瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 网络监控 发现这个!我该怎么处理!谢谢!

123   2  /  3  页   跳转

网络监控 发现这个!我该怎么处理!谢谢!

正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 508][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
[PID: 816][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 860][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 872][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1044][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1096][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1204][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1224][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1356][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 1424][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 1436][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1484][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 30>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [c:\program files\rising\rfw\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1708][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1920][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1964][C:\WINDOWS\system32\msdtc.exe]  <Microsoft Corporation><2001.12.4720.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 212][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
[PID: 196][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 340][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  <Microsoft Corporation><6.0.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 372][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  <Microsoft Corporation><7.10.3077>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
gototop
 

[PID: 420][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.7184>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 524][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 576][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 624][C:\WINDOWS\system32\Dfssvc.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 756][C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\mssearch.exe]  <Microsoft Corporation><9.107.5512.0>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1288][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\System32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1812][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\InfoMz.Ime]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.7184>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.7184>
    [C:\WINDOWS\system32\nvshell.dll]  <NVIDIA Corporation><6.14.10.10035>
[PID: 2144][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
gototop
 



[PID: 2272][C:\WINDOWS\system32\RUNDLL32.EXE]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\NvMcTray.dll]  <NVIDIA Corporation><6.14.10.7184>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.7184>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
[PID: 2304][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
[PID: 2316][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 2332][C:\Program Files\Iparmor\Iparmor.exe]  <luosoft.com><5.5.0.0>
    [C:\Program Files\Iparmor\getportlistxp.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Iparmor\socketinit.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 2636][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
[PID: 2840][C:\WINDOWS\system32\wbem\wmiprvse.exe]  <Microsoft Corporation><5.2.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
[PID: 3152][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.3790.0 (srv03_rtm.030324-2048)>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 496][D:\SystTools\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\system32\apihookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

?????????
gototop
 

【回复“eein”的帖子】
日志没有问题

Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/mir2.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
或是:
Process Name: C:\WINDOWS\Explorer.EXE
Remote Ip: 219.153.32.73
Remote Port: 80
In/Out: Out
GET /zhwe/Hgz.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
Host: www.zhwe.com
Connection: Keep-Alive
这些日志是用什么工具查出来的?
gototop
 

谢谢!

这是用木马克星拦截到的!

从拦截结果,我想是Explorer被捆绑了!可是具体模块我就是找不出来!也不知道是那个!
虽然现在能用木马克星拦截Explorer的网络访问,但是Explorer就这么不停的动作也真让人难受!
对了,顺便提一下,之前Trojan在Service下建立了一个名为Hgz的Service,之后我手动的把它清除了!

再次谢谢你!
gototop
 

怎么没有人继续了?
我的问题还没有解决呢!
谢谢!
gototop
 

怎么没有人遇到过这样的问题么???
gototop
 

【回复“eein”的帖子】
之前Trojan在Service下建立了一个名为Hgz的Service?
Hgz应该就是灰鸽子
是一个远程控制工具

彻底搞定了吗?
gototop
 

服务是删除了,我在注册表中做的,在服务列表中是找不到了.但是不知道还要做些什么.

谢谢了!
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT