hijacking item] on the left, find the project corresponding to O26 on the right, right-click, select Delete from the pop-up menu.In [advanced functions]-> [IE and OS repair], click [repair ].
Some Virus File Information:
File Description: C:/Windows/anistio. exeAttribute: ---An error occurred while obtaining the file version information!Creation Time:Modification time:Access time:Size: 16201 bytes, 15.841 KBMD5: e32230ed6197e2e21796eb66e6b013f5Sha1: b59e4b2c1aaa38a7299333340983e4c3b6276788CRC32
kakatool. dll of the card assistant. (the result of running the virtual machine and the content in the program code are verified)
In order to block the "back-to-back" of the poisoned person, another mean method was adopted.Modify the hosts file to block the website of anti-virus software vendors. The kaka community is "lucky" to become one of the blocked members:This is what we later saw with SREng, and the corresponding content in the program code is also available:
127.0.0.1 mmsk.cn127.0.0.1
Kakatool.dll (did so, the results of the virtual machine run and the contents of the program code are matched)
In order to block the "back" of the poisoned people, another despicable method was adopted.
To modify the Hosts file, shielding antivirus software manufacturer's website, the card community "fortunate" to become one of the masked members:
This is the result that later uses Sreng to see, in the program code also has the corresponding content:
127.0.0.1 mmsk.cn
127.0.0.1 ikaka.com
127.
Rootkit. win32.ressdt. O/Trojan-Downloader.Win32.Agent.mjp Analysis
Original endurer2008-04-10 1st
It is something that Xialu has published on its official website.
Rootkit. win32.ressdt. O/Trojan-Downloader.Win32.AgentHttp://endurer.bokee.com/6681893.htmlHttp://blog.csdn.net/Purpleendurer/archive/2008/04/09/2271747.aspxHttp://blog.sina.com.cn/s/blog_49926d910100926n.html
File Description: D:/test/svcos.exeAttribute: ---An error occurred while obtaining the file version information!Created at:
nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
FoundTrojan-Downloader.Win32.Agent.aqr
NOD32
Found probably unknownNewheur_pe(Probable variant)
Norman Virus Control
Found nothing
Una
Found nothing
Virusbuster
Found nothing
Vba32
Found nothing
Antivirus
Version
Update
Result
AntiVir
7.1.1.11
09.06.2006
TR/dldr. Agent
Down.exe/virus. win32.autorun. Z/Trojan. PWS. maran.262
EndurerOriginal2Added replies from Kaspersky.1Version
When you open a page that is occasionally used in the Forum, rising prompts you to download and run suspicious files.
Search by Google, and Google has already marked it:Http://www.google.cn/search? Complete = 1 HL = ZH-CN newwindow = 1 Q = % E8 % BF % 98% E7 % 8f % A0 % E5 % 8C % Ba + % E6 % 97% A7 % e9 % 9B % A8 % E6 % a5 % BC % E6 % B8 %
:34:20Size: 93240 bytes, 91.56 KBMD5: ef70da-91d050cc898319acbb044e847
Kaspersky reportsWorm. win32.viking. II
After 0.exe is run, other malicious files will be downloaded and the EXE file will be infected.
The following is a record of Kaspersky 6 after 0.exe is run:/----Detected: Risk SoftwareTrojan. GenericRunning process: D:/test/0.exeDetected: Trojan programTrojan-PSW.Win32.Magania.jmFile: C:/winnt/syst
100000 zadd sortedset 10 _ rand_int __Zadd sortedset 10 _ rand_int __: 25227.04 requests per second
Remote.dev.com: 6379> zcard sortedset(Integer) 63118
About 40 us
At this point, we found that the gap between the two was not as big as we thought. Now we suspect that it is a problem with the Lua script. Replace the Lua script in the first test with the simple redis zrange Key 0 0 command and then test it.
A. Local Machine 137 us (0.1 MS)
B. Dev machine 2100 NS (2.1 MS)
It seems that the reason
, and then scan. Sure enough, cured has a large number of EXE files.
I found that there are many *. tmp files in C:/windows. It is estimated that the files are still not cleared. Download and install AntiVir, scan the files after upgrade, and scan and kill one piece ......
File Description: C:/auto.exeAttribute: ---Language: English (USA)File version: 0. 0. 0. 0Note:Copyright:Note:Product Version: 0.0.0.0Product Name:Company Name:Legal trademark:Internal Name:Source File Name:Creation Time: 22:2
The system time is modified to use the xibgptd.exe, netdde32.exe, and so on.
EndurerOriginal1Version
File Description: C:/Windows/netdde32.exeProperty:-sh-An error occurred while obtaining the file version information!Creation Time:Modification time: 9:19:16Access time:Size: 46080 bytes, 45.0 KBMD5: a51350e65839a16ab5f5de5de6c525e8
Subject:
Re: netdde32.exe [KLAB-2608379]
Sender:
""
Sent:
Hello,Netdde32.exed-Trojan-Downloader.Win32.QQHelper.wkNew malicious soft
Anti-virus software is always a hot topic, especially free anti-virus software. It is said that the entire anti-virus industry is slowly switching to free, regardless of whether you agree or not, you always need to learn more about this free tide. We have checked 43 free anti-virus software. What do you know?
1. Avast! Free Antivirus
Official Website: http://www.avast.com/
More than 0.1 billion of users from the Czech Republic worldwide, nearly 20 million of which were introduced.
2. Avira Anti
match your own security software without slowing down the system speed. Let's take a look at my Configuration:
Kaspersky Internet Security Package latest version + AVG7.5 + Skynet firewall + wooden star and 360 security guard.
Use of these software:
With real-time monitoring of Kabbah, Skynet, and AVG enabled, wooden mark Star 2007 will be upgraded after two days, because AVG7.5 is sometimes not sensitive
and click Details to view the details of the certificate:
In this case, special attention needs to be paid to see if the digital signature is valid, the digital signature is valid, the software is trustworthy, the digital signature is invalid, the software is suspicious, and the issuer, if the issuer is obscure, also needs attention. A few of the more common are: COMODO, VeriSign, Microsoft, and so on.
Second, based on the results of the multi-engine scan site to judge:
This is a
\windows\currentversion\explorer\advanced\folder\hidden\showall " CheckedValue "
Old Data:01, 00, 00, 00 modified so that the system does not show hidden files
New data:00, 00, 00, 00
hkey_local_machine\system\currentcontrolset\control\deviceclasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}\##?# pci#ven_8086dev_24c5subsys_4720414crev_02#313c0b0c50fd#{ 6994ad04-93ef-11d0-a3cc-00a0c9223196}\ #Wave \device Parameters\mixer\0\ Mute the system
Close a window with the following characters
Security guar
First, the solution of Kaspersky Scan suddenly fixed problem
There are several reasons for this situation:
1, the hard drive has a very large file in operation, if the hard drive lights flashing words is at work, and so on.
2, in Kaspersky set inside, scan inside have a custom, inside have a more than time 30 seconds automatically skip, the front dozen a hook, if you are not good, please scan in safe mod
must install anti-virus software. However, we cannot regard anti-virus software as a one-step security solution, but should regard IT as a layer of IT security in-depth protection methods, but some home users or small businesses do not realize they need a deep protection policy to protect their data. Currently, they only know how to install anti-virus software or some firewall. Similar to this lack of knowledge about anti-virus software, the usage of free anti-virus software has always exceeded
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.