进程名称 路径 数值名称 数值数据 操作日期 操作方式 操作结果
C:\Documents and Settings\Administrator.ZND44IGLM5M1VNE\「开始」菜单\程序\启动\Reboot.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE Execute C:\WINDOWS\System32\Tools\DelFolders.exe 2007-05-09 11:59 修改 拒绝修改
D:\装机必备工具\powershadow_ch_2.8.2.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN RunShadowTip C:\WINDOWS\system32\shadow\ShadowTip.exe 2007-05-09 12:03 修改 同意修改
C:\WINDOWS\system32\Rundll32.exe HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN CTFMON.EXE C:\WINDOWS\system32\CTFMON.EXE 2007-05-09 12:04 修改 同意修改
C:\Program Files\Internet Explorer\iexplore.exe HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN Start Page http://www.baidu.com/ 2007-05-09 12:21 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\csrss.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wosa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\woso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\svchost32.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN ztsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\ztso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\smss.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN mhsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\mhso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\services.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN fysa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\fyso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\svchost.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN jtsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\jtso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\conime.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wlsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\wlso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\ctfmon.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wgsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\wgso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\mmc.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wmsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\wmso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\IEXPLORE.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN qjsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\qjso.exe 2007-05-09 12:32 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\stpgldk.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN rxsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\rxso.exe 2007-05-09 12:33 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\srogm.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wdsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\wdso.exe 2007-05-09 12:33 修改 同意修改
C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\spglsdr.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN tlsa C:\DOCUME~1\ADMINI~1.ZND\LOCALS~1\Temp\tlso.exe 2007-05-09 12:33 修改 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN rxsa 2007-05-09 12:36 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wosa 2007-05-09 12:43 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN mhsa 2007-05-09 12:43 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wlsa 2007-05-09 12:43 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN jtsa 2007-05-09 12:44 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN tlsa 2007-05-09 12:44 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wdsa 2007-05-09 12:44 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN qjsa 2007-05-09 12:44 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wgsa 2007-05-09 12:44 删除 同意修改
C:\ftc\Trojanwall.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN fysa 2007-05-09 12:44 删除 同意修改
C:\WINDOWS\System32\WScript.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN wmsa 2007-05-09 12:46 删除 同意修改
C:\windows\regedit.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN Windows木马防 2007-05-09 19:50 删除 同意修改
C:\windows\regedit.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN dsa 2007-05-09 19:50 修改 同意修改
大家复制到TXT文本就可以看清楚了,就不会乱乱的。我自己也是学电脑的,很郁闷呀,都没见过这是啥病毒。