异常注册表项目:
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services]
<Irmon>c:\windows\system32\rimon.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
{BF50AC63-19DA-487E-AD4A-0B452D823B59}<c:\windows\system32\fsutk.dll>
异常文件(建议将以下异常文件打包压缩,上传瑞星鉴定)
c:\autorun.inf
c:\sos.exe
d:\autorun.inf
d:\sos.exe
e:\autorun.inf
e:\sos.exe
f:\autorun.inf
f:\sos.exe
c:\windows\system32\rimon.dll
c:\windows\system32\fsutk.dll