<TBMonEx><C:\WINNT\Fonts\00-E0-4C-CF-3D-83\system\wdfmgr.exe> []
<inudhya><C:\WINNT\Fonts\00-E0-4C-CF-3D-83\system\soundma.exe> []
<DbgHlp32><C:\WINNT\DbgHlp32.exe> []
<SHAProc><C:\WINNT\SHAProc.exe> []
<PTSShell><C:\WINNT\PTSShell.exe> []
<WSockDrv32><C:\WINNT\WSockDrv32.exe> []
<upxdnd><C:\WINNT\upxdnd.exe> []
<LotusHlp><C:\WINNT\LotusHlp.exe> []
<AVPSrv><C:\WINNT\AVPSrv.exE> []
<Kvsc3><C:\WINNT\Kvsc3.exE> []
<NAVMon32><C:\WINNT\NAVMon32.exE> []
<kkaddmin><C:\WINNT\Fonts\00-E0-4C-CF-3D-83\system\fbd.exe> []
<{3c285e83-783b-4edf-829e-a64fd1f43fd3}><C:\WINNT\system32\ayFKKFKK1052.dll> []
<{73627e95-ccad-47bb-a7a6-3180cb5dfb0d}><C:\WINNT\system32\ayNNBNNB1042.dll> []
<{34743023-ddce-4387-81c1-def2083a716b}><C:\WINNT\system32\ayCBDCBD1041.dll> []
<{6167F471-EF2B-41DD-A5E5-C26ACDB5C096}><C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys> []
[XDSERVER / XDSERVER][Stopped/Auto Start]
<C:\WINDOWS\system\tes.exe><N/A>
[msert / msert][Stopped/Manual Start]
<\??\C:\WINNT\system32\DRIVERS\mselk.sys><N/A>
[MS / MS][Stopped/Disabled]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpD.tmp><N/A>
[C:\WINNT\system32\DbgHlp32.dlL] [N/A, ]
[C:\WINNT\Fonts\00-E0-4C-CF-3D-83\system\inudhya.dll] [N/A, ]
[C:\WINNT\system32\SHAProc.dat] [N/A, ]
[C:\WINNT\system32\cuhad.dll] [N/A, ]
[C:\WINNT\system32\MSVCP60.DLL] [Microsoft Corporation, 6.00.8972.0]
[C:\WINNT\system32\PTSShell.dll] [N/A, ]
[C:\WINNT\system32\oqnauhc.dll] [N/A, ]
[C:\WINNT\system32\upxdnd.dll] [N/A, ]
[C:\WINNT\system32\WSockDrv32.dll] [N/A, ]
[C:\WINNT\system32\AVPSrv.dll] [N/A, ]
[C:\WINNT\system32\LotusHlp.dll] [N/A, ]
[C:\WINNT\system32\ijougiemnaw.dll] [N/A, ]
[C:\WINNT\system32\Kvsc3.dll] [N/A, ]
[C:\WINNT\system32\yqhs.dll] [N/A, ]
[C:\WINNT\system32\bchib.dll] [N/A, ]
[C:\WINNT\system32\NAVMon32.dll] [N/A, ]
[C:\WINNT\system32\xjxr.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys] [N/A, ]
[C:\WINNT\system32\ayFKKFKK1052.dll] [N/A, ]
[C:\WINNT\system32\ayNNBNNB1042.dll] [N/A, ]
[C:\WINNT\system32\ayCBDCBD1041.dll] [N/A, ]
Autorun.inf
[C:\]
[AutoRun]
OPEN=ntldr.exe
shellexecute=ntldr.exe
shell\打开(&O)\command=ntldr.exe
[D:\]
[AutoRun]
OPEN=ntldr.exe
shellexecute=ntldr.exe
shell\打开(&O)\command=ntldr.exe
[E:\]
[AutoRun]
OPEN=ntldr.exe
shellexecute=ntldr.exe
shell\打开(&O)\command=ntldr.exe
[F:\]
[AutoRun]
OPEN=ntldr.exe
shellexecute=ntldr.exe
shell\打开(&O)\command=ntldr.exe
logogo及其下载的木马群