回复: 帮忙看下我的LOG
威胁注册表[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<lljy_df><C:\WINDOWS\system\llzjy080615.exe> [File is missing]
服务[National Instruments Domain Service / National][Stopped/Auto Start]
<><(File is missing)>
[PeanuthullCore / PeanuthullCore][Stopped/Auto Start]
<><(File is missing)>
[RemoteAccess Auto Connection Manager / RaAuto][Stopped/Auto Start]
<><(File is missing)>
驱动[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Kernel Mode service / HookDrv][Stopped/Manual Start]
<\??\G:\外挂\HookDrv.sys><N/A>
[SWW / SWW][Stopped/Manual Start]
<\??\C:\Documents and Settings\user\桌面\冒险岛055SF内部挂\SWW.sys><N/A>
风险DLL [C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[C:\WINDOWS\system32\nvshell.dll] [, ]