以下是我个人认为的问题项目,不排除误判:
=================================================
注册表[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MPMKrnl><rundll32 "C:\WINDOWS\MKMKrnl.dll",KMainProc> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Webcam><C:\Program Files\Messenger\msgswcam.dll> [File is missing] <ThunderAdvise><> [N/A]
<C:\WINDOWS\system32\gffqfjnj.dll><> [N/A]上面红色的注册表值项已经怀疑很久了,苦无证据……
服务[Windows Presentation Foundaution (WPF) / appliuucation][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k appliuucation-->C:\WINDOWS\system32\ZCOGYcQSidi.dll><N/A>
[MS Media Controler / MediaC][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k krnlsrvc-->C:\WINDOWS\system32\NerrtHG.dll><@ Microsoft Corporation. All rights reserved.>
[National Instruments Domain Service / National][Running/Auto Start]
<C:\WINDOWS\system32\QQPlatform.exe><>
[SRAT_Service / SRAT_Service][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\drivers\etc\eMthxqlT.dll><N/A>
[WINNT / WINNTMAGE][Running/Auto Start]
<C:\WINDOWS\doc><N/A>
[zjadfz / zjadfz][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k zjadfz-->%SystemRoot%\System32\ycoaut.dll><N/A>
驱动程序[00018075 / 00018075][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\00018075.sys><N/A>
[014839e1 / 014839e1][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\014839e1.sys><N/A>
[compbatcDrv / compbatcDrv][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\compbatc.sys><N/A>
[yjadfzbs / yjadfzbs][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ycoaut.sys><N/A>
[yqhjwhen / yqhjwhen][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\gplpax.sys><N/A>
浏览器加载项[网址大全]
{C18CB140-0BBB-11D4-8FE8-0088CC102438} <
http://www.k369.com, N/A>
正在运行的进程
c:\windows\system32\nerrthg.dll
C:\WINDOWS\system32\QQPlatform.exe
C:\WINDOWS\doc
C:\WINDOWS\MKMKrnl.dll
===============================================