiz.exe /install> [NVIDIA Corporation]
<NvMediaCenter><; RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)NVIDIA Corporation]
<NvCplDaemon><; RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup> [(Verified)NVIDIA Corporation]
<WingKav><; D:\流行病毒统杀工具2007\wingkav2007.exe> [81915]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\windows\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><wbsys.dll> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><C:\登陆界面替换工具\川流不息的丛林\川流不息的丛林.exe> [Newton Workshop]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\windows\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[avast! iAVS4 Control Service / aswUpdSv][Running/Auto Start]
<"C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"><N/A>
[avast! Antivirus / avast! Antivirus][Running/Auto Start]
<"C:\Program Files\Alwil Software\Avast4\ashServ.exe"><N/A>
[avast! Mail Scanner / avast! Mail Scanner][Stopped/Manual Start]
<"C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service><ALWIL Software>
[avast! Web Scanner / avast! Web Scanner][Running/Manual Start]
<"C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service><ALWIL Software>
[Diskeeper / Diskeeper][Stopped/Manual Start]
<D:\Diskeeper-v10.0H\DkService.exe><Diskeeper Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[musichack.3322.org / musichack.3322.org][Stopped/Auto Start]
<C:\windows\system32\musichack.3322.org.exe><N/A>
[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
<C:\windows\system32\nvsvc32.exe><NVIDIA Corporation>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[Aspi32 / Aspi32][Running/Auto Start]
<System32\drivers\aspi32.sys><Adaptec>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ICatch (VI) PC Camera / CA561][Stopped/Manual Start]
<System32\Drivers\SPCA561.SYS><SP>
[cdrmkaun / cdrmkaun][Stopped/Manual Start]
<\??\C:\DOCUME~1\user\LOCALS~1\Temp\cdrmkaun.sys><N/A>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dtscsi / dtscsi][Stopped/Manual Start]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[EagleNT / EagleNT][Stopped/Manual Start]
<\??\C:\windows\system32\drivers\EagleNT.sys><N/A>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><N/A>
[GDTdiInterceptor / GDTdiInterceptor][Running/Auto Start]
<\??\C:\windows\system32\drivers\GDTdiIcpt.sys><>
[HookCont / HookCont][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><N/A>
[HookReg / HookReg][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><N/A>
[HookSys / HookSys][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><N/A>
[IsDrv120 / IsDrv120][Running/Boot Start]
<2 - 系统找不到指定的文件。
><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\qq\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PnpWmkDrv / PnpWmkDrv][Running/System Start]
<\??\C:\windows\system32\drivers\PnpWmkDrv.sys><N/A>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
<\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
<\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Running/Auto Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology>
[StarForce Protection Environment Driver (version 1.x.a) / sfdrv01a][Running/Boot Start]
<\SystemRoot\System32\drivers\sfdrv01a.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 2.x) / sfsync02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfsync02.sys><Protection Technology>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04][Running/Boot Start]
<\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology (StarForce)>
[StarForce Protection VFS Driver (version 2.x) / sfvfs02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfvfs02.sys><Protection Technology (StarForce)>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TSP / TSP][Stopped/Manual Start]
<\??\C:\windows\system32\drivers\klif.sys><N/A>
[vcs / vcs][Stopped/Auto Start]
<\??\C:\Documents and Settings\user\桌面\AV VCS 3.0\AV VCS 3.0\vcs.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[WmNdisDrv / WmNdisDrv][Stopped/Manual Start]
<System32\Drivers\WmNdisDrv.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>