用瑞星听诊器扫面结果:
系统活动进程
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\6469A797.DLL
C:\WINDOWS\SYSTEM32\962C0390.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\DOWN\RUNDLL32.EXE
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\RISING\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\2006\RISING\RAV\RAV.EXE
D:\2006\RISING\RAV\PLUGIN\RSPGSCAN.DLL
D:\2006\RISING\RAV\RSAPPMGR.DLL
D:\2006\RISING\RAV\CFGDLL.DLL
D:\2006\RISING\RAV\RSCOMMX.DLL
D:\2006\RISING\RAV\RAVUI.DLL
D:\2006\RISING\RAV\RSGUILIB.DLL
D:\2006\RISING\RAV\PNGDLL.DLL
D:\2006\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\TDLL.DLL
D:\2006\RISING\RAV\SCANNER.DLL
D:\2006\RISING\RAV\BWLIST.DLL
D:\2006\RISING\RAV\RAVUIMSG.DLL
D:\2006\RISING\RAV\PSAPI.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\2006\RISING\RAV\RAVSCRCH.DLL
D:\2006\RISING\RAV\RSSTORE.DLL
D:\2006\RISING\RAV\RAVQU.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
D:\2006\RISING\RAV\LIBLOAD.DLL
D:\2006\RISING\RAV\VIRUSLIB.DLL
D:\2006\RISING\RAV\MVENGINE.DLL
D:\2006\RISING\RAV\ENGINE.DLL
D:\2006\RISING\RAV\SCANEXEC.DLL
D:\2006\RISING\RAV\UNPACKER.DLL
D:\2006\RISING\RAV\UNEXE.DLL
D:\2006\RISING\RAV\SCANEX.DLL
D:\2006\RISING\RAV\RSUNPACK.DLL
D:\2006\RISING\RAV\EXTFILE.DLL
D:\2006\RISING\RAV\POSTTRT.DLL
D:\2006\RISING\RAV\NVFILE.DLL
D:\2006\RISING\RAV\SCANMAC.DLL
D:\2006\RISING\RAV\SCANSCT.DLL
D:\2006\RISING\RAV\EXTMAIL.DLL
D:\2006\RISING\RAV\EXTOLE.DLL
D:\2006\RISING\RAV\RSLOG.DLL
D:\2006\RISING\RAV\SCANELF.DLL
D:\2006\RISING\RAV\SCANNET.DLL
E:\屏幕抓图工具\EPSNAP.EXE
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MSADP32.ACM
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\6469A797.DLL
C:\WINDOWS\SYSTEM32\962C0390.DLL
C:\WINDOWS\SYSTEM32\WINDHCP.OCX
C:\PROGRA~1\WINDOW~2\WMPBAND.DLL
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\FLASHGET\JCCATCH.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\2006\RISING\RAV\RSCOMMON.DLL
D:\2006\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\TDLL.DLL
D:\2006\RISING\RFW\RFWSRV.EXE
D:\2006\RISING\RFW\RFWRULE.DLL
D:\2006\RISING\RFW\RFWLOG.DLL
D:\2006\RISING\RFW\RFWDRV.DLL
D:\2006\RISING\RFW\PSAPI.DLL
D:\2006\RISING\RFW\MONDRV.DLL
D:\2006\RISING\RFW\PROCLIB.DLL
D:\2006\RISING\RFW\RFWMAIN.EXE
D:\2006\RISING\RFW\RSGUILIB.DLL
D:\2006\RISING\RFW\RSCOMMON.DLL
D:\2006\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\TDLL.DLL
D:\2006\RISING\RAV\RAVTASK.EXE
D:\2006\RISING\RAV\RSCOMMON.DLL
D:\2006\RISING\RAV\RSAPPMGR.DLL
D:\2006\RISING\RAV\CFGDLL.DLL
D:\2006\RISING\RAV\RSCOMMX.DLL
C:\WINDOWS\TDLL.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
D:\QQ\QQIEHELPER.DLL
D:\FLASHGET\JCCATCH.DLL
C:\WINDOWS\TDLL.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\2006\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\RICHDLL.DLL
G:\HOME\E盘\心锐志远\RISING 2006\RSDETECT.EXE
C:\WINDOWS\TDLL.DLL
C:\WINDOWS\SYSTEM32\CMD.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\LOGO1_.EXE
C:\WINDOWS\TDLL.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
SoundMan = SOUNDMAN.EXE
load = C:\WINDOWS\UNINSTALL\RUNDL132.EXE
r = C:\WINDOWS\DOWN\RUNDLL32.EXE
sys = C:\WINDOWS\INTEL\RUNDLL32.EXE
mhs = C:\DOCUME~1\NIZHENYU\LOCALS~1\TEMP\MHS.EXE
RavTask = "D:\2006\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "D:\2006\RISING\RFW\RFWMAIN.EXE" -STARTUP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay = C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNONCE.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
szLiveUpdate = "D:\E\LIVEUPDATE.EXE" -A -L VOLVO 726973696E6732303036
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL