每次开机后都能查到病毒 Trojan.PSW.LMir.atf ,是在内存里查杀到的。
WINLOGON.EXE>>E:\WINDOWS\WINLOGON.EXE
怎么样才能彻底清除?
当前运行的进程:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.exe
E:\WINDOWS\System32\ctfmon.exe
E:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
E:\Program Files\VMware\VMware Workstation\vmware-authd.exe
E:\WINDOWS\System32\vmnat.exe
E:\Program Files\IBM\SQLLIB\BIN\db2jds.exe
E:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
E:\WINDOWS\System32\vmnetdhcp.exe
E:\Program Files\Rising\Rav\Rav.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\WINDOWS\System32\wuauclt.exe
E:\Program Files\Rising\Rav\RsLogVw.exe
E:\new file\winrar\Hijackthis1991zww\HijackThis1991zww.exe
F2 - REG:system.ini: Shell=Explorer.exe 1
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\new file\program\QQIEHelper.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - E:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL (file missing)
O2 - BHO: NS Security Class - {95AB740B-D32D-41E8-85EA-CED0FD08AE2B} - E:\WINDOWS\060219a.dll (file missing)
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\new file\program\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\new file\program\QQ.EXE (file missing)
O23 - NT 服务: DB2 - DB2 (DB2) - International Business Machines Corporation - E:\PROGRA~1\IBM\SQLLIB\bin\db2syscs.exe
O23 - NT 服务: DB2DAS - DB2DAS00 (DB2DAS00) - International Business Machines Corporation - E:\Program Files\IBM\SQLLIB\\bin\db2dasrrm.exe
O23 - NT 服务: DB2 控制器 (DB2GOVERNOR) - International Business Machines Corporation - E:\Program Files\IBM\SQLLIB\BIN\db2govds.exe
O23 - NT 服务: DB2 JDBC Applet 服务器 (DB2JDS) - International Business Machines Corporation - E:\Program Files\IBM\SQLLIB\BIN\db2jds.exe
O23 - NT 服务: DB2 安全服务器 (DB2NTSECSERVER) - International Business Machines Corporation - E:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: VMware Authorization Service (VMAuthdService) - VMware, Inc. - E:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - NT 服务: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - E:\WINDOWS\System32\vmnetdhcp.exe
O23 - NT 服务: VMware NAT Service - VMware, Inc. - E:\WINDOWS\System32\vmnat.exe