可疑注册表项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<sua><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\suad.exe> []
<5cfead0a><rundll32.exe "C:\WINDOWS\system32\lqkdvemt.dll",b> []
可疑驱动程序
[fypakry9 / fypakry9][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\fypakry9.sys><N/A>
[gsjpyey / gsjpyey0][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\gsjpyey0.sys><N/A>
[lemflhpf / lemflhpf][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\lemflhpf.sys><N/A>
[Sys Process Notify for NT. / SysPrNty][Running/Manual Start]
<\??\C:\WINDOWS\system32\SysPrNty.sys><N/A>
可疑浏览器加载项
[]
{4D2EAF15-81D0-42DA-8C39-19EDD39E0FB3} <C:\WINDOWS\system32\yzljeqgsxg.dll, >
[]
{BEF826F1-63A3-4463-898E-5FFBE9FF6B30} <C:\WINDOWS\system32\jkhfc.dll, N/A>
[]
{F5E39B75-9D21-44C9-85FA-B8411267462A} <C:\WINDOWS\system32\jvpcdqne.dll, N/A>
可疑文件
C:\WINDOWS\system32\lqkdvemt.dll
C:\WINDOWS\system32\drivers\fypakry9.sys
C:\WINDOWS\System32\DRIVERS\gsjpyey0.sys
C:\WINDOWS\System32\drivers\lemflhpf.sys
C:\WINDOWS\system32\SysPrNty.sys
C:\WINDOWS\system32\yzljeqgsxg.dll
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\jvpcdqne.dll
C:\WINDOWS\system32\SysPrNty.sys