1.[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<360tray><C:\WINDOWS\dyloty\spoolsv.vbs> []
<360safe><C:\WINDOWS\system32\sdfi\pool.vbs> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe]
<IFEO[guard.exe]><SvchoSt.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmain.exe]
<IFEO[wmain.exe]><SvchoSt.exe> [(Verified)Microsoft Windows Component Publisher]被SvchoSt.exe劫持了……
2.启动文件夹
[32B236]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\32B236.lnk --> C:\WINDOWS\system32\431CAD\32B236.EXE [File is missing]><N>
3.服务
[5288F63 / 5288F63][Stopped/Auto Start]
<C:\WINDOWS\Fonts\EE8FFAA4.EXE -k><(File is missing)>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
<D:\360杀毒\EHttpSrv.exe><(File is missing)>
[Eset Service / ekrn][Stopped/Auto Start]
<D:\360杀毒\ekrn.exe><(File is missing)>
[HID Input Service / HidServ][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
isale_pgsql_service / isale_pgsql_service][Stopped/Auto Start]
<f:/Program Files/isale_postgres/bin/pg_ctl.exe runservice -N "isale_pgsql_service" -D "f:/Program Files/isale_postgres/data"><(File is missing)>
[Windows Audios / Windows Audios][Stopped/Auto Start]
<C:\WINDOWS\Cursors\sevev.exe><(File is missing)>
[GJMCBDMEY / YZZYZRGMIG][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k YCDWILDDZ-->C:\Windows\system32\Microsoft\OVIJEOIWYB.DLL><N/A>
4.[davo / davo][Stopped/Boot Start]
<\SystemRoot\system32\drivers\hfuyt.sys><N/A>
[epfwtdir / epfwtdir][Running/System Start]
<system32\DRIVERS\epfwtdir.sys><N/A>
[mlinkgc / mlinkgc][Stopped/Boot Start]
<\SystemRoot\system32\drivers\vxwuk.sys><N/A>
[wakw / wakw][Running/Boot Start]
<\SystemRoot\system32\drivers\wakw.sys><N/A>
5.[iSee 保存所有图片]
<D:\iSee\iSeeSavePicAll.htm, N/A>
[iSee保存Flash]
<D:\iSee\iSeeSaveFlash.htm, N/A>
[iSee保存所有图片]
<D:\iSee\iSeeSavePicAll.htm, N/A>
[iSee读取Exif]
<D:\iSee\iSeeReadExif.htm, N/A>
[添加相册用户到iSee收藏]
<D:\iSee\iSeeAddToAlbum.htm, N/A>
6.[D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\Program Files\Tencent\QQ\MSIMG32.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\FinePlus.dll] [N/A, ]
7.特殊特权被允许: SeLoadDriverPrivilege [PID = 668, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2096, D:\CTFMEN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3716, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\FEIFEI.EXE]