注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<u1rjs10ri1uew03><C:\DOCUME~1\cui\LOCALS~1\Temp\Servera.exe> [N/A]
<ym6t5yvzdk2rm><C:\DOCUME~1\cui\LOCALS~1\Temp\winlog0n.exe> [N/A]
<rg60qte9qw61w><C:\DOCUME~1\cui\LOCALS~1\Temp\crasos.exe> [N/A]
<dtb46vxxrkiub><C:\DOCUME~1\cui\LOCALS~1\Temp\iexp10re.exe> [N/A]
<qhm2><C:\DOCUME~1\cui\LOCALS~1\Temp\iexpl0re.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<sun><C:\WINDOWS\SysSun1\svchost.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<upxdnd><C:\DOCUME~1\cui\LOCALS~1\Temp\upxdnd.exe> [N/A]
<winform><C:\WINDOWS\winform.exe> [N/A]
<IEBarUp><RunDll32 "C:\WINDOWS\System32\msUPT.dll",Run> []
<mppds><C:\WINDOWS\mppds.exe> [N/A]
<Desktop><"C:\WINDOWS\System32\internet.exe"> [Microsoft Corporation]
<Internet><"C:\WINDOWS\system32\internet.exe"> [Microsoft Corporation]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> [CNNIC]
<tcjfcji><C:\Program Files\Intel\tcjfcji.exe> [N/A]
<pxdnd><C:\DOCUME~1\cui\LOCALS~1\Temp\pxdnd.exe> [N/A]
<nwiztlbb><C:\WINDOWS\System32\nwiztlbb.exe> [N/A]
<nwizqqfo><C:\WINDOWS\System32\nwizqqfo.exe> [N/A]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> [N/A]
<msccrt><C:\WINDOWS\msccrt.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\System32\NTDLL32.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
<IFEO[avp.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccEvtMgr.exe]
<IFEO[ccEvtMgr.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSetApp.exe]
<IFEO[ccSetApp.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSetMgr.exe]
<IFEO[ccSetMgr.exe]><svchost.exe> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DefWatch.exe]
<IFEO[DefWatch.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe]
<IFEO[KAVStart.exe]><svchost.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMaiMon.exe]
<IFEO[KMaiMon.exe]><svchost.exe> [(Verified)Tencent Technology(Shenzhen) Company Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe]
<IFEO[KPfwSvc.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvsrvxp.exe]
<IFEO[kvsrvxp.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVWSC.exe]
<IFEO[KVWSC.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe]
<IFEO[KWatch.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McAgent.exe]
<IFEO[McAgent.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctskshd.exe]
<IFEO[mctskshd.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdmgr.exe]
<IFEO[mcupdmgr.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe]
<IFEO[nod32krn.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe]
<IFEO[nod32kui.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe]
<IFEO[PFW.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ras.exe]
<IFEO[ras.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe]
<IFEO[Rav.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMON.exe]
<IFEO[RavMON.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ravmond.exe]
<IFEO[Ravmond.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe]
<IFEO[RavStub.exe]><svchost.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
<IFEO[RavTask.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe]
<IFEO[RfwMain.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
<IFEO[rfwsrv.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe]
<IFEO[rtvscan.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe]
<IFEO[runiep.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
启动文件夹
[yfhlgc]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\yfhlgc.lnk --> C:\PROGRA~1\MICROS~4\yfhlgcj.exe [N/A]><N>
==================================
==================================
驱动程序
[cjebihhf / cjebihhf][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\cjebihhf.sys><N/A>
[dibaabae / dibaabae][Running/Manual Start]
<\??\C:\WINDOWS\system32\drivers\dibaabae.sys><N/A>
[jcaehcga / jcaehcga][Running/Manual Start]
<\??\C:\WINDOWS\system32\drivers\jcaehcga.sys><N/A>
[kmsinput / kmsinput][Running/Manual Start]
<\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
==================================
正在运行的进程
[PID: 556][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 628][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\febd.dll] [N/A, ]
[C:\WINDOWS\System32\330f.dll] [ , 1, 0, 0, 3]
[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\webpageparser.dll] [N/A, ]
[C:\WINDOWS\System32\Charset.dll] [N/A, ]
[C:\WINDOWS\System32\CreateDomTree.dll] [N/A, ]
[C:\WINDOWS\System32\winlib .dll] [N/A, ]
[C:\WINDOWS\System32\febd.dll] [N/A, ]
[C:\WINDOWS\System32\330f.dll] [ , 1, 0, 0, 3]
[c:\progra~1\kbfs\xosf.dll] [, 1, 0, 0, 6]
[c:\progra~1\kbfs\ctxk.dll] [ , 1, 0, 0, 6]
怎么越看越觉得运行的都是病毒啊,象征性的把前面的拿出来了 ,其他的觉得也是……好多……
==================================
Autorun.inf
[C:\]
[AutoRun]
Open=sxs.exe
Shell\Open=打开(&O)
Shell\Open\Command=sxs.exe
Shell\Open\Default=1
Shell\Explore=资源管理器(&X)
Shell\Explore\Command=sxs.exe
[D:\]
[AutoRun]
Open=sxs.exe
Shell\Open=打开(&O)
Shell\Open\Command=sxs.exe
Shell\Open\Default=1
Shell\Explore=资源管理器(&X)
Shell\Explore\Command=sxs.exe
[E:\]
[AutoRun]
Open=sxs.exe
Shell\Open=打开(&O)
Shell\Open\Command=sxs.exe
Shell\Open\Default=1
Shell\Explore=资源管理器(&X)
Shell\Explore\Command=sxs.exe
[F:\]
[AutoRun]
Open=sxs.exe
Shell\Open=打开(&O)
Shell\Open\Command=sxs.exe
Shell\Open\Default=1
Shell\Explore=资源管理器(&X)
Shell\Explore\Command=sxs.exe
还有一个问题,hosts文件里面的,是病毒么?还是有一把这些网址屏蔽掉了?