用瑞星听诊器扫描后的信息,打包提取失败.
未知家族病毒分析
扫描结果:
C:\Program Files\Internet Explorer\IEXPLORE.EXE --> 与 Backdoor.Gpigeon 100%相似.
系统活动进程
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\PROGRAM FILES\SAMSUNG\MAGICKBD\MAGICKBD.EXE
C:\PROGRAM FILES\SAMSUNG\MAGICKBD\EASYBOXDLL.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SAMSUNG\MAGICKBD\SITSNDMX.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\SAMSUNG\MAGICKBD\SITKBDHK.DLL
C:\PROGRAM FILES\SAMSUNG\MAGICKBD\KBDHID9X.DLL
C:\WINDOWS\VM_STI.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\SRS LABS\WOWXT AND TSXT DRIVER\SRS_POSTINSTALLER.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\FASTLOAD.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\WBHELP.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\WBHELP.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\WINDOW~2\WMPBAND.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPHTB.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASBAR.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL
C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YWIPER.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\WBHELP.DLL
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMWDMIF.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\WINDOWS\SYSTEM32\SYNCOM.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\SYSTEM32\SYNCOM.DLL
C:\WINDOWS\SYSTEM32\SYNTPAPI.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\AGRSMMSG.EXE
C:\PROGRAM FILES\LTMOH\LTMOH.EXE
C:\PROGRAM FILES\LTMOH\MOHAPI.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\WINDOWS\SYSTEM32\BTHCRP.DLL
C:\WINDOWS\SYSTEM32\WIDCOMMSDK.DLL
C:\WINDOWS\SYSTEM32\WBTAPI.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\WBHELP.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\RAINLENDAR\RAINLENDAR.EXE
C:\PROGRAM FILES\RAINLENDAR\RAINLENDAR.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
D:\常灵的文档\下载\软件\RSDETECT.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\WINDOWS\SYSTEM32\WBSYS.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SunJavaUpdateSched = C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
nwiz = NWIZ.EXE /INSTALL
High Definition Audio 属性页快捷方式 = HDASHCUT.EXE
SoundMAXPnP = C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
SoundMAX = C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAX4.EXE /TRAY
SynTPLpr = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
SynTPEnh = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
AGRSMMSG = AGRSMMSG.EXE
LtMoh = C:\PROGRAM FILES\LTMOH\LTMOH.EXE
MagicKeyboard = C:\PROGRAM FILES\SAMSUNG\MAGICKBD\PREMKBD.EXE
YLive.exe = C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
NeroFilterCheck = C:\WINDOWS\SYSTEM32\NEROCHECK.EXE
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
yassistse = "C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE"
BigDogPath = C:\WINDOWS\VM_STI.EXE USB PC CAMERA 301P
StormCodec_Helper = "C:\PROGRAM FILES\RINGZ STUDIO\STORM CODEC\STORMSET.EXE" /S /OPTI
InsertImage = D:\!SUNV\DFVCD\INSERTIMAGE.EXE
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = wbsys.dll
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
WB = C:\PROGRAM FILES\STARDOCK\
OBJECT DESKTOP\THEMEMANAGER\FASTLOAD.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{0005A87D-D626-4B3A-84F9-1D9571695F55} = C:\WINDOWS\system32\xunleibho_v14.dll
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
{38928D50-8A48-44C2-945F-D2F23F771410} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
{54EBD53A-9BC1-480B-966A-843A333CA162} = D:\常灵的文档\Tencent\QQ\QQIEHelper.dll
{62EED7C6-9F02-42f9-B634-98E2899E147B} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
{6671A431-5C3D-463d-A7CF-5587F9B7E191} = C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
{B580CF65-E151-49C3-B73F-70B13FCA8E86} = C:\Program Files\Baidu\Bar\BaiduBar.dll