感觉以下部分很可疑
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
<IFEO[auto.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSDOS.bat]
<IFEO[MSDOS.bat]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe]
<IFEO[ntldr.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
<IFEO[pagefile.pif]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
<IFEO[sos.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe]
<IFEO[sxs.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe]
<IFEO[test.exe]><AUTOGUARDER GUARDED.> [N/A]
进程
[PID: 1628][C:\WINDOWS\system32\shadow\ShadowService.exe] [N/A, ]
[PID: 1648][F:\安装软件包\系统工具\CPU超线程\ProcessTamerTray.exe] [, 1, 0, 0, 1]
问一下那个分析助手进程模块列表颜色表示什么
看下我电脑里这个值有问题不?
[HID Input Service / HidServ][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>