同事的电脑用瑞星听诊器扫描结果如下:
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\PROGRAM FILES\TENCENT\QQTOOLBAR\IEBAR.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\TOOLBAR.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\TBADDR.DLL
D:\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.DLL
C:\WINDOWS\SYSTEM32\ATL71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
D:\ACROBAT 7.0\ACROBAT\ACROIEFAVCLIENT.CHS
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
C:\PROGRAM FILES\TENCENT\SSPLUS\SADDR2.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
C:\WINDOWS\SYSTEM32\URLFILTER.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\URLRULE.DLL
D:\360SAFE\SAFEMON\SAFEMON.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\QQMAIL.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\SHUQIAN.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\WENWEN.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\WEATHER.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\POPUPBLOCKER.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\HIGHLIGHT.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\QQDOCTOR.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\MUSICBOX.DLL
C:\DOCUMENTS AND SETTINGS\TAO\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\HOT.DLL
D:\RAV\RAVSCRCH.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\RAV\RAVMOND.EXE
D:\RAV\BWLIST.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
D:\RAV\RSAPPMGR.DLL
D:\RAV\CFGDLL.DLL
D:\RAV\RSLOG.DLL
D:\RAV\PROCCOM.DLL
D:\RAV\RSCOMMX2.DLL
D:\RAV\MONRULE.DLL
D:\RAV\HOOKSYS.DLL
D:\RAV\HOOKREG.DLL
D:\RAV\HOOKNTOS.DLL
D:\RAV\RSWALMON.DLL
D:\RAV\RECOMP.DLL
D:\RAV\REFS.DLL
D:\RAV\FFR.DLL
D:\RAV\RSSTORE.DLL
D:\RAV\HOOKCONT.DLL
D:\RAV\FAKESCAN.DLL
D:\RAV\SCANNER.DLL
D:\RAV\VIRUSLIB.DLL
D:\RAV\RELIBLDR.DLL
D:\RAV\HOOKWEB.DLL
D:\RAV\EXTFILE.DLL
D:\RAV\PEARC.DLL
D:\RAV\NVFILE.DLL
D:\RAV\SCANEXEC.DLL
D:\RAV\UNEXE.DLL
D:\RAV\SCANEX.DLL
D:\RAV\SCANPACK.DLL
D:\RAV\REVM.DLL
D:\RAV\URUTILS.DLL
D:\RAV\UR000.DAT
D:\RAV\SCANSCT.DLL
D:\RAV\EXTMAIL.DLL
D:\RAV\EXTOLE.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\ADOBEPDF.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
D:\ACROBAT 7.0\DISTILLR\ADISTRES.CHS
C:\WINDOWS\SYSTEM32\CNMLM6E.DLL
C:\WINDOWS\SYSTEM32\ZLHP1020.DLL
C:\WINDOWS\SYSTEM32\ZLM.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPD6E.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\IMFPRINT.DLL
C:\WINDOWS\SYSTEM32\IMF32.DLL
C:\WINDOWS\SYSTEM32\ZTAG32.DLL
C:\WINDOWS\SYSTEM32\ZSPOOL.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
D:\RAV\RAVSTUB.EXE
D:\RAV\PROCCOM.DLL
D:\RAV\RSCOMMX2.DLL
D:\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\PROGRAM FILES\COMMON FILES\AUTODESK SHARED\ACSIGNCORE16.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
D:\ACROBAT 7.0\ACTIVEX\PDFSHELL.CHS
C:\WINDOWS\SYSTEM32\IGFXPPH.DLL
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
C:\WINDOWS\SYSTEM32\IGFXRES.DLL
C:\WINDOWS\SYSTEM32\IGFXRESS.DLL
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\SHELL\PSICON.DLL
C:\PROGRAM FILES\TENCENT\QQ\QDSHM.DLL
C:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\RAV\RSCOMMON.DLL
D:\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
D:\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.CHS
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
C:\PROGRAM FILES\TENCENT\SSPLUS\SADDR2.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
D:\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
D:\RAV\RAVTASK.EXE
D:\RAV\PROCCOM.DLL
D:\RAV\RSCOMMX2.DLL
D:\RAV\RSCOMMON.DLL
D:\RAV\RSAPPMGR.DLL
D:\RAV\CFGDLL.DLL
D:\RAV\RAVMON.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
D:\RAV\PROCCOM.DLL
D:\RAV\RSCOMMX2.DLL
D:\RAV\RSCOMMON.DLL
D:\RAV\RECOMP.DLL
D:\RAV\REFS.DLL
D:\RAV\VIRUSLIB.DLL
D:\RAV\RELIBLDR.DLL
D:\RAV\RSAPPMGR.DLL
D:\RAV\CFGDLL.DLL
D:\RAV\MONRULE.DLL
D:\RAV\PNGDLL.DLL
D:\RAV\RSGUILIB.DLL
D:\RAV\RSXML.DLL
C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE
C:\PROGRAM FILES\STORMII\STORMLIV.EXE
C:\PROGRAM FILES\STORMII\MSVCP60.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL
C:\PROGRAM FILES\TENCENT\QQ\TXPLATFORM.EXE
D:\FOXMAIL\FOXMAIL.EXE
C:\WINDOWS\SYSTEM32\MAPI32.DLL
D:\FOXMAIL\FOXANTISPAM.DLL
D:\FOXMAIL\PCRE.DLL
D:\FOXMAIL\3RDPARTY\PUNYLIB.DLL
D:\备份软件\瑞星听诊器 在 XIEGUIYU (HELIKE-XIEGUIYU) 上\RSDETECT.EXE
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavTask = "D:\RAV\RAVTASK.EXE" -SYSTEM
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
igfxcui = IGFXDEV.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233} = C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = D:\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{0C7C23EF-A848-485B-873C-0ED954731014} = C:\Program Files\TENCENT\SSPlus\SAddr2.dll
{29CF293A-1E7D-4069-9E11-E39698D0AF95} = C:\Program Files\Tencent\QQToolbar\IEBar.dll
{889D2FEB-5411-4565-8998-1DD2C5261283} = C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} = C:\WINDOWS\system32\urlFilter.dll
{AE7CD045-E861-484f-8273-0445EE161910} = D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} = D:\360safe\safemon\safemon.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B9B4B426-1D88-4286-8C08-D2D9650DF40F}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B9B4B426-1D88-4286-8C08-D2D9650DF40F}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{25BD8B81-EB28-4BB5-BC51-1B777A43ADDD}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{25BD8B81-EB28-4BB5-BC51-1B777A43ADDD}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5216022-8BD6-44A9-8302-19B87C2FB23A}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5216022-8BD6-44A9-8302-19B87C2FB23A}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5C70973-1A2A-46C2-A128-9E9B1129F6E6}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5C70973-1A2A-46C2-A128-9E9B1129F6E6}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6EC3C179-710C-4B92-B09B-8EFD60B2DC76}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6EC3C179-710C-4B92-B09B-8EFD60B2DC76}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL