问题项目如下(不代表全部要删除,一些项目需要修改):
==================================
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HBService32><System.exe> [HB Software]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<dlnjjbdfa><C:\WINDOWS\system\llwzjy080929.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><HBmhly.dll,kmon.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{E560642D-A32D-432c-9E7E-9A135CC37E0F}><C:\WINDOWS\system32\wcsiskfv.dll> []
<{8566F82E-03A4-416E-AEAC-66600D8881F1}><8566F82E.dll> []
<{71A78CD4-E470-4a18-8457-E0E0283DD507}><C:\WINDOWS\system32\mjbdocmd.dll> [File is missing]
<{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}><C:\WINDOWS\system32\qahxbaod.dll> [File is missing]
<{AF976DCD-754F-4ac2-BE49-951DC7AA57D2}><C:\WINDOWS\system32\dizapdku.dll> [File is missing]
<{F0930A2F-D971-4828-8209-B7DFD266ED44}><C:\WINDOWS\system32\mfqylxfa.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<wcsiskfv.dll><C:\WINDOWS\system32\wcsiskfv.dll> []
<mjbdocmd.dll><C:\WINDOWS\system32\mjbdocmd.dll> [File is missing]
<qahxbaod.dll><C:\WINDOWS\system32\qahxbaod.dll> [File is missing]
<dizapdku.dll><C:\WINDOWS\system32\dizapdku.dll> [File is missing]
<mfqylxfa.dll><C:\WINDOWS\system32\mfqylxfa.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRun.exe]
<IFEO[AutoRun.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RStray.exe]
<IFEO[RStray.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
<IFEO[taskmgr.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
==================================
启动文件夹
[dfjje]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\dfjje.exe --> [File is missing]><N>
==================================
服务
[Background Intelligent Transfer Service / BITS][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\RmmptqC.dll><@ Microsoft Corporation. All rights reserved.>
==================================
驱动程序
[d4f876 / d4f876][Running/Manual Start]
<\??\C:\WINDOWS\system32\d4f876.sys><N/A>
[HBKernel32 Driver / HBKernel32][Stopped/Boot Start]
<\SystemRoot\system32\drivers\HBKernel32.sys><N/A>
[TKP / TKP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\154e><N/A>
[Two Rabbits Live Bus / TwoRabts][Stopped/Manual Start]
<system32\DRIVERS\TwoRabts.sys><N/A>
==================================
浏览器加载项
[]
{74381DEC-D78B-43E4-BA5D-5244F669EBE4} <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys, N/A>
[BDHlprObj Class]
{CA92B524-BC8A-4610-BD2C-6BD3E28155D0} <C:\WINDOWS\DOWNLO~1\BDHelper.dll, >
[快捷工具条3.1.5]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[]
{74381DEC-D78B-43E4-BA5D-5244F669EBE4} <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys, N/A>
[快捷工具条3.1.5]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[BDHlprObj Class]
{CA92B524-BC8A-4610-BD2C-6BD3E28155D0} <C:\WINDOWS\DOWNLO~1\BDHelper.dll, >
==================================
正在运行的进程
C:\WINDOWS\system32\System.exe
C:\WINDOWS\DOWNLO~1\BDHelper.dll
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\mfqylxfa.dll
C:\WINDOWS\system32\wcsiskfv.dll
C:\WINDOWS\system32\8566F82E.dll
==================================
Autorun.inf
[D:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=auto.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=auto.exe
[E:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=auto.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=auto.exe
[F:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=auto.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=auto.exe
==================================
特殊特权被允许: SeDebugPrivilege [PID = 2096, C:\WINDOWS\SYSTEM32\SYSTEM.EXE]