【回复“無馀爱ㄛ冰”的帖子】
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\DRIVERS\CDANTSRV.EXE
D:\PROGRAM FILES\MAXTHON\MAXTHON.EXE
D:\PROGRAM FILES\MAXTHON\MAXZLIB.DLL
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\WINDOWS\SYSTEM32\ODBCBCP.DLL
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\CORPERFMONEXT.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
D:\PROGRAM FILES\MAXTHON\SERVICES\REALTIME\REAL_TIME.DLL
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\UNISPIM5.IME
C:\PROGRAM FILES\COMMON FILES\AUTODESK SHARED\ACSIGNCORE16.DLL
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
C:\PROGRAM FILES\VNETCLIENT1.6\VNETCLIENT.EXE
C:\PROGRAM FILES\VNETCLIENT1.6\COMMUNICATE.DLL
C:\PROGRAM FILES\VNETCLIENT1.6\DIALMODULE.DLL
C:\PROGRAM FILES\VNETCLIENT1.6\MFC42.DLL
C:\PROGRA~1\VNETCL~1.6\CLIENT~1.DLL
C:\PROGRA~1\VNETCL~1.6\PLUGIN~1.OCX
C:\PROGRA~1\VNETCL~1.6\SIGN.DLL
C:\PROGRA~1\VNETCL~1.6\SETUPP~1.DLL
C:\PROGRA~1\VNETCL~1.6\WEBPLU~1.DLL
C:\PROGRAM FILES\VNETCLIENT1.6\SYSPLUG\BCD35F41-3E51-4E2C-BF82-3B8E8C2310AC\RFPLUG.DLL
C:\PROGRA~1\VNETCL~1.6\ADVERT~1.OCX
C:\PROGRA~1\VNETCL~1.6\VNETBS.OCX
C:\PROGRA~1\VNETCL~1.6\ACCOUN~2.DLL
C:\PROGRA~1\VNETCL~1.6\ACCOUNTMGR.DLL
C:\PROGRA~1\VNETCL~1.6\VNETSKIN.OCX
C:\PROGRA~1\VNETCL~1.6\DIALOGSTYLE.DLL
C:\PROGRA~1\VNETCL~1.6\BDSEARCH.OCX
C:\PROGRA~1\VNETCL~1.6\TIMER.OCX
C:\PROGRA~1\VNETCL~1.6\PLUGIN~2.OCX
C:\PROGRA~1\VNETCL~1.6\NEWMES~1.DLL
C:\PROGRA~1\VNETCL~1.6\PASSCTRL.DLL
C:\WINDOWS\SYSTEM32\WPCAP.DLL
C:\WINDOWS\SYSTEM32\PTHREADVC.DLL
C:\WINDOWS\SYSTEM32\PACKET.DLL
C:\PROGRA~1\VNETCL~1.6\PLUGPUSH.DLL
C:\PROGRA~1\VNETCL~1.6\ALLINT~1.DLL
C:\PROGRA~1\VNETCL~1.6\VNETLO~1.OCX
C:\PROGRA~1\VNETCL~1.6\STATNUM.DLL
C:\PROGRA~1\VNETCL~1.6\VNETON~1.OCX
C:\PROGRA~1\VNETCL~1.6\ALLFUN~1.DLL
C:\PROGRA~1\VNETCL~1.6\VNETOPTLOG.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\PROGRA~1\VNETCL~1.6\DLGSKIN.OCX
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\STDSVER.DLL
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\DOCUMENTS AND SETTINGS\HENRY\桌面\EWIDO4.0\EWIDO ANTI-SPYWARE 4.0\EWIDO.EXE
C:\DOCUMENTS AND SETTINGS\HENRY\桌面\EWIDO4.0\EWIDO ANTI-SPYWARE 4.0\ENGINE.DLL
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\PROGRAM FILES\COMMON FILES\AUTODESK SHARED\ACSIGNCORE16.DLL
C:\WINDOWS\WEBWORK\WEBWORK.NLS
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\DOWNLO~1\LYLIZ.DLL
C:\WINDOWS\SYSTEM32\MSXML4.DLL
C:\PROGRA~1\BAIDU\BAR\BAIDUBAR.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\SMFLASH.OCX
C:\WINDOWS\SYSTEM32\STDUP.DLL
D:\PROGRA~1\KUGOO2\KUGOO3~1.OCX
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\DOCUMENTS AND SETTINGS\HENRY\桌面\EWIDO4.0\EWIDO ANTI-SPYWARE 4.0\SHELLEXECUTEHOOK.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\VCDPLAYX.EXE
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
D:\PROGRAM FILES\RINGZ STUDIO\STORM DOWNLOADER\STORMDOWNLOADER.EXE
D:\PROGRAM FILES\RINGZ STUDIO\STORM DOWNLOADER\BOOST_THREAD-VC6-MT-1_31.DLL
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\QQPETNURSE0719(2.16)\QQPETNURSE0719(2.16)\QQPETNURSE.EXE
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
D:\PROGRAM FILES\TENCENT\QQ\CORALASSIST.DLL
D:\PROGRAM FILES\TENCENT\QQ\CORALQQ.DLL
D:\PROGRAM FILES\TENCENT\QQ\IPSEARCHER.DLL
D:\PROGRAM FILES\TENCENT\QQ\MSVCR80.DLL
D:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
D:\PROGRAM FILES\TENCENT\QQ\MSVCP80.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQBASECLASSINDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQHELPERDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\BASICCTRLDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED32.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED20.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
D:\PROGRAM FILES\TENCENT\QQ\LOGINCTRL.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKCNTC.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKPDB.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQRES.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQMAINFRAME.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\NEWSKIN.DLL
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
D:\PROGRAM FILES\TENCENT\QQ\HOSTINGMGR.DLL
D:\PROGRAM FILES\TENCENT\QQ\CAMERADLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\MAILSUMMARY.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSPACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\VBSCRIPT.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQGROUPMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\GROUPLIVE.DLL
D:\PROGRAM FILES\TENCENT\QQ\USERDEFINEDHEAD.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQALLINONE.DLL
D:\PROGRAM FILES\TENCENT\QQ\SCCORE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQCUSTOMFACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\GDIPLUS.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MSADP32.ACM
D:\PROGRAM FILES\TENCENT\QQ\QQPET.DLL
D:\PROGRAM FILES\TENCENT\QQ\LONGCONNECTION.DLL
D:\PROGRAM FILES\TENCENT\QQ\QRINGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\GROUPCONNECTION.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\DOCUMENTS AND SETTINGS\HENRY\桌面\EWIDO4.0\EWIDO ANTI-SPYWARE 4.0\SHELLEXECUTEHOOK.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQCONFIGPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\PHONEAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\DIALERALLINONE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQAVATAR.DLL
D:\PROGRAM FILES\TENCENT\QQ\FLASHAVATARDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSYSMSGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\BQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\COMMERCESMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\PERSONALDESKTOP.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQUDPGETFILELIB.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQADDR.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPHONEHELPER.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
D:\PROGRAM FILES\TENCENT\QQ\QQMAGICFACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSCENEMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\IMAGEOLE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQZIP.DLL
C:\WINDOWS\SYSTEM32\UNISPIM5.IME
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPET\QQPET.EXE
C:\WINDOWS\SYSTEM32\ODBCBCP.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPET\QQPETRESDOWNLOAD.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPET\QQPETCOMMUNITY.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\WSHCON32.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUMENTS AND SETTINGS\HENRY\桌面\RAV\RSDETECT.EXE
C:\WINDOWS\DOWNLO~1\HVGEE.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
nwiz = NWIZ.EXE /INSTALL
vcdplayx = "C:\WINDOWS\VCDPLAYX.EXE"
MINI_BFYY = D:\PROGRAM FILES\RINGZ STUDIO\STORM DOWNLOADER\STORMDOWNLOADER.EXE
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
stup.exe = C:\PROGRA~1\TENCENT\ADPLUS\STUP.EXE
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
!ewido = "C:\DOCUMENTS AND SETTINGS\HENRY\桌面\EWIDO4.0\EWIDO ANTI-SPYWARE 4.0\EWIDO.EXE" /MINIMIZED
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
bgswitch = C:\WINDOWS\SYSTEM32\BGSWITCH.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "D:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe