我的C盘根目录出现一个名字为1的未知文件大小126,976 字节 可以更改文件的名字和扩展名 但就是无法删除 在DOS下也无法删除 我装了全套瑞星 在DOS下没有发现病毒 用UNlocker也无法删除 谁能帮我看下有问题没
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
D:\TENCENT\QQ\TIMPLATFORM.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\TENCENT\QQ\TIMPROXY.DLL
D:\TENCENT\QQ\QQ.EXE
D:\TENCENT\QQ\QQBASECLASSINDLL.DLL
D:\TENCENT\QQ\QQHELPERDLL.DLL
D:\TENCENT\QQ\BASICCTRLDLL.DLL
D:\TENCENT\QQ\MFC42.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
D:\TENCENT\QQ\RICHED32.DLL
D:\TENCENT\QQ\RICHED20.DLL
D:\TENCENT\QQ\QQAPI.DLL
D:\TENCENT\QQ\TIMPROXY.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\TENCENT\QQ\LOGINCTRL.DLL
D:\TENCENT\QQ\NPKCNTC.DLL
D:\TENCENT\QQ\NPKPDB.DLL
D:\TENCENT\QQ\QQRES.DLL
D:\TENCENT\QQ\QQMAINFRAME.DLL
D:\TENCENT\QQ\CQQAPPLICATION.DLL
D:\TENCENT\QQ\NEWSKIN.DLL
D:\TENCENT\QQ\HOSTINGMGR.DLL
D:\TENCENT\QQ\CAMERADLL.DLL
D:\TENCENT\QQ\MAILSUMMARY.DLL
D:\TENCENT\QQ\QQKNOWLEDGESEARCH.DLL
D:\TENCENT\QQ\QQALLINONE.DLL
D:\TENCENT\QQ\GROUPLIVE.DLL
D:\TENCENT\QQ\SCCORE.DLL
D:\TENCENT\QQ\GDIPLUS.DLL
D:\TENCENT\QQ\QQSPACE.DLL
D:\TENCENT\QQ\VBSCRIPT.DLL
D:\TENCENT\QQ\QQGROUPMNG.DLL
D:\TENCENT\QQ\QQSETTINGCTRL.DLL
D:\TENCENT\QQ\QQSYSMSGMNG.DLL
D:\TENCENT\QQ\USERDEFINEDHEAD.DLL
D:\TENCENT\QQ\QQPLUGIN.DLL
D:\TENCENT\QQ\QQCONFIGPLUGIN.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\TENCENT\QQ\QRINGMNG.DLL
D:\TENCENT\QQ\LONGCONNECTION.DLL
D:\TENCENT\QQ\QQAVATAR.DLL
D:\TENCENT\QQ\FLASHAVATARDLL.DLL
D:\TENCENT\QQ\QQPET.DLL
D:\TENCENT\QQ\PHONEAPI.DLL
D:\TENCENT\QQ\DIALERALLINONE.DLL
D:\TENCENT\QQ\BQQAPPLICATION.DLL
D:\TENCENT\QQ\COMMERCESMNG.DLL
D:\TENCENT\QQ\PERSONALDESKTOP.DLL
D:\TENCENT\QQ\QQADDR.DLL
D:\TENCENT\QQ\QQSCENEMNG.DLL
D:\TENCENT\QQ\QQPHONEHELPER.DLL
D:\TENCENT\QQ\QQCUSTOMFACE.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSADP32.ACM
D:\TENCENT\QQ\QQMAGICFACE.DLL
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WINLIB .DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\APPPATCH\ACADPROC.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\WINDOWS\SYSTEM32\WPDSHSERVICEOBJ.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\PORTABLEDEVICETYPES.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\TBPANELEXT.DLL
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
D:\UNLOCKER\UNLOCKERCOM.DLL
D:\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\ANTIARP STAND-ALONE EDITION\ANTIARP.EXE
D:\ANTIARP STAND-ALONE EDITION\XANTIARP.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEP_CTRL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\MICROS~1\WCESCOMM.EXE
C:\WINDOWS\SYSTEM32\CEUTIL.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\RAPI.DLL
D:\MICROS~1\TCP2UDP.DLL
D:\MICROSOFT ACTIVESYNC\RAPIPROXYSTUB.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\MICROS~1\DTPTDNS.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\MICROS~1\RAPIMGR.EXE
C:\WINDOWS\SYSTEM32\CEUTIL.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
D:\MICROS~1\MSVCP71.DLL
D:\MICROSOFT ACTIVESYNC\RAPIPROXYSTUB.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\RSDETECT.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\WINDOWS\SYSTEM32\IEUI.DLL
C:\WINDOWS\SYSTEM32\XMLLITE.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEPROXY.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IEAPFLTR.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
G:\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_006.DLL
G:\THUNDER NETWORK\THUNDER\COMDLLS\THUNDERAGENT_005.DLL
D:\浩方对战平台\GAMECLIENT.EXE
D:\浩方对战平台\GAMESHELL.DLL
D:\浩方对战平台\PROXY.DLL
D:\浩方对战平台\MFC42.DLL
D:\浩方对战平台\METEORCHECK.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
D:\浩方对战平台\COMCTRLLIB.DLL
D:\浩方对战平台\SKINPLUSPLUSDLL.DLL
D:\浩方对战平台\MSVCP60.DLL
D:\浩方对战平台\GAMEDATA.DLL
D:\浩方对战平台\USERAVATAR.DLL
D:\浩方对战平台\ISHOWSOCKET.DLL
D:\浩方对战平台\IMUIDLL.DLL
D:\浩方对战平台\IMBASE.DLL
D:\浩方对战平台\IMRES.DLL
D:\浩方对战平台\GAMERES.DLL
D:\浩方对战平台\RICHED32.DLL
D:\浩方对战平台\RICHED20.DLL
D:\浩方对战平台\ADSMANAGER.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\浩方对战平台\FNSOCKET.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\WINDOWS\SYSTEM32\IEUI.DLL
C:\WINDOWS\SYSTEM32\XMLLITE.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEPROXY.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IEAPFLTR.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\IDNDL.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
NVMixerTray = "C:\PROGRAM FILES\NVIDIA CORPORATION\NVMIXER\NVMIXERTRAY.EXE"
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
nwiz = NWIZ.EXE /INSTALL
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
Gainward = C:\WINDOWS\TBPANEL.EXE /A
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
AntiARPStandalone = D:\ANTIARP STAND-ALONE EDITION\ANTIARP.EXE
runeip = C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
H/PC Connection Agent = "D:\MICROS~1\WCESCOMM.EXE"