觉得可疑的地方:
c:\windows\system32\bfd03\svchost.exe
d:\program files\rising\rav\hookcont.dll
d:\program files\rising\rav\rscommx.dll
d:\program files\rising\rav\rsvm.dll
d:\program files\rising\rav\spameng.dll (这几个没有瑞星的签名,不是很确定)
c:\windows\system32\da77whcy.dll
c:\windows\system32\jrpavu79.dll
d:\program files\alisoft\wangwang\ali_res.dll
d:\program files\alisoft\wangwang\messagenotify.dll
d:\program files\alisoft\wangwang\ww_network.dll
d:\program files\alisoft\wangwang\zlib.dll (这几个没有阿里旺旺的签名,不是很肯定)
d:\program files\tencent\qq\bqqapplication.dll
d:\program files\tencent\qq\cqqapplication.dll (这两个没有qq的签名)
驱动非常的不清楚,拿出来这几项问问吧:
c:\windows\system32\drivers\w0zy.sys
c:\windows\system32\drivers\secdrv.sys
c:\windows\system32\drivers\prchm19k.sys
c:\windows\system32\drivers\jrpavu79.sys
c:\program files\igalive\igalive.sys
d:\program files\rising\rav\hookreg.sys
d:\program files\rising\rav\expscan.sys
c:\windows\system32\drivers\eaglent.sys
[Yahoo Service / YahooSvr] <C:\WINDOWS\system32\BFD03\svchost.exe>
[w0zy / w0zy] <\??\C:\WINDOWS\system32\drivers\w0zy.sys>
[Secdrv / Secdrv] <system32\DRIVERS\secdrv.sys>
[prchm19 / prchm19k] <\SystemRoot\System32\DRIVERS\prchm19k.sys>
[jrpavu7 / jrpavu79] <\SystemRoot\System32\DRIVERS\jrpavu79.sys>
[IGALIVE / IGALIVE] <\??\C:\Program Files\IGALIVE\IGALIVE.sys>
[HookReg / HookReg] <\??\D:\PROGRAM FILES\RISING\RAV\HookReg.sys>
[ExpScaner / ExpScaner] <\??\D:\PROGRAM FILES\RISING\RAV\ExpScan.sys>
[EagleNT / EagleNT] <\??\C:\WINDOWS\system32\drivers\EagleNT.sys>