问题项目如下:
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
<RegNetPass><C:\WINDOWS\system32\regcsp.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><msosdrop00.dll,msoscqit00.dll,msosmhfp00.dll,msosmnsf00.dll,msosjtio00.dll,nicozftp00.dll,fmsiocps.dll,msosdohs00.dll,msosptfs00.dll,raqjuf.dll,qekube.dll,umtokf.dll> []
驱动程序
[cqit / cqit][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2D.tmp><N/A>
[drop / drop][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp34.tmp><N/A>
[jtio / jtio][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp37.tmp><N/A>
[kaohsg / kaohsg][Running/]
<2 - 系统找不到指定的文件。><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp32.tmp><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[msp2p32 / msp2p32][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys><N/A>
[ptfs / ptfs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp3B.tmp><N/A>
[zftp / zftp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp29.tmp><N/A>
[qaoep / qaoep][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\qaoep.sys><N/A>
浏览器加载项
[Promote Class]
{0FA24E3E-422C-4D94-A125-104F32352C90} <C:\WINDOWS\system32\promote.dll, >
[DragSearch BHO]
{EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} <C:\PROGRA~1\YiSou\yisoub.dll, >
[一搜工具条]
{115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} <C:\Program Files\YiSou\yisou.dll, 3721>
[Promote Class]
{0FA24E3E-422C-4D94-A125-104F32352C90} <C:\WINDOWS\system32\promote.dll, >
[一搜工具条]
{115F6E46-FCBC-41ED-B3B5-3BDDD4AAB5E5} <C:\Program Files\YiSou\yisou.dll, 3721>
[AutoLive]
{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, 国风因特软件(北京)有限公司>
[DragSearch BHO]
{EF1D17A9-089F-40CC-8D64-7324CDEBA0DB} <C:\PROGRA~1\YiSou\yisoub.dll, >
[!搜一搜(&S)]
<res://C:\Program Files\YiSou\yisou.dll/232, N/A>
正在运行的进程(不包括以上问题项目对应的相关文件)
[C:\WINDOWS\system32\msosdrop00.dll] [N/A, ]
[C:\WINDOWS\system32\msoscqit00.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ]
[C:\WINDOWS\system32\msosjtio00.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs00.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs00.dll] [N/A, ]
感想:流氓软件培养大师……