瑞星卡卡安全论坛
eein - 2006-4-10 2:23:00
网络监控 发现这个!我该怎么处理!谢谢!
(以下为监控内容!)
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/hyjl.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
不言放弃 - 2006-4-10 8:51:00
【回复“eein”的帖子】
hyjl.exe倒像是还原精灵的程序
eein - 2006-4-10 11:12:00
可是有时是这样的:
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/mir2.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
或是:
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/Hgz.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
而且 在系统服务中莫名的添加了Hgz服务项(服务已经手动清除),但是 依旧会在访问网络的时候 有explorer访问网络 而且 捆绑主页为www.zhwe.com .
在系统中Tem目录下生成Hgz.exe(或mir2.exe) 然后转变为hyjl.exe文件,直到文件重www.zhwe.com/hyjl.exe(压缩文件)下载完毕后,解压在系统目录下生成 pj.exe等几个文件,自动运行进程名为pj.exe,文件运行的状态为在活动图标栏添加名为"还原精灵"的程序,通过手动结束进程,并把所解压的文件删除后, 问题循环.
eein - 2006-4-10 11:47:00
怎么沉的好快啊!
不言放弃 - 2006-4-10 12:43:00
【回复“eein”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
eein - 2006-4-11 0:02:00
System Repair Engineer 2.0.12.350
可以道日志么?
我用Hijackthis,的日志为:
Logfile of HijackThis v1.99.1
Scan saved at 23:59:44, on 2006-4-10
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\WINDOWS\system32\ctfmon.exe
D:\ApplTools\Kingsoft\Powerword 2003\Xdict.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\SystTools\HiJackThis\HijackThis.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [iparmor] C:\Program Files\Iparmor\Iparmor.exe mini
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\ChatTools\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - D:\DownTools\KuGoo2\KuGoo3DownX.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\DownTools\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\DownTools\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\ChatTools\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\ChatTools\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\ChatTools\Tencent\QQ\SendMMS.htm
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: apihookdll.dll
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\AutoTools\Matlab\webserver\bin\win32\matlabserver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
其实我很想知道,怎么样才能使我的explorer.exe不和 www.zhwe.com捆绑?不太清楚其注入explorer.exe的线程.
谢谢了!
eein - 2006-4-11 13:17:00
点击率到是不少,怎么没有人回帖啊!
我真的不大希望我的电脑老和HK的捆在一起!
顶一下!!!!
不言放弃 - 2006-4-11 13:36:00
【回复“eein”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
eein - 2006-4-11 21:39:00
2006-04-11,21:36:30
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows Server 2003 Enterprise Edition - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<iparmor><C:\Program Files\Iparmor\Iparmor.exe mini>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
服务
[MATLAB Server / matlabserver]
<D:\AutoTools\Matlab\webserver\bin\win32\matlabserver.exe><N/A>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[Java Plug-in 1.4.2]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll, JavaSoft / Sun Microsystems, Inc.>
[Java Plug-in 1.4.0]
{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.0\bin\npjpi140.dll, JavaSoft / Sun Microsystems, Inc.>
[Java Plug-in 1.4.2]
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll, JavaSoft / Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<D:\ChatTools\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\DownTools\KuGoo2\KuGoo3DownX.htm, N/A>
[使用网际快车下载]
<D:\DownTools\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\DownTools\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<D:\ChatTools\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\ChatTools\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\ChatTools\Tencent\QQ\SendMMS.htm, N/A>
==================================
eein - 2006-4-11 21:40:00
正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 508][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 816][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 860][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 872][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1044][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1096][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1204][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1224][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1356][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 1424][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 1436][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1484][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 30>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[c:\program files\rising\rfw\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1708][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1920][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1964][C:\WINDOWS\system32\msdtc.exe] <Microsoft Corporation><2001.12.4720.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 212][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[PID: 196][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 340][C:\WINDOWS\system32\inetsrv\inetinfo.exe] <Microsoft Corporation><6.0.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 372][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] <Microsoft Corporation><7.10.3077>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 420][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 524][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 576][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 624][C:\WINDOWS\system32\Dfssvc.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 756][C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\mssearch.exe] <Microsoft Corporation><9.107.5512.0>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1288][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1812][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\InfoMz.Ime] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\WINDOWS\system32\nvcpl.dll] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\nvshell.dll] <NVIDIA Corporation><6.14.10.10035>
[PID: 2144][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
eein - 2006-4-11 21:43:00
正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 508][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 816][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 860][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 872][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1044][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1096][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1204][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1224][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1356][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 1424][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 1436][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1484][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 30>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[c:\program files\rising\rfw\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1708][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1920][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1964][C:\WINDOWS\system32\msdtc.exe] <Microsoft Corporation><2001.12.4720.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 212][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[PID: 196][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 340][C:\WINDOWS\system32\inetsrv\inetinfo.exe] <Microsoft Corporation><6.0.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 372][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] <Microsoft Corporation><7.10.3077>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
eein - 2006-4-11 21:44:00
[PID: 420][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 524][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 576][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 624][C:\WINDOWS\system32\Dfssvc.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 756][C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\mssearch.exe] <Microsoft Corporation><9.107.5512.0>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1288][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\System32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1812][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\InfoMz.Ime] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\WINDOWS\system32\nvcpl.dll] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\nvshell.dll] <NVIDIA Corporation><6.14.10.10035>
[PID: 2144][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
eein - 2006-4-11 21:44:00
[PID: 2272][C:\WINDOWS\system32\RUNDLL32.EXE] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\NvMcTray.dll] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.7184>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[PID: 2304][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[PID: 2316][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 2332][C:\Program Files\Iparmor\Iparmor.exe] <luosoft.com><5.5.0.0>
[C:\Program Files\Iparmor\getportlistxp.dll] <><1, 0, 0, 1>
[C:\Program Files\Iparmor\socketinit.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 2636][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[PID: 2840][C:\WINDOWS\system32\wbem\wmiprvse.exe] <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[PID: 3152][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.3790.0 (srv03_rtm.030324-2048)>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 496][D:\SystTools\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\WINDOWS\system32\apihookdll.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
eein - 2006-4-12 17:05:00
?????????
不言放弃 - 2006-4-12 17:14:00
【回复“eein”的帖子】
日志没有问题
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/mir2.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
或是:
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/Hgz.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
这些日志是用什么工具查出来的?
eein - 2006-4-13 13:57:00
谢谢!
这是用木马克星拦截到的!
从拦截结果,我想是Explorer被捆绑了!可是具体模块我就是找不出来!也不知道是那个!
虽然现在能用木马克星拦截Explorer的网络访问,但是Explorer就这么不停的动作也真让人难受!
对了,顺便提一下,之前Trojan在Service下建立了一个名为Hgz的Service,之后我手动的把它清除了!
再次谢谢你!
eein - 2006-4-14 1:44:00
怎么没有人继续了?
我的问题还没有解决呢!
谢谢!
eein - 2006-4-15 1:11:00
怎么没有人遇到过这样的问题么???
不言放弃 - 2006-4-15 8:30:00
【回复“eein”的帖子】
之前Trojan在Service下建立了一个名为Hgz的Service?
Hgz应该就是灰鸽子
是一个远程控制工具
彻底搞定了吗?
eein - 2006-4-15 17:29:00
服务是删除了,我在注册表中做的,在服务列表中是找不到了.但是不知道还要做些什么.
谢谢了!
eein - 2006-4-16 19:38:00
没有搞定.
eein - 2006-4-17 23:00:00
fasd;lkf j;lskdfja;sdlkfja;sdlkf
怎么没有人回答了?
1
© 2000 - 2026 Rising Corp. Ltd.