今天上午再使用电脑过程中,忽然提示“虚拟内存最小值太低”(不是原话,意思就是这样),然后就发现瑞星监控中心已经退出了,手动启动也不行,重启之后仍然无法启动(不仅不会开机自动启动,手动也不行)!但是瑞星杀毒软件可以打开,杀毒缺没有任何病毒(7月19号更新),在安全模式下杀毒也一样没有病毒。
使用瑞星听诊器,生成的听诊信息内容如下:
未知家族病毒分析
扫描结果:
C:\WINDOWS\WINLOGON.EXE --> 与 Trojan.PSW.LMir 80%相似.
系统活动进程
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SYSTEM32\HCCUTILS.DLL
C:\WINDOWS\SYSTEM32\IGFXDEV.DLL
C:\WINDOWS\SYSTEM32\IGFXSRVC.DLL
C:\WINDOWS\SYSTEM32\IGFXHK.DLL
C:\WINDOWS\SYSTEM32\IGFXRES.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\THUNDER\PROGRAM\THUNDER5.EXE
C:\PROGRAM FILES\THUNDER\PROGRAM\UPDATEDOWNLOAD.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\LOG4CPLUS.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\STLPORT_VC646.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\ASYN_DNS.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\MSGMANAGE.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\HISTORYINFO_MANAGE.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\REGISTERDLL.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\FLOATBAR.DLL
C:\PROGRAM FILES\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
C:\PROGRAM FILES\THUNDER\COMPONENTS\INMEDIA\IEMBED.DLL
C:\PROGRAM FILES\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\THUNDER\PROGRAM\ITARGETAD.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSVBVM50.DLL
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\DOCUME~1\EVILVI~1\LOCALS~1\APPLIC~1\1C2492D\1.DLL
C:\DOCUME~1\EVILVI~1\LOCALS~1\APPLIC~1\1C2492D\3.DLL
C:\DOCUME~1\EVILVI~1\LOCALS~1\APPLIC~1\1C2492D\4.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V8.DLL
C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\WINDOWS\SYSTEM\B66O3370.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\DOCUMENTS AND SETTINGS\EVILVISTA\桌面\RSDETECT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\B66D3370.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
C:\PROGRAM FILES\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
IgfxTray = C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
HotKeysCmds = C:\WINDOWS\SYSTEM32\HKCMD.EXE
SoundMan = SOUNDMAN.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
Torjan Program = C:\WINDOWS\WINLOGON.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
bgswitch = C:\WINDOWS\SYSTEM32\BGSWITCH.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
D:\Autorun.inf
AUTORUN = D:\pagefile.pif
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe 1
SCRNSAVE.EXE = C:\WINDOWS\system32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
igfxcui = IGFXSRVC.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE 1
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{0005A87D-D626-4B3A-84F9-1D9571695F55} = C:\WINDOWS\system32\xunleibho_v8.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{259F616C-A300-44F5-B04A-ED001A26C85C} = NULL
{889D2FEB-5411-4565-8998-1DD2C5261283} = C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll
{F2E37336-BFDB-409B-8D0E-6F013C438B20} = C:\WINDOWS\system\b66o3370.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{2D4F823A-0E56-4AD4-AEE6-15A06037D948}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{2D4F823A-0E