用sreng2扫描发现Explorer.EXE进程调用了很多未知程序,请帮忙看看
附件1.rar包含这些文件,上个月底这些文件出现以后开始出现问题,explorer占用CPU50%,占内存接近200M。
[PID: 2264][C:\winnt\Explorer.EXE] [(Verified) Microsoft Corporation, 5.00.3700.6690]
[C:\winnt\appHelp.dll] [N/A, ]
[c:\winnt\system32\wmvfile.dll] [, 1, 0, 0, 1]
[c:\winnt\system32\mpgfile.dll] [, 1, 0, 0, 1]
[c:\winnt\system32\wmacore.dll] [, 1, 0, 0, 1]
[c:\winnt\system32\iedecode.dll] [, 1, 0, 0, 1]
[C:\winnt\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
[c:\winnt\system32\us.dll] [, 1, 0, 0, 1]
[D:\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1009]
[C:\winnt\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\winnt\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\winnt\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
[C:\winnt\SYSTEM32\DWRCShell.DLL] [DameWare Development LLC, 4, 5, 0, 0]
[C:\Program Files\UltraEdit\ue32ctmn.dll] [, 1.0]
[C:\WINNT\system32\msimtf.dll] [Microsoft Corporation, 1.00.2409.41 built by: Lab06_N]
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MAXTHON 2.0)