注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<hdzsifa><C:\WINDOWS\system32\cyundav.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{2D83FA50-3EA4-E950-0B61-940A61D73EA5}><C:\WINDOWS\system32\UZOTJODI.dll> []
启动文件夹
[DELLmouse]
<C:\Documents and Settings\user\「开始」菜单\程序\启动\DELLmouse.exe --> [N/A]><H>(戴尔鼠标驱动采取这种启动方式?怀疑……)
下面这三个文件高度怀疑中……
C:\WINDOWS\system32\UZOTJODI.dll
C:\WINDOWS\system32\cyundav.dll
:\Documents and Settings\user\「开始」菜单\程序\启动\DELLmouse.exe