05-14/capture hijack. dll and worm. win32.agent. Z that will disable real-time monitoring by rising./v2

Source: Internet
Author: User

EndurerOriginal
2Supplement the reaction of rising
1Version

A friend said that the real-time monitoring of rising in his computer will be automatically disabled, even if it is manually turned on, it will be automatically closed after a while, and the USB flash disk cannot be opened, so that I can help with the repair.

Check found that this friend used the Rising Star virus database, which could not be upgraded.

Pe_xscan is used to scan logs and analyze the logs. The following suspicious items are found:
/=
Pe_xscan 07-03-17 by Purple endurer
21:31:14
Windows XP Service Pack 2 (5.1.2600)
Administrator user group

C:/Windows/explorer. EXE * 1400 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/program files/Internet Explorer/plugins/hijack. DLL | MICROSOFT (r) Windows (r) system | 5.00.1.0.1 | Microsoft Corporation windows DLL | copyright (c) 2006.6 | 1. 0. 0. 1 | Microsoft Corporation |? | System. dll

H:/autorun. inf
/-----
[Autorun]
Open = ghost. pif
ShellExecute = ghost. pif
Shell/auto/command = ghost. pif
Shell = auto
-----/

O24-[]-{03f6e661-0d5f-3fad-3e2b-e261e3cb6cd2} = C:/program files/Internet Explorer/plugins/hijack. dll
===/

H: indicates the USB flash drive.

Check the H disk and find ghost. PIF and timp1atform.exe.

Download fileinfo and bat_do 0.0.0003 beta1 from http://purpleendurer.ys168.com.

Use fileinfo to extract file information as follows:

File Description: C:/program files/Internet Explorer/plugins/hijack. dll
Property: ash-
Language: Chinese (China)
File version: 1. 0. 0. 1
Note: Microsoft Corporation windows DLL
Copyright: Copyright (c) 2006.6
Note:
Product Version: 5.00.1.0.1
Product Name: Microsoft (r) Windows (r) System
Company Name: Microsoft Corporation
Legal trademark:
Internal name: System
Source File Name: system. dll
Creation Time: 11:41:25
Modification time:
Access time:
Size: 12341 bytes, 12.53 KB
MD5: f3d36c0a5bac3eae2a28063cac087102

Kaspersky reportsTrojan-Downloader.Win32.Agent.bmo, Rising:Trojan. Hijack.

File Description: H:/ghost. pif
Property: ash-
An error occurred while obtaining the file version information!
Creation Time: 16:12:50
Modification time: 11:41:22
Access time:
Size: 18997 bytes, 18.565 KB
MD5: 45680654f7e984aa1781fbee26603042

Kaspersky reportsTrojan-Downloader.Win32.Agent.bmo

File Description: H:/timp1atform.exe
Attribute: ashr
An error occurred while obtaining the file version information! Creation Time: 10:14:35
Modification time: 16:57:42
Access time:
Size: 266752 bytes, 260.512 KB
MD5: 049058e75e502174052a23655034cbaa

Kaspersky reportsWorm. win32.agent. Z

Use bat_do 0.0.0003 beta1 to call RAR package and use delayed deletion.

After restarting the computer, rising real-time monitoring will not be automatically disabled ......

Install the rising Card Security Assistant and uninstall o24 items.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.