用卡卡扫描发现有一盗号木马病毒,立马清除,但重起后又出现,再杀,重起,还在,用瑞星杀毒没有发现病毒,还在我无语了。望哪位大侠出手相助。
这是用瑞星听诊器扫描的文件
未知家族病毒分析扫描结果:
无可疑文件
系统活动进程C:\WINDOWS\SYSTEM32\SPOOLSV.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE E:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\BOBOTURBO\BOBOTURBO.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE C:\WINDOWS\SYSTEM32\CSRSS.EXE E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
D:\PROGRAM FILES\IVT CORPORATION\BLUESOLEIL\BTNTSERVICE.EXE E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\WINLOGON.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\ICPB.DLL
C:\WINDOWS\SYSTEM32\IRMON64.DLL
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\WINDOWS\USNSVC.EXE C:\WINDOWS\TELEM32.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE E:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
E:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
E:\PROGRAM FILES\RISING\RAV\RSLOG.DLL
E:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RAV\MONRULE.DLL
E:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RAV\HOOKREG.DLL
E:\PROGRAM FILES\RISING\RAV\HOOKNTOS.DLL
E:\PROGRAM FILES\RISING\RAV\RSWALMON.DLL
E:\PROGRAM FILES\RISING\RAV\RECOMP.DLL
E:\PROGRAM FILES\RISING\RAV\REFS.DLL
E:\PROGRAM FILES\RISING\RAV\FFR.DLL
E:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL
E:\PROGRAM FILES\RISING\RAV\HOOKCONT.DLL
E:\PROGRAM FILES\RISING\RAV\FAKESCAN.DLL
E:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
E:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
E:\PROGRAM FILES\RISING\RAV\RELIBLDR.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL
E:\PROGRAM FILES\RISING\RAV\NVFILE.DLL
E:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL
E:\PROGRAM FILES\RISING\RAV\UNEXE.DLL
E:\PROGRAM FILES\RISING\RAV\SCANEX.DLL
E:\PROGRAM FILES\RISING\RAV\PEARC.DLL
E:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL
E:\PROGRAM FILES\RISING\RAV\SCANPACK.DLL
E:\PROGRAM FILES\RISING\RAV\REVM.DLL
E:\PROGRAM FILES\RISING\RAV\URUTILS.DLL
E:\PROGRAM FILES\RISING\RAV\UR000.DAT
E:\PROGRAM FILES\RISING\RAV\SCRIPTCI.DLL
E:\PROGRAM FILES\RISING\RAV\UROUTINE.DLL
E:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL
E:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
E:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
E:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
E:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
E:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
E:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_CTRL.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RFW\UNVDET.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
E:\PROGRAM FILES\RISING\RFW\RFWPROXY.EXE C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
E:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
E:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
E:\PROGRAM FILES\RISING\RFW\URLRULE.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RFW\MONMID.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
C:\WINDOWS\SYSTEM32\SYSWINDRV.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\OFFICE2003\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RFW\RFWSTUB.EXE C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
E:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
E:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
E:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
E:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
E:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
E:\PROGRAM FILES\RISING\RFW\RSXML.DLL
E:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
E:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE E:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
E:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
E:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
E:\PROGRAM FILES\RISING\RAV\RAVMON.EXE C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
E:\PROGRAM FILES\RISING\RAV\RECOMP.DLL
E:\PROGRAM FILES\RISING\RAV\REFS.DLL
E:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
E:\PROGRAM FILES\RISING\RAV\RELIBLDR.DLL
E:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
E:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
E:\PROGRAM FILES\RISING\RAV\MONRULE.DLL
E:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
E:\PROGRAM FILES\RISING\RAV\RSXML.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\RAS.EXE E:\PROGRAM FILES\RISING\卡卡上网助手\MFC71.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\MSVCR71.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\MSVCP71.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\TOPSOFT.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\NCOMM.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
E:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
E:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\RASGUI.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\RSXML.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\KTROJAN.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\ENGINE.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\RSDIALOG.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\SCANUNV.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\SECSCAN.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\SECEX.DLL
E:\PROGRAM FILES\RISING\卡卡上网助手\ZIP.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
E:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
F:\RSDETECT.EXE E:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
E:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\UXTHEME.DLL
普通自启动项HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RfwMain = "E:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
RavTask = "E:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
runeip = "E:\PROGRAM FILES\RISING\卡卡上网助手\RUNIEP.EXE" /STARTUP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay = E:\PROGRAM FILES\RISING\卡卡上网助手\RUNONCE.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\office2003\WinWord.exe" "%1"
其它启动项WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)