瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【求助】本人XP系统中了ROOTKIT变种,F盘文件离奇失踪!
点挠矮子饼 - 2006-2-10 16:58:00
Logfile of Kaka v2. 0. 0. 7 Scan Module v2. 0. 0. 1
Scan saved at 16:53:41, on 2006-02-10
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"

[rfwProxy.exe]
CommandLine = "c:\program files\rising\rfw\rfwproxy.exe"

[rfwsrv.exe]
CommandLine = "c:\program files\rising\rfw\rfwsrv.exe"

[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE

[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"

[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[rfwmain.exe]
CommandLine =  -StartUp

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: IEHandle Class - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - C:\Program Files\Common Files\Collegesoft\Share Components\TPHANDLE.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O5 - control.ini: inetcpl.cpl=no
O8 - Extra context menu item: 上传到QQ网络硬盘 -
O8 - Extra context menu item: 查看Internet星号密码 - C:\Program Files\Internet Explorer\passward.htm
O8 - Extra context menu item: 添加到QQ自定义面板 -
O8 - Extra context menu item: 添加到QQ表情 -
O8 - Extra context menu item: 用QQ彩信发送该图片 -
O9 - Extra Button: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O9 - Extra 'Tools' menuitem: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138094982500
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E65B597-2360-4E31-BE3F-02974A3D1B00}: NameServer = 219.150.32.132,202.102.152.3,219.146.0.130
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
怀疑的文件:


附件: 6502122006210165836.PNG
BlackStone - 2006-2-10 17:13:00
用IceSword工具试试
http://forum.ikaka.com/topic.asp?board=28&artid=7538008
点挠矮子饼 - 2006-2-10 17:33:00
好几个文件被感染了
不止IEXPLORER

附件: 6502122006210173344.PNG
BlackStone - 2006-2-10 17:38:00
用icesword能看到F:\文件不
点挠矮子饼 - 2006-2-10 17:47:00
正解,本人XP系统该怎样修复?
BlackStone - 2006-2-10 18:03:00
首先看看用icesword能不能看到文件,若能看看有没有驱动保护文件
点挠矮子饼 - 2006-2-10 18:07:00
一开始有一个
结果扫出来个CMD碎片
CMD.EXE-087B4001.pf
点挠矮子饼 - 2006-2-10 18:08:00
看不到驱动保护文件啊
点挠矮子饼 - 2006-2-10 18:10:00
svchost.exe有没有可能被插入了?
BlackStone - 2006-2-10 18:16:00
注意看贴
用IceSword工具的文件浏览看看能否看到F盘的隐藏文件
点挠矮子饼 - 2006-2-10 18:22:00
看不到啊,关键是我把那些隐藏的文件夹删了。后悔啊!
BlackStone - 2006-2-10 18:23:00
Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
点挠矮子饼 - 2006-2-10 18:45:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ WinRAR shell extensione:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IEHandle ClassIEHandler for ScenicPlayer江苏科建教育软件有限责任公司c:\program files\common files\collegesoft\share components\tphandle.dll

HKLM\System\CurrentControlSet\Services

+ RfwProxySrvRising Personal Proxy ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwproxy.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ALCXSENSSensaura WDM 3D Audio DriverSensaura Ltdc:\windows\system32\drivers\alcxsens.sys

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ FETNDISNDIS 5.0 miniport driverVIA Technologies, Inc.              c:\windows\system32\drivers\fetnd5.sys

+ FETNDISBNDIS 5.0 miniport driverVIA Technologies, Inc.              c:\windows\system32\drivers\fetnd5b.sys

+ HOOKAPIHOOKAPI Driver瑞星软件有限公司c:\program files\rising\rav\hookapi.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.e:\program files\tencent\npkcrypt.sys

+ NTSIMNetwork Device Monitor UtilityVIA Technologies, Inc.              c:\windows\system32\ntsim.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys

+ S3PsddrS3 ProSavage(DDR) & Twister Miniport DriverS3 Graphics, Inc.c:\windows\system32\drivers\s3gnbm.sys

+ S3SavageNBS3 ProSavage(DDR) & Twister Miniport DriverS3 Graphics, Inc.c:\windows\system32\drivers\s3gnbm.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ viaagp1VIA NT AGP FilterVIA Technologies, Inc.c:\windows\system32\drivers\viaagp1.sys

+ ZSMC301bVideo streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys

点挠矮子饼 - 2006-2-11 10:05:00
没人救救我吗?
拉丁的哥哥 - 2006-2-11 10:11:00
有!帅哥来啦!!!!!!!!!!
点挠矮子饼 - 2006-2-11 10:42:00
救命啊!
不言放弃 - 2006-2-11 10:44:00
引用:
【点挠矮子饼的贴子】看不到啊,关键是我把那些隐藏的文件夹删了。后悔啊!
...........................

系统盘下的文件也删除了?
点挠矮子饼 - 2006-2-11 10:48:00
没有,不过好象被人远程登陆了一样,
我明明用的是本地用户啊
怎么显示网络用护呢?
点挠矮子饼 - 2006-2-11 10:51:00
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed2006-2-11 10:4280 bytesData mismatch between Windows API and raw hive data.
用RootkitRevealer扫了半天就出来个这个东西
不言放弃 - 2006-2-11 10:51:00
【回复“点挠矮子饼”的帖子】
用户名一样吗?

实在不行
重装系统算
点挠矮子饼 - 2006-2-11 10:55:00
拥护名不一样
我明明用的是TEMPORARY
平时我很注重系统安全,可以说一个漏洞都没有。
刚刚做系统才几天。
只是因为这一个文件
心不甘啊!


附件: 6502122006211105542.PNG
点挠矮子饼 - 2006-2-11 11:00:00
这个ROOTKIT变种是从洪恩上下载的
当时求学心切,用杀软查了一变没问题。
大意了啊!
最后看防火墙老是有个没进程的访问网络。
用TcpView一查发现好几个IE进程一会蹦出来一会自动结束
老是访问别人IP的80端口
点挠矮子饼 - 2006-2-11 11:16:00
我中毒了重装也就算了,可是F盘枯计10多G的空间就变成坏道了。
不想让更多的人中毒啊!我已经向瑞星提交可疑文件了(目前任何杀毒软件都查不出来)。
病毒文件地址:
http://duxing.108.tofor.com/swinapi.sfx.exe
但愿能够通过升级彻底让此病毒消失。
这家伙比灰鸽子还难杀。
我恨死它了!
点挠矮子饼 - 2006-2-11 12:21:00
没人能救了吗?
1
查看完整版本: 【求助】本人XP系统中了ROOTKIT变种,F盘文件离奇失踪!