以下木马克星扫描日志
C:\System Volume Information\_restore{EB64E17A-F156-4AA0-8E97-B0E43410E362}\RP76\A0108866.dll 发现广告程序:spyware0531d
C:\System Volume Information\_restore{EB64E17A-F156-4AA0-8E97-B0E43410E362}\RP76\A0108866.dll广告已经清除.
木马中分离地址:dl.dudu.com
C:\WINDOWS\Downloaded Program Files\3721inst.dll 文件被捆绑
C:\WINDOWS\Downloaded Program Files\3721inst.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\3721inst.dll 怀疑为baidu广告
C:\WINDOWS\Downloaded Program Files\cnshint.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\CnsHook.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\cnsio.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\CnsMin.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\CnsMinEx.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\CnsMinEx.dll 怀疑为yisou广告
C:\WINDOWS\Downloaded Program Files\CnsMinIO.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\ddtdesk.exe 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\DDTInit.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\keepmain.dll 怀疑为3721广告
C:\WINDOWS\Downloaded Program Files\rssreader.exe 怀疑为baidu广告
C:\WINDOWS\system32\cns.dll 怀疑为3721广告
C:\WINDOWS\system32\cns.dll 怀疑为CNNIC广告
C:\WINDOWS\system32\cns.exe 怀疑为baidu广告
C:\WINDOWS\system32\cns.exe 怀疑为CNNIC广告