Rootkit. win32.kernelbot, rootkit. win32.mnless, Trojan. win32.patched, backdoor. win32.rwx, etc. 1
EndurerOriginal
2008-07-141Version
A friend recently experienced a slow computer response. When using QQ, he always asked for activation. he suspected that he had hacked Trojans in the computer. Please help me with the repair.
Download pe_xscan and run it. Use the task manager to stop the assumer.exe process, scan logs, and analyze the logs. The following suspicious items are found:
Pe_xscan 08-07-01 by Purple endurer
Windows XP Service Pack 2 (5.1.2600)
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode
C:/Windows/system32/winlogon.exe * 992 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/WBEM/wmideprv. DLL | 11:56:11 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | WMI | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Wmisvc. dll | wmisvc. dll
C:/Windows/system32/winlib. dll
C:/Windows/system32/svchost.exe * 1236 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/Proxy. dll | com services | 03.00.00.4414 |? | Copyright (c) Microsoft Corp. 1995-1999 | 2001.12.4414.308 | Microsoft Corporation | MICROSOFT (R) is a registered trademark of Microsoft Corporation. windows (TM) is a trademark of Microsoft Corporation | colbact. DLL |?
C:/Windows/system32/svchost.exe * 1380 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/Proxy. dll | com services | 03.00.00.4414 |? | Copyright (c) Microsoft Corp. 1995-1999 | 2001.12.4414.308 | Microsoft Corporation | MICROSOFT (R) is a registered trademark of Microsoft Corporation. windows (TM) is a trademark of Microsoft Corporation | colbact. DLL |?
C:/Windows/system32/svchost.exe * 1464 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/Proxy. dll | com services | 03.00.00.4414 |? | Copyright (c) Microsoft Corp. 1995-1999 | 2001.12.4414.308 | Microsoft Corporation | MICROSOFT (R) is a registered trademark of Microsoft Corporation. windows (TM) is a trademark of Microsoft Corporation | colbact. DLL |?
Tool bar BHO-{489873ce-f3e1-44a3-8e89-04be26be4446} = C:/program files/zztoolbar/toolbar_bho.dll | 6:18:32
O2-BHO-{54fae856-ad58-20cb-a025-cd4895fa6e45} = C:/Windows/system32/pjjxedwd. dll | 6:40:39
O2-BHO-{6e091341-6715-2098-51f0-178425ae53e6} = C:/Windows/system32/fgsbkuy. dll |
O9-IE Toolbar extension button HKLM: Knowledge Base-{06926b30-450e-4f1c-8ee3-543cd96573dc}-hxxp: // blank. La /? H
O9-ie tool menu extension item HKLM:-{06926b30-450e-4f1c-8ee3-543cd96573dc}-hxxp: // blank. La /? H
O20-appinit_dlls = zembila. dll, msbod. dll, quaryfy. dll, verpthr. dll, wpuplder. dll, padlevels. dll, jordspa. dll, verptw. dll
O20-Winlogon notify: wmiApSrv-C:/Windows/system32/WBEM/wmideprv. dll | 11:56:11
O23-service: acpidisk (acpidisk)-C:/Windows/system32/Drivers/acpidisk. sys | 1:27:25 (automatic)
O23-service: apcdli (apcdli)-C:/program files/Microsoft Office/system/apcdli. sys (automatic)
O23-service: Connection Sharing (icekers) (winddows system32 services)-C:/events and settings/all users/s2.exe (automatic)
O23-service: ntptdb ()-C:/Documents and Settings/all users/Application Data/Microsoft/office/system/ntptdb. sys (automatic)
O23-service: spcvlsvs (spcvl SRV)-C:/Windows/system32/spcvls.exe | (automatic)
O23-service: spcvlsvsdrv (spcvlsvsdrv)-C:/Windows/system32/spcvls. sys (manual)
O23-service: tyts9 (tyts9)-system32/Drivers/tyts9.sys (pilot)
O23-service: wmiacpi (Microsoft Windows Management Interface for ACPI)-system32/Drivers/wmiacpi. sys | (system)
O23-service: xbn3u0q (xbn3u0q)-system32/Drivers/xbn3u0q. sys | (BOOT)
O24-shlexechook: [Microsoft]-{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC} = C:/Windows/system32/wklsdd. dll
O24-shlexechook: [Microsoft]-{C0595A7E-2E2F-4B34-A83A-019270A0A464} = C:/Windows/system32/tdffdl. dll
O24-shlexechook: [Microsoft]-{8c41b7f7-4408-400d-a702-0e7efe0ba304} = C:/Windows/system32/sgrefg. dll
O24-shlexechook: [Microsoft]-{6e6ca8a1-81bc-4707-a54c-f4903dd70bad} = C:/Windows/system32/zgxfdx. dll
O24-shlexechook: [Microsoft]-{17dfd111-bf3a-4cb4-adb0-88fcbfe69821} = C:/Windows/system32/hhrdxd. dll
O24-shlexechook: [Microsoft]-{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6} = C:/Windows/system32/fsrgeb. dll
O24-shlexechook: [Microsoft]-{7e54996d-821e-4631-87fa-406383955a10} = C:/Windows/system32/qdsrfn. dll
O24-shlexechook: [Microsoft]-{1e51c0fd-ee36-434b-ad2a-fd1ff3731c38} = C:/Windows/system32/wyrsdj. dll
O24-shlexechook: [Microsoft]-{45aadfaa-dd36-42ab-83ad-0521bbf58c24} = C:/Windows/system32/zgrjdx. dll
O24-shlexechook: [5]-{54fae856-ad58-20cb-a025-cd4895fa6e45} = C:/Windows/system32/pjjxedwd. dll | 6:40:39, 2004-8-8
O24-shlexechook: [Microsoft]-{189f087f-4378-405f-85fa-37d955ad7a8c} = C:/Windows/system32/mtewdh. dll
O24-shlexechook: [6]-{6e091341-6715-2098-51f0-178425ae53e6} = C:/Windows/system32/fgsbkuy. dll |
O24-shlexechook: [Microsoft]-{84143167-b645-4bff-b873-da1dc886e9a7} = C:/Windows/system32/cedafb. dll
O24-shlexechook: [3]-{3d698451-2015-6358-9871-2015987452d3} = 3
O24-shlexechook: [6]-{6c648541-1025-9650-9057-637958720c6} = 6
O26-ifeo: adam.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: agentsvr.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: unzip vc32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ati2evxx.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: autoruns.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: avconsol.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: avgrssvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: avmonitor.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: avp.com-> C:/Windows/system32/svchost.exe
O26-ifeo: avp.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ccenter.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ccsvchst.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: egui.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: esafe.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: filedsty.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ftcleanershell.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: hijackthis.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: icesword.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: idag.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: iparmor.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ispwdsvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kabaload.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kaccore.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kascrscn. scr-> C:/Windows/system32/svchost.exe
O26-ifeo: kasmain.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kastask.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kav32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavdx.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavpf.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavpfw.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavsetup.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavstart.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavsvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kavsvcui.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kislnchr.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kissvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kmailmon.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kmfilter.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kpfw32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kpfwsvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kppmain.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kregex.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: krepair.com-> C:/Windows/system32/svchost.exe
O26-ifeo: ksloader.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvcenter. KXP-> C:/Windows/system32/svchost.exe
O26-ifeo: kvdetect.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvfw. exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvfwmcl.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvmonxp_1.kxp-> C:/Windows/system32/svchost.exe
O26-ifeo: kvol.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvolself.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvreport. KXP-> C:/Windows/system32/svchost.exe
O26-ifeo: kvscan. KXP-> C:/Windows/system32/svchost.exe
O26-ifeo: kvsrvxp.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvstub. KXP-> C:/Windows/system32/svchost.exe
O26-ifeo: kvupload.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kvwsc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kwatch.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kwatch9x.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: kwatchx.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: magicset.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: mcconsol.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: mmqczj.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: mmsk.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: navapsvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: navapw32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: nod32krn.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: npfmntor.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ollydbg. exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ollyice. exe-> C:/Windows/system32/svchost.exe
O26-ifeo: pfw.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: pfwliveupdate.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: procexp.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: qhset.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: qqkav.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: qqsc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ras.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rav.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravmon.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravmond.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravstub.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravtask.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravtimer.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: ravtool.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: regclean.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: regtool.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rfwmain.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rfwproxy.exefyfirewall.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rfwsrv.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rfwstub.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rising.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: rsaupd.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: runiep.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: safelive.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: scan32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: shw.32.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: smartup.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: Sreng. exe-> C:/Windows/system32/svchost.exe
O26-ifeo: symlcsvc.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: syssafe.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: trojandetector.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: trojanwall.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: trojdie. KXP-> C:/Windows/system32/svchost.exe
O26-ifeo: uihost.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: umxagent.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: umxattachment.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: umxcmd.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: umxfwhlp.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: umxpol.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: uplive.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: vsstat.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: webscanx.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: windbg.exe-> C:/Windows/system32/svchost.exe
O26-ifeo: wopticlean.exe-> C:/Windows/system32/svchost.exe
O29-hkcu-start page = hxxp: // about. Blank. LA? G
(To be continued)