<RAV008C><C:\WINDOWS\system32\RAV008C.exe> []
<RAV00B2><C:\WINDOWS\system32\RAV00B2.exe> []
<RAV0142><C:\WINDOWS\system32\RAV0142.exe> []
[npkcrypt / npkcrypt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkycryp.sys><N/A> [C:\WINDOWS\system32\mscomm.dll] [N/A, ]
[c:\progra~1\vmpo\fwzy.dll] [ , 5, 0, 0, 7]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[c:\progra~1\vmpo\kbed.dll] [ , 5, 0, 0, 7]
[c:\progra~1\vmpo\bsvu.dll] [, 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\mscomm.dll] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\mscomm.dll] [N/A, ]
[C:\WINDOWS\system32\RAV0142.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV00B2.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV008C.DAT] [N/A, ]
[c:\progra~1\vmpo\izcb.dll] [, 5, 0, 0, 7]
[c:\progra~1\vmpo\nehg.dll] [ , 5, 0, 0, 7]
[C:\WINDOWS\system32\mscomm.dll] [N/A, ]
隐藏进程
[3868] C:\WINDOWS\system32\usrinit.exe
建议搜索以上的文件(搜索时勾选高级选项_搜索隐藏的文件)
然后上报给瑞星。http://up.rising.com.cn/webmail/uploadnew.htm
PS:其中可能包含有某摄像头驱动,但其行为有些可疑。