未知家族病毒分析
扫描结果:
C:\DOCUME~1\vaio\LOCALS~1\Temp\~2.tmp.exe --> 与 Worm.Bobic 78%相似.
C:\WINDOWS\System32\spooIsv.exe --> 与 Backdoor.IRCbot 94%相似.
系统活动进程
C:\WINDOWS\SYSTEM32\ICO.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\DOCUME~1\VAIO\LOCALS~1\TEMP\~2.TMP.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\COMMON FILES\ULEAD SYSTEMS\DVD\ULCDRSVR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
D:\PROGRA~1\3721\SKE\CONTMENU.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\PROGRA~1\FTC\COMMENU.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\MSVCR71.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM32\ATRPUIXX.CHS
C:\WINDOWS\SYSTEM32\ATIPDSXX.DLL
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\SYSTEM32\SYNTPAPI.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKRES.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\JOG DIAL UTILITY\JOGDIAL.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SONY UTILITIES\SNYUTILS.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SXBIOS\SXBIOS.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\JOGSERV2.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\COMCENTER.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\JOGLOCALE.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\STATEMGR.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\VIEW.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\TRAYICON.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\REMOCON.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\SOUND.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\INDCTR.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\SETTING.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SONY UTILITIES\SNYUTILS.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SXBIOS\SXBIOS.DLL
D:\易发\BIN\YFDOWN.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\D-TOOLS\DAEMON.EXE
C:\WINDOWS\DAEMON.DLL
C:\PROGRAM FILES\D-TOOLS\PFCTOC.DLL
C:\PROGRAM FILES\D-TOOLS\PLUGINS\IMAGES\BW5MOUNT.DLL
C:\PROGRAM FILES\D-TOOLS\PLUGINS\IMAGES\CCDMOUNT.DLL
C:\PROGRAM FILES\D-TOOLS\PLUGINS\IMAGES\MDSMOUNT.DLL
C:\PROGRAM FILES\D-TOOLS\PLUGINS\IMAGES\NRGMOUNT.DLL
C:\PROGRAM FILES\D-TOOLS\PLUGINS\IMAGES\PDIMOUNT.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\SKYNET\FIREWALL\PFW.EXE
C:\PROGRAM FILES\SKYNET\FIREWALL\SKYMISC.DLL
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SPOOISV.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\UILIBRARY\UILIB.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\UILIBRARY\TASTES\GOLD.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\ENGPM.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PMDM.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\ENGDM.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PTLACPI.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SONY UTILITIES\SNYUTILS.DLL
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\SXBIOS\SXBIOS.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\POWERPANEL\PROGRAM\BSACPICM.DLL
C:\PROGRAM FILES\POWERPANEL\PROGRAM\BSNTSBS.DLL
C:\DOCUMENTS AND SETTINGS\VAIO\MY DOCUMENTS\RSDETECT.EXE
C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\WMHOOK.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
ATIModeChange = ATI2MDXX.EXE
AtiPTA = ATIPTAXX.EXE
SynTPLpr = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
SynTPEnh = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
HKSERV.EXE = C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
JOGSERV2.EXE = C:\PROGRAM FILES\SONY\JOG DIAL NAVIGATOR\JOGSERV2.EXE
IMEKRMIG6.1 = C:\WINDOWS\IME\IMKR6_1\IMEKRMIG.EXE
yfdown = D:\易发\BIN\YFDOWN.EXE
DAEMON Tools-1033 = "C:\PROGRAM FILES\D-TOOLS\DAEMON.EXE" -LANG 1033
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
SKYNET Personal FireWall = C:\PROGRAM FILES\SKYNET\FIREWALL\PFW.EXE
Spooler SubSystem App = C:\WINDOWS\SYSTEM32\SPOOISV.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
MSMSGS = "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /BACKGROUND
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B2BB133F-FFDC-46CC-8E91-5C72183F043B}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B2BB133F-FFDC-46CC-8E91-5C72183F043B}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{89BC8E2E-544B-48F2-BD84-38E93207BD69}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{89BC8E2E-544B-48F2-BD84-38E93207BD69}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL