If the system time is modified, use the xibgptd.exe,netdde32.exe file to be hijacked. <1
EndurerOriginal
1Version
When an error occurs in the ghost program, the advertisement window is occasionally displayed. Allow Remote Assistance via QQ.
Download hijackthis, procview from http://endurer.ys168.com first. Run procview, which is directly disabled. Rename hijackthis.exe to h.exe, and then run the step manager provided by Fu hijackthisto stop the nweb.exe process.
Then download pe_xscan and analyze the logs. The following suspicious items are found:
/=
Pe_xscan 07-07-21 by Purple endurer
2005-10-19 12:46:14
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
[System process] * 0
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/1mb0pe. l6v | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/winlogon.exe * 700 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/45119f1b. dll | 10:33:54 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?
C:/Windows/system32/services.exe * 748 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | services and controller app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Services.exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/lsass.exe * 760 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | LSA shell (export version) |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Lsass.exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/svchost.exe * 928 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/explorer. EXE * 1900 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/kb908024.log | 2005-10-19 10:32:52
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/45119f1b. dll | 10:33:54 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?
C:/Windows/netdde32.exe | 9:19:16
C:/Windows/system32/netdde32.exe | 9:19:16
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/mshttpapp. dll | mshttpapp | 1.0.0.1 | mshttpapp | Microsoft Corporation. All Rights Reserved. | 1.0.0.1 | Microsoft Corporation |? | Mshttpapp. dll | mshttpapp. dll
C:/program files/common files/Microsoft shared/xibgptd.exe * 160 |
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/program files/ocins/idnsvr.exe * 192 | 2, 6, 0, 0 | international domain name support module | copyright CNNIC 2006-2007 | 2, 6, 0, 0 | China Internet Information Center (CNNIC) | idnsvr | idnsvr.exe
C:/program files/ocins/idnsvr.exe | 2, 6, 0, 0 | Support Module for international domain names | copyright CNNIC 2006-2007 | 2, 6, 0, 0 | China Internet Information Center (CNNIC) | idnsvr | idnsvr.exe
C:/program files/ocins/idnsvr. DLL | 2, 6, 0, 0 | Support Module for international domain names | copyright CNNIC 2006-2007 | 2, 6, 0, 2 | China Internet Information Center (CNNIC) | idnsvr. DLL
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/program files/common files/system/xmjisnw.exe * 200 |
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/ctfmon.exe * 240 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/svrsvc.exe * 500 |
C:/Windows/svrsvc.exe |
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/dllcache/1028/svchost.exe * 780 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/program files/qq2006/qq.exe * 2144 | 19:30:50 | QQ | 1998, 2007, | QQ | copyright (c)-Tencent Inc. all rights reserved |, | Tencent | comqqd | qq.exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/1mb0pe. l6v | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16
C:/program files/qq2006/timplatform.exe * 2252 | 15:17:20 | QQ |, | timplatform | copyright? 2005 bytes 2007 Tencent Inc. All Rights Reserved |, | Tencent | timplatform | timplatform.exe
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/rundll32.exe * 3972 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/dhcpri. dll | 9:13:52
F2-Reg: system. ini: userinit = C:/Windows/system32/userinit.exe
O1-hosts: 61.152.244.167 search.114.vnet.cn
O1-hosts: 61.152.244.167 auto.search.msn.com
O1-hosts: 61.152.244.167 www.hao123.com
O1-hosts: 61.152.244.167 hao123.com
O1-hosts: 61.152.244.167 www.360safe.com
O1-hosts: 61.152.244.167 360safe.com
O1-hosts: 222.73.126.115 update.360safe.com
O1-hosts: 61.152.244.167 dl.360safe.com
O1-hosts: 61.152.244.167 bbs.360safe.com
O1-hosts: 61.152.244.167 www.btbaicai.com
O1-hosts: 61.152.244.167 btbaicai.com
O1-hosts: 61.152.244.167 www.pctutu.com
O1-hosts: 61.152.244.167 www.7322.com
O1-hosts: 61.152.244.167 www.5566.net
O1-hosts: 61.152.244.167 www.9991.com
O1-hosts: 61.152.244.167 9991.com
O1-hosts: 61.152.244.167 forum.ikaka.com
O1-hosts: 61.152.244.167 www.ikaka.com
O1-hosts: 222.73.126.115 update.ikaka.com
O1-hosts: 61.152.244.167 forum.jiangmin.com
O1-hosts: 222.73.126.115 update.jiangmin.com
O1-hosts: 61.152.244.167 post.baidu.com
O1-hosts: 222.73.126.115 update.rising.com.cn
O1-hosts: 61.152.244.167 online.rising.com.cn
O1-hosts: 222.73.126.115 center.rising.com.cn
O1-hosts: 61.152.244.167 up.duba.net
O1-hosts: 61.152.244.167 shadu.baidu.com
O1-hosts: 61.152.244.167 security.tetec.com
O1-hosts: 61.152.244.167 shadu.duba.net
O1-hosts: 61.152.244.167 online.jiangmin.com
O1-hosts: 61.152.244.167 cn.mcafee.com
O1-hosts: 61.152.244.167 www.ahn.com.cn
O1-hosts: 61.152.244.167 www.kaspersky.com.cn
O1-hosts: 61.152.244.167 www.pcav.cn
O1-hosts: 61.152.244.167 mopery. Hits. Io
O1-hosts: 61.152.244.167 www.luosoft.com
O1-hosts: 61.152.244.167 luosoft.com
O1-hosts: 61.152.244.167 www.im286.com
O1-hosts: 61.152.244.167 bbs.htmlman.net
O1-hosts: 61.152.244.167 2.16.286er.com
O1-hosts: 61.152.244.167 im286.net
O1-hosts: 61.152.244.167 cool.47555.com
O1-hosts: 61.152.244.167 ju.qihoo.com
O1-hosts: 61.152.244.167 bbs.chinaz.com
O1-hosts: 222.73.126.115 dnl-cn1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru12.kaspersky-labs.com
O2-BHO cadlogic object-{11f09afd-75ad-4e51-ab43-e09e9351ce16}-C:/program files/common files/cpush/cpush0.dll
O2-BHO ieaux class-{7605cc7c-00fd-4a5f-bafd-828342de6279}-C:/progra ~ 1/ocins/ieaux. dll
O4-hkcu/../run: [msetup] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/install.exe
D:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/
E:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/
F:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/
(Log unfinished)