未知家族病毒分析
扫描结果:
C:\DOCUME~1\wsx\LOCALS~1\Temp\kwatlog.exe --> 与 Trojan.PSW.LMir 76%相似.
系统活动进程
F:\瑞星安装\VIKINGKILLER.SCR
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\PDM.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MSDBG2.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RAV\RSPPSYS.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL
C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
C:\PROGRAM FILES\RISING\RAV\REGMON.DLL
C:\PROGRAM FILES\RISING\RAV\PSAPI.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL
C:\PROGRAM FILES\RISING\RAV\MEMMON.DLL
C:\PROGRAM FILES\RISING\RAV\EXPSCAN.DLL
C:\PROGRAM FILES\RISING\RAV\MPORTS.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKCONT.DLL
C:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL
C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL
C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL
C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL
C:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL
C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL
C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL
C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL
C:\PROGRAM FILES\RISING\RAV\SCANPACK.DLL
C:\PROGRAM FILES\RISING\RAV\RSVM.DLL
C:\PROGRAM FILES\RISING\RAV\UROUTINE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNET.DLL
C:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL
C:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANELF.DLL
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\WINDOWS\SYSTEM32\IGFXRES.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\STSYSTRA.EXE
C:\WINDOWS\SYSTEM32\STLANG.DLL
C:\WINDOWS\SYSTEM32\STACAPI.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEP_CTRL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\DOCUME~1\WSX\LOCALS~1\TEMP\KWATLOG.EXE
C:\DOCUME~1\WSX\LOCALS~1\TEMP\OAOE.DLL
C:\DOCUME~1\WSX\LOCALS~1\TEMP\PACKET.DLL
C:\DOCUME~1\WSX\LOCALS~1\TEMP\WANPACKET.DLL
C:\DOCUME~1\WSX\LOCALS~1\TEMP\NPPTOOLS.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\IGFXPPH.DLL
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
C:\WINDOWS\SYSTEM32\IGFXRES.DLL
C:\WINDOWS\SYSTEM32\IGFXRESS.DLL
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\RUNDL132.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MSDBG2.DLL
C:\WINDOWS\SYSTOM.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE
C:\PROGRAM FILES\SOGOU PXP\VODSVR.DLL
C:\PROGRAM FILES\SOGOU PXP\PXPNET.DLL
C:\PROGRAM FILES\SOGOU PXP\P2PCLIENT.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RSXML.DLL
C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\TASKMANAGER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ASYN_DNS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\BHOSTUB.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\FLOATBAR.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ITARGETAD.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\DIAGNOSEHELPER\DIAGNOSEHELPER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\PORTVERIFY\PORTVERIFY.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\EXPLORERHELPER\EXPLORERHELPER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\DTAG\DTAG.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\LIVEUPDATE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBED08.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\COMMUNITY\XLCOMMUNITY.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\REGISTERDLL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\SEARCH\XLSEARCH.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\VPSHELL\VPSHELL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\VPSHELL\VIDEOPICTURE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PLUGINS\BHOADV\BHO_ADV.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\PDM.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MSDBG2.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\MSGMANAGE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\MEDIAADDIN11.DLL
C:\DOCUMENTS AND SETTINGS\WSX\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\4PIJ81AV\RSDETECT[1].EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\RAV\RAV.EXE
C:\PROGRAM FILES\RISING\RAV\PLUGIN\RSPGSCAN.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RAVUI.DLL
C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RAV\RSXML.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\PDM.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MSDBG2.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_007.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\THUNDERAGENT_007.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
IgfxTray = C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
HotKeysCmds = C:\WINDOWS\SYSTEM32\HKCMD.EXE
Persistence = C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
SigmatelSysTrayApp = STSYSTRA.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
runeip = C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
个人密盘 = (NULL)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
myzq = C:\WINDOWS\RUNDL132.EXE
myzq = C:\WINDOWS\RUNDL132.EXE
ksmry8zqt2b7 = C:\WINDOWS\SYSTOM.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =