异常注册表项:
1、[HKLM\System\CurrentControlSet\Services]
<NTGDT>
<PciHardDisk>
<qgx90g7>
<t0rj>
2、[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{5598FF45-DA60-F48A-BC43-10AC47853D55}
3、[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<WinAutoUp>
4、[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs>
以下文件压缩上传瑞星鉴定:
c:\windows\system32\drivers\ntgdt.sys
c:\windows\system32\drivers\pcidisk.sys
c:\windows\system32\rarjepi.dll
c:\windows\autoup.exe
c:\windows\system32\drivers\t0rj.sys
c:\windows\system32\drivers\qgx90g7.sys