瑞星听诊信息
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
E:\360SAFE\SAFEMON\360TRAY.EXE
E:\360SAFE\SAFEMON\SAFEMON.DLL
E:\360SAFE\SAFEMON\SAFEKRNL.DLL
E:\360SAFE\ANTIADWA.DLL
E:\360SAFE\LIVE.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
E:\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
E:\RISING\RAV\RAVMON.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING\RAV\PROCCOM.DLL
E:\RISING\RAV\RSCOMMX2.DLL
E:\RISING\RAV\RSCOMMON.DLL
E:\RISING\RAV\RECOMP.DLL
E:\RISING\RAV\REFS.DLL
E:\RISING\RAV\VIRUSLIB.DLL
E:\RISING\RAV\RELIBLDR.DLL
E:\RISING\RAV\RSAPPMGR.DLL
E:\RISING\RAV\CFGDLL.DLL
E:\RISING\RAV\MONRULE.DLL
E:\RISING\RAV\PNGDLL.DLL
E:\360SAFE\SAFEMON\SAFEMON.DLL
E:\RISING\RAV\RSGUILIB.DLL
E:\RISING\RAV\RSXML.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\EXPLORER.EXE
E:\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
E:\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
E:\PROGRAM FILES\STORMII\STORMLIV.EXE
E:\PROGRAM FILES\STORMII\MSVCP60.DLL
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\DOCUMENTS AND SETTINGS\FZZN\桌面\RSDETECT.EXE
E:\360SAFE\SAFEMON\SAFEMON.DLL
E:\RISING\RAV\CCENTER.EXE
E:\RISING\RAV\RAVTASK.EXE
E:\RISING\RAV\PROCCOM.DLL
E:\RISING\RAV\RSCOMMX2.DLL
E:\RISING\RAV\RSCOMMON.DLL
E:\RISING\RAV\RSAPPMGR.DLL
E:\RISING\RAV\CFGDLL.DLL
E:\360SAFE\SAFEMON\SAFEMON.DLL
E:\RISING\RAV\RAVMOND.EXE
E:\RISING\RAV\BWLIST.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING\RAV\RSAPPMGR.DLL
E:\RISING\RAV\CFGDLL.DLL
E:\RISING\RAV\RSLOG.DLL
E:\RISING\RAV\PROCCOM.DLL
E:\RISING\RAV\RSCOMMX2.DLL
E:\RISING\RAV\MONRULE.DLL
E:\RISING\RAV\HOOKSYS.DLL
E:\RISING\RAV\HOOKREG.DLL
E:\RISING\RAV\HOOKNTOS.DLL
E:\RISING\RAV\RSWALMON.DLL
E:\RISING\RAV\RECOMP.DLL
E:\RISING\RAV\REFS.DLL
E:\RISING\RAV\FFR.DLL
E:\RISING\RAV\RSSTORE.DLL
E:\RISING\RAV\FAKESCAN.DLL
E:\RISING\RAV\SCANNER.DLL
E:\RISING\RAV\HOOKWEB.DLL
E:\RISING\RAV\VIRUSLIB.DLL
E:\RISING\RAV\RELIBLDR.DLL
E:\RISING\RAV\NVFILE.DLL
E:\RISING\RAV\SCANSCT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
E:\360SAFE\SAFEMON\SAFEMON.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
E:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
E:\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL
C:\WINDOWS\SYSTEM32\JPWB.IME
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
360Safetray = E:\360SAFE\SAFEMON\360TRAY.EXE /START
RavTask = "E:\RISING\RAV\RAVTASK.EXE" -SYSTEM
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\logon.scr
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)