Kupqytu. dll/Trojan. win32.undef. fzq, kmwprnp. dll/Trojan. win32.agent. LMO 1
EndurerOriginal
2008-06-031Version
Today, the last user who encountered gjlbj. vya/Trojan. win32.agent. Kle (for details, see gjlbj. vya/Trojan. win32.agent. Kle) said the virus has recursed ~
Pass pe_xscan and send it back to a netizen to scan logs, which is similar to the following:
Pe_xscan 08-04-26 by Purple endurer
6.0.2900.2180
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode
[System process] * 0
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fhrkmik. dll | 2004-8-
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/explorer. EXE * 2036 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.3156 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/ctfmon.exe * 388 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/conime.exe * 464 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | console IME |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Console | conime. exe
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/program files/Internet Explorer/iexplore.exe * 968 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
O22-sharedtaskscheduler: ()-{851d962f-a63e-51e9-63fb-0c941da62fb8} = C:/Windows/system32/qtvnp. dll
O22-sharedtaskscheduler: ()-{62ea63fc-730b-2eb6-30c8-d961ea730c95} = C:/Windows/system32/yacuw. dll
O22-sharedtaskscheduler: ()-{2fb730c9-40d8-fb83-0d95-a63eb740c952} = C:/Windows/system32/wzbtv. dll
O22-sharedtaskscheduler: ()-{D962EA73-EB74-962F-B740-41DA52EB740D} = C:/Windows/system32/npsum. dll
O22-sharedtaskscheduler: ()-{FB830C95-0D95-B840-D961-63FB740D962F} = C:/Windows/system32/bdgxa. dll
O22-sharedtaskscheduler: ()-{EA73FB74-FB84-A73F-C841-51EA62FB841D} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{FB74FC85-0C95-B740-C952-62FB730C952E} = C:/Windows/system32/nprul. dll
O22-sharedtaskscheduler: ()-{C851D962-DA63-851E-A63F-30C941D962FB} = C:/Windows/system32/cehjb. dll
O22-sharedtaskscheduler: ()-{C850D962-DA62-851D-A63E-30C841D962FB} = C:/Windows/system32/wybsv. dll
O22-sharedtaskscheduler: ()-{730c841d-851e-30c9-51ea-eb74fc851ea7} = C:/Windows/system32/dfikc. dll
O22-sharedtaskscheduler: ()-{63fb730c-740d-3fb8-40d9-da63eb740d96} = C:/Windows/system32/knprj. dll
O22-sharedtaskscheduler: ()-{1ea62fb8-3fc7-ea72-fc84-952da63fc851} = C:/Windows/system32/hkmeg. dll
O22-sharedtaskscheduler: ()-{B740C851-C952-740D-952E-2FB830C951EA} = C:/Windows/system32/vxacu. dll
O22-sharedtaskscheduler: ()-{D962EA63-EA73-962E-B730-40D951EA730C} = C:/Windows/system32/jloqi. dll
O22-sharedtaskscheduler: ()-{41d952ea-62ea-1da5-2fb7-c840c952eb74} = C:/Windows/system32/ehjbd. dll
O22-sharedtaskscheduler: ()-{EA63EB74-FB84-A63F-B841-51EA62FB841D} = C:/Windows/system32/moqtk. dll
O22-sharedtaskscheduler: ()-{0d951ea7-2eb6-d961-eb73-841c952eb740} = C:/Windows/system32/cfhzb. dll
O22-sharedtaskschedld: ()-{A63FB740-B841-63FC-841D-1EA72FB840D9} = C:/Windows/system32/egjld. dll
O22-sharedtaskscheduler: ()-{62fb730c-740d-2fb8-40d9-da63eb740d96} = C:/Windows/system32/iknph. dll
O22-sharedtaskscheduler: ()-{52ea62fb-63fb-2ea6-3fc7-c951da63fc85} = C:/Windows/system32/twyqs. dll
O22-sharedtaskscheduler: ()-{1ea62fb8-3fc7-ea72-fc84-952da63fc841} = C:/Windows/system32/zcewy. dll
O22-sharedtaskscheduler: ()-{40c84142551e9-0c94-1ea6-b74fc851ea73} = C:/Windows/system32/kmogi. dll
O22-sharedtaskscheduler: ()-{FC850D96-1DA6-C851-DA63-730C841DA63F} = C:/Windows/system32/psuxo. dll
O22-sharedtaskscheduler: ()-{EA62EB74-FB83-A63E-B840-51E962FB841D} = C:/Windows/system32/moqik. dll
O22-sharedtaskscheduler: ()-{FC840D96-1DA5-C850-DA62-730B841DA63F} = C:/Windows/system32/dgiac. dll
O22-sharedtaskscheduler: ()-{C851D962-DA62-851E-A63F-30C840D962FB} = C:/Windows/system32/suxzr. dll
O22-sharedtaskscheduler: ()-{EB73FC85-0C94-B74F-C951-62FA730C952E} = C:/Windows/system32/ortln. dll
O22-sharedtaskscheduler: ()-{841d952e-962f-4110862fb-fc850d962fb8} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{D961EA63-EA72-962E-B73F-40D851EA730C} = C:/Windows/system32/dfizc. dll
O22-sharedtaskscheduler: ()-{EB74FC85-0C95-B740-C952-62FB730C952E} = C:/Windows/system32/qtvyp. dll
O22-sharedtaskscheduler: ()-{EA73FB84-FC85-A730-C851-52EB63FC851E} = C:/Windows/system32/gilnf. dll
O22-sharedtaskscheduler: ()-{1da62eb7-2fb8-da63-fb84-851e962eb740} = C:/Windows/system32/jloqi. dll
O22-sharedtaskscheduler: ()-{EA72FB84-FC84-A73F-C850-52EA63FC851E} = C:/Windows/system32/oqtkn. dll
O22-sharedtaskscheduler: ()-{740d851e-952e-40d9-52eb-fb840c952ea7} = C:/Windows/system32/xacfw. dll
O22-sharedtaskscheduler: ()-{63fc740d-841d-3fc8-41108ea73fb841da6} = C:/Windows/system32/mprul. dll
O22-sharedtaskscheduler: ()-{C851D962-DA63-851E-A63F-30C941DA63FC} = C:/Windows/system32/gilnf. dll
O22-sharedtaskscheduler: ()-{3fc740d9-41d9-fc84-1da5-a73fb740d962} = C:/Windows/system32/zbevy. dll
O22-sharedtaskscheduler: ()-{B841C951-D952-841D-962E-3FB830C952EB} = C:/Windows/system32/begja. dll
O22-sharedtaskscheduler: ()-{2eb63fc8-30c8-eb73-0c94-962ea63fc851} = C:/Windows/system32/acfwz. dll
O22-sharedtaskscheduler: ()-{52ea63fb-73fb-2eb6-30c8-d951da63fc85} = C:/Windows/system32/begya. dll
O22-sharedtaskscheduler: ()-{B840C851-C952-840D-952E-2FB830C952EB} = C:/Windows/system32/fikme. dll
O22-sharedtaskscheduler: ()-{3fc840c9-40d9-fc84-1d96-a63fb740d962} = C:/Windows/system32/rtwyq. dll
O22-sharedtaskscheduler: ()-{0c941da6-1ea6-c951-ea72-740c851ea63f} = C:/Windows/system32/yadux. dll
O22-sharedtaskscheduler: ()-{0c951da6-1ea7-c952-ea73-740d851ea63f} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{40d95141751ea-0d95-2ea7-b740c851ea73} = C:/Windows/system32/yadfx. dll
O22-sharedtaskscheduler: ()-{3fc740c9-40d8-fc84-1d95-a63eb740d962} = C:/Windows/system32/prulo. dll
O22-sharedtaskscheduler: ()-{30c94142551ea-0c95-1ea7-b740c841da63} = C:/Windows/system32/twybs. dll
O22-sharedtaskscheduler: ()-{0d961ea7-2eb7-d962-eb74-841d952eb740} = C:/Windows/system32/wzbev. dll
O22-sharedtaskscheduler: ()-{30c84142551e9-0c94-1ea6-b74fc841da63} = C:/Windows/system32/dgiac. dll
O22-sharedtaskscheduler: ()-{841c952e-962e-41d9-62fa-fc840d962fb8} = C:/Windows/system32/oqtkn. dll
O22-sharedtaskscheduler: ()-{1ea72fb8-3fc8-ea73-fc85-952ea63fc841} = C:/Windows/system32/xacfw. dll
O22-sharedtaskscheduler: ()-{730b841d-851d-30c8-51e9-eb73fc851ea7} = C:/Windows/system32/xzctw. dll
O22-sharedtaskscheduler: ()-{952ea63f-a730-52eb-730c-0d961ea730c8} = C:/Windows/system32/pruwo. dll
O22-sharedtaskscheduler: ()-{41da52ea-62eb-1da6-2fb7-c841c952eb74} = C:/Windows/system32/qtvyp. dll
O22-sharedtaskscheduler: ()-{62fa730c-740c-2fb7-40d8-da62eb740d96} = C:/Windows/system32/wybsv. dll
O22-sharedtaskscheduler: ()-{B740C851-C952-740D-952E-2FB830C851EA} = C:/Windows/system32/tvyas. dll
O22-sharedtaskscheduler: ()-{2ea62fb8-3fc7-ea72-fc84-952da63fc851} = C:/Windows/system32/egiac. dll
O22-sharedtaskscheduler: ()-{51ea62eb-62fb-1ea6-3fb8-c851d962fb84} = C:/Windows/system32/lnqsk. dll
No new startup items found ......
At noon, I went to the Netizen's house to check and found that the virus was quite cool: The security mode could not go in, the Security Assistant of rising star Kaka, and Kingsoft's cleaning experts could not run, and hijackthis would be deleted as soon as it was run ~
Download bat_do and fileinfo to the http://purpleendurer.ys168.com.
Use fileinfo to extract Suspicious File Information, use bat_do to delete it in a delayed manner, generate a command to remove attributes, delete attributes, and rename the file, and execute the command at the next startup.
When regedit.exe is run, two startup items for viruses are accidentally found when o22 is deleted:
/---
"{Region}" = "oytucxy.exe C: // windows // system32 // {62d4650a-ea5c-3fa1-fb6d-ea5ced82fd02} // kupqytu. dll S"
"{Signature}" = "oqatvrt.exe C: // windows // system32 // {6e8bbb5c-e603-3b58-f714-e60333d4b63d} // kmwprnp. dll S"
---/
The position of the startup Item is odd. It is estimated that no system analysis scanner can scan the item ~
(To be continued)