1.<QQ><C:\WINDOWS\system\QQ.exe> []QQ都没有公司签名很可疑啊
2.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{CC3596CB-D6C1-ECA1-AE51-DEEA63F6C21C}><C:\Program Files\Internet Explorer\OnlO0r.dll> [N/A]
<{61C1B9CE-1A6F-4994-B4A4-0E7C99AD4C28}><C:\WINDOWS\system32\mndoor0.dll> [N/A]
<{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}><C:\WINDOWS\system32\qhdoor0.dll> [N/A]
<{49C496E9-732D-4F5D-BEE9-EC113FAA1C97}><C:\WINDOWS\system32\qzdoor0.dll> [N/A]
<{C26A8AB5-B935-400C-A152-0488714725B1}><C:\WINDOWS\system32\qsdoor0.dll> [N/A]
<{F859245F-345D-BC13-AC4F-145D47DA34FF}><C:\WINDOWS\Fonts\avzxomn.dll> [N/A]
<{76255dcf-d686-4d89-82d1-78fef7b3dc00}><C:\WINDOWS\system32\IGB_WD_1026.dll> [N/A]
<{4FA10261-B890-F432-A453-69F1023513F4}><C:\WINDOWS\Fonts\gjcsdyc.dll> [N/A]
<{9963387B-212E-4643-B207-82DAEA0E713D}><C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys> [N/A]
<{8DFA2904-9664-43AE-8929-4347554D24B6}><C:\WINDOWS\system32\csavpw1.dll> [N/A]
<{471B15AD-7A9C-491D-9C19-4E15B12DCE00}><C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys> [N/A]
<{80F15C30-5E9D-4CB9-BE85-F3D5564C6F83}><C:\WINDOWS\system32\fhdoor0.dll> []这些是什么/
3.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]这都没有公司签名啊
4.[QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ.lnk --> C:\WINDOWS\system\QQ.exe [N/A]><N>这个路径对么?还没有签名,与上面的对照很可疑
5.驱动
npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\QQ2007\npkcrypt.sys><INCA Internet Co., Ltd.>路径?
[msskye / msskye][Running/Auto Start]
<system32\DRIVERS\msaclue.sys><N/A>
[Network Monitor Protocol Driver / Ndisprot][Stopped/Manual Start]
<system32\DRIVERS\winsys.sys><N/A>这个也可疑
6.浏览器加载项
[]
{471B15AD-7A9C-491D-9C19-4E15B12DCE00} <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys, N/A>
[]
{9963387B-212E-4643-B207-82DAEA0E713D} <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys, N/A>
[]
{C2626E66-D21B-E628-C1DF-1DACCFA36ED2} <C:\Program Files\Common Files\fjOs0r.dll, N/A>
[]
{471B15AD-7A9C-491D-9C19-4E15B12DCE00} <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys, N/A>
……加载项名称为空还是不明白是什么原因,怎么解决,直接删除么?而且都没有公司签名
7.剩下的大概没什么了,感觉现在才有点入门了