未知家族病毒分析
扫描结果:
C:\Program Files\Internet Explorer\IEXPLORE.EXE --> 与 Backdoor.Gpigeon 100%相似.
系统活动进程
C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\SRVCSURG.EXE
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\INITSRVC.DLL
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\TASKCTX.DLL
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\APPSRVCS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLMANGR.EXE
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\W95SCM.DLL
C:\WINDOWS\SYSTEM32\SQLUNIRL.DLL
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLSVC.DLL
C:\WINDOWS\SYSTEM32\ODBCBCP.DLL
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLRESLD.DLL
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\RESOURCES\2052\SQLSVC.RLL
C:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\RESOURCES\2052\SQLMANGR.RLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\PROGRAM FILES\COMMON FILES\SYSTEM\MSSEARCH\BIN\MSSEARCH.EXE
C:\PROGRAM FILES\COMMON FILES\SYSTEM\MSSEARCH\BIN\MSSWS.DLL
C:\PROGRA~1\COMMON~1\SYSTEM\MSSEARCH\BIN\MSSRCH.DLL
C:\PROGRAM FILES\COMMON FILES\SYSTEM\MSSEARCH\BIN\TQUERY.DLL
C:\PROGRA~1\COMMON~1\SYSTEM\MSSEARCH\BIN\PROPDEFS.DLL
C:\PROGRA~1\COMMON~1\SYSTEM\MSSEARCH\BIN\SRCHIDX.DLL
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\APPMGR.EXE
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\TASKCTX.DLL
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\ELEMENTMGR.EXE
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\SYSTEM32\INETSRV\INETINFO.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SQLSERVR.EXE
C:\PROGRA~1\MICROS~1\MSSQL\BINN\OPENDS60.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\UMS.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SQLSORT.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\RESOURCES\2052\SQLEVN70.RLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SSNETLIB.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SSNMPN70.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SSMSLPCN.DLL
C:\PROGRA~1\MICROS~1\MSSQL\BINN\SQLFTQRY.DLL
C:\PROGRAM FILES\COMMON FILES\SYSTEM\OLE DB\SQLOLEDB.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\SAEVFLTR.DLL
C:\WINDOWS\SYSTEM32\SERVERAPPLIANCE\APPSRVCS.DLL
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
C:\PROGRAM FILES\TENCENT\QQ\QQBASECLASSINDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQHELPERDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\BASICCTRLDLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
C:\PROGRAM FILES\TENCENT\QQ\RICHED32.DLL
C:\PROGRAM FILES\TENCENT\QQ\RICHED20.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQAPI.DLL
C:\PROGRAM FILES\TENCENT\QQ\TMDLLS\TIMPROXY.DLL
C:\PROGRAM FILES\TENCENT\QQ\LOGINCTRL.DLL
C:\PROGRAM FILES\TENCENT\QQ\NPKCNTC.DLL
C:\PROGRAM FILES\TENCENT\QQ\NPKPDB.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQRES.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQMAINFRAME.DLL
C:\PROGRAM FILES\TENCENT\QQ\CQQAPPLICATION.DLL
C:\PROGRAM FILES\TENCENT\QQ\NEWSKIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\HOSTINGMGR.DLL
C:\PROGRAM FILES\TENCENT\QQ\CAMERADLL.DLL
C:\PROGRAM FILES\TENCENT\QQ\MAILSUMMARY.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQSPACE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQGROUPMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\GROUPLIVE.DLL
C:\PROGRAM FILES\TENCENT\QQ\USERDEFINEDHEAD.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQPLUGIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQALLINONE.DLL
C:\PROGRAM FILES\TENCENT\QQ\SCCORE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQCUSTOMFACE.DLL
C:\PROGRAM FILES\TENCENT\QQ\GDIPLUS.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MSADP32.ACM
C:\PROGRAM FILES\TENCENT\QQ\QQPET.DLL
C:\PROGRAM FILES\TENCENT\QQ\LONGCONNECTION.DLL
C:\PROGRAM FILES\TENCENT\QQ\SHAREFILES.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQZIP.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQCONFIGPLUGIN.DLL
C:\PROGRAM FILES\TENCENT\QQ\FLASHAVATARDLL.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\PROGRAM FILES\TENCENT\QQ\QRINGMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\IMAGEOLE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQMAGICFACE.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQAVATAR.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQSCENEMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\GROUPCONNECTION.DLL
C:\PROGRAM FILES\TENCENT\QQ\PHONEAPI.DLL
C:\PROGRAM FILES\TENCENT\QQ\DIALERALLINONE.DLL
C:\PROGRAM FILES\TENCENT\QQ\VPORTAL.DLL
C:\PROGRAM FILES\TENCENT\QQ\BQQAPPLICATION.DLL
C:\PROGRAM FILES\TENCENT\QQ\PERSONALDESKTOP.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\TENCENT\QQ\COMMERCESMNG.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQADDR.DLL
C:\PROGRAM FILES\TENCENT\QQ\QQPHONEHELPER.DLL
C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE
C:\PROGRAM FILES\TENCENT\QQ\TMDLLS\TIMPROXY.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_004.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\RSDETECT.EXE
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
DrvMon.exe = C:\WINDOWS\SYSTEM32\DRVMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
D:\Autorun.inf
AUTORUN = Recycled.exe
E:\Autorun.inf
AUTORUN = Recycled.exe
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
dimsntfy = DIMSNTFY.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{889D2FEB-5411-4565-8998-1DD2C5261283} = C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_004.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD nwlnkipx [IPX] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD nwlnkspx [SPX] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD nwlnkspx [SPX] [Pseudo Stream] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD nwlnkspx [SPX II] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD nwlnkspx [SPX II] [Pseudo Stream] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B91DF45D-60A6-481A-9555-ABB5BD38D8C4}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B91DF45D-60A6-481A-9555-ABB5BD38D8C4}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{31B46209-885E-409B-8639-AE9B9FE9B256}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{31B46209-885E-409B-8639-AE9B9FE9B256}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0D0DD789-F391-4D33-A730-241BCD57B434}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0D0DD789-F391-4D33-A730-241BCD57B434}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8F1451E6-6C7C-4885-9295-904C11BCB7CC}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8F1451E6-6C7C-4885-9295-904C11BCB7CC}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D01EE00A-AE7B-4C06-8CFE-4E72046CE63C}] SEQPACKET 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D01EE00A-AE7B-4C06-8CFE-4E72046CE63C}] DATAGRAM 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL