EndurerOriginal
2Added kasersky's response to some suspicious files.
1Version
Two days ago, a report from a netizen's computer reported thatRootkit. Agent. VaThe file name is ynqcq. sys, but it cannot be cleared. Another Trojan Scan software is used to find an advertisement program. It cannot be cleared because it is not registered.
Rising's pre-Logon scan was good at dealing with Rootkit, but unfortunately this user used Windows to automatically log on ......
You can use pe_xscan to scan logs and find the following suspicious items (with the Analysis page, the efficiency is improved a lot ):
/---
Pe_xscan 07-03-17 by Purple endurer
2007-3-29 15:17:54
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
C:/Windows/system32/svchost.exe * 916 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/progra ~ 1/common ~ 1/lgqmidb. dll | 2, 8, 0, 1 | 2, 8, 0, 1 |
C:/Windows/explorer. EXE * 1260 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/wswci. dll
C:/Windows/system32/rundll32.exe * 164 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/progra ~ 1/nund/xexq. dll | 14:58:29 | ADDM | 4, 1, 0, 4 | ADDM | copyright? 2006 | 4, 1, 0, 4 | ADDM | addm.exe
C:/progra ~ 1/nund/cjcv. dll | 14:58:29 | stdvote | 1, 0, 0, 6 | stdvote | copyright? 2006 | 1, 0, 0, 6 | stdvote. dll
C:/Windows/system32/zlglfef.exe * 2068 |
C:/Windows/system32/zlglfef.exe |
O4-HKLM/../policies/Explorer/run: [sys41] C:/program files/common files/d1216.exe
O4-HKLM/../policies/Explorer/run: [sys42] C:/Documents and Settings/NetworkService/Local Settings/history/d16704.exe
O4-Global startup: sys41.lnk-> C:/program files/common files/d1216.exe
O4-Global startup: sys42.lnk->
O6-hkcu/software/policies/Microsoft/Internet Explorer/restrictions the existence of IE or Internet options may be limited
The existence of IE or Internet Options in o6-hkcu/software/policies/Microsoft/Internet Explorer/control panel may be limited
O23-service: dump_wmimmc (dump_wmimmc)-C:/Windows/system32/Drivers/dump_wmimmc.sys (manual)
O23-service: fgqmcb ()-C:/Windows/system32/svchost.exe-K netsvcs-> C:/progra ~ 1/common ~ 1/lgqmidb. dll | 2, 8, 0, 1 | 2, 8, 0, 1 | (automatic)
O23-service: ndcia (ndcia)-C:/Windows/system32/Drivers/ndcia. sys (automatic)
O23-service: NPF (netgroup Packet Filter)-system32/Drivers/NPF. sys | NPF driver | 3, 0, 0, 18 | NPF driver-tme extensions | copyright? 2003 | 3, 0, 0, 18 | Politecnico di Torino | NPF + tme | NPF. RC (manual)
O23-service: npkcrypt (npkcrypt)-C:/Windows/system32/qqedit/npkcrypt. sys | 18:17:18 | nprotect keycrypt driver | 4. 0. 0. 0 | nprotect keycrypt driver | copyright (c) Inca Internet. 2000-2005 | 2005. 6. 22. 1 | Inca Internet Co ., ltd. |? | Npkcrypt. sys | npkcrypt. sys (automatic)
O23-service: npptnt2 (npptnt2)-C:/Windows/system32/npptnt2.sys | nprotect NPSC Kernel Mode Driver for NT | 2005, 1, 5, 1 | nprotect NPSC Kernel Mode Driver for NT | copyright? 2000-2005 Inca Internet | 2005, 1, 5, 1 | Inca Internet Co., Ltd. | nprotect | npptnt2 | npptnt2.sys (manual)
O23-service: pxxzqo84 (pxxzqo84)-system32/Drivers/pxxzqo84.sys (disabled)
O23-service: romman (romman)-C:/Windows/system32/Drivers/romman. sys (automatic)
O23-service: stdio (stdio)-C:/Windows/system32/Drivers/stdio. sys | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | stdio manager library | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Stdio. dll | stdio. dll (automatic) the value of Kaspersky isTrojan. win32.agent. AFB
O23-service: vssl (STD vssl Service)-C:/Windows/system32/rundll32.exe C:/progra ~ 1/nund/xexq. dll, service-s (automatic)
O23-service: ynqcq (ynqcq)-system32/Drivers/ynqcq. sys (pilot)
---/
Download Dr. Web cureitscan and clear only malicious files opened by D such as d1216.exe.
Use icesword to forcibly Delete ynqcq. sys, stdio. sys, and its service items in the registry.
Stdio. sys is relatively good. After the name is changed, it is automatically restored to its original name. The service items in the registry cannot be deleted in regedit.
Another ox file is C:/Windows/system32/wswci. dll, and Kaspersky reportsTrojan-Downloader.Win32.Agent.bbbWindows does not recognize the existence of this file, and the file time cannot be obtained. Fortunately, I copied one with icesword, passed it back, and deleted it forcibly. I used icesword to unmount it from the memory, but it would be better to remotely use icesword ......
Some suspicious files were found in C:/Windows/system32: realsled.exe (Kaspersky reportedNot-a-virus: adware. win32.agent. BSWhen _ ao1.exe (Kaspersky reportsTrojan-Downloader.Win32.Agent.bld), Baidu. dll, ntdl1.dll (Kaspersky reportedNot-a-virus: adware. win32.agent. BS.
Use hijackthis to fix the issue. Among them, O4-HKLM/../policies/Explorer/run cannot be fixed by hijackthis 1.99.1 and can be canceled by the Security Assistant of rising star Kaka.
C:/progra ~ 1/common ~ 1/lgqmidb, C:/progra ~ 1/nund: the stuff in these two folders is suspicious.
C:/progra ~ 1/nund/xexq.dll's internal name is addm.exe, AD download and Manager (AD Download Manager )?
C:/progra ~ 1/nund/cjcv. dll is named stdvote. dll, which is the same as a file in stdstub ......
The netizens said that the system was backed up and not processed ......
As a result, after restarting the computer, the trojan Scan software still reported that the advertisement program was found ...... Let netizens use icesword to delete these two folders ......