Kupqytu. dll/Trojan. win32.undef. fzq, kmwprnp. dll/Trojan. win32.agent. LMO 1

Source: Internet
Author: User

Kupqytu. dll/Trojan. win32.undef. fzq, kmwprnp. dll/Trojan. win32.agent. LMO 1

EndurerOriginal
2008-06-031Version

Today, the last user who encountered gjlbj. vya/Trojan. win32.agent. Kle (for details, see gjlbj. vya/Trojan. win32.agent. Kle) said the virus has recursed ~

Pass pe_xscan and send it back to a netizen to scan logs, which is similar to the following:

 

 

Pe_xscan 08-04-26 by Purple endurer

6.0.2900.2180
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode

[System process] * 0
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fhrkmik. dll | 2004-8-
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/explorer. EXE * 2036 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.3156 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/ctfmon.exe * 388 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/conime.exe * 464 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | console IME |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Console | conime. exe
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/program files/Internet Explorer/iexplore.exe * 968 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/fhrkmik. dll |
C:/Windows/system32/xzjceac. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jlvoqmo. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
C:/Windows/system32/fpkltop. dll | 1666-12-28
C:/Windows/system32/xhcdlgh. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | advanced windows 32 base API | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Advapi32.dll | advapi32.dll
C:/Windows/system32/jtopxst. DLL | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.3119 | Windows NT base API client DLL | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) | Microsoft Corporation |? | Kernel32 | Kernel32
O22-sharedtaskscheduler: ()-{851d962f-a63e-51e9-63fb-0c941da62fb8} = C:/Windows/system32/qtvnp. dll
O22-sharedtaskscheduler: ()-{62ea63fc-730b-2eb6-30c8-d961ea730c95} = C:/Windows/system32/yacuw. dll
O22-sharedtaskscheduler: ()-{2fb730c9-40d8-fb83-0d95-a63eb740c952} = C:/Windows/system32/wzbtv. dll
O22-sharedtaskscheduler: ()-{D962EA73-EB74-962F-B740-41DA52EB740D} = C:/Windows/system32/npsum. dll
O22-sharedtaskscheduler: ()-{FB830C95-0D95-B840-D961-63FB740D962F} = C:/Windows/system32/bdgxa. dll
O22-sharedtaskscheduler: ()-{EA73FB74-FB84-A73F-C841-51EA62FB841D} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{FB74FC85-0C95-B740-C952-62FB730C952E} = C:/Windows/system32/nprul. dll
O22-sharedtaskscheduler: ()-{C851D962-DA63-851E-A63F-30C941D962FB} = C:/Windows/system32/cehjb. dll
O22-sharedtaskscheduler: ()-{C850D962-DA62-851D-A63E-30C841D962FB} = C:/Windows/system32/wybsv. dll
O22-sharedtaskscheduler: ()-{730c841d-851e-30c9-51ea-eb74fc851ea7} = C:/Windows/system32/dfikc. dll
O22-sharedtaskscheduler: ()-{63fb730c-740d-3fb8-40d9-da63eb740d96} = C:/Windows/system32/knprj. dll
O22-sharedtaskscheduler: ()-{1ea62fb8-3fc7-ea72-fc84-952da63fc851} = C:/Windows/system32/hkmeg. dll
O22-sharedtaskscheduler: ()-{B740C851-C952-740D-952E-2FB830C951EA} = C:/Windows/system32/vxacu. dll
O22-sharedtaskscheduler: ()-{D962EA63-EA73-962E-B730-40D951EA730C} = C:/Windows/system32/jloqi. dll
O22-sharedtaskscheduler: ()-{41d952ea-62ea-1da5-2fb7-c840c952eb74} = C:/Windows/system32/ehjbd. dll
O22-sharedtaskscheduler: ()-{EA63EB74-FB84-A63F-B841-51EA62FB841D} = C:/Windows/system32/moqtk. dll
O22-sharedtaskscheduler: ()-{0d951ea7-2eb6-d961-eb73-841c952eb740} = C:/Windows/system32/cfhzb. dll
O22-sharedtaskschedld: ()-{A63FB740-B841-63FC-841D-1EA72FB840D9} = C:/Windows/system32/egjld. dll
O22-sharedtaskscheduler: ()-{62fb730c-740d-2fb8-40d9-da63eb740d96} = C:/Windows/system32/iknph. dll
O22-sharedtaskscheduler: ()-{52ea62fb-63fb-2ea6-3fc7-c951da63fc85} = C:/Windows/system32/twyqs. dll
O22-sharedtaskscheduler: ()-{1ea62fb8-3fc7-ea72-fc84-952da63fc841} = C:/Windows/system32/zcewy. dll
O22-sharedtaskscheduler: ()-{40c84142551e9-0c94-1ea6-b74fc851ea73} = C:/Windows/system32/kmogi. dll
O22-sharedtaskscheduler: ()-{FC850D96-1DA6-C851-DA63-730C841DA63F} = C:/Windows/system32/psuxo. dll
O22-sharedtaskscheduler: ()-{EA62EB74-FB83-A63E-B840-51E962FB841D} = C:/Windows/system32/moqik. dll
O22-sharedtaskscheduler: ()-{FC840D96-1DA5-C850-DA62-730B841DA63F} = C:/Windows/system32/dgiac. dll
O22-sharedtaskscheduler: ()-{C851D962-DA62-851E-A63F-30C840D962FB} = C:/Windows/system32/suxzr. dll
O22-sharedtaskscheduler: ()-{EB73FC85-0C94-B74F-C951-62FA730C952E} = C:/Windows/system32/ortln. dll
O22-sharedtaskscheduler: ()-{841d952e-962f-4110862fb-fc850d962fb8} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{D961EA63-EA72-962E-B73F-40D851EA730C} = C:/Windows/system32/dfizc. dll
O22-sharedtaskscheduler: ()-{EB74FC85-0C95-B740-C952-62FB730C952E} = C:/Windows/system32/qtvyp. dll
O22-sharedtaskscheduler: ()-{EA73FB84-FC85-A730-C851-52EB63FC851E} = C:/Windows/system32/gilnf. dll
O22-sharedtaskscheduler: ()-{1da62eb7-2fb8-da63-fb84-851e962eb740} = C:/Windows/system32/jloqi. dll
O22-sharedtaskscheduler: ()-{EA72FB84-FC84-A73F-C850-52EA63FC851E} = C:/Windows/system32/oqtkn. dll
O22-sharedtaskscheduler: ()-{740d851e-952e-40d9-52eb-fb840c952ea7} = C:/Windows/system32/xacfw. dll
O22-sharedtaskscheduler: ()-{63fc740d-841d-3fc8-41108ea73fb841da6} = C:/Windows/system32/mprul. dll
O22-sharedtaskscheduler: ()-{C851D962-DA63-851E-A63F-30C941DA63FC} = C:/Windows/system32/gilnf. dll
O22-sharedtaskscheduler: ()-{3fc740d9-41d9-fc84-1da5-a73fb740d962} = C:/Windows/system32/zbevy. dll
O22-sharedtaskscheduler: ()-{B841C951-D952-841D-962E-3FB830C952EB} = C:/Windows/system32/begja. dll
O22-sharedtaskscheduler: ()-{2eb63fc8-30c8-eb73-0c94-962ea63fc851} = C:/Windows/system32/acfwz. dll
O22-sharedtaskscheduler: ()-{52ea63fb-73fb-2eb6-30c8-d951da63fc85} = C:/Windows/system32/begya. dll
O22-sharedtaskscheduler: ()-{B840C851-C952-840D-952E-2FB830C952EB} = C:/Windows/system32/fikme. dll
O22-sharedtaskscheduler: ()-{3fc840c9-40d9-fc84-1d96-a63fb740d962} = C:/Windows/system32/rtwyq. dll
O22-sharedtaskscheduler: ()-{0c941da6-1ea6-c951-ea72-740c851ea63f} = C:/Windows/system32/yadux. dll
O22-sharedtaskscheduler: ()-{0c951da6-1ea7-c952-ea73-740d851ea63f} = C:/Windows/system32/mortl. dll
O22-sharedtaskscheduler: ()-{40d95141751ea-0d95-2ea7-b740c851ea73} = C:/Windows/system32/yadfx. dll
O22-sharedtaskscheduler: ()-{3fc740c9-40d8-fc84-1d95-a63eb740d962} = C:/Windows/system32/prulo. dll
O22-sharedtaskscheduler: ()-{30c94142551ea-0c95-1ea7-b740c841da63} = C:/Windows/system32/twybs. dll
O22-sharedtaskscheduler: ()-{0d961ea7-2eb7-d962-eb74-841d952eb740} = C:/Windows/system32/wzbev. dll
O22-sharedtaskscheduler: ()-{30c84142551e9-0c94-1ea6-b74fc841da63} = C:/Windows/system32/dgiac. dll
O22-sharedtaskscheduler: ()-{841c952e-962e-41d9-62fa-fc840d962fb8} = C:/Windows/system32/oqtkn. dll
O22-sharedtaskscheduler: ()-{1ea72fb8-3fc8-ea73-fc85-952ea63fc841} = C:/Windows/system32/xacfw. dll
O22-sharedtaskscheduler: ()-{730b841d-851d-30c8-51e9-eb73fc851ea7} = C:/Windows/system32/xzctw. dll
O22-sharedtaskscheduler: ()-{952ea63f-a730-52eb-730c-0d961ea730c8} = C:/Windows/system32/pruwo. dll
O22-sharedtaskscheduler: ()-{41da52ea-62eb-1da6-2fb7-c841c952eb74} = C:/Windows/system32/qtvyp. dll
O22-sharedtaskscheduler: ()-{62fa730c-740c-2fb7-40d8-da62eb740d96} = C:/Windows/system32/wybsv. dll
O22-sharedtaskscheduler: ()-{B740C851-C952-740D-952E-2FB830C851EA} = C:/Windows/system32/tvyas. dll
O22-sharedtaskscheduler: ()-{2ea62fb8-3fc7-ea72-fc84-952da63fc851} = C:/Windows/system32/egiac. dll
O22-sharedtaskscheduler: ()-{51ea62eb-62fb-1ea6-3fb8-c851d962fb84} = C:/Windows/system32/lnqsk. dll

No new startup items found ......

At noon, I went to the Netizen's house to check and found that the virus was quite cool: The security mode could not go in, the Security Assistant of rising star Kaka, and Kingsoft's cleaning experts could not run, and hijackthis would be deleted as soon as it was run ~

Download bat_do and fileinfo to the http://purpleendurer.ys168.com.

Use fileinfo to extract Suspicious File Information, use bat_do to delete it in a delayed manner, generate a command to remove attributes, delete attributes, and rename the file, and execute the command at the next startup.

When regedit.exe is run, two startup items for viruses are accidentally found when o22 is deleted:
/---
"{Region}" = "oytucxy.exe C: // windows // system32 // {62d4650a-ea5c-3fa1-fb6d-ea5ced82fd02} // kupqytu. dll S"
"{Signature}" = "oqatvrt.exe C: // windows // system32 // {6e8bbb5c-e603-3b58-f714-e60333d4b63d} // kmwprnp. dll S"
---/

The position of the startup Item is odd. It is estimated that no system analysis scanner can scan the item ~

(To be continued)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.