启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<36tray><C:\WINDOWS\jhkk\sv.vbs> []
<360tray><C:\WINDOWS\ljjkky\spoolsv.vbs> []
[mtlrd / mtlrd][Stopped/Auto Start]
==================================
驱动程序
<\??\C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft\Media Player\wmp\mtlrd.sys><N/A> 病毒
==================================
正在运行的进程
[PID: 1592 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 788 / SYSTEM][C:\Program Files\AVG\AVG8\avgcsrvx.exe] [AVG Technologies CZ, s.r.o., 8.5.0.300]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 1668 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 15520 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\System32\HtmlPeek.dll] [N/A, ]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 20968 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 31032 / Administrator][C:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 8,0,1300,1881]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 36472 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 7.00.6000.16791 (vista_gdr.081217-1620)]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 65320 / Administrator][C:\Program Files\Java\jre6\bin\javaw.exe] [Sun Microsystems, Inc., 6.0.150.3]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
[PID: 68724 / Administrator][D:\sreng2\SREf0465bfe.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\Com\1.2.8\WndHook.dll] [N/A, ]
==================================
卸载驱动病毒 上报可疑项:上传病毒样本到可疑文件交流区,地址为:
http://bbs.ikaka.com/showforum-20002.aspx或者直接发送给瑞星的邮件服务中心【病毒样本】地址为:
http://mailcenter.rising.com.cn/uploadnew.aspx