EndurerOriginal
1Version
A report from rising's computer reported that rootkit. vanti. kN, Trojan. psw. jhonline. EQO, Trojan. psw. lmir. KTN and other viruses have been detected.
Run the rising registry Repair Tool first, and no modified project is found.
Then, check the anti-virus history of rising stars, open the Rising Star injection window, and find that the rising star virus database is still in December August 10, and upgrade immediately. Check the regular upgrade settings of rising. The upgrade frequency is changed to once a day every week.
After the upgrade is completed, the system detects and removes memory, boot area, and drive C.
At the same time download hijackthis scan log to the http://endurer.ys168.com, no suspicious items found.
Use WinRAR to check C:/, C:/Windows, C:/Windows/debug, C:/Windows/Downloaded Program Files, C:/Windows/system32, and C: /Windows/temp, C:/Documents and Settings/ABC/Local Settings/temp, C:/program files, C:/program files/Internet Explorer, D:/, etc, suspicious files discovered:
/-------------
C:/Windows/hacker.com.cn.exe
C:/Windows/setup1.exe
-------------/
It is very likely that it is a gray pigeon. It is deleted after packaging and backup.
Rising scan results are as follows:
/-------------
Rootkit. vanti. kN deleted successfully file monitoring C:/docume ~ 1/ABC/locals ~ 1/temp ud2aniap. dll
Rootkit. vanti. kN deleted ~ 1/ABC/locals ~ 1/temp ud2aniap. dll
Trojan. DL. Delf. Cop deleted ~ 1/ABC/locals ~ 1/temp hh.exe
Trojan. psw. lmir. KTN deleted ~ 1/ABC/locals ~ 1/temp foxrar.exe
Trojan. psw. lmir. KTN deleted successfully file monitoring C:/Documents and Settings/ABC/Local Settings/temp win1a29.exe
Trojan. psw. wowar. HQ deleted successfully file monitoring C:/Windows/system32 mywow. dll
Trojan. psw. zhengtu. ee deleted successfully file monitoring
C:/Windows/system32 myztr. dll
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
Trojan. psw. wowar. HQ deleted successfully file monitoring C:/Windows/system32 launcher.exe
Trojan. psw. wowar. HQ deleted successfully file monitoring C:/Windows/system32 systemd.exe
Trojan. psw. zhengtu. ee deleted successfully file monitoring C:/Windows/system32 systemb.exe
Trojan. psw. jhonline. EQO restart the computer and delete the file monitoring C:/Windows/system32 systema. dll
-------------/
Among them, Trojan. psw. jhonline. EQO rising cannot be cleared directly.
Download procview, icesword, and auto_del from the http://endurer.ys168.com. Using procview to export the line feed list, we found that C:/Windows/system32/systema. DLL inserted multiple processes, and several processes were processed using icesword, which was too slow.
Run auto_del.exe, add C:/Windows/system32/systema. DLL to the list of files to be deleted, and click "change all file names" and "Delete the next Startup finance.
The rising Registration Table monitoring prompts auto_del.exe to modify the registry, select "allow", and click "OK ".
So how does C:/Windows/system32/systema. dll start?
Use hijackthis to scan and generate a list of startup items. We found that:
/--------------------------------------------------
Startuplist report, 22:18:26
Startuplist version: 1.52.2
Enumerating Windows NT/2000/XP services
Enumerating Windows NT logon/logoff scripts:
* No scripts set to run *
Windows NT checkdisk command:
Bootexecute = autocheck autochk *
Windows NT 'wininit. ini ':
Pendingfilerenameoperations: C:/Windows/system32/systema. dll | C:/Windows/system32/systema. dll. DEL
--------------------------------------------------/
This should be set by rising to delete files after restarting the computer.
Open the Registry Editor, search for "systema. dll", and find the following:
1,
/****************
Windows Registry Editor Version 5.00
[Hkey_classes_root/CLSID/{C54B4AFB-7A2A-6C3E-BA4D-C20F0294B728}/inprocserver32]
@ = "C: // windows // system32 // systema. dll"
"Threadingmodel" = "apartment"
****************/
2,
/****************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/software/classes/CLSID/{C54B4AFB-7A2A-6C3E-BA4D-C20F0294B728}/inprocserver32]
@ = "C: // windows // system32 // systema. dll"
"Threadingmodel" = "apartment"
****************/
3,
/****************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/system/controlset001/control/Session Manager]
"Pendingfilerenameoperations" = hex (7): 5C, 00, 3f, 00, 3f, 00, 5C, 00,43, 00, 3A, 00, 5C, 00 ,/
, 00, 4E, 44, 00, 4f, 53, 00, 5C ,/
00, 6d, 00, 5C, 00, 00 ,/
64, 00, 6C, 00, 6C, 00, 00, 00, 5C, 00, 3f, 00, 3f, 00, 5C, 00, 3A, 00, 5C,/
, 49, 00, 4E, 00, 4f, 00, 5C, 00 ,/
6d, 32, 00, 5C ,/
00, 6C, 00, 6C, 00, 2e, 65, 00, 6C, 00, 00
****************/
4,
/****************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/system/CurrentControlSet/control/Session Manager]
"Pendingfilerenameoperations" = hex (7): 5C, 00, 3f, 00, 3f, 00, 5C, 00,43, 00, 3A, 00, 5C, 00 ,/
, 00, 4E, 44, 00, 4f, 53, 00, 5C ,/
00, 6d, 00, 5C, 00, 00 ,/
64, 00, 6C, 00, 6C, 00, 00, 00, 5C, 00, 3f, 00, 3f, 00, 5C, 00, 3A, 00, 5C,/
, 49, 00, 4E, 00, 4f, 00, 5C, 00 ,/
6d, 32, 00, 5C ,/
00, 6C, 00, 6C, 00, 2e, 65, 00, 6C, 00, 00
****************/
Among them, 1 and 2 are started by systema. dll, and 3 and 4 are used by rising to delete files after restarting the computer.