|
无畏鲐背狮
- 帖子:54672
- 注册:
2005-08-02
- 来自:石家庄
|
发表于:
2006-11-03 22:42
|
只看楼主
短消息
资料
附上日志,请专家看看
未知家族病毒分析 扫描结果: 无可疑文件
系统活动进程 C:\WINDOWS\SYSTEM32\NVSVC32.EXE C:\WINDOWS\SYSTEM32\WDFMGR.EXE C:\WINDOWS\SYSTEM32\SMSS.EXE C:\WINDOWS\SYSTEM32\CSRSS.EXE C:\WINDOWS\SYSTEM32\WINLOGON.EXE C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE C:\WINDOWS\SYSTEM32\LSASS.EXE C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\PROGRA~1\COMMON~1\NOKIA\MPAPI\MPAPI3S.EXE C:\PROGRAM FILES\COMMON FILES\NOKIA\MPAPI\MPAPIPS.DLL
C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM32\MSACM32.DRV C:\WINDOWS\SYSTEM32\NVSHELL.DLL
D:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE D:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL D:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL D:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL D:\PROGRAM FILES\RISING\RFW\PSAPI.DLL D:\PROGRAM FILES\RISING\RFW\MONDRV.DLL D:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE C:\WINDOWS\SYSTEM32\MDIMON.DLL C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM\CMICNFG.CPL
D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE D:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL D:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL D:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
D:\PROGRA~1\NOKIA\NOKIAP~1\LAUNCH~1.EXE C:\WINDOWS\SYSTEM32\CONNAPI.DLL C:\WINDOWS\SYSTEM32\MSVCP71.DLL C:\WINDOWS\SYSTEM32\MSVCR71.DLL D:\PROGRA~1\NOKIA\NOKIAP~1\PCSCM.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\CONFSERVER\CONFSERVER.DLL C:\WINDOWS\SYSTEM32\ATL71.DLL C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL D:\PROGRA~1\NOKIA\NOKIAP~1\LANG\LAUNCHAPPLICATION_CHI-SC.NLR
D:\HEROSOFT\HEROV8\SYSEXPLR.EXE D:\HEROSOFT\HEROV8\AVCDROM.DLL D:\HEROSOFT\HEROV8\COOLMENU.DLL D:\HEROSOFT\HEROV8\SYS936.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE C:\WINDOWS\SYSTEM32\CTFMON.EXE D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSYNC2.EXE D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSCM.DLL C:\WINDOWS\SYSTEM32\CONNAPI.DLL C:\WINDOWS\SYSTEM32\MSVCP71.DLL C:\WINDOWS\SYSTEM32\MSVCR71.DLL C:\WINDOWS\SYSTEM32\MFC71U.DLL D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSL.DLL D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\LANG\PCSYNC2_CHI-SC.NLR D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\RESOURCE\PCSYNC2_NOKIA.NGR C:\PROGRAM FILES\COMMON FILES\NOKIA\ADAPTERS\NCLSET.DLL C:\PROGRAM FILES\COMMON FILES\NOKIA\ADAPTERS\NCLAEO.DSC C:\PROGRAM FILES\COMMON FILES\NOKIA\MPAPI\MPAPIPS.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\CONFSERVER\CONFSERVER.DLL C:\WINDOWS\SYSTEM32\ATL71.DLL C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\COMMONSELECTDEVICE.DLL
D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIECLI.EXE C:\WINDOWS\SYSTEM32\MSVBVM60.DLL C:\WINDOWS\SYSTEM32\VB6CHS.DLL D:\PROGRA~1\SUPERR~1\MAGICSET\SHLOBJ71.OCX
C:\WINDOWS\SYSTEM32\INETSRV\INETINFO.EXE D:\铃声\RSDETECT.EXE C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\MSVCR71.DLL C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\MSVCP71.DLL
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE C:\WINDOWS\SYSTEM32\NCLTOOLS.DLL C:\WINDOWS\SYSTEM32\MSVCP71.DLL C:\WINDOWS\SYSTEM32\MSVCR71.DLL C:\WINDOWS\SYSTEM32\ATL71.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\TRANSPORTS\NCLIRDAMM.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\TRANSPORTS\NCLRSMM.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\TRANSPORTS\NCLUSBMM.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\TRANSPORTS\NCLMSBTMM.DLL C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\NCLDS.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE C:\WINDOWS\SYSTEM32\CONIME.EXE C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE D:\PROGRA~1\SUPERR~1\MAGICSET\HAOKANBAR.DLL D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL C:\WINDOWS\SYSTEM32\MSACM32.DRV D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PHONEBROWSER.DLL D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSCM.DLL C:\WINDOWS\SYSTEM32\CONNAPI.DLL C:\WINDOWS\SYSTEM32\MSVCP71.DLL C:\WINDOWS\SYSTEM32\MSVCR71.DLL D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\LANG\PHONEBROWSER_CHI-SC.NLR D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\RESOURCE\PHONEBROWSER_NOKIA.NGR C:\WINDOWS\SYSTEM32\AUDIODEV.DLL C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
普通自启动项 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32 PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME Cmaudio = RUNDLL32 CMICNFG.CPL,CMICTRLWND NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP nwiz = NWIZ.EXE /INSTALL NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD RavTask = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM RfwMain = "D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP StormCodec_Helper = "D:\PROGRAM FILES\RINGZ STUDIO\STORM CODEC\STORMSET.EXE" /S /OPTI NeroFilterCheck = C:\WINDOWS\SYSTEM32\NEROCHECK.EXE PCSuiteTrayApplication = D:\PROGRA~1\NOKIA\NOKIAP~1\LAUNCH~1.EXE -STARTUP SysExplr = D:\HEROSOFT\HEROV8\SYSEXPLR.EXE TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE PcSync = D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSYNC2.EXE /NODIALOG Super Rabbit IEPro = D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIECLI.EXE /LOAD
AppInit_DLLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs =
系统文件关联 .exe ==> exefile = "%1" %* .com ==> comfile = "%1" %* .cmd ==> cmdfile = "%1" %* .bat ==> batfile = "%1" %* .txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1 .scr ==> scrfile = "%1" /S .reg ==> regfile = regedit.exe "%1" .doc ==> Word.Document.8 = "D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项 WIN.INI 无信息
SYSTEM.INI SHELL = Explorer.exe
Winlogon 启动项 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify crypt32chain = CRYPT32.DLL cryptnet = CRYPTNET.DLL cscdll = CSCDLL.DLL ScCertProp = WLNOTIFY.DLL Schedule = WLNOTIFY.DLL sclgntfy = SCLGNTFY.DLL SensLogn = WLNOTIFY.DLL termsrv = WLNOTIFY.DLL wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE, shell = EXPLORER.EXE
IE - BHO HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} = D:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
Winsock SPI MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{FB4A97B4-DA6B-4EAF-A613-341099E75406}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{FB4A97B4-DA6B-4EAF-A613-341099E75406}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{A708A198-F83B-4343-8D45-616CD204D53D}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{A708A198-F83B-4343-8D45-616CD204D53D}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{9832C00A-B6A3-4973-9582-B863BF9B2366}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{9832C00A-B6A3-4973-9582-B863BF9B2366}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{70A88EB8-0045-4F01-9E2D-C4FD6FA4018D}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{70A88EB8-0045-4F01-9E2D-C4FD6FA4018D}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{B115D2A8-8525-4223-998E-302E856744DC}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{B115D2A8-8525-4223-998E-302E856744DC}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{C23AAE4A-335A-4C29-BE00-D7E3CB6C70F6}] SEQPACKET 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL MSAFD NetBIOS [\Device\NetBT_Tcpip_{C23AAE4A-335A-4C29-BE00-D7E3CB6C70F6}] DATAGRAM 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
|