Beep. sys/backdoor. win32.agent, dova/backdoor. win32.hupigon, myrat. rmvb/Trojan. win32.delf, etc. 1

Source: Internet
Author: User
Tags snmp

Beep. sys/backdoor. win32.agent, dova/backdoor. win32.hupigon, myrat. rmvb/Trojan. win32.delf, etc. 1

Original endurer
2008-06-20 1st

A friend's computer recently experienced a slow computer response. Rising detected the virus. After clearing the computer, the computer appeared again. In addition, the system often prompts that the system file is replaced, prompting you to insert a system disc for recovery. Please help. Open the task manager and find that a process named 1.exe takes a lot of CPU time and terminates it first. Pe_xscan is used to scan logs and analyze the logs. The following suspicious items are found:

Pe_xscan 08-04-26 by Purple endurer 16:15:56 Windows XP Service Pack 2 (5.1.2600) MSIE: 6.0.2900.2180 administrator user group normal mode C:/Windows/system32/SVCHOST. EXE * 996 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe C:/Windows/system32/bitsex. DLL | svchost | 5.1.2600.2180 | Microsoft SNMP manager API (uses winsnmp) | copyright @ 2004 | 5.1.2600.2180 | @ Microsoft Corporation. all rights reserved. | svchost | SVCHOST. dll c:/Windows/system32/shared/smss.exe * 1664 | 2:44:14 C:/Windows/system32/SVCHOST. EXE * 1696 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe C:/program files/myrat. rmvb | 2:44:19 | 1.0.0.0 | 1.0.0.500 | C:/Windows/system32/shared/services.exe * 328 | F2-Reg: system. INI: userinit = <USERINIT. EXE, C:/Windows/system32/kinds/1.exe> o23-service: adhelper (Active Directory helper)-C:/Windows/system32/shared/smss.exe | 2:44:14 (automatic) o23-service: bits (Background Intelligent Transfer Service)-C:/Windows/system32/svchost.exe-K netsvcs-> C:/Windows/system32/bitsex. DLL | svchost | 5.1.2600.2180 | Microsoft SNMP manager API (uses winsnmp) | copyright @ 2004 | 5.1.2600.2180 | @ Microsoft Corporation. all rights reserved. | svchost | SVCHOST. DLL (automatic) o23-service: COM + event (COM + Event irat)-C:/Windows/system32/svchost.exe-K krnlsrvc-> C: /program files/myrat. rmvb | 2:44:19 | 1.0.0.0 | 1.0.0.500 | (automatic) o23-service: Drivers desktop (drivers Desktop Management)-C: /Windows/system32/explore.exe | 2:44:38 (automatic) o23-service: microsoftpvsy (microsoftpvsy)-C:/Windows/dova | (automatic)

From the log, the final path 1.exe corresponds to the C:/Windows/system32/kinds/1.exe file.

(To be continued)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.