未知家族病毒分析
扫描结果:
C:\Windows\system32\LSYGNTA.EXE --> 与 Trojan.QQMSG.MsgSender 40%相似.
系统活动进程
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\NVIDIA CORPORATION\NVMIXER\NVMIXERTRAY.EXE
C:\PROGRAM FILES\NVIDIA CORPORATION\NVMIXER\NVMIXERENU.DLL
C:\PROGRAM FILES\COMMON FILES\NVIDIA SHARED\AUDIO\NVAUDIOMOD.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\CFOSSPEED\CFOSSPEED.EXE
C:\WINDOWS\SYSTEM32\LSYGNTA.EXE
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\DAEMON TOOLS\DAEMON.EXE
C:\PROGRAM FILES\DAEMON TOOLS\DAEMON.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PFCTOC.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PLUGINS\IMAGES\BW5MOUNT.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PLUGINS\IMAGES\CCDMOUNT.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PLUGINS\IMAGES\MDSMOUNT.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PLUGINS\IMAGES\NRGMOUNT.DLL
C:\PROGRAM FILES\DAEMON TOOLS\PLUGINS\IMAGES\PDIMOUNT.DLL
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\SYSTEM32\VM31BPRP.AX
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPDSXX.DLL
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPDXXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\EWIDO ANTI-SPYWARE 4.0\EWIDO.EXE
C:\PROGRAM FILES\EWIDO ANTI-SPYWARE 4.0\ENGINE.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\DVDIDL~1\DVDSHELL.DLL
C:\PROGRAM FILES\EWIDO ANTI-SPYWARE 4.0\SHELLEXECUTEHOOK.DLL
C:\PROGRA~1\WINDOW~2\WMPBAND.DLL
C:\WINDOWS\SYSTEM32\WPDSHSERVICEOBJ.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICETYPES.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NERODIGITALEXT.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MFC71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCR71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
C:\WINDOWS\SYSTEM32\QYELTZFMR.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\NWCJPXCJ.DLL
C:\PROGRAM FILES\NERO\NERO 7\NERO BACKITUP\NBSHELL.DLL
C:\PROGRAM FILES\NERO\NERO 7\NERO BACKITUP\MFC71U.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\EWIDO ANTI-SPYWARE 4.0\CONTEXT.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE10\MSOHEV.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\UPDATEDOWNLOAD.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\LOG4CPLUS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\STLPORT_VC646.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ASYN_DNS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\MSGMANAGE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\HISTORYINFO_MANAGE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\REGISTERDLL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\FLOATBAR.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PLUGINS\TINGTING\TINGTING.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBED04.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\DVDIDL~1\DVDSHELL.DLL
C:\PROGRAM FILES\EWIDO ANTI-SPYWARE 4.0\SHELLEXECUTEHOOK.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ITARGETAD.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MFPLAT.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\WMVDECOD.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\CFOSSPEED\SPD.EXE
C:\DOCUMENTS AND SETTINGS\QINYANGWEN\桌面\软件\DOWNBANK061023 PRCMGR\PRCMGR\PRCMGR.EXE
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\WINDOWS\SYSTEM32\VB6CHS.DLL
C:\WINDOWS\SYSTEM32\DAO360.DLL
C:\WINDOWS\SYSTEM32\COMCTL32.OCX
C:\WINDOWS\SYSTEM32\MSCOMCTL.OCX
附件:
79099620061123163955.JPG