C:\System Volume Information\_restore{A71234BC-4E
1D-473B-95E1-6E5AF32CF3DE}\RP32\A0092869.dll>>upx_
病毒:Trojan.Delf.rxc
C:\System Volume Information\_restore{A71234BC-4E
1D-473B-95E1-6E5AF32CF3DE}\RP32\A0092870.dll>>upac
病毒:Trojan.Delf.rww
C:\System Volume Information\_restore{A71234BC-4E
1D-473B-95E1-6E5AF32CF3DE}\RP32\A0092871.exe>>upac
病毒:Trojan.PSW.WLOnline.jgx
C:\System Volume Information\_restore{A71234BC-4E
1D-473B-95E1-6E5AF32CF3DE}\RP32\A0092872.dll
病毒:Trojan.PSW.WLOnline.jgx
C:\System Volume Information\_restore{A71234BC-4E
1D-473B-95E1-6E5AF32CF3DE}\RP32\A0092873.exe>>upac
k0.36
病毒:Trojan.PSW.WLOnline.jgx
当前的运行状态是:
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows XP Publisher]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows XP Publisher]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows XP Publisher]
<SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows XP Publisher]
<MS-4011 Memory Patch><D:\杀毒软件\RavSasser.exe -Patch> [Beijing Rising Tech. Co., Ltd.]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<farstone><NULL> [N/A]
<RestoreIT!><"C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Thunder><"C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s> [Thunder Networking Technologies,LTD]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<RavTask><"D:\杀毒软件\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<load><C:\WINDOWS\uninstall\rundl132.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
后面还有————