日志中异常部分如下:
=================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe C:\PROGRA~1\COMMON~1\Microsoft\CTHELPER.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExitCmd.exe]
<IFEO[ExitCmd.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svcrer.exe]
<IFEO[svcrer.exe]><ntsd -d> [N/A]
==================================
服务
[Heal Certificate Management / msnapa][Others/Auto Start]
<C:\Program Files\Microsoft Office\smss.exe><N/A>
==================================
驱动程序
[CLDHWNTBBKFHZXNNDTDDAZUCHOZTSEM / CLDHWNTBBKFHZXNNDTDDAZUCHOZTSEM][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[CNFJPXKGVILYHQPXLGCVAUZMMCMGOZJ / CNFJPXKGVILYHQPXLGCVAUZMMCMGOZJ][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[FGCOALVPGSOMGMNSMRTYAGCMRPWOTRG / FGCOALVPGSOMGMNSMRTYAGCMRPWOTRG][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[FZRQBUSUGBTDNXZJSFEGMMWLBGFJEKE / FZRQBUSUGBTDNXZJSFEGMMWLBGFJEKE][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[HDYDJQYXUEFIGIOCRWCRYIPHBWERFLW / HDYDJQYXUEFIGIOCRWCRYIPHBWERFLW][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[KOVPHPYMJTXYDVISFMLFLOCVCUQXZMS / KOVPHPYMJTXYDVISFMLFLOCVCUQXZMS][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[MCDILEUTNXPQDJOMMJLQHKBIBCJUFJB / MCDILEUTNXPQDJOMMJLQHKBIBCJUFJB][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
[NDXPJITAFFDFSUWQBWXYCPTOXBXBOHL / NDXPJITAFFDFSUWQBWXYCPTOXBXBOHL][Stopped/Manual Start]
<\??\F:\超级\StrongBox\StrongBox\StrongBox.sys><N/A>
上面一群驱动不知道是什么,驱动的注册表子项名称很奇怪,怀疑……
[Hy Pen / hypen][Running/Boot Start]
<\SystemRoot\System32\Drivers\hypen.sys><N/A>
上述驱动可能是汉王手写板的,自己确定下。
===================================
【建议】
将以下文件分别用WINRAR压缩,将压缩包批量提交“可疑文件交流区”鉴定:
C:\PROGRAM FILES\COMMON FILES\Microsoft\CTHELPER.EXE
C:\Program Files\Microsoft Office\smss.exe
C:\Program Files\Microsoft Office\krnln.fnr
F:\超级\StrongBox\StrongBox\StrongBox.sys