The system time is modified to use the xibgptd.exe, netdde32.exe, and so on.
EndurerOriginal
1Version
(Continued log)
O9-IE Toolbar extension button HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exe
O9-ie tool menu extension item HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exe
O20-appinit_dlls: jzupli. dll
O23-service: aea6eaec (aea6eaec)-C:/Windows/system32/2dd519ed. exe-p | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |? (Automatic)
O23-service: eaglent (eaglent)-C:/Windows/system32/Drivers/eaglent. sys (manual)
O23-service: he1p (he1p)-C:/Windows/system32/he1p.exe-service | MICROSOFT (r) Windows (r) operating System | 5.1.2600.2180 | iexplorer | copyright (c) 2007 | 1, 0, 0, 1 | Microsoft Corporation | iexplorer | iexplorer.exe (automatic)
O23-service: qgqelbr (qgqelbr)-C:/Windows/system32/Drivers/qgqelbr. sys | 14:13:22 | sys application | 1, 0, 1, 3 | sys application | copyright (c) 2006 | 1, 0, 1, 3 | Beijing sanqi eryi Technology Co., Ltd. |? | Sys | sys.exe (pilot)
O23-service: remotedbg (Remote debug Service)-C:/Windows/system32/rundll32.exe remotedbg. dll, input (automatic)
O23-service: svchost (svchost)-C:/Windows/system32/dllcache/svchost.exe-G | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |? (Automatic)
O23-service: svcsvr (svcsvr)-C:/Windows/svrsvc.exe | (automatic)
O23-service: tessafe (tessafe)-C:/Windows/system32/tessafe. sys | 13:39:28 (manual)
O23-service: windhcpsvc (Windows Dhcp Service)-C:/Windows/system32/rundll32.exe windhcp. ocx, input (automatic)
O24-shlexechook: []-{16b05af4-16b0-9e38-f49e-5af49e38d27c} = C:/Windows/system32/jqxelw. dll
O24-shlexechook: []-{32311a42-ac1b-158f-fd32-5674345f23a3} = C:/Windows/system32/dhcpri. dll
O24-shlexechook: []-{525ab2f3-234a-7469-2f43-e341713abfa5} = C:/Windows/system32/wgepri. dll
O24-shlexechook: []-{4562452f-fa36-ba4f-892a-ff5fbbac5314} = C:/Windows/system32/mydpri. dll
O24-shlexechook: []-{759afd5b-159f-acd8-954c-acd545fa6587} = C:/Windows/system32/jzupli. dll
O26-ifeo: 360rpt.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: 360safe.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: 360tray.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: adam.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: agentsvr.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: unzip vc32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: arswp.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ast.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: autoruns.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: avconsol.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: avgrssvc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: avmonitor.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: avp.com-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: avp.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ccenter.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ccsvchst.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: eghost.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: assumer.exe-> C:/Windows/system32/netdde32.exe
O26-ifeo: filedsty.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ftcleanershell.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: fyfirewall.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: hijackthis.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: icesword.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: iparmo.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: iparmor.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ispwdsvc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kabaload.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kascrscn. scr-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kasmain.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kastask.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kav32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kavdx.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kavpf.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kavpfw.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kavsetup.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kavstart.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kislnchr.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kmailmon.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kmfilter.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kpfw32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kpfw32x.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kpfwsvc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kregex.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: krepair.com-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ksloader.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvcenter. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvdetect.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvfwmcl.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvmonxp. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvmonxp_1.kxp-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvol.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvolself.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvreport. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvscan. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvsrvxp.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvstub. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvupload.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvwsc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvxp. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kvxp_1.kxp-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kwatch.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kwatch9x.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: kwatchx.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: loaddll.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: magicset.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: mcconsol.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: mmqczj.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: mmsk.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: navapsvc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: navapw32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: nod32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: nod32krn.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: nod32kui.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: npfmntor.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: pfw.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: pfwliveupdate.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qhset.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qqdoctor.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qqkav.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qqliveupdate.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qqsc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: qqupdatecenter.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ras.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rav.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ravmon.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ravmond.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ravstub.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: ravtask.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: regclean.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rfwcfg.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rfwmain.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rfwsrv.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rsagent.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rsaupd.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: rstrui.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: runiep.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: safelive.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: scan32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: shw.32.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: smartup.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: Sreng. exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: symlcsvc.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: syssafe.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: timwp.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: trojandetector.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: trojanwall.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: trojdie. KXP-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: uihost.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: umxagent.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: umxattachment.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: umxw..exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: umxfwhlp.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: umxpol.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: upiea.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: uplive.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: usbcleaner.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: vsstat.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: webscanx.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
O26-ifeo: wopticlean.exe-> C:/program files/common files/Microsoft shared/xibgptd.exe
The HKLM/showall value is not 1.
===/
The system time has been changed.
Use Image hijacking to prevent anti-virus software from starting.
Modified the hosts file to prevent the anti-virus software from being upgraded.
Use ie (O2), System Service (o23), shell exec hook (o24), and autorun. inf (O4) to activate malicious programs.