启动
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<xptqhhx><C:\WINDOWS\system32\kriahqe.exe> []
<loftbgv><C:\WINDOWS\system32\vftabxk.exe> []
服务
[Distributed Application Client / SHipING][Stopped/Disabled]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\XHYYE.DLL,Export 1087><N/A>
[Network Provisioning help / xphelp][Stopped/Disabled]
<C:\WINDOWS\system32\svahost.exe><N/A>
[kernl32 / kernl32][Running/Auto Start]
<C:\WINDOWS\system32\kernl32.exe><N/A>[svchost / svchost][Running/Auto Start]
<C:\WINDOWS\svchost.exe><N/A>
[ip139 / ip139][Running/Auto Start]
<C:\WINDOWS\system32\23.exe><N/A>
驱动
[yvdd / yvddd][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\yvddd.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
正在运行的程序
[PID: 1684][C:\WINDOWS\system32\kriahqe.exe] [N/A, ]
[PID: 1720][C:\WINDOWS\system32\vftabxk.exe] [N/A, ]
以上为看出有问题的,蓝色为可疑项目。请高手指点。