未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\UPHCLEAN\UPHCLEAN.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\WGALOGON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\APPPATCH\ACADPROC.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\ATIPDLXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\RUNIEP.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
F:\RAVRETRY\RSDETECT.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\ATIPDLXX.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\SHLHOOK.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\WINDOWS\SYSTEM32\WPDSHSERVICEOBJ.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICETYPES.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIACMXX.DLL
C:\PROGRAM FILES\迅雷5\THUNDER\COMDLLS\TDATONCE_NOW.DLL
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL
F:\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9C.OCX
C:\WINDOWS\SYSTEM32\XPSP3RES.DLL
F:\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORIE.DLL
C:\PROGRAM FILES\迅雷5\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
C:\PROGRAM FILES\迅雷5\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
C:\PROGRAM FILES\迅雷5\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
F:\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE
C:\PROGRAM FILES\CHINANET\COMMUNICATE.DLL
C:\PROGRAM FILES\CHINANET\DIALMODULE.DLL
C:\PROGRAM FILES\CHINANET\MFC42.DLL
C:\PROGRA~1\CHINANET\CLIENT~1.DLL
C:\PROGRA~1\CHINANET\PLUGIN~1.OCX
C:\PROGRA~1\CHINANET\SIGN.DLL
C:\PROGRA~1\CHINANET\POSTPLUG.DLL
C:\PROGRA~1\CHINANET\ADVERT~1.OCX
C:\PROGRA~1\CHINANET\VNETBS.OCX
C:\PROGRA~1\CHINANET\ACCOUN~2.DLL
C:\PROGRA~1\CHINANET\ACCOUNTMGR.DLL
C:\PROGRA~1\CHINANET\VNETSKIN.OCX
C:\PROGRA~1\CHINANET\DIALOGSTYLE.DLL
C:\PROGRA~1\CHINANET\TIMER.OCX
C:\PROGRA~1\CHINANET\PLUGIN~2.OCX
C:\PROGRA~1\CHINANET\NEWMES~1.DLL
C:\PROGRA~1\CHINANET\PASSCTRL.DLL
C:\WINDOWS\SYSTEM32\WPCAP.DLL
C:\WINDOWS\SYSTEM32\PTHREADVC.DLL
C:\WINDOWS\SYSTEM32\PACKET.DLL
C:\PROGRA~1\CHINANET\PLUGPUSH.DLL
C:\PROGRA~1\CHINANET\ALLINT~1.DLL
C:\PROGRA~1\CHINANET\VNETLO~1.OCX
C:\PROGRA~1\CHINANET\STATNUM.DLL
C:\PROGRA~1\CHINANET\VNETON~1.OCX
C:\PROGRA~1\CHINANET\ALLFUN~1.DLL
C:\PROGRA~1\CHINANET\VNETOPTLOG.DLL
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
F:\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\CHINANET\DLGSKIN.OCX
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9C.OCX
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
runeip = "C:\PROGRAM FILES\RISING\KAKATOOLBAR\RUNIEP.EXE" /STARTUP
RavTask = "F:\RISING\RAV\RAVTASK.EXE" -SYSTEM
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent = ATI2EVXX.DLL
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
WgaLogon = WGALOGON.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233} = C:\Program Files\迅雷5\Thunder\ComDlls\TDAtOnce_Now.dll
{2F364305-AA45-47B5-9F9D-39A8B94E7EF7} = C:\Program Files\迅雷5\Thunder\ComDlls\xunleiBHO_Now.dll
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} = C:\Program Files\FlashGet\jccatch.dll
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} = c:\PROGRA~1\chinanet\VNETTR~1.DLL
{669751ED-D558-49AE-B01A-3B374CC7910E} = NULL
{AA58ED58-01DD-4d91-8333-CF10577473F7} = c:\program files\google\googletoolbar1.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} = C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} = F:\360safe\safemon\safemon.dll
{F166BC04-3C84-44cc-A6E9-2315EC4844B9} = NULL
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{53552B0A-0126-4719-BFEF-AC24AAE90763}] SEQPACKET 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{53552B0A-0126-4719-BFEF-AC24AAE90763}] DATAGRAM 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D55B698F-481B-4C15-8881-827E9950A7ED}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D55B698F-481B-4C15-8881-827E9950A7ED}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DEDC2825-F4CD-46A7-A802-73D03264528C}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DEDC2825-F4CD-46A7-A802-73D03264528C}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{58EBE41B-D783-46DC-BF4A-B91066AEAF32}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{58EBE41B-D783-46DC-BF4A-B91066AEAF32}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8744CF03-7350-4D53-8D3B-8985BB126354}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8744CF03-7350-4D53-8D3B-8985BB126354}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{073CC87E-6429-4C28-B9D8-6EBC961E7AF3}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{073CC87E-6429-4C28-B9D8-6EBC961E7AF3}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)