1   1  /  1  页   跳转

求助:Win32.Downloader.af

求助:Win32.Downloader.af

我的电脑里大量的Win32.Downloader.af病毒,每天杀完了又有,我是正版软件,好多天了,今天刚装了系统。有的程序也没有用,要重新装。怎么杀完了还没有用,请各位指导。谢谢了。

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler ; .NET CLR 1.1.4322)
最后编辑2008-04-12 01:04:38.140000000
分享到:
gototop
 




未知家族病毒分析
扫描结果:
无可疑文件


系统活动进程
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
E:\RISING安装\RAVTASK.EXE
E:\RISING安装\PROCCOM.DLL
E:\RISING安装\RSCOMMX2.DLL
E:\RISING安装\RSCOMMON.DLL
E:\RISING安装\RSAPPMGR.DLL
E:\RISING安装\CFGDLL.DLL

E:\RISING安装\RSAGENT.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING安装\PROCCOM.DLL
E:\RISING安装\RSCOMMX2.DLL

E:\RISING安装\RAVMON.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING安装\PROCCOM.DLL
E:\RISING安装\RSCOMMX2.DLL
E:\RISING安装\RSCOMMON.DLL
E:\RISING安装\RECOMP.DLL
E:\RISING安装\REFS.DLL
E:\RISING安装\VIRUSLIB.DLL
E:\RISING安装\RELIBLDR.DLL
E:\RISING安装\RSAPPMGR.DLL
E:\RISING安装\CFGDLL.DLL
E:\RISING安装\MONRULE.DLL
E:\RISING安装\PNGDLL.DLL
E:\RISING安装\RSGUILIB.DLL
E:\RISING安装\RSXML.DLL

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL

E:\QQ2007安装3\QQ.EXE
E:\QQ2007安装3\QQBASECLASSINDLL.DLL
E:\QQ2007安装3\QQHELPERDLL.DLL
E:\QQ2007安装3\BASICCTRLDLL.DLL
E:\QQ2007安装3\MFC42.DLL
E:\QQ2007安装3\RICHED32.DLL
E:\QQ2007安装3\RICHED20.DLL
E:\QQ2007安装3\QQAPI.DLL
E:\QQ2007安装3\LOGINCTRL.DLL
E:\QQ2007安装3\LOGINCTRLRES.DLL
E:\QQ2007安装3\QQRES.DLL
E:\QQ2007安装3\CQQAPPLICATION.DLL
E:\QQ2007安装3\QQMAINFRAME.DLL
E:\QQ2007安装3\GDIPLUS.DLL
E:\QQ2007安装3\QQPLUGIN.DLL
E:\QQ2007安装3\UNREADMSGMGR.DLL
E:\QQ2007安装3\FLASHAVATARDLL.DLL
E:\QQ2007安装3\NEWSKIN.DLL
E:\QQ2007安装3\MAILSUMMARY.DLL
E:\QQ2007安装3\QQGROUPMNG.DLL
E:\QQ2007安装3\QQSPACE.DLL
E:\QQ2007安装3\VBSCRIPT.DLL
E:\QQ2007安装3\USERDEFINEDHEAD.DLL
E:\QQ2007安装3\QQCONFIGPLUGIN.DLL
E:\QQ2007安装3\QQALLINONE.DLL
E:\QQ2007安装3\SCCORE.DLL
E:\QQ2007安装3\CAMERADLL.DLL
E:\QQ2007安装3\QQAVATAR.DLL
E:\QQ2007安装3\PHONEAPI.DLL
E:\QQ2007安装3\DIALERALLINONE.DLL
E:\QQ2007安装3\BQQAPPLICATION.DLL
E:\QQ2007安装3\QRINGMNG.DLL
E:\QQ2007安装3\QQKNOWLEDGESEARCH.DLL
E:\QQ2007安装3\OEMAPPLICATION.DLL
E:\QQ2007安装3\QQCUSTOMFACE.DLL
E:\QQ2007安装3\QQPET.DLL
E:\QQ2007安装3\QQSYSMSGMNG.DLL
E:\QQ2007安装3\LONGCONNECTION.DLL
E:\QQ2007安装3\COMMERCESMNG.DLL
E:\QQ2007安装3\PERSONALDESKTOP.DLL
E:\QQ2007安装3\QQADDR.DLL
E:\QQ2007安装3\QQFILETRANSFER.DLL
E:\QQ2007安装3\QQSCENEMNG.DLL
E:\QQ2007安装3\ADDRSEARCH.DLL
E:\QQ2007安装3\IMAGEOLE.DLL
E:\QQ2007安装3\QQLIVEQMNG.DLL
E:\QQ2007安装3\QQMAGICFACE.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
E:\QQ2007安装3\QQDOCTOR\TSFSCAN.DAT
E:\QQ2007安装3\QQDOCTOR\TSELODER.DAT
E:\QQ2007安装3\GROUPCONNECTION.DLL
E:\QQ2007安装3\QQDOCTOR\TSVULMDW.DAT
E:\QQ2007安装3\QQDOCTOR\TSVULCHK.DAT
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MSADP32.ACM
E:\QQ2007安装3\VIDEODEVICE.DLL
E:\QQ2007安装3\INPLUS.DLL
C:\WINDOWS\SYSTEM32\L3CODECA.ACM

C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\MICROSOFT OFFICE2003\OFFICE11\MSOHEV.DLL
E:\RISING安装\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\CONIME.EXE
E:\QQ2007安装3\TXPLATFORM.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
E:\TT2\TTRAVELER.EXE
E:\TT2\PLUGINS\QQFLOATBAR\QQFLOATBAR4TT2.DLL
E:\RISING安装\RAVSCRCH.DLL
E:\TT2\TTNETFAVOR.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORIE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLD.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV

E:\RISING安装\RAV.EXE
E:\RISING安装\PROCCOM.DLL
E:\RISING安装\RSCOMMX2.DLL
E:\RISING安装\RSGUILIB.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING安装\RSXML.DLL
E:\RISING安装\PNGDLL.DLL
E:\RISING安装\RSCOMMON.DLL
E:\RISING安装\RAVPAGEM.DLL
E:\RISING安装\HTMLLIB.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
E:\RISING安装\RAVPAGEW.DLL
E:\RISING安装\RSAPPMGR.DLL
E:\RISING安装\CFGDLL.DLL
E:\RISING安装\FAKESCAN.DLL
E:\RISING安装\SCANNER.DLL
E:\RISING安装\BWLIST.DLL
E:\RISING安装\SYSMAIL.DLL

E:\RISING安装\RSLOGVW.EXE
E:\RISING安装\PROCCOM.DLL
E:\RISING安装\RSCOMMX2.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
E:\RISING安装\RSGUILIB.DLL
E:\RISING安装\RSXML.DLL
E:\RISING安装\PNGDLL.DLL
E:\RISING安装\RSCOMMON.DLL
E:\RISING安装\RECOMP.DLL
E:\RISING安装\REFS.DLL
E:\RISING安装\VIRUSLIB.DLL
E:\RISING安装\RELIBLDR.DLL

C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL

E:\代写论文\RSDETECT.EXE

普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched = C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE
RavTask = "E:\RISING安装\RAVTASK.EXE" -SYSTEM
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
RfwMain = "E:\RISING防火墙\RFWMAIN.EXE" -STARTUP
SoundMan = SOUNDMAN.EXE

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE


AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =


系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "D:\Microsoft Office2003\OFFICE11\WINWORD.EXE" /n /dde

其它启动项
WIN.INI
无信息

SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\lo
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT