未知家族病毒分析
扫描结果:
C:\WINNT\system32\msime.exe --> 与 Trojan.PSW.LMir 72%相似.
系统活动进程
C:\WINNT\SYSTEM32\SMSS.EXE
C:\WINNT\SYSTEM32\WINLOGON.EXE
C:\WINNT\SYSTEM32\CSRSS.EXE
C:\WINNT\SYSTEM32\SERVICES.EXE
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
C:\WINNT\SYSTEM32\LSASS.EXE
C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\SPOOLSV.EXE
C:\WINNT\SYSTEM32\ADOBEPDF.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ADISTRES.CHS
C:\WINNT\SYSTEM32\ZLHP1020.DLL
C:\WINNT\SYSTEM32\ZLM.DLL
C:\WINNT\SYSTEM32\SPOOL\PRTPROCS\W32X86\IMFPRINT.DLL
C:\WINNT\SYSTEM32\IMF32.DLL
C:\WINNT\SYSTEM32\ZTAG32.DLL
C:\WINNT\SYSTEM32\ZSPOOL.DLL
C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\UNIMDM.TSP
C:\WINNT\SYSTEM32\KMDDSP.TSP
C:\WINNT\SYSTEM32\NDPTSP.TSP
C:\WINNT\SYSTEM32\IPCONF.TSP
C:\WINNT\SYSTEM32\H323.TSP
C:\WINNT\SYSTEM32\NVSVC32.EXE
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSERVICE.EXE
D:\PROGRAM FILES\RISING\RAV\MFC42.DLL
D:\PROGRAM FILES\RISING\RAV\MSVCP60.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\WINNT\SYSTEM32\MSXML3.DLL
C:\WINNT\NTSERVICE.EXE
C:\WINNT\SYSTEM32\MSVBVM60.DLL
C:\WINNT\SYSTEM32\VB6CHS.DLL
C:\WINNT\NTSVC.OCX
C:\WINNT\SYSTEM32\MSTASK.EXE
C:\WINNT\SYSTEM32\STISVC.EXE
C:\WINNT\SYSTEM32\VIPTRAY.EXE
C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\MSXML3.DLL
C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET_FILTER.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\WINNT\SYSTEM32\NOTEPAD.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
D:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
D:\PROGRAM FILES\RISING\RAV\MFC42.DLL
D:\PROGRAM FILES\RISING\RAV\MSVCP60.DLL
D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
D:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
D:\绿色\GREENBROWSERGB\GREENBROWSER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\WINNT\SYSTEM32\MSCOREE.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\CORPERFMONEXT.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINNT\SYSTEM32\WINABC.IME
C:\WINNT\SYSTEM32\WINWB86.IME
C:\WINNT\SYSTEM32\MSDMO.DLL
C:\WINNT\SYSTEM32\FREEWB.IME
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORIE.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLD.DLL
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\ROBOFORM\ROBOFORM.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH8B.OCX
C:\WINNT\SYSTEM32\MSRATELC.DLL
C:\WINNT\EXPLORER.EXE
C:\WINNT\APPPATCH\ACLAYERS.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRA~1\MYAPPL~1\IEBHO.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINNT\SYSTEM32\RAVEXT.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.CHS
C:\WINNT\SYSTEM32\NVSHELL.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\WINDEFENDOR.DLL
C:\WINNT\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\MSIME.EXE
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\N.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
D:\PROGRAM FILES\RISING\RAV\MFC42.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
D:\PROGRAM FILES\RISING\RAV\RAVTRAY.EXE
D:\PROGRAM FILES\RISING\RAV\MFC42.DLL
D:\PROGRAM FILES\RISING\RAV\MSVCP60.DLL
D:\PROGRAM FILES\RISING\RAV\RAVTRAY936.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
D:\PROGRAM FILES\RISING\RAV\RAVTIMER.EXE
D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
D:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\DOCUMENTS AND SETTINGS\SALES51\桌面\RSDETECT.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.CHS
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\DOWNS.EXE
C:\WINNT\SYSTEM32\MSVBVM60.DLL
C:\WINNT\SYSTEM32\VB6CHS.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\WINNT\SYSTEM32\MSINET.OCX
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\INTERNAT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\WINNT\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\IE-BAR\CAST\DMIPN.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\PROGRA~1\IE-BAR\CAST\DMSHELL.DLL
C:\PROGRA~1\IE-BAR\CAST\221~1.0\DMPLAYER.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\MICROBAK\DOWNS.EXE
C:\WINNT\SYSTEM32\MSVBVM60.DLL
C:\WINNT\SYSTEM32\VB6CHS.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\WINNT\SYSTEM32\MSINET.OCX
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\ROBOFORM\ROBOTASKBARICON.EXE
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\ROBOFORM\ROBOFORM.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\DOCUMENTS AND SETTINGS\SALES51\桌面\RSDETECT.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
C:\WINNT\SYSTEM32\ATL71.DLL
C:\WINNT\SYSTEM32\MSVCP71.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.CHS
C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
C:\WINNT\SYSTEM32\WINDEFENDOR.DLL
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
C:\PROGRA~1\MYAPPL~1\IEBHO.DLL
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\ROBOFORM\ROBOFORM.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\XDICT.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\IHOOKS.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\ITEXTOUT.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTAB32.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\XIMAGE32.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\NEWWORD.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\XFILE.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\ITTSENGINE.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RAR$EX00.438\HIJACKTHIS1991ZWW.EXE
C:\WINNT\SYSTEM32\MSVBVM60.DLL
C:\WINNT\SYSTEM32\VB6CHS.DLL
D:\PROGRAM FILES\KINGSOFT\XDICT\CJKTL32.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\SYSTEM.SYS
C:\DOCUME~1\SALES51\LOCALS~1\TEMP\RSXAOZ.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = MOBSYNC.EXE /LOGON
nwiz = NWIZ.EXE /INSTALL
Acrobat Assistant 7.0 = "D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE"
(Default) = (NULL)
NvCplDaemon = RUNDLL32.EXE C:\WINNT\SYSTEM32\NVCPL.DLL,NVSTARTUP
Systems32 = C:\WINNT\SYSTEM32\SERVER.EXE
RavTimer = D:\PROGRAM FILES\RISING\RAV\RAVTIMER.EXE
RavTray = D:\PROGRAM FILES\RISING\RAV\RAVTRAY.EXE
RavMon = D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE -SYSTEM
\\lambda\EPSON Stylus C67 Series = C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE /P32 "\\LAMBDA\EPSON STYLUS C67 SERIES" /O6 "USB001" /M "STYLUS C67"
downs = C:\WINNT\SYSTEM32\DOWNS.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
KernelFaultCheck = C:\WINNT\SYSTEM32\MSIME.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internat.exe = INTERNAT.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = (无)
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
wzcnotif = WZCDLG.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINNT\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{2D99E8F4-56B7-457B-9A92-61B5D247D263} = C:\WINNT\system32\WinDefendor.dll
{77FEF28E-EB96-44FF-B511-3185DEA48697} = C:\Program Files\Baidu\bar\BaiduBar.DLL
{9593496E-F7B8-49D5-ABD2-74A71335D26E} = C:\PROGRA~1\MYAPPL~1\IEBHO.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [UDP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [RAW/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
RSVP UDP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{4C6A3D68-285E-4C89-A6EF-6CE3BD59BB71}] SEQPACKET 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{4C6A3D68-285E-4C89-A6EF-6CE3BD59BB71}] DATAGRAM 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{3897F4D1-1B14-4D69-AA01-D854D9462047}] SEQPACKET 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{3897F4D1-1B14-4D69-AA01-D854D9462047}] DATAGRAM 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2F6506B-CC73-4935-9FE8-6A5643DC7B2B}] SEQPACKET 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2F6506B-CC73-4935-9FE8-6A5643DC7B2B}] DATAGRAM 2 = C:\WINNT\SYSTEM32\MSAFD.DLL