中毒后的autoruns日志:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ cmdbcsc:\windows\cmdbcs.exe
+ Kvsc3c:\windows\kvsc3.exe
+ mppdsc:\windows\mppds.exe
+ upxdndc:\windows\upxdnd.exe
+ yeyinhic:\program files\common files\microsoft shared\pumthsg.exe
+ ykubdtec:\program files\common files\system\rujrmue.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ 360rpt.exec:\program files\common files\microsoft shared\pumthsg.exe
+ 360Safe.exec:\program files\common files\microsoft shared\pumthsg.exe
+ 360tray.exec:\program files\common files\microsoft shared\pumthsg.exe
+ adam.exec:\program files\common files\microsoft shared\pumthsg.exe
+ AgentSvr.exec:\program files\common files\microsoft shared\pumthsg.exe
+ AppSvc32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ ArSwp.exec:\program files\common files\microsoft shared\pumthsg.exe
+ AST.exec:\program files\common files\microsoft shared\pumthsg.exe
+ autoruns.exec:\program files\common files\microsoft shared\pumthsg.exe
+ avconsol.exec:\program files\common files\microsoft shared\pumthsg.exe
+ avgrssvc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ AvMonitor.exec:\program files\common files\microsoft shared\pumthsg.exe
+ avp.comc:\program files\common files\microsoft shared\pumthsg.exe
+ avp.exec:\program files\common files\microsoft shared\pumthsg.exe
+ CCenter.exec:\program files\common files\microsoft shared\pumthsg.exe
+ ccSvcHst.exec:\program files\common files\microsoft shared\pumthsg.exe
+ EGHOST.exec:\program files\common files\microsoft shared\pumthsg.exe
+ FileDsty.exec:\program files\common files\microsoft shared\pumthsg.exe
+ FTCleanerShell.exec:\program files\common files\microsoft shared\pumthsg.exe
+ FYFireWall.exec:\program files\common files\microsoft shared\pumthsg.exe
+ HijackThis.exec:\program files\common files\microsoft shared\pumthsg.exe
+ IceSword.exec:\program files\common files\microsoft shared\pumthsg.exe
+ iparmo.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Iparmor.exec:\program files\common files\microsoft shared\pumthsg.exe
+ isPwdSvc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ kabaload.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KaScrScn.SCRc:\program files\common files\microsoft shared\pumthsg.exe
+ KASMain.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KASTask.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAV32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAVDX.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAVPF.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAVPFW.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAVSetup.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KAVStart.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KISLnchr.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KMailMon.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KMFilter.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KPFW32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KPFW32X.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KPfwSvc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KRegEx.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KRepair.comc:\program files\common files\microsoft shared\pumthsg.exe
+ KsLoader.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KVCenter.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KvDetect.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KvfwMcl.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KVMonXP.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KVMonXP_1.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ kvol.exec:\program files\common files\microsoft shared\pumthsg.exe
+ kvolself.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KvReport.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KVScan.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KVSrvXP.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KVStub.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ kvupload.exec:\program files\common files\microsoft shared\pumthsg.exe
+ kvwsc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KvXP.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KvXP_1.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ KWatch.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KWatch9x.exec:\program files\common files\microsoft shared\pumthsg.exe
+ KWatchX.exec:\program files\common files\microsoft shared\pumthsg.exe
+ loaddll.exec:\program files\common files\microsoft shared\pumthsg.exe
+ MagicSet.exec:\program files\common files\microsoft shared\pumthsg.exe
+ mcconsol.exec:\program files\common files\microsoft shared\pumthsg.exe
+ mmqczj.exec:\program files\common files\microsoft shared\pumthsg.exe
+ mmsk.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Navapsvc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Navapw32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ nod32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ nod32krn.exec:\program files\common files\microsoft shared\pumthsg.exe
+ nod32kui.exec:\program files\common files\microsoft shared\pumthsg.exe
+ NPFMntor.exec:\program files\common files\microsoft shared\pumthsg.exe
+ PFW.exec:\program files\common files\microsoft shared\pumthsg.exe
+ PFWLiveUpdate.exec:\program files\common files\microsoft shared\pumthsg.exe
+ QHSET.exec:\program files\common files\microsoft shared\pumthsg.exe
+ QQDoctor.exec:\program files\common files\microsoft shared\pumthsg.exe
+ QQKav.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Ras.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Rav.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RavMon.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RavMonD.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RavStub.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RavTask.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RegClean.exec:\program files\common files\microsoft shared\pumthsg.exe
+ rfwcfg.exec:\program files\common files\microsoft shared\pumthsg.exe
+ rfwmain.exec:\program files\common files\microsoft shared\pumthsg.exe
+ rfwsrv.exec:\program files\common files\microsoft shared\pumthsg.exe
+ RsAgent.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Rsaupd.exec:\program files\common files\microsoft shared\pumthsg.exe
+ runiep.exec:\program files\common files\microsoft shared\pumthsg.exe
+ safelive.exec:\program files\common files\microsoft shared\pumthsg.exe
+ scan32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ shcfg32.exec:\program files\common files\microsoft shared\pumthsg.exe
+ SmartUp.exec:\program files\common files\microsoft shared\pumthsg.exe
+ SREng.EXEc:\program files\common files\microsoft shared\pumthsg.exe
+ symlcsvc.exec:\program files\common files\microsoft shared\pumthsg.exe
+ SysSafe.exec:\program files\common files\microsoft shared\pumthsg.exe
+ TrojanDetector.exec:\program files\common files\microsoft shared\pumthsg.exe
+ Trojanwall.exec:\program files\common files\microsoft shared\pumthsg.exe
+ TrojDie.kxpc:\program files\common files\microsoft shared\pumthsg.exe
+ UIHost.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UmxAgent.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UmxAttachment.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UmxCfg.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UmxFwHlp.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UmxPol.exec:\program files\common files\microsoft shared\pumthsg.exe
+ upiea.exec:\program files\common files\microsoft shared\pumthsg.exe
+ UpLive.exec:\program files\common files\microsoft shared\pumthsg.exe
+ USBCleaner.exec:\program files\common files\microsoft shared\pumthsg.exe
+ vsstat.exec:\program files\common files\microsoft shared\pumthsg.exe
+ webscanx.exec:\program files\common files\microsoft shared\pumthsg.exe
+ WoptiClean.exec:\program files\common files\microsoft shared\pumthsg.exe