Mssock
[A ] 14. c:\windows\system32\mssock.sys + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
UIHost
[A ] 18. c:\program files\logonui\logonui.exe 映像劫持
+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Launcher.exe
[A ] 36. c:\windows\system\7.exe
my.exe
[A ] 37. c:\windows\system\2.exe
WoW.exe
[A ] 36. c:\windows\system\7.exe + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[ M] 40. c:\windows\system32\remotedbg.dll
[AM] 26. c:\windows\system32\zxepri.dll
[AM] 27. c:\windows\system32\wgdpri.dll
[ M] 54. c:\windows\system32\mscomm.dll
[ M] 43. c:\windows\system32\msimms32.dll
[AM] 28. c:\windows\system32\mycpri.dll
[ M] 41. c:\windows\system32\rav009b.dat
[ M] 42. c:\windows\system32\rav008c.dat
[AM] 29. c:\windows\system32\qhbpri.dll
[AM] 30. c:\windows\system32\jzepri.dll推荐楼主将那些蓝色的文件上报给瑞星:
http://up.rising.com.cn/webmail/uploadnew.htm
楼主可能中木马群了.