回复:请版主帮我看一下这个扫描日志
启动项目
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon]
<WinlogonNotify: DfLogon><LogonDll.dll> []
==================================
正在运行的进程
[PID: 1100 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\LogonDll.dll] [N/A, ]
卸载模块:
C:\WINDOWS\system32\LogonDll.dll
删除文件:
C:\WINDOWS\system32\LogonDll.dll
删除注册表:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon