启动项目
注册表
<ctfmon.exe><C:\WINNT\system32\ctfmon.exe> []
<NvidMediaCenter><C:\Program Files\Common Files\System\wmsncs.exe> [File is missing]
<Spool Driver Service><C:\WINNT\system32\spool\drivers\wmsncs.exe> [File is missing]
<Wmsncs Service><C:\WINNT\Fonts\wmsncs.exe> [File is missing]
<Wins Service><C:\WINNT\system32\wins\wmsncs.exe> [File is missing]
<MYSYIN><C:\WINDOWS\Fonts\MYSYIN.exe> [File is missing]
<MYSYIM><C:\WINDOWS\Fonts\MYSYIM.exe> [File is missing]
<N/A><C:\WINNT\Fonts\wmsncs.exe> [File is missing]
==================================
驱动程序
[abopxyzq / abopxyzq][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\abopxyzq.sys><N/A>
[abpcxyqr / abpcxyqr][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\abpcxyqr.sys><N/A>
[abzpcaxy / abzpcaxy][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\abzpcaxy.sys><N/A>
[autorun / autorun][Stopped/Manual Start]
<\??\c:\huadio.tmp><N/A>
[boqpxay / boqpxay][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\boqpxay.sys><N/A>
[bpcxyq / bpcxyq][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\bpcxyq.sys><N/A>
[bpqcabyo / bpqcabyo][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\bpqcabyo.sys><N/A>
[debzw / debzw][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_tmp.bat><N/A>
[llefc / llefc][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_tmp.bat><N/A>
[opxyzqab / opxyzqab][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\opxyzqab.sys><N/A>
[pcxyqrab / pcxyqrab][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\pcxyqrab.sys><N/A>
[qabopx / qabopx][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\qabopx.sys><N/A>
[rabpcxyq / rabpcxyq][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\rabpcxyq.sys><N/A>
[xyqrabpc / xyqrabpc][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\xyqrabpc.sys><N/A>
[xyzqabop / xyzqabop][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\xyzqabop.sys><N/A>
[yqrabp / yqrabp][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\yqrabp.sys><N/A>
[yzqabopx / yzqabopx][Stopped/Manual Start]
<\??\C:\WINNT\system32\drivers\yzqabopx.sys><N/A>
==================================
正在运行的进程
[C:\WINNT\system32\msbxkig.dll] [N/A, ]
==================================
隐藏进程
[596] C:\WINNT\system32\mskisg.exe