04-03/encounters rookit/ynqcq. sys, wswci. dll, xexq. dll, Baidu. dll, and other advertising programs/Version 2

Source: Internet
Author: User

EndurerOriginal
2Added kasersky's response to some suspicious files.
1Version

Two days ago, a report from a netizen's computer reported thatRootkit. Agent. VaThe file name is ynqcq. sys, but it cannot be cleared. Another Trojan Scan software is used to find an advertisement program. It cannot be cleared because it is not registered.

Rising's pre-Logon scan was good at dealing with Rootkit, but unfortunately this user used Windows to automatically log on ......

You can use pe_xscan to scan logs and find the following suspicious items (with the Analysis page, the efficiency is improved a lot ):
/---
Pe_xscan 07-03-17 by Purple endurer
2007-3-29 15:17:54
Windows XP Service Pack 2 (5.1.2600)
Administrator user group

C:/Windows/system32/svchost.exe * 916 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/progra ~ 1/common ~ 1/lgqmidb. dll | 2, 8, 0, 1 | 2, 8, 0, 1 |

C:/Windows/explorer. EXE * 1260 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/wswci. dll

C:/Windows/system32/rundll32.exe * 164 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe

C:/progra ~ 1/nund/xexq. dll | 14:58:29 | ADDM | 4, 1, 0, 4 | ADDM | copyright? 2006 | 4, 1, 0, 4 | ADDM | addm.exe

C:/progra ~ 1/nund/cjcv. dll | 14:58:29 | stdvote | 1, 0, 0, 6 | stdvote | copyright? 2006 | 1, 0, 0, 6 | stdvote. dll

C:/Windows/system32/zlglfef.exe * 2068 |
C:/Windows/system32/zlglfef.exe |

O4-HKLM/../policies/Explorer/run: [sys41] C:/program files/common files/d1216.exe
O4-HKLM/../policies/Explorer/run: [sys42] C:/Documents and Settings/NetworkService/Local Settings/history/d16704.exe
O4-Global startup: sys41.lnk-> C:/program files/common files/d1216.exe
O4-Global startup: sys42.lnk->

O6-hkcu/software/policies/Microsoft/Internet Explorer/restrictions the existence of IE or Internet options may be limited
The existence of IE or Internet Options in o6-hkcu/software/policies/Microsoft/Internet Explorer/control panel may be limited

O23-service: dump_wmimmc (dump_wmimmc)-C:/Windows/system32/Drivers/dump_wmimmc.sys (manual)

O23-service: fgqmcb ()-C:/Windows/system32/svchost.exe-K netsvcs-> C:/progra ~ 1/common ~ 1/lgqmidb. dll | 2, 8, 0, 1 | 2, 8, 0, 1 | (automatic)

O23-service: ndcia (ndcia)-C:/Windows/system32/Drivers/ndcia. sys (automatic)

O23-service: NPF (netgroup Packet Filter)-system32/Drivers/NPF. sys | NPF driver | 3, 0, 0, 18 | NPF driver-tme extensions | copyright? 2003 | 3, 0, 0, 18 | Politecnico di Torino | NPF + tme | NPF. RC (manual)

O23-service: npkcrypt (npkcrypt)-C:/Windows/system32/qqedit/npkcrypt. sys | 18:17:18 | nprotect keycrypt driver | 4. 0. 0. 0 | nprotect keycrypt driver | copyright (c) Inca Internet. 2000-2005 | 2005. 6. 22. 1 | Inca Internet Co ., ltd. |? | Npkcrypt. sys | npkcrypt. sys (automatic)

O23-service: npptnt2 (npptnt2)-C:/Windows/system32/npptnt2.sys | nprotect NPSC Kernel Mode Driver for NT | 2005, 1, 5, 1 | nprotect NPSC Kernel Mode Driver for NT | copyright? 2000-2005 Inca Internet | 2005, 1, 5, 1 | Inca Internet Co., Ltd. | nprotect | npptnt2 | npptnt2.sys (manual)

O23-service: pxxzqo84 (pxxzqo84)-system32/Drivers/pxxzqo84.sys (disabled)

O23-service: romman (romman)-C:/Windows/system32/Drivers/romman. sys (automatic)

O23-service: stdio (stdio)-C:/Windows/system32/Drivers/stdio. sys | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | stdio manager library | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Stdio. dll | stdio. dll (automatic) the value of Kaspersky isTrojan. win32.agent. AFB

O23-service: vssl (STD vssl Service)-C:/Windows/system32/rundll32.exe C:/progra ~ 1/nund/xexq. dll, service-s (automatic)

O23-service: ynqcq (ynqcq)-system32/Drivers/ynqcq. sys (pilot)
---/

Download Dr. Web cureitscan and clear only malicious files opened by D such as d1216.exe.
Use icesword to forcibly Delete ynqcq. sys, stdio. sys, and its service items in the registry.
Stdio. sys is relatively good. After the name is changed, it is automatically restored to its original name. The service items in the registry cannot be deleted in regedit.

Another ox file is C:/Windows/system32/wswci. dll, and Kaspersky reportsTrojan-Downloader.Win32.Agent.bbbWindows does not recognize the existence of this file, and the file time cannot be obtained. Fortunately, I copied one with icesword, passed it back, and deleted it forcibly. I used icesword to unmount it from the memory, but it would be better to remotely use icesword ......

Some suspicious files were found in C:/Windows/system32: realsled.exe (Kaspersky reportedNot-a-virus: adware. win32.agent. BSWhen _ ao1.exe (Kaspersky reportsTrojan-Downloader.Win32.Agent.bld), Baidu. dll, ntdl1.dll (Kaspersky reportedNot-a-virus: adware. win32.agent. BS.

Use hijackthis to fix the issue. Among them, O4-HKLM/../policies/Explorer/run cannot be fixed by hijackthis 1.99.1 and can be canceled by the Security Assistant of rising star Kaka.

C:/progra ~ 1/common ~ 1/lgqmidb, C:/progra ~ 1/nund: the stuff in these two folders is suspicious.

C:/progra ~ 1/nund/xexq.dll's internal name is addm.exe, AD download and Manager (AD Download Manager )?
C:/progra ~ 1/nund/cjcv. dll is named stdvote. dll, which is the same as a file in stdstub ......

The netizens said that the system was backed up and not processed ......

As a result, after restarting the computer, the trojan Scan software still reported that the advertisement program was found ...... Let netizens use icesword to delete these two folders ......
 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.