[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<4l1su><C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\Servera.exe> [N/A]
<166h><; C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\iexp10re.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Wingin><C:\WINDOWS\System32\Wingin.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{0a1d93b9-0e5d-4239-94df-6e673bf85067}><C:\WINDOWS\System32\IIA-IIA-1030.dll> [N/A]
<{94f833b0-726d-4d09-b715-6352f632ece7}><C:\WINDOWS\System32\QAB_QAB_1011.dll> [N/A]
<{b5345280-2ea6-493c-bad5-d92ed78076b0}><C:\WINDOWS\System32\QAB-QAB-1012.dll> [N/A]
驱动程序
[33g8ta2 / 33g8ta21][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\33g8ta21.sys><N/A>
C:\WINDOWS\System32\userinit.exe被病毒感染了。