问题项目如下:
==================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<ming9bstart><C:\WINDOWS\system\ming9b090423.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{153FC33C-8D26-4620-ACBA-3371AAC67A23}><C:\WINDOWS\System32\flysoft.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe]
<IFEO[apvxdwin.exe]><ntsd -d> [N/A]
……………………………………………………(此处省略n处病毒添加的IFEO项)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xnlscn.exe]
<IFEO[xnlscn.exe]><ntsd -d> [N/A]
==================================
服务
[Application Management / AppMgmt][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>(该系统服务的映像文件可能被感染)
[Microsoft Device Logical / porting][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k "porting"-->C:\WINDOWS\system32\c5883c.dll><Microsoft Corporation>
==================================
驱动程序
[klan / klan][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\klan.sys><N/A>(未知驱动程序)
[mtlrd / mtlrd][Running/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\wmp\mtlrd.sys><N/A>
[wvtvo / wvtvo][Running/Boot Start]
<\SystemRoot\system32\drivers\kztxy.sys><N/A>
==================================
正在运行的进程
[c:\windows\system32\appmgmts.dll] [N/A, ](系统文件,可能已被感染)
[C:\Program Files\Common Files\PushWare\cpush.dll] [, 1.1.4.1]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
==================================
核心就是这个C:\WINDOWS\system32\Com\1.2.8\WndHook.dll病毒文件。