瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】卡卡版2.0.0.2和HiJackThisV1.99.1版的为何结果差别大?

1   1  /  1  页   跳转

【求助】卡卡版2.0.0.2和HiJackThisV1.99.1版的为何结果差别大?

【求助】卡卡版2.0.0.2和HiJackThisV1.99.1版的为何结果差别大?

请楼主给分析下问题和解决方法,急盼.


Logfile of Kaka v2. 0. 0. 2 Scan Module v2. 0. 0. 1
Scan saved at 12:58:02, on 2005-12-08
Platform: Microsoft Windows 98 SE
MSIE: Internet Explorer v6.00 SP1;Q832894;Q330994;Q313829;Q837009;Q831167;Q823353;Q867801;Q833989;Q834707;Q889293;Q890923;Q891781;Q883939;Q903235;Q896727;Q896688; (6.00.2800.1106)


Running processes:
[KERNEL32.DLL]
CommandLine =

[MSGSRV32.EXE]
CommandLine =

[MPREXE.EXE]
CommandLine = C:\WINDOWS\SYSTEM\MPREXE.EXE

[RAVMON.EXE]
CommandLine = C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM

[CCENTER.EXE]
CommandLine = C:\PROGRA~1\RISING\RAV\CCENTER.EXE

[RAVMOND.EXE]
CommandLine = C:\PROGRA~1\RISING\RAV\RAVMOND.EXE

[mmtask.tsk]
CommandLine =

[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.exe

[RPCSS.EXE]
CommandLine = RPCSS

[CTFMON.EXE]
CommandLine = "C:\WINDOWS\SYSTEM\ctfmon.exe"

[RFWMAIN.EXE]
CommandLine = "C:\Program Files\rising\rfw\rfwmain.exe"

[RFWSRV.EXE]
CommandLine = "C:\PROGRAM FILES\RISING\RFW\rfwsrv.exe" -start

[SPOOL32.EXE]
CommandLine = C:\WINDOWS\SYSTEM\spool32.exe

[WINWORD.EXE]
CommandLine = "C:\Program Files\Microsoft Office\Office10\WINWORD.EXE"

[IEXPLORE.EXE]
CommandLine = "C:\PROGRA~1\INTERN~1\iexplore.exe"

[DDHELP.EXE]
CommandLine = ddhelp.exe

[KKSCAN.EXE]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\SYSTEM\KAKATOOL.DLL
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\RunServices: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\RunServices: [RsCcenter] C:\PROGRA~1\RISING\RAV\CCENTER.EXE
O4 - HKLM\..\RunServices: [RavMond] C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
O9 - Extra Button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra Button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINDOWS\SYSTEM\dajava.cab
O16 - DPF: Internet Explorer Classes for Java - file://C:\WINDOWS\SYSTEM\iejava.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP:  NameServer = 202.102.134.68,202.102.152.3
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM\ITSS.DLL
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\SYSTEM\INETCOMM.DLL
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM\ITSS.DLL
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL



HijackThis_815汉化版扫描日志 V1.99.1
保存于      16:45:13, 日期 05-12-8
操作系统:  Windows 98 SE (Win9x 4.10.2222A)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\CTFMON.EXE
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\PROGRAM FILES\RISING\RAV\RSAGENT.EXE
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\RISING\KAKATOOLBAR\KKSCAN.EXE
D:\KAKA2005\HIJACKTHIS1991ZWW.EXE

O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\SYSTEM\KAKATOOL.DLL
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\RunServices: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\RunServices: [RsCcenter] C:\PROGRA~1\RISING\RAV\CCENTER.EXE
O4 - 启动项HKLM\\RunServices: [RavMond] C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.102.134.68,202.102.152.3

最后编辑2005-12-10 22:42:09
分享到:
gototop
 

谢谢飞跃迷离版主:

哪些O18项有问题,俺好下手;
HiJackThis1.99.1里O14项和O16项也没有,是否有BUG?
gototop
 

感谢魔头,只是菜鸟不理解,能多些笔墨或提供一些参考文章吗.
gototop
 

收到花版主的参考,有入段感觉,非常感谢!

问题来了:
1.HiJacThiS的"设置"里IE内容不是想要的,(之前注册表下修改了默认主页的键值为HTTP://WWW.Microsoft.com/China/,使桌面上IE图标的属性下"使用默认页"恢复正常,但日志扫描的IE与O14项基本相同),如何修?
2.3721早已卸载且注册表也清理,WIN9X自带搜索没有发现Rundll32.exe,可"自启动列表"文件却露出尾巴,请支招.
3.所有文件均不隐藏,"自启动列表"文件却还有,可疑,咋办?

附自启动列表

启动项报告:      05-12-9, 11:22:26
启动项扫描器版本: 1.52.2
开始于:      D:\KAKA2005\HIJACKTHIS1991ZWW.EXE
系统检测:    Windows 98 SE (Win9x 4.10.2222A)
系统检测:    Internet Explorer v6.00 SP1 (6.00.2800.1106)
* 使用默认选项             
* 选择“列出主要的部分(标准)”方式               
==================================================

当前运行的进程:         

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
D:\KAKA2005\HIJACKTHIS1991ZWW.EXE

--------------------------------------------------

注册表中的启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

RavMon = C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM

--------------------------------------------------

注册表中的启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

RavMon = C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
RsCcenter = C:\PROGRA~1\RISING\RAV\CCENTER.EXE
RavMond = C:\PROGRA~1\RISING\RAV\RAVMOND.EXE

--------------------------------------------------

文件打开方式关联 for    .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(黙认) =  system\notepad.exe %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {89820200-ECBD-11cf-8B85-00AA005B4383}

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[{88899C21-D2E2-455f-9E89-17F3C3E7362A}] *
StubPath = C:\WINDOWS\RunDll32.exe C:\WINDOWS\SYSTEM\RONVIDIAT.DLL,EntryPoint

[{88899C22-D2E2-455f-9E89-17F3C3E7362A}] *
StubPath = C:\WINDOWS\RunDll32.exe C:\WINDOWS\SYSTEM\NVWRSKOS.DLL,EntryPoint

[{44BBA851-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exeadvpack.dll

--------------------------------------------------

外壳扩展和屏幕保护程序的键值  从            C:\WINDOWS\SYSTEM.INI:

Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 5/12/2005, 9:36:56)

[rename]
NUL=C:\WINDOWS\DOWNLO~1\CNSHOOK.DLL
NUL=C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
NUL=C:\WINDOWS\DOWNLO~1\CNSMINIO.DLL
NUL=C:\WINDOWS\DOWNLO~1\CNSIO.DLL
DIRNUL=C:\WINDOWS\DOWNLOADED PROGRAM FILES\3721

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET BLASTER=A220 I7 D1 H7 P330 T6
SET SBPCI=C:\SBPCI
PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
PATH=C:\WINDOWS;C:\WINDOWS\COMMAND;%PATH%
SET PATH=%PATH%;C:\PROGRA~1\COMMON~1\AUTODE~1

--------------------------------------------------

C:\CONFIG.SYS listing:

DEVICE=C:\WINDOWS\HIMEM.SYS
DEVICE=C:\WINDOWS\EMM386.EXE

--------------------------------------------------

C:\WINDOWS\DOSSTART.BAT listing:

C:\SBPCI\SBINIT

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

列举“计划任务”服务:                   

启用 Application Start.job
Windows 重要更新通知.job

--------------------------------------------------

列举下载的程序文件:                       

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8.OCX
CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab

--------------------------------------------------

列举 ShellServiceObjectDelayLoad 项目:           

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL

--------------------------------------------------
报告完毕,共 5,568 字节         
报告生成用时:0.175秒     

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full    - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only



gototop
 

魔教主,您好:

问题1.是那么改的,但HiJackThis扫描为
about:blank
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

问题2.昨天在坛里看到"Rundll32.exe是3721和百度的自启动程序",菜鸟相信.

问题3.自启动列表中有HIDDEN!(已经不隐藏了,怎么?)
Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden


gototop
 

教主,先谢了!

2.是否有捆绑;
3.有后门吗?

拜托教主传授点功夫,俺好羡慕.
gototop
 

谢谢版主:

有点不明白,"图解HijackThis的使用说明---之中文教程(二)"中把日志"O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe "作为有恶意的例子,真假?
gototop
 

请版主明示那些虫虫或相关文献,菜鸟爱钻牛角,得罪之处多多包涵呀.
gototop
 

收藏,感谢!

再多一事:日志里的"O16"项不在风之咏者版主介绍的"无Class ID"之列,能详解一下好吗?
gototop
 

谢谢版主:

日志里的O18项特别多,这种现象是否WIN98系统相对WIN2000/XP要多,有关"协议"方面请多多指指路.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT