系统服务
[AM] 1. c:\windows\system32\rundllforour.exe
内核驱动
cnprov
[A ] 23. c:\windows\system32\drivers\cnprov.sys
csufhp09
[A ] 24. c:\windows\system32\drivers\csufhp09.sys
ctumcl99
[A ] 25. c:\windows\system32\drivers\ctumcl99.sys
fzyeey43
[A ] 33. c:\windows\system32\drivers\fzyeey43.sys
idnaux
[A ] 39. c:\windows\system32\drivers\idnaux.sys
jnnccy04
[A ] 41. c:\windows\system32\drivers\jnnccy04.sys
kqsvfb02
[A ] 42. c:\windows\system32\drivers\kqsvfb02.sys
NPF
[A ] 46. c:\windows\system32\drivers\npf.sys nykkec73
[A ] 48. c:\windows\system32\drivers\nykkec73.sys
SVKP
[A ] 58. c:\windows\system32\svkp.sys +
用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
wosa
[A ] 94. c:\documents and settings\administrator\local settings\temp\woso.exe
VL橸谚?_Y??G,QV?褤瑒,
ztsa
[A ] 95. c:\documents and settings\administrator\local settings\temp\ztso.exe
VL橸谚?_Y??G,QV?褤瑒,
mhsa
[A ] 96. c:\documents and settings\administrator\local settings\temp\mhso.exe
VL橸谚?_Y??G,QV?褤瑒,
fysa
[A ] 97. c:\documents and settings\administrator\local settings\temp\fyso.exe
VL橸谚?_Y??G,QV?褤瑒,
jtsa
[A ] 98. c:\documents and settings\administrator\local settings\temp\jtso.exe
VL橸谚?_Y??G,QV?褤瑒,
wlsa
[A ] 99. c:\documents and settings\administrator\local settings\temp\wlso.exe
VL橸谚?_Y??G,QV?褤瑒,
wgsa
[A ] 100. c:\documents and settings\administrator\local settings\temp\wgso.exe
VL橸谚?_Y??G,QV?褤瑒,
wmsa
[A ] 101. c:\documents and settings\administrator\local settings\temp\wmso.exe
VL橸谚?_Y??G,QV?褤瑒,
qjsa
[A ] 102. c:\documents and settings\administrator\local settings\temp\qjso.exe
VL橸谚?_Y??G,QV?褤瑒,
wdsa
[A ] 103. c:\documents and settings\administrator\local settings\temp\wdso.exe
VL橸谚?_Y??G,QV?褤瑒,
tlsa
[A ] 104. c:\documents and settings\administrator\local settings\temp\tlso.exe
VL橸谚?_Y??G,QV?褤瑒,
rxsa
[A ] 105. c:\documents and settings\administrator\local settings\temp\rxso.exe
VL橸谚?_Y??G,QV?褤瑒,
dasa
[A ] 106. c:\documents and settings\administrator\local settings\temp\daso.exe
VL橸谚?_Y??G,QV?褤瑒,
IdnSvr
[AM] 110. c:\program files\ocins\idnsvr.exe
删除以上项目及对应的文件