问题项目如下:
注册表:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<hefcndy><; C:\WINDOWS\hefcndy.exe> [File is missing]
<ticisms><C:\WINDOWS\ticisms.exe> [File is missing]
<cinfonmc><C:\WINDOWS\cinfonmc.exe> [File is missing]
<isndntio><C:\WINDOWS\isndntio.exe> [File is missing]
<fmsiocps><C:\WINDOWS\fmsiocps.exe> [File is missing]
<anistio><C:\WINDOWS\anistio.exE> [File is missing]
<dionpis><C:\WINDOWS\dionpis.exe> [File is missing]
<mfchlp64><C:\WINDOWS\mfchlp64.exe> [File is missing]
<jscuwqve><C:\WINDOWS\suqepzru.exe> [File is missing]
<fmsjhif><C:\WINDOWS\fmsjhif.exe> [File is missing]
<fmsbbqi><C:\WINDOWS\fmsbbqi.exe> [File is missing]
<dbhlp32><C:\WINDOWS\dbhlp32.exe> [File is missing]
<tciocp64><C:\WINDOWS\tciocp64.exe> [File is missing]
<ptshell><C:\WINDOWS\ptshell.exe> [File is missing]
<huifitc><C:\WINDOWS\huifitc.exe> [File is missing]
<bincdwsa><C:\WINDOWS\bincdwsa.exe> [File is missing]
<fmbiost><C:\WINDOWS\fmbiost.exe> [File is missing]
<dndsioc><C:\WINDOWS\dndsioc.exe> [File is missing]
<yuiabct><C:\WINDOWS\yuiabct.exe> [File is missing]
<wipicdec><C:\WINDOWS\wipicdec.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
<IFEO[360safe.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
<IFEO[360safebox.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPPMain.exe]
<IFEO[KPPMain.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe]
<IFEO[KWatch.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe]
<IFEO[QQDoctor.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe]
<IFEO[QQKav.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe]
<IFEO[RavMon.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
<IFEO[RavMonD.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe]
<IFEO[safeboxTray.exe]><ntsd -D> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tqat.exe]
<IFEO[tqat.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><SysDaJHv.dll,fmsiocps.dll,davuqe.dll,msosmhfp01.dll,nzcbhs.dll,msoscqit00.dll,nicozftp01.dll,msosdohs02.dll,msosfmsq01.dll,msosmnsf00.dll,msosjtio01.dll,msosptfs00.dll,wipicdec.dll> [File is missing]
驱动程序:
[Atixeve23750 / Atixeve23750][Stopped/Manual Start]
<\??\C:\WINDOWS\TEMP\~wxp2ins.468.tmp><N/A>
[cafesvr / cafesvr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cafesvr><N/A>
[cqit / cqit][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpD.tmp><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp11.tmp><N/A>
[fmsq / fmsq][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpF.tmp><N/A>
[ilgta / ilgta9][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ilgta9.sys><N/A>
[jtio / jtio][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp15.tmp><N/A>
[k9xv / k9xv][Stopped/Boot Start]
<\SystemRoot\system32\drivers\k9xv.sys><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp1.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp13.tmp><N/A>
[msfpfis64 / msfpfis64][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[msp2p32 / msp2p32][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys><N/A>
[ping / ping][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp19.tmp><N/A>
[pmkkge / pmkkge][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\pmkkge><N/A>
[ptfs / ptfs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp17.tmp><N/A>
[zftp / zftp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9.tmp><N/A>
[zzxurs / zzxurs][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\zzxurs><N/A>
浏览器加载项
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[]
{398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\DosSys16.Sys, N/A>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[]
{398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\DosSys16.Sys, N/A>
正在运行的进程(不含以上问题项目对应的文件)
C:\WINDOWS\system32\davuqe.dll
C:\WINDOWS\system32\nzcbhs.dll