EndurerOriginal
1Version
A netizen'sComputerAfter virus detection and removal, there is an error prompt before entering the desktop at startup. Allow remote maintenance via QQ.
To http://endurer.ys168.comDownloadHijackthis scan log, no exception.
Use pe_xscan to scan and discover suspicious service items:
/----
Pe_xscan by Purple endurer
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
O23-service: windhcpsvc (Windows Dhcp Service)-C:/Windows/system32 // rundll32.exe windhcp. ocx, input (automatically started)
----/
Deleted from the registry.
Three virus files are restored from the virus isolation area.
1)tian.exe
Use pecompact 2.x-> Jeremy collake shelling.
/----
File Description: D:/test/tian.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 11:34:23
Modification time: 11:34:24
Access time:
Size: 46592 bytes, 45.512 KB
MD5: 752b10c91caa7e768d11c8fcfcf5dba1
----/
Kaspersky reportsTrojan. Win32.agent. abf
RisingReportedTrojan. psw. jhonline. FBD
Scanned file: tian.exe-infected |
Tian.exe-infected by Trojan. win32.agent. abf
Statistics:
| Known viruses: |
264433 |
Updated: |
03-02-2007 |
| File size (Kb ): |
46 |
Virus bodies: |
1 |
| Files: |
1 |
Warnings: |
0 |
| Archives: |
0 |
Suspicious: |
0 |
22.16j.exe Developed using Microsoft Visual C ++ 6.0. /---- File Description: D:/test/j.exe Attribute: --- An error occurred while obtaining the file version information! Creation Time: 11:52:23 Modification time: 11:52:24 Access time: Size: 13824 bytes, 13.512 KB MD5: 1273f2e3f3252c73286862f31d1ee4c ----/ The startup Item is created in the run key of the Registry. In the rising registry monitoring Prompt window, click "allow" and "Skip" Search for the Kaspersky warning window in the title of AVP. alertdialog, and click "allow" and "Skip" Send the wm_close message to the notification window (Class Name: AVP. product_notification) of Kaspersky to end the window. Run cmdbc.exe to load cmdbc. dll Create a remote thread and inject it into the assumer.exe Process Set the hook program to get the password of the online game "Jianghu" account Kaspersky reportsTrojan-PSW.Win32.OnLineGames.es RisingTrojan. psw. Agent. iwx |
Scanned file: j.exe-infected |
J.exe-infected by Trojan-PSW.Win32.OnLineGames.es
Statistics:
| Known viruses: |
264433 |
Updated: |
03-02-2007 |
| File size (Kb ): |
14 |
Virus bodies: |
1 |
| Files: |
1 |
Warnings: |
0 |
| Archives: |
0 |
Suspicious: |
0 |
|
3) windhcp. ocx
Use pecompact v2.08-> bitsum technologies (signature by loveboom) to shell.
/----
File Description: D:/test/windhcp. ocx
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 11:28:15
Modification time: 11:28:16
Access time:
Size: 41984 bytes, 41.0 KB
MD5: 24a46bea179948ac35e66cdd885306c6
----/
Kaspersky reportsTrojan. win32.agent. abf
Rising news:Trojan. Spy. Agent. CNS
Scanned file: windhcp. ocx-infected |
Windhcp. ocx-infected by Trojan. win32.agent. abf
Statistics:
| Known viruses: |
264437 |
Updated: |
03-02-2007 |
| File size (Kb ): |
41 |
Virus bodies: |
1 |
| Files: |
1 |
Warnings: |
0 |
| Archives: |
0 |
Suspicious: |
0 |
|