未知家族病毒分析
扫描结果:
C:\Windows\system32\JUGREPALXITEPA.EXE --> 与 Trojan.QQMSG.MsgSender 40%相似.
C:\Windows\system32\UAHMUYEJ.EXE --> 与 Trojan.QQMSG.MsgSender 40%相似.
C:\Windows\system32\ZFKQXDINSXC.EXE --> 与 Trojan.QQMSG.MsgSender 40%相似.
系统活动进程
D:\WINDOWS\SYSTEM32\RUNDLL32.EXE
D:\WINDOWS\SYSTEM32\WINDOWN_5.DLL
D:\WINDOWS\TDLL.DLL
D:\WINDOWS\ZTGA.DLL
D:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\BHMRYDINVAE.DLL
D:\WINDOWS\SYSTEM32\WDMAUD.DRV
D:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\WINDOWS\TDLL.DLL
D:\WINDOWS\ZTGA.DLL
D:\PROGRAM FILES\WINRAR\RAREXT.DLL
D:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SSC\VPSHELL2.DLL
D:\WINDOWS\SYSTEM32\ADNRY.DLL
E:\TOOLS\EWIDO ANTI-SPYWARE 4.0\CONTEXT.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\DWHWIZRD.EXE
E:\PROGRA~1\SYMANT~1\SYMANT~1\I2LDVP3.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAPI32.DLL
D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVEX32A.DLL
D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVENG32.DLL
E:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\NAVAP32.DLL
D:\WINDOWS\SYSTEM32\SMSS.EXE
D:\WINDOWS\SYSTEM32\CSRSS.EXE
D:\WINDOWS\SYSTEM32\WINLOGON.EXE
D:\WINDOWS\SYSTEM32\WDMAUD.DRV
D:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\WINDOWS\SYSTEM32\NAVLOGON.DLL
D:\WINDOWS\SYSTEM32\SERVICES.EXE
D:\WINDOWS\SYSTEM32\LSASS.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\WINDOWS\SYSTEM32\ADNRY.DLL
C:\OLITE\BIN\OCI.DLL
C:\OLITE\BIN\ORA805.DLL
C:\OLITE\BIN\CORE40.DLL
C:\OLITE\BIN\NLSRTL33.DLL
C:\OLITE\BIN\NL80.DLL
C:\OLITE\BIN\OTRACE80.DLL
C:\OLITE\BIN\NS80.DLL
C:\OLITE\BIN\NASNS80.DLL
C:\OLITE\BIN\NZ80.DLL
C:\OLITE\BIN\NNFG80.DLL
C:\OLITE\BIN\NNCI80.DLL
C:\OLITE\BIN\NNG80.DLL
C:\OLITE\BIN\NMP80.DLL
C:\OLITE\BIN\NPL80.DLL
C:\OLITE\BIN\NR80.DLL
C:\OLITE\BIN\NT80.DLL
C:\OLITE\BIN\NCR80.DLL
C:\OLITE\BIN\NMS80.DLL
C:\OLITE\BIN\NNFD80.DLL
C:\OLITE\BIN\NNFN80.DLL
C:\OLITE\BIN\NI80.DLL
C:\OLITE\BIN\PLS805.DLL
C:\OLITE\BIN\NDWSI80.DLL
C:\OLITE\BIN\SQLLIB80.DLL
C:\OLITE\BIN\XA80.DLL
C:\WINDOWS\SYSTEM32\JUGREPALXITEPA.EXE
D:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
E:\PROGRAM FILES\TENCENT\QQ\QQLIVEUPDATE.EXE
E:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
D:\WINDOWS\ZTGA.DLL
D:\WINDOWS\TDLL.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SQLSERVR.EXE
D:\WINDOWS\SYSTEM32\MSVCP71.DLL
D:\WINDOWS\SYSTEM32\MSVCR71.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\OPENDS60.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SQLSORT.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\UMS.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\RESOURCES\2052\SQLEVN70.RLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SSNETLIB.DLL
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SSMSLPCN.DLL
D:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SSNMPN70.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\RTVSCAN.EXE
D:\WINDOWS\SYSTEM32\CBA.DLL
D:\WINDOWS\SYSTEM32\MSGSYS.DLL
D:\WINDOWS\SYSTEM32\NTS.DLL
D:\WINDOWS\SYSTEM32\PDS.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\NAVLU.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\I2LDVP3.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAPI32.DLL
D:\WINDOWS\SYSTEM32\WBEM\WWJXT.DLL
D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVEX32A.DLL
D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVENG32.DLL
E:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\NAVAP32.DLL
D:\WINDOWS\SYSTEM32\SPOOLSV.EXE
D:\WINDOWS\SYSTEM32\EBPMON2.DLL
D:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\VPRPROC.DLL
D:\WINDOWS\DOWN\RUNDLL32.EXE
D:\WINDOWS\TDLL.DLL
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.EXE
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\WINDOWS\ZTGA.DLL
D:\WINDOWS\TDLL.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\VPTRAY.EXE
D:\WINDOWS\TDLL.DLL
E:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\CLISCAN.DLL
E:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL
D:\WINDOWS\ZTGA.DLL
E:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\CLIPROXY.DLL
D:\WINDOWS\SYSTEM32\CTFMON.EXE
D:\WINDOWS\TDLL.DLL
D:\WINDOWS\ZTGA.DLL
D:\WINDOWS\INTERL\SVCH0ST.EXE
D:\WINDOWS\ZTGA.DLL
D:\WINDOWS\TDLL.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.REMOTESERVICE.EXE
D:\WINDOWS\SYSTEM32\MSCOREE.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORWKS.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\FUSION.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLIB.DLL
D:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\MSCORLIB\1.0.5000.0__B77A5C561934E089_67D8F6E6\MSCORLIB.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORSN.DLL
D:\WINDOWS\ASSEMBLY\GAC\MSCORLIB.RESOURCES\1.0.5000.0_ZH-CHS_B77A5C561934E089\MSCORLIB.RESOURCES.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.SERVICEPROCESS\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.SERVICEPROCESS.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM\1.0.5000.0__B77A5C561934E089\SYSTEM.DLL
D:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM\1.0.5000.0__B77A5C561934E089_04F93CC4\SYSTEM.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORJIT.DLL
D:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\DIASYMREADER.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.ENTERPRISEMANAGEMENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.RESUMABLEFILETRANSFER.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.SERVICEUPDATE.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\LOG4NET.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.XML\1.0.5000.0__B77A5C561934E089\SYSTEM.XML.DLL
D:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.XML\1.0.5000.0__B77A5C561934E089_31737381\SYSTEM.XML.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.STUBIMPLEMENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.STUB.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.COMMONUTIL.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.BUYERSERVICEMANAGEMENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.MESSAGEMANAGEMENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.PRICEANDORDERMANAGEMENT.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.RUNTIME.REMOTING\1.0.5000.0__B77A5C561934E089\SYSTEM.RUNTIME.REMOTING.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.ORMAPPING.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.DATA\1.0.5000.0__B77A5C561934E089\SYSTEM.DATA.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WEB\1.0.5000.0__B03F5F7F11D50A3A\SYSTEM.WEB.DLL
E:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.COMMONFUNCTION.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\BD5F4B90\00AB8C33_9F31AE01\ES3000ENT.APPCOMPONENTS.BLACKCASKETSERVER.EXE
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\46B4682E\00AB8C33_9F31AE01\ES3000ENT.APPCOMPONENTS.CONTROLFORMSERVICE.EXE
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.WINDOWS.FORMS\1.0.5000.0__B77A5C561934E089\SYSTEM.WINDOWS.FORMS.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\4BEEF79F\00AB8C33_9F31AE01\ES3000ENT.FRAMEWORK.MP1.EXE
D:\WINDOWS\ASSEMBLY\NATIVEIMAGES1_V1.1.4322\SYSTEM.WINDOWS.FORMS\1.0.5000.0__B77A5C561934E089_BBB8BB5E\SYSTEM.WINDOWS.FORMS.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.SERVICEPROCESS.RESOURCES\1.0.5000.0_ZH-CHS_B03F5F7F11D50A3A\SYSTEM.SERVICEPROCESS.RESOURCES.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\CC52EA47\00A4ABA1_068CC501\ES3000ENT.APPCOMPONENTS.BLACKCASKET.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\2A15362E\00A4ABA1_068CC501\ES3000ENT.FRAMEWORK.INTERFACEMPI.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\6B18F199\00A4ABA1_068CC501\ES3000ENT.COMMONCOMPONENTS.ORMAPPING.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\748CBBD4\00A4ABA1_068CC501\ES3000ENT.APPCOMPONENTS.DOWNLOADEDDATAPARSER.DLL
D:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\ASSEMBLY\DL2\ER028G7A.X8P\40RE99CB.KRC\66D74A57\00F0E69C_068CC501\IRDEXCLIENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.APIINVOKER.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.SECURITY.DLL
D:\WINDOWS\ASSEMBLY\GAC\SYSTEM.RESOURCES\1.0.5000.0_ZH-CHS_B77A5C561934E089\SYSTEM.RESOURCES.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.PERMISSIONMANAGEMENT.DLL
D:\PROGRAM FILES\NINETOWNS CORP\ICSP_SM\ICSP.WEBSERVER.DLL
请高手帮忙分析下!!小弟在此谢谢