未知家族病毒分析
扫描结果:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\118.exe --> 与 Trojan.PSW.WoWar 46%相似.
系统活动进程
D:\RSDETECT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CMD.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\PNKBSTRB.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\HPZLL4PI.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\HPZPP4PI.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RSV10.TMP
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\THUNDER\PROGRAM\THUNDER5.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
D:\THUNDER\PROGRAM\TASKMANAGER.DLL
D:\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
D:\THUNDER\PROGRAM\STLPORT_VC646.DLL
D:\THUNDER\PROGRAM\ASYN_DNS.DLL
D:\THUNDER\PROGRAM\ITARGETAD.DLL
D:\THUNDER\PROGRAM\BHOSTUB.DLL
D:\THUNDER\PROGRAM\FLOATBAR.DLL
D:\THUNDER\COMPONENTS\DOWNANDPLAY\DOWNANDPLAY.DLL
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9C.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
D:\THUNDER\COMPONENTS\INMEDIA\IEMBED10.DLL
D:\THUNDER\COMPONENTS\COMMUNITY\XLCOMMUNITY.DLL
D:\THUNDER\PROGRAM\REGISTERDLL.DLL
D:\THUNDER\PROGRAM\MSVCIRT.DLL
D:\THUNDER\COMPONENTS\SECURITY\THUNDERSAFE.DLL
D:\THUNDER\PROGRAM\XLNET.DLL
D:\THUNDER\COMPONENTS\SEARCH\XLSEARCH.DLL
D:\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
D:\THUNDER\PROGRAM\LIVEUPDATE.DLL
D:\THUNDER\PLUGINS\BHOADV\BHO_ADV.DLL
D:\THUNDER\COMPONENTS\DOWNLOADSTAT\DOWNLOADSTAT.DLL
D:\THUNDER\COMPONENTS\EXPLORERHELPER\EXPLORERHELPER.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
D:\THUNDER\COMPONENTS\DOWNANDPLAY\DAPPLAYER_NOW.DLL
D:\THUNDER\COMPONENTS\TIPS\TIPSCLIENT.DLL
D:\THUNDER\COMPONENTS\VPSHELL\VPSHELL.DLL
D:\THUNDER\COMPONENTS\VPSHELL\VIDEOPICTURE.DLL
D:\THUNDER\COMPONENTS\USEREXPERIENCE\USEREXPERIENCE.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DSXLCOM.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
D:\THUNDER\COMPONENTS\RESWORKER\MEDIAWORKER.DLL
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\SHLHOOK.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\SYSTEM6.INS
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.WIN
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\WINDOWS\RICHDLL.DLL
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
D:\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\LOGO1_.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\RUNIEP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\118.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\WINSYS64.SYS
D:\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
D:\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\RISING\KAKATOOLBAR\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE32.SYS
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9C.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL
C:\WINDOWS\RICHDLL.DLL
普通自启动项
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
E:\Autorun.inf
AUTORUN = AutoRun.exe
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\JOGABO~1.SCR