刚注册完就上不来了!真TMD郁闷!!!!
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\VM_STI.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\SE3CLMON.DLL
C:\WINDOWS\EXPLORER.EXE
C:\PROGRA~1\WINKLD\WINKLD.DAT
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\MSOSIOCP.DLL
C:\WINDOWS\SYSTEM32\WSOCKDRV32.DLL
C:\WINDOWS\SYSTEM32\MSIMMS32.DLL
C:\WINDOWS\SYSTEM32\MPPDS.DLL
C:\WINDOWS\SYSTEM32\AVPSRV.DLL
C:\WINDOWS\SYSTEM32\UPXDND.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\WINDOWS\SYSTEM32\TCIOCP32.DLL
C:\WINDOWS\SYSTEM32\FMSBBQI.DLL
C:\WINDOWS\SYSTEM32\MSCCRT.DLL
C:\WINDOWS\SYSTEM32\DBGHLP32.DLL
C:\WINDOWS\SYSTEM32\CMDBCS.DLL
C:\WINDOWS\SYSTEM32\RZYSDHBX.DLL
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\LOTUSHLP.DLL
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\KVSC3.DLL
C:\WINDOWS\SYSTEM32\MFCHLP32.DLL
C:\WINDOWS\SYSTEM32\DNDSIOC.DLL
C:\WINDOWS\SYSTEM32\WINSVR32.DLL
C:\WINDOWS\SYSTEM32\FMBIOST.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\IGFXPPH.DLL
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
D:\PROGRAM FILES\TENCENT\QQ\QDSHM.DLL
D:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\WINDOWS\SYSTEM32\VB6CHS.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRA~1\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
E:\PROGRAM FILES\FLASHGET NETWORK\FLASHGET\COMDLLS\BHOCATCH.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\WSOCKDRV32.DLL
C:\WINDOWS\SYSTEM32\WINABCX.IME
C:\WINDOWS\SYSTEM32\MSIMMS32.DLL
C:\WINDOWS\SYSTEM32\MPPDS.DLL
C:\WINDOWS\SYSTEM32\AVPSRV.DLL
C:\WINDOWS\SYSTEM32\UPXDND.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9E.OCX
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL
C:\WINDOWS\SYSTEM32\TCIOCP32.DLL
C:\WINDOWS\SYSTEM32\FMSBBQI.DLL
C:\WINDOWS\SYSTEM32\MSCCRT.DLL
C:\WINDOWS\SYSTEM32\CMDBCS.DLL
C:\WINDOWS\SYSTEM32\DBGHLP32.DLL
C:\WINDOWS\SYSTEM32\RZYSDHBX.DLL
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\LOTUSHLP.DLL
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\DNDSIOC.DLL
C:\WINDOWS\SYSTEM32\MFCHLP32.DLL
C:\WINDOWS\SYSTEM32\KVSC3.DLL
C:\WINDOWS\SYSTEM32\WINSVR32.DLL
C:\WINDOWS\SYSTEM32\FMBIOST.DLL
D:\DOWNLOADS\RSDETECT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWSYS32.SYS
C:\WINDOWS\SYSTEM32\UAMIJW.DLL
C:\WINDOWS\SYSTEM32\UKERWV.DLL
C:\WINDOWS\SYSTEM32\FMBIOST.DLL
C:\WINDOWS\SYSTEM32\WINSVR32.DLL
C:\WINDOWS\SYSTEM32\DNDSIOC.DLL
C:\WINDOWS\SYSTEM32\MFCHLP32.DLL
C:\WINDOWS\SYSTEM32\KVSC3.DLL
C:\WINDOWS\SYSTEM32\LOTUSHLP.DLL
C:\WINDOWS\SYSTEM32\RZYSDHBX.DLL
C:\WINDOWS\SYSTEM32\CMDBCS.DLL
C:\WINDOWS\SYSTEM32\DBGHLP32.DLL
C:\WINDOWS\SYSTEM32\MSCCRT.DLL
C:\WINDOWS\SYSTEM32\FMSBBQI.DLL
C:\WINDOWS\SYSTEM32\TCIOCP32.DLL
C:\WINDOWS\SYSTEM32\UPXDND.DLL
C:\WINDOWS\SYSTEM32\AVPSRV.DLL
C:\WINDOWS\SYSTEM32\MPPDS.DLL
C:\WINDOWS\SYSTEM32\MSIMMS32.DLL
C:\WINDOWS\SYSTEM32\WSOCKDRV32.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
BigDogPath = C:\WINDOWS\VM_STI.EXE VIMICRO USB PC CAMERA (ZC0301PL)
WSockDrv32 = C:\WINDOWS\WSOCKDRV32.EXE
AVPSrv = C:\WINDOWS\AVPSRV.EXE
upxdnd = C:\WINDOWS\UPXDND.EXE
tciocp32 = C:\WINDOWS\TCIOCP32.EXE
fmsbbqi = C:\WINDOWS\FMSBBQI.EXE
msccrt = C:\WINDOWS\MSCCRT.EXE
DbgHlp32 = C:\WINDOWS\DBGHLP32.EXE
cmdbcs = C:\WINDOWS\CMDBCS.EXE
igzwzslm = C:\WINDOWS\GWSMHXUQ.EXE
PTSShell = C:\WINDOWS\PTSSHELL.EXE
LotusHlp = C:\WINDOWS\LOTUSHLP.EXE
SHAProc = C:\WINDOWS\SHAPROC.EXE
mfchlp32 = C:\WINDOWS\MFCHLP32.EXE
WINSvr32 = C:\WINDOWS\WINSVR32.EXE
mppds = C:\WINDOWS\MPPDS.EXE
MsIMMs32 = C:\WINDOWS\MSIMMS32.EXE
Kvsc3 = C:\WINDOWS\KVSC3.EXE
dndsioc = C:\WINDOWS\DNDSIOC.EXE
fmbiost = C:\WINDOWS\FMBIOST.EXE
SoundMan = SOUNDMAN.EXE
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\ssmypics.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
igfxcui = IGFXDEV.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORE