驱动程序
[uizqqunyt / uizqqunyt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\02.tmp><N/A>
[uvrddtc / uvrddtc][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\01.tmp><N/A>
用SRENG扫描工具删除后重启电脑……
正在运行的进程
[PID: 216 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\CNAB4LMK.DLL] [CANON INC., 3.00.0.003]
[C:\WINDOWS\system32\CNAB4SMK.DLL] [CANON INC., 3.01.0.004]
[C:\WINDOWS\system32\CNAB4PTU.DLL] [CANON INC., 3.00.0.003]
[C:\WINDOWS\system32\E_SL2059.DLL] [SEIKO EPSON CORPORATION, 2, 8, 0, 0]
[C:\WINDOWS\system32\EBPMON2.DLL] [SEIKO EPSON CORPORATION, 2, 20, 0, 0]
[C:\WINDOWS\system32\HPBMMON.DLL] [Hewlett-Packard, 10.00.14]
[C:\WINDOWS\system32\hpdomon.dll] [Hewlett-Packard, 03.42.00]
[C:\WINDOWS\system32\HPBHealr.dll] [N/A, ] [C:\WINDOWS\system32\ZLhp1020.DLL] [Zenographics, Inc., 5, 53, 2714, 0]
[C:\WINDOWS\system32\ZLM.dll] [Zenographics, Inc., 5, 50, 1416, 0]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\system32\pdfcmnnt.dll] [N/A, ]
[C:\WINDOWS\system32\redmonnt.dll] [N/A, ]…………………………………………………………红的是可疑模块,插入了spoolsv.exe进程。