这个是我在瑞星文件夹里看到的,我现在机器上打开网络连接,有两个程序(怀疑为木马)连接到远程IP,一个为伪装的IE已知是鸽子,另外一个RUNDLL32.EXE,这个在防火墙里只停留一下就看不到了,这个木马连接到的IP有好几个有日本美国的!因为本人是菜鸟所以想请教一下专家们,谢谢.本人
自启动项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Currentversion\Run
PHIME2002ASync = rem C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = rem C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
SiSUSBRG = rem C:\WINDOWS\SiSUSBrg.exe
SiS KHooker = rem C:\WINDOWS\System32\khooker.exe
snpstd3 = rem C:\WINDOWS\vsnpstd3.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
NMGameX_AutoRun = C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa
Install Alitalk = C:\WINDOWS\temp\alitalk\alitalk.exe -hideframe
RfwMain = rem "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
RavTask = "C:\Program Files\Rising\Rav\RavTask.exe" -system
YLive.exe = rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
yassistse = rem "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
CnsMin = rem Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
helper.dll = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
HKEY_CURRENT_USER Software\Microsoft\Windows\Currentversion\Run
DEVELIT = C:\WINDOWS\system32\Paykel.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shell32.dll = C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RavExt.dll= Rising Execute File Exts hook
C:\WINDOWS\system32\RavExt.dll= Rising Execute File Exts hook
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
PostBootReminder = %SystemRoot%\system32\SHELL32.dll
CDBurn = %SystemRoot%\system32\SHELL32.dll
WebCheck = %SystemRoot%\System32\webcheck.dll
SysTray = C:\WINDOWS\System32\st
object.dll
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
%SystemRoot%\System32\browseui.dll= Browseui 预加载程序
%SystemRoot%\System32\browseui.dll= 组件类别缓存程序
SYSTEM.INI BOOT SHELL Explorer.exe
其他相关项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon DefaultUserName ----> Owner
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon AltDefaultUserName ----> Owner
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit ----> C:\WINDOWS\system32\Userinit.exe,
Hosts
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
进程列表
[System Process]
System
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\Owner\桌面\RavDetect.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\WINDOWS\system32\wuauclt.exe
进程详细信息
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll
!7!7QQh
n _^][
tXHt HHuc
HtlHHt7-
>!7!7uWP
S_][^Y
St[Hua
Software\Yahoo\Assistant\
#32770
YAssistant_Live
SCEventInvoke
Action
Yalpath
HelperFunc
Assist
Yassistpath
FuncInvoke
EventInvoke
cnspath
|IEXPLORE.EXE|EXPLORER.EXE|NEO20.EXE|NEO.EXE|NP.EX
ExecFunc
regkper.dll
ylive_mutex
autolive.dll
CabinetWClass
ExploreWClass
IEFrame
Shell Doc
Object View
yscrblock.dll
mshta.exe
iexplore.exe
helperex.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
SOFTWARE\Microsoft\Internet Explorer\Toolbar
{BB936323-19FA-4521-BA29-ECA6A121BC78}
CLSID\{BB936323-19FA-4521-BA29-ECA6A121BC78}\Inpro
DllCBTProc
Button
C:\PROGRA~1\Yahoo!\ASSIST~1\
C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll
SVWh 2
VSPhT1
VWj@Y3
VWj@Y3
Ht;HHt'HHt
SVWj@3
PWVhF3
QQSVWj/
SWj@Y3
VPVVVVh$
SPSSSSh@
Yv!h,8
VWj@Y3
SVWj@3
SVWj@3
j'Ph,\
HtSHtBH
VWj@Y3
SSSAt$
u7WWj1S
uVSSSS
HtTHu@
tbHt1Hu_
FSOFTWARE\Microsoft\Code Store Database\Distributi
2.0.0.1001
1.0.2.8
2.0.0.1013
2.1.1.1039
Yaltimeisw
Yalinisw
http://cn.download.zs.yahoo.com/download/yalvsw.in
Yaltimei
Yalini
http://cn.download.zs.yahoo.com/download/yalive.in
YALive
Yalliveex
Yalliveex.dll
Yalpath
Software\Yahoo\Assistant\YALive\UserCatch
CFile2
yal03.dat
yal01.dat
YLive.exe
Yalhelper
Yhelper.dll
YAlive.dll
YAlive.inf
Yahoo!Live
Install
{57421194-58FB-49ae-9B4F-FD48869B9AD4}
YALive Class
CurVer
YALive.Live.1
YALive.Live
YNOTIFIER
YSRCBLOCK
YHELPER
YALIVE
ASSIST
Yahoo!\ASSIST~1\
Yallasttime
CheckIntegrity
CLSID\%s\InprocServer32
Software\Yahoo\Assistant
CabinetWClass
ExploreWClass
IEFrame
CLSID\{57421194-58FB-49ae-9B4F-FD48869B9AD4}\Inpro
CNSAutoUpdateMutex
Yalname
Yalinim
Yalicon
Yallastmoduletimesw
Yallasttimesw
Yallastmoduletime
Software\Yahoo\Assistant\%s
Yalreg
%s(%d):
E:\20060224B\yLive\AutoLive\AutoUpdate.cpp
WindowProp_FileScale
WindowProp_UpdatingStatus
WindowProp_UpdatingName
RunParam
Relation
NotifyFlag
Details
%[^=]=%s
Update\
%s%s%d
%s%s%s
SetModuleUpdateSucc
cn.download.zs.yahoo.com
Yalnotifytime
WindowProp_AutoLive
ObjectYaldetails
http://cn.zs.yahoo.com
.1.log
\\.\Global\CnsMinKP
\\.\CnsMinKP
\\.\CnsMinKP.Vxd
Software\Yahoo\Assistant\
Software\Microsoft\Windows\CurrentVersion\Run
Apartment
ThreadingModel
CLSID\%s
Yahoo%s%d
Yahoo%d
%[^,-],-%d
ProgramFiles
SOFTWARE\Microsoft\Windows\CurrentVersion
ProgramFilesDir
SYSTEM\CurrentControlSet\Services\CnsMinKP
SYSTEM\CurrentControlSet\Services\VxD\CnsMinKP
Global\KPSetupMutex
\cnsinfo.dat
NUL=%s
DIRNUL=%s
[rename]
wininit.ini
%d.%d.%d.%d
Software\Microsoft\Windows\CurrentVersion\RunOnce
rundll32.exe %s,%s
regsvr32 /s %s
Ynotifier.dll
1.0.0.1
Yscrblock.dll
1.0.0.2
SYSTEM\CurrentControlSet\Control\Session Manager
PendingFileRenameOperations
progra~1\Yahoo!\Assistant\%s
%sdownlo~1\%s
%sdownlo~1\
SOFTWARE\Microsoft\Internet Explorer\ActiveX Compa
{62EED7C6-9F02-42f9-B634-98E2899E147B}
{406F94F0-504F-4a40-8DFD-58B0666ABEBD}
{2283BB66-A15D-4ac8-BA72-9C8C9F5A1691}
{E3128A3A-C191-4149-8631-C632C8FC9919}
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8}
{38928D50-8A48-44C2-945F-D2F23F771410}
{59E99ADD-E926-40e8-BD6F-1532124A4AAA}
%sYahoo!\Assistant\
%sYahoo!\Assistant\%s
%s%s\%s
CLSID\{178DA2CB-5660-42f4-B2E1-2815401C5910}\Inpro
Assistant
helperex.dll
Yalvsw.ini
regkp01.dat
Ypatch*.dll
NewUp.ini
Yalive.ini
regkper.dll
SoftWare\Yahoo
COption
CStyle
SoftWare\Yahoo\Assistant
Software\Yahoo\Assistant\YALive
CLSID\{57421194-58FB-49ae-9B4F-FD48869B9AD4}
yassist.dll
Assist
yasbar.dll
Software\Yahoo\Assistant\Assist
%sUpdate\
ires.dat
QueryInfo
UpdatingText
%program%
%windows%
%system%
software\Yahoo\Assistant\%s
SeShutdownPrivilege
WndProp_Gif
ObjectWndProp_UpdateParam
software\Yahoo\Assistant
_BLANK
HTTP/1.1
CnsMin Agent
cn.zs.yahoo.com
EasyFunctionEx
software\Yahoo\Assistant\assist
assistpath
AssistantBarCtrl
about:blank
Software\Yahoo\Assistant\YALive\Yalrex
cnsminreferer
alrex=
close=
delay=
adcheck=
zorder=
toolbar=
status=
resize=
menubar=
center=
height=
width=
ActionEx
UpdateAlert
FreeGifAni
PauseGifAni
StopGifAni
PlayGifAni
SetPositionGifAni
LoadGifAni
StartActiveXCatch
SCEventInvoke
EventInvoke
Delete
NoRemove
ForceRemove
CSubClass Pointer
.?AV_com_error@@
.?AVtype_info@@
CNSAutoUpdateMutex
C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll
Service Pack 2
C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll
LiveErrorMode
ActionEx
Action
lSIST~1\Yalliveex.dll