【回复“232445”的帖子】
启动项目
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{2D908534-AD45-920F-AC89-4024FA9D26D2}><C:\WINDOWS\Fonts\gjfhbyc.dll> []
<{4FA10261-B890-F432-A453-69F1023513F4}><C:\WINDOWS\Fonts\gjcsdyc.dll> []
<{DB681598-AD5F-BC8C-77DC-748FAC8D3FBD}><C:\WINDOWS\Fonts\kafymzy.dll> []
<{54909874-8982-F344-A322-7898787FA745}><C:\WINDOWS\Fonts\swjqezc.dll> []
<{992FADFA-BCDE-ACDF-CDEF-21054865CBA9}><C:\WINDOWS\Fonts\wsmsgzx.dll> []
<{0c8edcd8-c51e-4485-94a1-9c9d831f026c}><C:\WINDOWS\system32\IGB_DJOL_1012.dll> []
驱动
[mseqsy / mseqsy][Stopped/Auto Start]
<system32\DRIVERS\msacpe.sys><N/A>
[phy / phy][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\phy.sys><N/A>
浏览器加载项
[]
{471B15AD-7A9C-491D-9C19-4E15B12DCE00} <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys, N/A>
Winsock 提供者
MSAPI Tcpip [TCP/IP]
C:\WINDOWS\system32\yld32.dll(, N/A)
MSAPI Tcpip [UDP/IP]
C:\WINDOWS\system32\yld32.dll(, N/A)