Auto.exe/backdoor. win32.agent. bgu, b8u6bvx912. sys/Trojan-Downloader.Win32.Hmir.don, etc. 2

Source: Internet
Author: User

Auto.exe/backdoor. win32.agent. bgu, b8u6bvx912. sys/Trojan-Downloader.Win32.Hmir.don, etc. 2

Original endurer 2008-06-30 1st

Download fileinfo and bat_do to the http://purpleendurer.ys168.com.

Use fileinfo to extract the information of the red files in the pe_xscan log. Use bat_do to package the backup, delete the files in a delayed manner, change the selected file name, and delete the files in a delayed manner.

Download and install the rising Kaka Security Assistant, switch to [advanced functions]-> [IE and system repair], repair o29, and hkcu-start page = hxxp: // www.258central.cn/and HKLM/showall values are not 1

Switch to [advanced functions]-> [plug-in management and uninstallation] to uninstall the O2 and O3 items.

Switch to [advanced functions]-> [system startup Item Management]

Click [logon items] on the left, find the items F2 and O4 on the right, right-click, and select Delete from the pop-up menu.

Click [service items] and [Driver] on the left, find the corresponding items in the o23 group, right-click, and choose delete from the pop-up menu.

Click [Application hijacking items] on the left, find the O26 items on the right, right-click, and choose delete from the pop-up menu.

Use WinRAR to delete windows temporary folders, ie temporary folders, and files that can be deleted in C:/Windows/prefetch.

Restart your computer ~

The computer is working properly now.

File Description: C:/auto.exe property: -- h-Digital Signature: No PE file: language: English (USA) Copyright: (c) Microsoft Corporation. all rights reserved. product Name: Microsoft (r) Windows (r) Operating System Company Name: Microsoft Corporation Creation Time: 21:36:51 modification time: 12:12:32 size: 18039 bytes 17.631 kb MD5: 226f2b376cbdae4f78687d37821165f2 sha1: 4110c7a2a74a8820425584014c7801f035aed406 CRC32: cec46279

Kaspersky reported backdoor. win32.agent. bgu, and rising reported worm. win32.agent. ioh.

File Description: C:/Windows/system32/12t9. dll attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: 17:47:20 modification time: 17:36:50 size: 159744 bytes 156.0 kb MD5: e735e347e5fba73c7b3d8c46b6e239ee sha1: javascrc32: aed47e01

File Description: C:/Windows/system32/iujznmouzpoul. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.0.0.0 Description: Windows time update Product Version: 1.0.0.0 Company Name: Microsoft Inc. creation Time: 21:19:48 modification time: 21:19:50 size: 228864 bytes 223.512 kb MD5: dda-c3e5a414a24b3b521d5d0ac27923 sha1: javascrc32: 4901f568

Kaspersky reported: not-a-virus: adware. win32.ejik. Ho. Rising: adware. win32.agent. BWI

C:/Windows/system32/ybxajyetgbrbf. dll is the same as C:/Windows/system32/iujznmouzpoul. dll

File Description: C:/Windows/system32/qzyejpgucs. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: 9:41:48 modification time: 9:42:28 size: 228352 bytes 223.0 kb MD5: 15ef8b15d314f3f3e9a9270b2ea9b11a sha1: javascrc32: 6d0eb2ea

File Description: C:/Windows/system32/iffpcgxvyk. dll is the same as C:/Windows/system32/qzyejpgucs. dll

File Description: C:/Windows/system32/zbzcaoetif. dll is the same as C:/Windows/system32/qzyejpgucs. dll

File Description: C:/Windows/system32/hecowsaukc. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: 9:19:48 modification time: 9:19:50 size: 228352 bytes 223.0 kb MD5: 70685b009a7fda2e08dff04bb5a97ead sha1: javascrc32: 0f65e045

Kaspersky reports not-a-virus: adware. win32.ejik. HT, and rising reports: adware. win32.agent. bzc

C:/Windows/system32/iwsidaybza. dll is the same as C:/Windows/system32/hecowsaukc. dll

File Description: C:/Windows/system32/a0w.mon.exe attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: 11:26:21 modification time: 18:51:44 size: 16384 bytes 16.0 kb MD5: 17ebe441ae51028417418da8d11e85f7 sha1: javascrc32: 6382692d

File Description: C:/Windows/system32/Drivers/b8u6bvx912. sys attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: modification time: Size: 52576 bytes 51.352 kb MD5: b719b8c442f0c5e048819d7aee6fd309 sha1: javascrc32: 063af5b7

Kaspersky daily for Trojan-Downloader.Win32.Hmir.don

File Description: C:/Windows/system32/6to4svc. DLL properties: A --- Digital Signature: Microsoft Corporation PE file: language: English (United States) file version: 5.1.2600.2975 (xpsp_sp2_gdr.060816-0059) Description: service that offers IPv6 connectivity over an IPv4 network. copyright :? Microsoft Corporation. All Rights Reserved. Product Version: 5.1.2600.2975 Product Name: Microsoft? Windows? Operating System Company Name: Microsoft Corporation internal name: 6to4svc. DLL source file name: 6to4svc. DLL Creation Time: modification time: Size: 100352 bytes 98.0 kb MD5: fe70b589ac507eeb313ba8dbaa8e4jwsha1: javascrc32: f28e3684

File Description: C:/Windows/system32/12143225231.exe attribute: A --- Digital Signature: No PE file: failed to get file version information size! Creation Time: 23:48:45 modification time: 23:48:56 size: 130848 bytes 127.800 kb MD5: 54bb2748c670e04a9a3d62a1b3c76b2f sha1: javascrc32: f4aa9884

C:/Windows/system32/12143261391.exe same as C:/Windows/system32/12143225231.exe

C:/Windows/system32/12143297611.exe same as C:/Windows/system32/12143225231.exe

File Description: C:/Windows/system32/d0afe1b2. DLL property: A --- Digital Signature: No PE file: language: English (United States) Creation Time: 21:37:29 modification time: 18:29:30 size: 114688 bytes 112.0 kb MD5: ee2ae6486b0256a77aac5de627dcbced sha1: 7a5af2ddaeb41dbc035a647948ee62cd9942a03d CRC32: 468dc0a5

Rising Star reports: Trojan. win32.undef. Ifo

File Description: C:/Windows/system32/b9735c84.exe attributes: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.00 product version: 1.00 Product Name: autoclick internal name: autoclick source file name: autoclick.exe Creation Time: 21:37:31 modification time: 18:29:36 size: 15656 bytes 15.296 kb MD5: mongosha1: javascrc32: 46b48552

The Kaspersky report is Worm. win32.downloader. Qm, and the rising report is Trojan. Clicker. win32.vb. XB.

File Description: C:/Windows/system32/divttstmdo. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.0.0.0 Description: Windows time update Product Version: 1.0.0.0 Company Name: Microsoft Inc. creation Time: 11:56:11 modification time: 11:56:14 size: 228352 bytes 223.0 kb MD5: 69108903b5281746355d6db71da26550 sha1: 127crc32: f24fdec4

Kaspersky reported not-a-virus: adware. win32.ejik. HR, and rising reported adware. win32.agent. BWI.

C:/Windows/system32/bqpjudiyoy. dll is the same as C:/Windows/system32/divttstmdo. dll

File Description: C:/Windows/system32/tytfclqmdi. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: modification time: Size: 228352 bytes 223.0 kb MD5: e35e48a68805d8ee1184246bff89b03c sha1: javascrc32: d2017ad6e

Kaspersky reports not-a-virus: adware. win32.ejik. HT, and rising reports: adware. win32.agent. bzc

C:/Windows/system32/tnomixllah. dll is the same as C:/Windows/system32/tytfclqmdi. dll

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.