1 of kapjazy.dll, yhpri.dll, winsys64.sys, nwiztlbu.exe, and myplayer.com
EndurerOriginal
1Version
Just now, a netizen said that the 360 guard on his computer kept prompting programs such as kapjazy. DLL to modify the Registry. Please help me.
However, I have been busy these days. Let him download the pe_xscan scan log and send it to me.
The following suspicious items are found in the log:
/=
Pe_xscan 07-08-30 by Purple endurer
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
[System process] * 0
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/Windows/system32/winlogon.exe * 524 | 7:39:24 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/services.exe * 572 | 7:39:24 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | services and controller app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Services.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/lsass.exe * 584 | 7:39:16 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | LSA shell (export version) |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Lsass.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/svchost.exe * 740 | 7:39:24 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/svchost.exe * 876 | 7:39:24 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/pchealth/helpctr/binaries/pchsvc. dll | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | MICROSOFT pchealth service holder |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Pchsvc. dll | pchsvc. dll
C:/Windows/system32/svchost.exe * 1032 | 7:39:24 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/explorer. EXE * 1244 | 7:39:12 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/program files/Internet Explorer/iw.e32.win | 14:45:40
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kawdbzy. dll |
C:/Windows/dbhelp. dll | 15:49:16
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/Windows/system32/ctfmon.exe * 1296 | 7:39:12 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kawdbzy. dll |
C:/Windows/dbhelp. dll | 15:49:16
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/Windows/system32/spoolsv.exe * 1508 | 7:53:32 | MICROSOFT? Windows? Operating System | 5.1.2600.2696 | spooler subsystem app |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Microsoft Corporation |? | Spoolsv.exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/program files/rising/RFW/rfwmain.exe * 1708 | 15:55:12 | rising personal firewall 2007 | 5, 0, 0, 0 | rising personal firewall main program | copyright (c) 1998-2007 Beijing rising Technology Corporation Limited | 5, 0, 0, 56 | Beijing rising Technology Co ., ltd. | rising | Beijing rising Technology Co ., ltd. | rfwmain. EXE
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kawdbzy. dll |
C:/Windows/dbhelp. dll | 15:49:16
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
D:/program files/360/safemon/360tray.exe * 1192 | 13:29:58 | 360 tray application | 3, 4, 0, 1001 | 360 real-time security guard protection module | copyright (c) 2006-2007 qihu Network | 3, 4, 0, 1001 | qihu Network | 360 tray | 360tray. EXE
C:/Windows/dbhelp. dll | 15:49:16
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/kawdbzy. dll |
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/program files/rising/rav/rsagent.exe * 2916 | 10:32:32 | rsagent application | 19, 0, 0, 12 | rsagent application | copyright (c) 1998-2007 Beijing rising Technology Corporation Limited | 19, 0, 0, 12 | Beijing rising Technology Co ., ltd. | rising | Beijing rising Technology Co ., ltd. | rsagent. EXE
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/dbhelp. dll | 15:49:16
C:/Windows/system32/kawdbzy. dll |
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/Windows/msagent/agentsvr.exe * 2944 | Microsoft Agent Server | 2.00.0.3424 | Microsoft Agent Server | copyright (c) Microsoft Corp. 1997-98 | 2.00.0.3424 | Microsoft Corporation | agentserver | agentsvr.exe
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/dbhelp. dll | 15:49:16
C:/Windows/system32/kawdbzy. dll |
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/Windows/system32/ctfmon.exe * 3948 | 7:39:12 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/Windows/system32/conime.exe * 3780 | 7:39:12 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | console IME |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Console | conime. exe
C:/Windows/system32/kapjazy. dll | 17:23:46
C:/program files/Internet Explorer/iw.e32.dat | 15:58:58
C:/Windows/dbhelp. dll | 15:49:16
C:/Windows/system32/kawdbzy. dll |
C:/Windows/system32/kvdxbma. dll | 17:19:16, 2007-9-8
C:/Windows/system32/kaqhczy. dll | 17:23:58
C:/program files/Internet Explorer/iw.e32.sys | 14:45:40
Iexplore.exe * 2632
F2-Reg: system. ini: userinit.exe,
O4-hkcu/../policies/Explorer/run: [w] % SystemRoot %/winrar.exe
O4-HKLM/../run: [kVp] C:/Windows/system32/Drivers/svchost.exe
Export procauto = D:/myplayer.com
O20-appinit_dlls: kaqhczy. dll
O23-service: new0 (new0)-C:/Windows/system32/New. sys | 11:27:12 (automatic)
O23-service: NPF (netgroup Packet Filter)-system32/Drivers/NPF. sys | Winpcap netgroup Packet Filter Driver | 3, 1, 0, 27 | NPF | copyright? 2005 cace technologies. Copyright? 2003-2005 netgroup, Politecnico di Torino. | 3, 1, 0, 27 | cace technologies | NPF + tme | NPF. sys (manual)
O23-service: ohilxultraviolet (ohilxultraviolet A)-system32/Drivers/ohilxultraviolet A. sys |? | 1.2.3.1033 |? |? | 1.2.3.1033 | Yahoo! China Corporation |? |? |? (Guide)
O23-service: ws2ifsl (Windows Socket 2.0 non-ifs service provider support environment)-C:/Windows/system32/Drivers/ws2ifsl. sys | MICROSOFT? Windows? Operating System | 5.1.2600.0 | Winsock2 ifs layer |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.0 (xpclient000017-1148) | Microsoft Corporation |? | Ws2ifsl. sys | ws2ifsl. sys (disabled)
O24-shlexechook: [8]-{8562452f-fa36-ba4f-892a-ff5fbbac5318} = C:/Windows/system32/myhpri. dll
O24-shlexechook: [1]-{1598ff45-da60-f48a-bc43-10ac47853d51} = C:/Windows/system32/rarjapi. dll
O24-shlexechook: []-{5d83ad9c-3bfc-43f5-979d-2904dbc54a8e} = C:/program files/Internet Explorer/plugins/winsys64.sys
O24-shlexechook: [B]-{B12BC423-3713-224D-3F55-32B35C62B11B} = C:/Windows/system32/tlvpri. dll
O24-shlexechook: [4]-{4f12545b-1212-1314-5679-4512acef8904} = C:/Windows/system32/wddpri. dll
O24-shlexechook: [9]-{9a65498a-7653-9801-1647-987114ab7f49} = C:/Windows/system32/zxipri. dll
O24-shlexechook: [8]-{84123ff1-8371-9834-9021-184518451fa8} = C:/Windows/system32/qjhpri. dll
O24-shlexechook: [1]-{1c87a354-abc3-de-ff33-3213fd7447c1} = C:/Windows/system32/kvdxama. dll
O24-shlexechook: [7]-{725ab2f3-234a-7469-2f43-e341713abfa7} = C:/Windows/system32/wgupli. dll
O24-shlexechook: [2]-{2231a43a-1642-641a-64fd-146adab223b2} = C:/Windows/system32/mxbman. dll
O24-shlexechook: []-{C5E87A05-F463-4841-B19E-DD3EC3862368} = C:/program files/Internet Explorer/iexplore32.sys
O24-shlexechook: []-{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} = C:/program files/Internet Explorer/iexplore32.win
O24-shlexechook: [2]-{2c87a354-abc3-de-ff33-3213fd7447c2} = C:/Windows/system32/kvdxbma. dll
O24-shlexechook: [2]-{28907901-1416-3389-9981-372178569982} = C:/Windows/system32/kawdbzy. dll
O24-shlexechook: [1]-{1a321487-4977-d98a-c8d5-6488257545a1} = C:/Windows/system32/kapjazy. dll
O25-inscom: {6a202101-f04d-11cf-64cd-31ff5fe1cf20} = C:/Windows/system32/nwiztlbu.exe
. Vbs-
===/
The malicious program impersonates winrar.exe.
Using procauto = D:/myplayer.com is also rare.