| 引用: |
【dodu的贴子】可以把样本直接发到我的信箱里 ........................... |
已发送了,包括瑞星听诊信息!请给个回信儿
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\INETSRV\INETINFO.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASBAR.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NERODIGITALEXT.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MFC71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCR71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCP71.DLL
C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\WPDSP.DLL
C:\WINDOWS\SYSTEM32\WDFAPI.DLL
C:\WINDOWS\SYSTEM32\WPDTRACE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YWIPER.DLL
C:\PROGRAM FILES\NERO\NERO 7\NERO BACKITUP\NBSHELL.DLL
C:\PROGRAM FILES\NERO\NERO 7\NERO BACKITUP\MFC71U.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRAM FILES\IDM COMPUTER SOLUTIONS\ULTRAEDIT-32\UE32CTMN.DLL
C:\PROGRA~1\3721\SKE\CONTMENU.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MEDIALIBRARYNSE.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.EXE
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.DLL
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\DPGCMD.DLL
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\IPRES.DLL
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\SRRES.DLL
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\SNMP.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\COMMON FILES\ULEAD SYSTEMS\DVD\ULCDRSVR.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL
F:\桌面日历秀\XDESKCAL.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YNOTIFIER.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\WINDOWS\SYSTEM32\UWDF.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\WPDMTPDR.DLL
C:\WINDOWS\SYSTEM32\WPDTRACE.DLL
C:\WINDOWS\SYSTEM32\WPDMTP.DLL
C:\WINDOWS\SYSTEM32\WPDMTPUS.DLL
C:\WINDOWS\SYSTEM32\WPDCONNS.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NERODIGITALEXT.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MFC71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCR71.DLL
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\MSVCP71.DLL
C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\WINDOWS\SYSTEM32\NVWRSZHC.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\WINDOWS\SYSTEM32\MQSVC.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YSCRBLOCK.DLL
C:\PROGRAM FILES\HUAQI\CHECKWP\SCRRUN.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASBAR.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPHTB.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASWIPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASIESEC.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASNOAD.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YZSNETPROTO.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YRSS.DLL
H:\动态网自由之门G123\GBHO.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQIEHELPER.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\SKCHUI.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\WPDSP.DLL
C:\WINDOWS\SYSTEM32\WDFAPI.DLL
C:\WINDOWS\SYSTEM32\WPDTRACE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH.OCX
C:\WINDOWS\SYSTEM32\HEIMA1.IME
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YADFIL~1.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YREPAIR.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASFSKS.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YOPTIMUM.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YXPSTYLE.DLL
C:\WINDOWS\SYSTEM32\MSXML4.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDSCHED.EXE
C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDCOMMON.DLL
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDLANGEN.DLL
C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDSCHEDPS.DLL
C:\PROGRAM FILES\RAXCO\PERFECTDISK\PDENGINEPS.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
C:\PROGRAM FILES\TENCENT\QQ\CORALASSIST.DLL
C:\PROGRAM FILES\TENCENT\QQ\CORALQQ.DLL
C:\PROGRAM FILES\TENCENT\QQ\IPSEARCHER.DLL
C:\PROGRAM FILES\TENCENT\QQ\MSVCR80.DLL
C:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
C:\PROGRAM FILES\TENCENT\QQ\MSVCP80.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQBASECLASSINDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQHELPERDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\BASICCTRLDLL.DLL
C:\WINDOWS\SYSTEM32\APIHOOKDLL.DLL
C:\WINDOWS\SYSTEM32\SYNCOR11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRAM FILES\TENCENT\QQ\RICHED32.DLL
C:\PROGRAM FILES\TENCENT\QQ\RICHED20.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQAPI.DLL
C:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
C:\PROGRAM FILES\TENCENT\QQ\LOGINCTRL.DLL
C:\PROGRAM FILES\TENCENT\QQ\NPKCNTC.DLL
C:\PROGRAM FILES\TENCENT\QQ\NPKPDB.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQRES.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQMAINFRAME.DLL
C:\PROGRAM FILES\TENCENT\QQ\CQQAPPLICATION.DLL
C:\PROGRAM FILES\TENCENT\QQ\NEWSKIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\HOSTINGMGR.DLL
C:\PROGRAM FILES\TENCENT\QQ\CAMERADLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\MAILSUMMARY.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQSPACE.DLL
C:\PROGRAM FILES\TENCENT\QQ\VBSCRIPT.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQGROUPMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\USERDEFINEDHEAD.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQPLUGIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQCONFIGPLUGIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\QRINGMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\PHONEAPI.DLL
C:\PROGRAM FILES\TENCENT\QQ\DIALERALLINONE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\TENCENT\QQ\QQSYSMSGMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQAVATAR.DLL
C:\PROGRAM FILES\TENCENT\QQ\FLASHAVATARDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\LONGCONNECTION.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQPET.DLL
C:\PROGRAM FILES\TENCENT\QQ\BQQAPPLICATION.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQALLINONE.DLL
C:\PROGRAM FILES\TENCENT\QQ\SCCORE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQCUSTOMFACE.DLL
C:\PROGRAM FILES\TENCENT\QQ\COMMERCESMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\PERSONALDESKTOP.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQUDPGETFILELIB.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQADDR.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQSCENEMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQPHONEHELPER.DLL
C:\PROGRAM FILES\TENCENT\QQ\GROUPCONNECTION.DLL
C:\WINDOWS\SYSTEM32\MSADP32.ACM
C:\PROGRAM FILES\TENCENT\QQ\GDIPLUS.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH.OCX
C:\PROGRAM FILES\TENCENT\QQ\QQMAGICFACE.DLL
C:\WINDOWS\SYSTEM32\HEIMA1.IME
C:\PROGRAM FILES\TENCENT\QQ\IMAGEOLE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQZIP.DLL