Auto.exe/backdoor. win32.agent. bgu, b8u6bvx912. sys/Trojan-Downloader.Win32.Hmir.don, etc. 2
Original endurer 2008-06-30 1st
Download fileinfo and bat_do to the http://purpleendurer.ys168.com.
Use fileinfo to extract the information of the red files in the pe_xscan log. Use bat_do to package the backup, delete the files in a delayed manner, change the selected file name, and delete the files in a delayed manner.
Download and install the rising Kaka Security Assistant, switch to [advanced functions]-> [IE and system repair], repair o29, and hkcu-start page = hxxp: // www.258central.cn/and HKLM/showall values are not 1
Switch to [advanced functions]-> [plug-in management and uninstallation] to uninstall the O2 and O3 items.
Switch to [advanced functions]-> [system startup Item Management]
Click [logon items] on the left, find the items F2 and O4 on the right, right-click, and select Delete from the pop-up menu.
Click [service items] and [Driver] on the left, find the corresponding items in the o23 group, right-click, and choose delete from the pop-up menu.
Click [Application hijacking items] on the left, find the O26 items on the right, right-click, and choose delete from the pop-up menu.
Use WinRAR to delete windows temporary folders, ie temporary folders, and files that can be deleted in C:/Windows/prefetch.
Restart your computer ~
The computer is working properly now.
File Description: C:/auto.exe property: -- h-Digital Signature: No PE file: language: English (USA) Copyright: (c) Microsoft Corporation. all rights reserved. product Name: Microsoft (r) Windows (r) Operating System Company Name: Microsoft Corporation Creation Time: 21:36:51 modification time: 12:12:32 size: 18039 bytes 17.631 kb MD5: 226f2b376cbdae4f78687d37821165f2 sha1: 4110c7a2a74a8820425584014c7801f035aed406 CRC32: cec46279
Kaspersky reported backdoor. win32.agent. bgu, and rising reported worm. win32.agent. ioh.
File Description: C:/Windows/system32/12t9. dll attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: 17:47:20 modification time: 17:36:50 size: 159744 bytes 156.0 kb MD5: e735e347e5fba73c7b3d8c46b6e239ee sha1: javascrc32: aed47e01
File Description: C:/Windows/system32/iujznmouzpoul. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.0.0.0 Description: Windows time update Product Version: 1.0.0.0 Company Name: Microsoft Inc. creation Time: 21:19:48 modification time: 21:19:50 size: 228864 bytes 223.512 kb MD5: dda-c3e5a414a24b3b521d5d0ac27923 sha1: javascrc32: 4901f568
Kaspersky reported: not-a-virus: adware. win32.ejik. Ho. Rising: adware. win32.agent. BWI
C:/Windows/system32/ybxajyetgbrbf. dll is the same as C:/Windows/system32/iujznmouzpoul. dll
File Description: C:/Windows/system32/qzyejpgucs. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: 9:41:48 modification time: 9:42:28 size: 228352 bytes 223.0 kb MD5: 15ef8b15d314f3f3e9a9270b2ea9b11a sha1: javascrc32: 6d0eb2ea
File Description: C:/Windows/system32/iffpcgxvyk. dll is the same as C:/Windows/system32/qzyejpgucs. dll
File Description: C:/Windows/system32/zbzcaoetif. dll is the same as C:/Windows/system32/qzyejpgucs. dll
File Description: C:/Windows/system32/hecowsaukc. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: 9:19:48 modification time: 9:19:50 size: 228352 bytes 223.0 kb MD5: 70685b009a7fda2e08dff04bb5a97ead sha1: javascrc32: 0f65e045
Kaspersky reports not-a-virus: adware. win32.ejik. HT, and rising reports: adware. win32.agent. bzc
C:/Windows/system32/iwsidaybza. dll is the same as C:/Windows/system32/hecowsaukc. dll
File Description: C:/Windows/system32/a0w.mon.exe attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: 11:26:21 modification time: 18:51:44 size: 16384 bytes 16.0 kb MD5: 17ebe441ae51028417418da8d11e85f7 sha1: javascrc32: 6382692d
File Description: C:/Windows/system32/Drivers/b8u6bvx912. sys attribute: A --- Digital Signature: No PE file: failed to get file version information! Creation Time: modification time: Size: 52576 bytes 51.352 kb MD5: b719b8c442f0c5e048819d7aee6fd309 sha1: javascrc32: 063af5b7
Kaspersky daily for Trojan-Downloader.Win32.Hmir.don
File Description: C:/Windows/system32/6to4svc. DLL properties: A --- Digital Signature: Microsoft Corporation PE file: language: English (United States) file version: 5.1.2600.2975 (xpsp_sp2_gdr.060816-0059) Description: service that offers IPv6 connectivity over an IPv4 network. copyright :? Microsoft Corporation. All Rights Reserved. Product Version: 5.1.2600.2975 Product Name: Microsoft? Windows? Operating System Company Name: Microsoft Corporation internal name: 6to4svc. DLL source file name: 6to4svc. DLL Creation Time: modification time: Size: 100352 bytes 98.0 kb MD5: fe70b589ac507eeb313ba8dbaa8e4jwsha1: javascrc32: f28e3684
File Description: C:/Windows/system32/12143225231.exe attribute: A --- Digital Signature: No PE file: failed to get file version information size! Creation Time: 23:48:45 modification time: 23:48:56 size: 130848 bytes 127.800 kb MD5: 54bb2748c670e04a9a3d62a1b3c76b2f sha1: javascrc32: f4aa9884
C:/Windows/system32/12143261391.exe same as C:/Windows/system32/12143225231.exe
C:/Windows/system32/12143297611.exe same as C:/Windows/system32/12143225231.exe
File Description: C:/Windows/system32/d0afe1b2. DLL property: A --- Digital Signature: No PE file: language: English (United States) Creation Time: 21:37:29 modification time: 18:29:30 size: 114688 bytes 112.0 kb MD5: ee2ae6486b0256a77aac5de627dcbced sha1: 7a5af2ddaeb41dbc035a647948ee62cd9942a03d CRC32: 468dc0a5
Rising Star reports: Trojan. win32.undef. Ifo
File Description: C:/Windows/system32/b9735c84.exe attributes: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.00 product version: 1.00 Product Name: autoclick internal name: autoclick source file name: autoclick.exe Creation Time: 21:37:31 modification time: 18:29:36 size: 15656 bytes 15.296 kb MD5: mongosha1: javascrc32: 46b48552
The Kaspersky report is Worm. win32.downloader. Qm, and the rising report is Trojan. Clicker. win32.vb. XB.
File Description: C:/Windows/system32/divttstmdo. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 1.0.0.0 Description: Windows time update Product Version: 1.0.0.0 Company Name: Microsoft Inc. creation Time: 11:56:11 modification time: 11:56:14 size: 228352 bytes 223.0 kb MD5: 69108903b5281746355d6db71da26550 sha1: 127crc32: f24fdec4
Kaspersky reported not-a-virus: adware. win32.ejik. HR, and rising reported adware. win32.agent. BWI.
C:/Windows/system32/bqpjudiyoy. dll is the same as C:/Windows/system32/divttstmdo. dll
File Description: C:/Windows/system32/tytfclqmdi. DLL property: A --- Digital Signature: No PE file: Language: Chinese (China) file version: 2.0.0.0 Description: Windows-update Product Version: 2.0.0.0 Company Name: nicrosoft Inc. creation Time: modification time: Size: 228352 bytes 223.0 kb MD5: e35e48a68805d8ee1184246bff89b03c sha1: javascrc32: d2017ad6e
Kaspersky reports not-a-virus: adware. win32.ejik. HT, and rising reports: adware. win32.agent. bzc
C:/Windows/system32/tnomixllah. dll is the same as C:/Windows/system32/tytfclqmdi. dll