When the system time is modified, use the xibgptd.exe, netdde32.exe, and so on.

Source: Internet
Author: User

If the system time is modified, use the xibgptd.exe,netdde32.exe file to be hijacked. <1

EndurerOriginal
1Version

When an error occurs in the ghost program, the advertisement window is occasionally displayed. Allow Remote Assistance via QQ.

Download hijackthis, procview from http://endurer.ys168.com first. Run procview, which is directly disabled. Rename hijackthis.exe to h.exe, and then run the step manager provided by Fu hijackthisto stop the nweb.exe process.

Then download pe_xscan and analyze the logs. The following suspicious items are found:
/=
Pe_xscan 07-07-21 by Purple endurer
2005-10-19 12:46:14
Windows XP Service Pack 2 (5.1.2600)
Administrator user group

[System process] * 0
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/1mb0pe. l6v | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/jzupli. dll | 9:14:30

C:/Windows/system32/winlogon.exe * 700 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/45119f1b. dll | 10:33:54 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?

C:/Windows/system32/services.exe * 748 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | services and controller app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Services.exe
C:/Windows/system32/jzupli. dll | 9:14:30

C:/Windows/system32/lsass.exe * 760 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | LSA shell (export version) |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Lsass.exe
C:/Windows/system32/jzupli. dll | 9:14:30

C:/Windows/system32/svchost.exe * 928 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/jzupli. dll | 9:14:30

C:/Windows/explorer. EXE * 1900 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/kb908024.log | 2005-10-19 10:32:52
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/45119f1b. dll | 10:33:54 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?
C:/Windows/netdde32.exe | 9:19:16
C:/Windows/system32/netdde32.exe | 9:19:16
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/mshttpapp. dll | mshttpapp | 1.0.0.1 | mshttpapp | Microsoft Corporation. All Rights Reserved. | 1.0.0.1 | Microsoft Corporation |? | Mshttpapp. dll | mshttpapp. dll

C:/program files/common files/Microsoft shared/xibgptd.exe * 160 |
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/dhcpri. dll | 9:13:52

C:/program files/ocins/idnsvr.exe * 192 | 2, 6, 0, 0 | international domain name support module | copyright CNNIC 2006-2007 | 2, 6, 0, 0 | China Internet Information Center (CNNIC) | idnsvr | idnsvr.exe
C:/program files/ocins/idnsvr.exe | 2, 6, 0, 0 | Support Module for international domain names | copyright CNNIC 2006-2007 | 2, 6, 0, 0 | China Internet Information Center (CNNIC) | idnsvr | idnsvr.exe
C:/program files/ocins/idnsvr. DLL | 2, 6, 0, 0 | Support Module for international domain names | copyright CNNIC 2006-2007 | 2, 6, 0, 2 | China Internet Information Center (CNNIC) | idnsvr. DLL
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/dhcpri. dll | 9:13:52

C:/program files/common files/system/xmjisnw.exe * 200 |
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/dhcpri. dll | 9:13:52

C:/Windows/system32/ctfmon.exe * 240 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/dhcpri. dll | 9:13:52

C:/Windows/svrsvc.exe * 500 |
C:/Windows/svrsvc.exe |
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/jzupli. dll | 9:14:30

C:/Windows/system32/dllcache/1028/svchost.exe * 780 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |?
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/remotedbg. dll | 9:13:46

C:/program files/qq2006/qq.exe * 2144 | 19:30:50 | QQ | 1998, 2007, | QQ | copyright (c)-Tencent Inc. all rights reserved |, | Tencent | comqqd | qq.exe
C:/Windows/system32/jzupli. dll | 9:14:30
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/dhcpri. dll | 9:13:52
C:/Windows/system32/1mb0pe. l6v | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/mydpri. dll | 9:14:12
C:/Windows/system32/wgepri. dll | 9:13:58
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16

C:/program files/qq2006/timplatform.exe * 2252 | 15:17:20 | QQ |, | timplatform | copyright? 2005 bytes 2007 Tencent Inc. All Rights Reserved |, | Tencent | timplatform | timplatform.exe
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/lazodyn. laz | 23:54:26 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/dhcpri. dll | 9:13:52

C:/Windows/system32/rundll32.exe * 3972 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/Windows/system32/remotedbg. dll | 9:13:46
C:/Windows/system32/windhcp. ocx |
C:/Windows/system32/jqxelw. dll | 23:54:26, 2007-4-16
C:/program files/qq2006/Q. dll | 23:54:26
C:/Windows/system32/1.1 | 1601-1-2
C:/Windows/system32/dhcpri. dll | 9:13:52

F2-Reg: system. ini: userinit = C:/Windows/system32/userinit.exe

O1-hosts: 61.152.244.167 search.114.vnet.cn
O1-hosts: 61.152.244.167 auto.search.msn.com
O1-hosts: 61.152.244.167 www.hao123.com
O1-hosts: 61.152.244.167 hao123.com
O1-hosts: 61.152.244.167 www.360safe.com
O1-hosts: 61.152.244.167 360safe.com
O1-hosts: 222.73.126.115 update.360safe.com
O1-hosts: 61.152.244.167 dl.360safe.com
O1-hosts: 61.152.244.167 bbs.360safe.com
O1-hosts: 61.152.244.167 www.btbaicai.com
O1-hosts: 61.152.244.167 btbaicai.com
O1-hosts: 61.152.244.167 www.pctutu.com
O1-hosts: 61.152.244.167 www.7322.com
O1-hosts: 61.152.244.167 www.5566.net
O1-hosts: 61.152.244.167 www.9991.com
O1-hosts: 61.152.244.167 9991.com
O1-hosts: 61.152.244.167 forum.ikaka.com
O1-hosts: 61.152.244.167 www.ikaka.com
O1-hosts: 222.73.126.115 update.ikaka.com
O1-hosts: 61.152.244.167 forum.jiangmin.com
O1-hosts: 222.73.126.115 update.jiangmin.com
O1-hosts: 61.152.244.167 post.baidu.com
O1-hosts: 222.73.126.115 update.rising.com.cn
O1-hosts: 61.152.244.167 online.rising.com.cn
O1-hosts: 222.73.126.115 center.rising.com.cn
O1-hosts: 61.152.244.167 up.duba.net
O1-hosts: 61.152.244.167 shadu.baidu.com
O1-hosts: 61.152.244.167 security.tetec.com
O1-hosts: 61.152.244.167 shadu.duba.net
O1-hosts: 61.152.244.167 online.jiangmin.com
O1-hosts: 61.152.244.167 cn.mcafee.com
O1-hosts: 61.152.244.167 www.ahn.com.cn
O1-hosts: 61.152.244.167 www.kaspersky.com.cn
O1-hosts: 61.152.244.167 www.pcav.cn
O1-hosts: 61.152.244.167 mopery. Hits. Io
O1-hosts: 61.152.244.167 www.luosoft.com
O1-hosts: 61.152.244.167 luosoft.com
O1-hosts: 61.152.244.167 www.im286.com
O1-hosts: 61.152.244.167 bbs.htmlman.net
O1-hosts: 61.152.244.167 2.16.286er.com
O1-hosts: 61.152.244.167 im286.net
O1-hosts: 61.152.244.167 cool.47555.com
O1-hosts: 61.152.244.167 ju.qihoo.com
O1-hosts: 61.152.244.167 bbs.chinaz.com
O1-hosts: 222.73.126.115 dnl-cn1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-cn15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-eu15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us12.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us13.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us14.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-us15.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru1.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru2.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru3.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru4.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru5.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru6.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru7.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru8.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru9.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru10.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru11.kaspersky-labs.com
O1-hosts: 222.73.126.115 dnl-ru12.kaspersky-labs.com

O2-BHO cadlogic object-{11f09afd-75ad-4e51-ab43-e09e9351ce16}-C:/program files/common files/cpush/cpush0.dll

O2-BHO ieaux class-{7605cc7c-00fd-4a5f-bafd-828342de6279}-C:/progra ~ 1/ocins/ieaux. dll

O4-hkcu/../run: [msetup] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/install.exe

D:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/
E:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/
F:/autorun. inf
/-----
[Autorun]
Opentracing pnxxupm.exe
Shell/open = open (& O)
Shell/Open/commandancpnxxupm.exe
Shell/Open/default = 1
Shell/volume E = Resource Manager (& X)
Shell/cmde/commandancpnxxupm.exe
-----/

(Log unfinished)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.