用 pe_xscan 扫描 log 并分析,发现如下可疑项: /=== pe_xscan 07-03-17 by Purple Endurer 2007-5-10 21:31:14 Windows XP Service Pack 2(5.1.2600) 管理员用户组
C:\WINDOWS\Explorer.EXE * 1400 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE C:\Program Files\Internet Explorer\PLUGINS\HiJack.dll | 2007-5-10 15:9:40 | Microsoft(R) Windows (R) System | 5.00.1.0.1 | Microsoft Corporation Windows DLL | Copyright (C) 2006.6 | 1. 0. 0. 1 | Microsoft Corporation| ? | System | System.dll