你说正常
日志见以下异常
注册表以下删除:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\fonts\CtmRes.dll C:\WINDOWS\fonts\ComRes.dll kgnjbgai.dll,glpjojdd.dll,khkejjob.dll,flhecgjj.dll,apnjegif.dll,cjohkmnm.dll,lgeciokg.dll,ocojfafd.dll,iedpgpbk.dll,elkniomb.dll,kcgngbgl.dll,epnpdmpf.dll,cjgojmmh.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{478932A2-862F-4A34-A264-54A6EB998FDE}><C:\Program Files\Internet Explorer\PowerNt.Onz> []
<{4073B0A2-C6D7-4695-A02B-E084A5B4533E}><C:\WINDOWS\system32\kgnjbgai.dll> []
<{059383DD-FD9A-4466-9396-737C19943D4E}><C:\WINDOWS\system32\glpjojdd.dll> []
<{414E338B-F66B-4418-BD78-5915E806B121}><C:\WINDOWS\system32\khkejjob.dll> []
<{F51EC033-7C85-4EE3-B12C-8500A13C4702}><C:\WINDOWS\system32\flhecgjj.dll> []
<{A973E02F-6E26-4A7B-801C-8AC09163C304}><C:\WINDOWS\system32\apnjegif.dll> []
<{C3814676-4354-474A-8D34-F6419F96F554}><C:\WINDOWS\system32\cjohkmnm.dll> []
<{50EC2840-4D98-411E-AB3B-53E8349B7033}><C:\WINDOWS\system32\lgeciokg.dll> []
<{8C83FAFD-BD1F-4BDD-99C0-C46570DAEB7B}><C:\WINDOWS\system32\ocojfafd.dll> []
<{2ED909B4-02FB-49F8-941F-0F08CA5542C9}><C:\WINDOWS\system32\iedpgpbk.dll> []
<{E547286B-9824-46C0-AD03-14F7F33D48E6}><C:\WINDOWS\system32\elkniomb.dll> []
<{4C070B05-D682-4FDC-B865-D7A2858F01CB}><C:\WINDOWS\system32\kcgngbgl.dll> []
<{E979D69F-59E1-4EA7-B25D-D1EE1BCDFB82}><C:\WINDOWS\system32\epnpdmpf.dll> []
<{C3083661-48BB-4FB2-BF1E-C9B113AE91A1}><C:\WINDOWS\system32\cjgojmmh.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<4073B0A2><C:\WINDOWS\system32\kgnjbgai.dll> []
<059383DD><C:\WINDOWS\system32\glpjojdd.dll> []
<414E338B><C:\WINDOWS\system32\khkejjob.dll> []
<F51EC033><C:\WINDOWS\system32\flhecgjj.dll> []
<A973E02F><C:\WINDOWS\system32\apnjegif.dll> []
<C3814676><C:\WINDOWS\system32\cjohkmnm.dll> []
<50EC2840><C:\WINDOWS\system32\lgeciokg.dll> []
<8C83FAFD><C:\WINDOWS\system32\ocojfafd.dll> []
<2ED909B4><C:\WINDOWS\system32\iedpgpbk.dll> []
<E547286B><C:\WINDOWS\system32\elkniomb.dll> []
<4C070B05><C:\WINDOWS\system32\kcgngbgl.dll> []
<E979D69F><C:\WINDOWS\system32\epnpdmpf.dll> []
<C3083661><C:\WINDOWS\system32\cjgojmmh.dll> []
驱动以下删除[Safe Mon 360 / SafeMon0][Running/System Start]
<\??\C:\WINDOWS\system32\6799EEB9.dat><N/A>