下面是“瑞星听诊器”扫描后的信息
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINNT\SYSTEM32\HPZIPM12.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\MSD9EF44.DLL
C:\WINNT\SYSTEM32\MSVBVM50.DLL
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL
E:\SYS-BAK\RSDETECT.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL
C:\WINNT\SYSTEM32\INTERNAT.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL
C:\WINNT\EXPLORER.EXE
C:\WINNT\APPPATCH\ACLAYERS.DLL
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\WINNT\SYSTEM32\H9EF44F5.LOG
C:\WINNT\SYSTEM32\HC16B9B5.LOG
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
C:\WINNT\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\FLASHGET\JCCATCH.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINNT\SYSTEM32\MSADP32.ACM
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL
C:\WINNT\SYSTEM32\TASKMGR.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL
普通自启动项
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internat.exe = INTERNAT.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
IE - BHO
Winsock SPI
MSAFD Irda [IrDA] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [TCP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [UDP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [RAW/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
RSVP UDP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B319B8F-5AD8-4F35-A85C-28E6B78D550C}] SEQPACKET 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B319B8F-5AD8-4F35-A85C-28E6B78D550C}] DATAGRAM 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{203F359B-EA80-415D-B0C2-FB285BBC3CF9}] SEQPACKET 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{203F359B-EA80-415D-B0C2-FB285BBC3CF9}] DATAGRAM 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2392D66-A9CA-47B6-8545-B6C54EAE136C}] SEQPACKET 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2392D66-A9CA-47B6-8545-B6C54EAE136C}] DATAGRAM 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
系统服务项
文件驱动
系统驱动项