Trojan. psw. win32.gameol, Trojan. win32.undef, Trojan. DL. win32.undef, etc. 1
Original endurer
Version 1st
Today, a friend's computer was very slow. Please help me with the repair.
Start the task manager and find a strange process named kcodn32.exe.
Pe_xscan is used to scan log analysis and the following suspicious items are found:
/=
Pe_xscan 08-08-01 by Purple endurer
17:36:12
Windows XP Service Pack 2 (5.1.2600)
MSIE: 6.0.2900.2180
Administrator user group
Normal Mode
[System process] * 0
C:/Windows/system32/tisqctyu. dll | 7:41:14
C:/Windows/system32/mmwlangh1006.dll | 7:44:43, 2000-7-9
C:/Windows/system32/imgutilhx2.dll | 7:42:53, 2001-7-9
C:/Windows/system32/ksuserfy. dll | 7:42:47, 2001-7-9
C:/Windows/system32/dispexcb. dll | 7:42:40, 2001-7-9
C:/Windows/system32/tscfgwmijxsj. dll | 7:42:34
C:/Windows/system32/bootvidgj. dll | 7:42:27, 2001-7-9
C:/Windows/system32/msobjstl. dll | 7:42:21, 2001-7-9
C:/Windows/system32/cliconfgzx. dll | 7:42:14, 2001-7-9
C:/Windows/system32/adsntzt. dll |
C:/Windows/system32/dpvvoxmh. dll |
C:/Windows/system32/winlogon.exe * 640 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/nhmxejkl. dll |
C:/Windows/system32/tisqctyu. dll | 7:41:14
C:/Windows/system32/mmwlangh1006.dll | 7:44:43, 2000-7-9
C:/Windows/system32/services.exe * 684 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | services and controller app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Services.exe
C:/Windows/system32/nhmxejkl. dll |
C:/Windows/system32/tisqctyu. dll | 7:41:14
C:/Windows/system32/mmwlangh1006.dll | 7:44:43, 2000-7-9
C:/Windows/system32/lsass.exe * 696 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | LSA shell (export version) |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Lsass.exe
C:/Windows/system32/nhmxejkl. dll |
C:/Windows/system32/tisqctyu. dll | 7:41:14
C:/Windows/system32/mmwlangh1006.dll | 7:44:43, 2000-7-9
C:/Windows/system32/svchost.exe * 840 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/nhmxejkl. dll |
C:/Windows/system32/tisqctyu. dll | 7:41:14
C:/Windows/system32/mmwlangh1006.dll | 7:44:43, 2000-7-9
C:/Windows/system32/kcodn32.dll | 23:58:35
C:/Windows/system32/imgutilhx2.dll | 7:42:53, 2001-7-9
C:/Windows/system32/ksuserfy. dll | 7:42:47, 2001-7-9
C:/Windows/system32/dispexcb. dll | 7:42:40, 2001-7-9
C:/Windows/system32/tscfgwmijxsj. dll | 7:42:34
C:/Windows/system32/bootvidgj. dll | 7:42:27, 2001-7-9
C:/Windows/system32/msobjstl. dll | 7:42:21, 2001-7-9
C:/Windows/system32/cliconfgzx. dll | 7:42:14, 2001-7-9
C:/Windows/system32/adsntzt. dll |
C:/Windows/system32/dpvvoxmh. dll |
R3-urlsearchhook: srchhook class-{F08555B0-9CC3-11D2-AA8E-000000000000}-C:/program files/hottools/iebho. dll
F2-shell = <assumer.exe,, glasf.exe>
O2-BHO-{38093456-9012-4568-9076-908765467183} = C:/Windows/system32/tisqctyu. dll | 7:41:14
O2-BHO-{43512378-9874-5641-1025-985420368734} = C:/Windows/system32/oswxdttb. dll | 7:41:35
O2-BHO-{57ac9076-c898-b098-d098-a18342580975} = C:/Windows/system32/nhmxejkl. dll |
O2-BHO srchhook class-{F08555B0-9CC3-11D2-AA8E-000000000000} = C:/program files/hottools/iebho. dll |
O3-IE Toolbar: shortcut toolbar 3.21-{BE830FD4-E393-417F-9F4B-CC70ABB3384C} = C:/program files/hottools/ietool. dll |
O4-HKLM/../run: [svchost] C:/Windows/MDM. exe
O4-HKLM/../policies/Explorer/run: [kcodn] kcodn32.exe
C:/autorun. inf
/-----
[Autorun]
Opentracing ravmon.exe
Shell/open = open (& O)
Shell/Open/command#ravmon.exe
Shell/volume E = Resource Manager (& X)
Shell/movie E/command = "ravmon.exe-e"
-----/
D:/autorun. inf
/-----
[Autorun]
Opentracing ravmon.exe
Shell/open = open (& O)
Shell/Open/command#ravmon.exe
Shell/volume E = Resource Manager (& X)
Shell/movie E/command = "ravmon.exe-e"
-----/
O20-appinit_dlls = pocolieov. DLL, nhmxejkl. DLL, tisqctyu. DLL, momusi. DLL, hwofw. DLL, webliso. DLL, wisoko. DLL, jerryi. DLL, xxpopo. DLL, jelens. DLL, jozasus. DLL, zbioscok. DLL, mmwlangh1006.dll
O21-ssodl-dpvvoxmh. dll (0)-{00070007-0007-0007-0007-00070007bb15} = C:/Windows/system32/dpvvoxmh. dll |
O21-ssodl-adsntzt. dll (0)-{00010001-0001-0001-0001-0001-00010001bb15} = C:/Windows/system32/adsntzt. dll |
O21-ssodl-cliconfgzx. dll (0)-{00050005-0005-0005-0005-00050005bb15} = C:/Windows/system32/cliconfgzx. dll | 7:42:14
O21-ssodl-msobjstl. dll (1)-{00170017-0017-0017-0017-00170017bb15} = C:/Windows/system32/msobjstl. dll | 7:42:21
O21-ssodl-bootvidgj. dll (0)-{00030003-0003-0003-0003-00030003bb15} = C:/Windows/system32/bootvidgj. dll | 7:42:27
O21-ssodl-tscfgwmijxsj. dll (3)-{00330033-0033-0033-0033-00330033bb15} = C:/Windows/system32/tscfgwmijxsj. dll | 7:42:34
O21-ssodl-dispexcb. dll (0)-{00060006-0006-0006-0006-00060006bb15} = C:/Windows/system32/dispexcb. dll | 7:42:40
O21-ssodl-ksuserfy. dll (1)-{00130013-0013-0013-0013-00130013bb15} = C:/Windows/system32/ksuserfy. dll | 7:42:47
O21-ssodl-imgutilhx2.dll (0)-{00300030-0030-0030-0030-00300030bb15} = C:/Windows/system32/imgutilhx2.dll | 7:42:53
O23-service: 682247f847c41458 (682247f847c41458)-C:/682247f847c41458. dat (manual)
O23-service: 807937ac67f36f77 (807937ac67f36f77)-C:/807937ac67f36f77. dat (manual)
O23-service: aa12ddf439b88f8 (aa12ddf439b88f8)-C:/aa12ddf439b88blob. dat (manual)
O23-service: hiddfldy (hiddfldy)-C:/Windows/system32/d32dx9. sys | 2000-7-9 (automatic)
O23-service: mscodesrv ()-C:/Windows/temp/runassrv.exe runsrv/name: "mscodesrv"/prinum: "32"/inter/Character Line: C: /Windows/autohal.exe-pssp S-1-5-21-2000478354-842925246-1202660629-500 "(automatic)
O24-shlexechook: [5]-{55694105-5108-9405-3695-954187462155} = C:/Windows/system32/mpwdeapi. dll | 7:40:46
O24-shlexechook: [6]-{6c648541-1025-9650-9057-637958720c6} = C:/Windows/system32/mndhfdwd. dll | 7:40:53
O24-shlexechook: [5]-{57ac9076-c898-b098-d098-a18342580975} = C:/Windows/system32/nhmxejkl. dll |
O24-shlexechook: [4]-{4d698451-2015-6358-9871-2015987452d4} = C:/Windows/system32/apzhdtde. dll |
O24-shlexechook: [3]-{38093456-9012-4568-9076-908765467183} = C:/Windows/system32/tisqctyu. dll | 7:41:14
O24-shlexechook: [4]-{40618412-c528-c784-c056-c164d1f7c504} = C:/Windows/system32/detxdiua. dll | 7:41:21, 2004-8-8
O24-shlexechook: [2]-{25fd6584-698f-bcd2-602c-698745210352} = C:/Windows/system32/rijxbkin. dll | 7:41:28
O24-shlexechook: [4]-{43512378-9874-5641-1025-985420368734} = C:/Windows/system32/oswxdttb. dll | 7:41:35
O24-shlexechook: [5]-{528df602-9541-a985-210a-984a698c6f25} = C:/Windows/system32/ptjhehlp. dll | 7:41:41, 2004-8-8
O24-shlexechook: [4]-{49109876-7619-9101-7012-901938475194} = C:/Windows/system32/ietzdpaq. dll | 7:41:48
O24-shlexechook: [4]-{470165f1-9f65-108f-f895-f14f58f000074} = C:/Windows/system32/lofsdjbo. dll | 7:41:55
O24-shlexechook: [5]-{00070007-0007-0007-0007-00070007bb15} = C:/Windows/system32/dpvvoxmh. dll |
O24-shlexechook: [5]-{00010001-0001-0001-0001-00010001bb15} = C:/Windows/system32/adsntzt. dll |
O24-shlexechook: [5]-{00050005-0005-0005-0005-00050005bb15} = C:/Windows/system32/cliconfgzx. dll | 7:42:14
O24-shlexechook: [5]-{00170017-0017-0017-0017-00170017bb15} = C:/Windows/system32/msobjstl. dll | 7:42:21
O24-shlexechook: [5]-{00030003-0003-0003-0003-00030003bb15} = C:/Windows/system32/bootvidgj. dll | 7:42:27
O24-shlexechook: [5]-{00330033-0033-0033-0033-00330033bb15} = C:/Windows/system32/tscfgwmijxsj. dll | 7:42:34, 2001-7-9
O24-shlexechook: [5]-{00060006-0006-0006-0006-00060006bb15} = C:/Windows/system32/dispexcb. dll | 7:42:40
O24-shlexechook: [5]-{00130013-0013-0013-0013-00130013bb15} = C:/Windows/system32/ksuserfy. dll | 7:42:47
O24-shlexechook: [5]-{00300030-0030-0030-0030-00300030bb15} = C:/Windows/system32/imgutilhx2.dll | 7:42:53
O24-shlexechook: [c]-{8942ff57-5cf4-4ef5-9ffa-1b6d48b4d3fc} = C:/Windows/system32/mmwlangh1006.dll | 2000-7-9 7:44:43
O24-shlexechook: [5]-{6351a63c-4042-433a-a64f-6974e875f835} = C:/Windows/system32/mmwlvahb1_5.dll | 7:44:50
O24-shlexechook: [4]-{9a5eed2d-0604-4b25-afc7-f1fd1_93b14} = C:/Windows/system32/mmhadpqg1102.dll | 2000-7-9 7:44:56
O26-ifeo: client.exe-> C:/Windows/system32/windg.exe
HKLM/showall type non-DWORD
===/
(To be continued)