安全威胁:[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<bgswitch><C:\WINDOWS\system32\bgswitch.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Alcmtr><anymie360.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [ORIONNET]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF}><C:\Program Files\Internet Explorer\PowerNeNt.Onz> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<35735A64><C:\WINDOWS\system32\jlnjlamk.dll> [File is missing]
<F218C024><C:\WINDOWS\system32\fihocgik.dll> []
<BABF2047><C:\WINDOWS\system32\babfigkn.dll> []
<ADCC24EC><C:\WINDOWS\system32\adccikec.dll> []
<97A9967C><C:\WINDOWS\system32\pnappmnc.dll> []
驱动[Safe Mon 360 / SafeMon0][Running/System Start]
<\??\C:\WINDOWS\system32\6AF3B7B3.dat><N/A>
运行的威胁 [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ]
[C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ]
[C:\WINDOWS\fonts\ctm11008.ttf] [N/A, ]
手动的话看置顶帖
自动的话以下工具下载到SYSTEM32下安装运行
都得用,一个一个的来如自动,则用完后说说效果,以便于其他求救者
1、
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/setup_7.0.0.290_30.01.2009_14-01.exe2、[url=http://cu003.
www.duba.net/duba/tools/dubatools/install.exe]http://cu003.
www.duba.net/duba/tools/dubatools/install.exe[/url]