EndurerOriginal
2Supplement the reaction of rising
1Version
A friend said that the real-time monitoring of rising in his computer will be automatically disabled, even if it is manually turned on, it will be automatically closed after a while, and the USB flash disk cannot be opened, so that I can help with the repair.
Check found that this friend used the Rising Star virus database, which could not be upgraded.
Pe_xscan is used to scan logs and analyze the logs. The following suspicious items are found:
/=
Pe_xscan 07-03-17 by Purple endurer
21:31:14
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
C:/Windows/explorer. EXE * 1400 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/program files/Internet Explorer/plugins/hijack. DLL | MICROSOFT (r) Windows (r) system | 5.00.1.0.1 | Microsoft Corporation windows DLL | copyright (c) 2006.6 | 1. 0. 0. 1 | Microsoft Corporation |? | System. dll
H:/autorun. inf
/-----
[Autorun]
Open = ghost. pif
ShellExecute = ghost. pif
Shell/auto/command = ghost. pif
Shell = auto
-----/
O24-[]-{03f6e661-0d5f-3fad-3e2b-e261e3cb6cd2} = C:/program files/Internet Explorer/plugins/hijack. dll
===/
H: indicates the USB flash drive.
Check the H disk and find ghost. PIF and timp1atform.exe.
Download fileinfo and bat_do 0.0.0003 beta1 from http://purpleendurer.ys168.com.
Use fileinfo to extract file information as follows:
File Description: C:/program files/Internet Explorer/plugins/hijack. dll
Property: ash-
Language: Chinese (China)
File version: 1. 0. 0. 1
Note: Microsoft Corporation windows DLL
Copyright: Copyright (c) 2006.6
Note:
Product Version: 5.00.1.0.1
Product Name: Microsoft (r) Windows (r) System
Company Name: Microsoft Corporation
Legal trademark:
Internal name: System
Source File Name: system. dll
Creation Time: 11:41:25
Modification time:
Access time:
Size: 12341 bytes, 12.53 KB
MD5: f3d36c0a5bac3eae2a28063cac087102
Kaspersky reportsTrojan-Downloader.Win32.Agent.bmo, Rising:Trojan. Hijack.
File Description: H:/ghost. pif
Property: ash-
An error occurred while obtaining the file version information!
Creation Time: 16:12:50
Modification time: 11:41:22
Access time:
Size: 18997 bytes, 18.565 KB
MD5: 45680654f7e984aa1781fbee26603042
Kaspersky reportsTrojan-Downloader.Win32.Agent.bmo
File Description: H:/timp1atform.exe
Attribute: ashr
An error occurred while obtaining the file version information! Creation Time: 10:14:35
Modification time: 16:57:42
Access time:
Size: 266752 bytes, 260.512 KB
MD5: 049058e75e502174052a23655034cbaa
Kaspersky reportsWorm. win32.agent. Z
Use bat_do 0.0.0003 beta1 to call RAR package and use delayed deletion.
After restarting the computer, rising real-time monitoring will not be automatically disabled ......
Install the rising Card Security Assistant and uninstall o24 items.