瑞星杀不掉,查杀病毒时也找不到病毒,但是每次打开文件夹或浏览网页时瑞星会提示:发现并删除病毒.
中毒前系统发生过一次严重错误,计算机自动重起.重新启动后瑞星监控提示一个系统程序要求删除注册表中的一项,我点了同意.附图中就是关于这个的记录.
发现病毒后,网络似乎也变的不稳定,掉线频繁.
以下是发现病毒的路径:C:\Documents and Settings\ Users\Application Data\Microsoft\Windows\system 文件名是termsv.exe 另一个路径是C:\Documents and Settings\ Users\Templates\Microsoft\Windows\system 文件名还是tetmsv.exe
以下是瑞星听诊器扫描的结果
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
F:\新建文件夹\RISING\RFW\RFWMAIN.EXE
F:\新建文件夹\RISING\RFW\RSGUILIB.DLL
F:\新建文件夹\RISING\RFW\RSCOMMON.DLL
F:\新建文件夹\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\IE_BITSCLASS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\HUAWEI TECHNOLOGIES\HUAWEI SMARTAX MT810\DSLMON.EXE
C:\PROGRAM FILES\HUAWEI TECHNOLOGIES\HUAWEI SMARTAX MT810\LANGUAGES\CHINESESIMP.DLL
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVWDDI.DLL
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVWDDI.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
E:\解压工具\WINZIP\WZSHLSTB.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
E:\新建文件夹\SKE\CONTMENU.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
F:\新建文件夹\RISING\RAV\RSCOMMON.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\SHELLEX.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\SCRCHPG.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\SCRCH_AG.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\FSSYNC.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_RMT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\CCCLIENT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\KLIPC.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\KLUTIL.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\RPT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\CCIFACE.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRLOADER.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRKERNEL.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRSTRING.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_SRV.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_CLNT.PPL
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\SHFUSION.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\WINDOWS\SYSTEM\IE_HEL~1.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
F:\新建文件夹\RISING\RFW\RFWSRV.EXE
F:\新建文件夹\RISING\RFW\RFWRULE.DLL
F:\新建文件夹\RISING\RFW\RFWLOG.DLL
F:\新建文件夹\RISING\RFW\RFWDRV.DLL
F:\新建文件夹\RISING\RFW\PSAPI.DLL
F:\新建文件夹\RISING\RFW\MONDRV.DLL
F:\新建文件夹\RISING\RFW\PROCLIB.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVWDDI.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
E:\杂牌小软\瑞星听诊器\RSDETECT.EXE
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVWDDI.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\NVIEW.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\WINDOWS\SYSTEM\IE_HEL~1.DLL
C:\WINDOWS\SYSTEM32\NVWDDI.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\SCRCHPG.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\SCRCH_AG.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\FSSYNC.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_RMT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\CCCLIENT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\KLIPC.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\KLUTIL.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\RPT.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\CCIFACE.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRLOADER.DLL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRKERNEL.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PRSTRING.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_SRV.PPL
F:\卡巴斯基\KASPERSKY ANTI-VIRUS PERSONAL PRO\PR_CLNT.PPL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORIE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLD.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
nwiz = NWIZ.EXE /INSTALL
SoundMan = SOUNDMAN.EXE
RavTask = "F:\新建文件夹\RISING\RAV\RAVTASK.EXE" -SYSTEM
(Default) = (NULL)
RfwMain = "F:\新建文件夹\RISING\RFW\RFWMAIN.EXE" -STARTUP
StormCodec_Helper = "E:\杂牌小软\播放器\STORM CODEC\STORMSET.EXE" /S /OPTI
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub = "F:\新建文件夹\RISING\RAV\RAVSTUB.EXE" /RUNONCE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
附件:
7615092006123195705.bmp