日志中异常项目如下:
注册表[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><> [N/A]
<{B960356A-458E-DE24-BD50-268F589A56AB}><C:\WINDOWS\Fonts\avwlkmn.dll> [File is missing]
<{1D908534-AD45-920F-AC89-4024FA9D26D1}><C:\WINDOWS\system32\gjfhayc.dll> [File is missing]
<{A8907901-1416-3389-9981-37217856998A}><C:\WINDOWS\Fonts\kawdjzy.dll> [File is missing]
<{D9FA4178-7749-A8D9-F5C8-88645525769D}><C:\WINDOWS\Fonts\kashmzy.dll> [File is missing]
<{D4783410-4F90-34A0-7820-3230ACD05F4D}><C:\WINDOWS\Fonts\raqjmpi.dll> [File is missing]
<{AA1247C1-53DA-FF43-ABD3-345F323A48DA}><C:\WINDOWS\Fonts\avwgjmn.dll> [File is missing]
<{3D098345-9012-8750-8910-9128098134D3}><C:\WINDOWS\Fonts\jsqxcyc.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{81716107-A10D-11cf-64CD-11115FE1CF41}]
<N/A><C:\WINDOWS\system32\nwizzhuxians.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{77709117-A10D-41cf-64CD-51FF5FE1CF41}]
<N/A><C:\WINDOWS\system32\nwizwmgjs.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A202101-A04D-21cf-65CD-31FF5FE1CF20}]
<N/A><C:\WINDOWS\system32\mydata.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{99371217-A10D-11cf-64CD-316F9FE1CF41}]
<N/A><C:\WINDOWS\system32\nwizwlwzs.exe> [File is missing]
服务
[NT Data Provider / MOVEESS][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE C:\WINDOWS\SYSTEM32\WBEM\NGDDZ.DLL,Export 1087><(File is missing)>
[ms cic / mscic][Stopped/Auto Start]
<C:\WINDOWS\system32\CIC~1.EXE><(File is missing)>
驱动程序[epfwtdir / epfwtdir][Running/System Start]
<system32\DRIVERS\epfwtdir.sys><N/A>
[ikrdsr / ikrdsr][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ikrdsr.sys><N/A>
[ltghy / ltghyd][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ltghyd.sys><N/A>
[mihll / mihlls][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\mihlls.sys><N/A>
[ngyiqv / ngyiqv][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ngyiqv.sys><N/A>
[spzmnd / spzmnd][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\spzmnd.sys><N/A>
[sysHostSvc / sysHostSvc][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\GuiHelp.sys><Microsoft Corporation>
[wlgva / wlgvaj][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\wlgvaj.sys><N/A>
[zvzce / zvzces][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\zvzces.sys><N/A>
浏览器加载项[YIEPro Class]
{17A95734-73BE-4E38-B46F-CF8EF298F339} <C:\WINDOWS\system32\shina.cpl, N/A>
正在运行的进程瑞星杀软 + NOD32的进程到处都能发现,还有个迅游网络加速器的进程C:\WINDOWS\system32\xunyount.dll到处插进程,我倒
Winsock 提供者
xunyou over MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou over MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou over MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou
C:\WINDOWS\system32\xunyount.dll(, N/A)
计划任务[已启用] AppleSoftwareUpdate.job
C:\Program Files\Apple Software Update\SoftwareUpdate.exe
[已启用] YneuU.job
C:\WINDOWS\system32\zfnjjfm.exe
【注意】想对新手说一下几个重要的安全知识,以避免你们再走弯路:1、个人认为,要想网络真正加速,去电信营运商那里申请更高带宽是最有效的。至于所谓的网络加速软件,基本都是扯淡,不仅加速效果基本看不到,而且带来的副作用多多,主要是篡改LSP;2、杀软安装一个足够,正所谓一山不容二虎,装2个以上的杀软,效果并非1+1>2,实际效果往往是1+1<2,甚至可能是1+1<1。这些基本常识问题,自己有时间先了解下吧。