个人发现的异常项目
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{00B4A0F0-5DF9-42C3-916E-5EE7D13D09DC}>< > [N/A]
<{D859245F-345D-BC13-AC4F-145D47DA34FD}><C:\WINDOWS\system32\avzxmmn.dll> [File is missing]
<{AE32FA58-3453-FA2D-BC49-F340348ACCEA}><C:\WINDOWS\system32\rsmyjpm.dll> [File is missing]
<{4A57CAD1-412F-9547-713F-9641FA3FC7A4}><C:\WINDOWS\system32\okmhdzy.dll> [File is missing]
<{45679330-4034-9021-7012-909856721374}><C:\WINDOWS\system32\wszjdzx.dll> [File is missing]
<{00BDB58C-E519-4187-ADF4-B4E313A99947}>< > [N/A]
<{DC3D30AE-0380-4151-8934-EE98A34B0370}><C:\WINDOWS\system32\mfdesy.dll> [File is missing]
驱动程序
[sys_flt / sys_flt][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~46.tmp><N/A>
[WD / WD][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp3.tmp><N/A>
文件
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw9.tmp\NSISArray.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw9.tmp\nsExec.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw9.tmp\nsA.tmp
C:\WINDOWS\system32\avzxmmn.dll
C:\WINDOWS\system32\rsmyjpm.dll
C:\WINDOWS\system32\okmhdzy.dll
C:\WINDOWS\system32\wszjdzx.dll
C:\WINDOWS\system32\mfdesy.dll
瑞星杀软出问题了,建议卸载瑞星杀软后,手工删除其安装目录,重装瑞性。