遭遇Trojan.DL.Win32.Autorun.yuz,Trojan.Win32.Inject.gh,Trojan.Win32.Agent.zsq等

來源:互聯網
上載者:User

遭遇Trojan.DL.Win32.Autorun.yuz,Trojan.Win32.Inject.gh,Trojan.Win32.Agent.zsq等

endurer 原創
2007-10-23 第1

pe_xscan 07-08-30 by Purple Endurer
2007-10-22 13:13:44
Windows XP Service Pack 2(5.1.2600)
管理使用者組

C:/WINDOWS/system32/winlogon.exe * 604 | 2004-8-8 4:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
    C:/WINDOWS/system32/winlib .dll
    C:/WINDOWS/system32/msplrct.dll

C:/WINDOWS/Explorer.EXE * 224 | 2007-6-13 21:21:56 | Microsoft(R) Windows(R) Operating System | 6.00.2900.3156 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
    C:/WINDOWS/Downlo~1/zux.dll | 2007-10-18 9:26:58 | Microsoft(R) Windows(R) Operating System | 5, 3, 2600, 2180 | Microsoft DirectMusic Interactive Engine | 著作權 (C) 2007 | 5, 3, 2600, 2180 | Microsoft Corporation |  | Microsoft DirectMusic Interactive Engine | miniDll.DLL
    C:/WINDOWS/Downlo~1/fap.dll | 2007-10-22 11:19:40 | Microsoft(R) Windows(R) Operating System | 5, 3, 2600, 2180 | Microsoft DirectMusic Interactive Engine | 著作權 (C) 2007 | 5, 3, 2600, 2180 | Microsoft Corporation |  | Microsoft DirectMusic Interactive Engine | miniDll.DLL
    C:/WINDOWS/Downlo~1/khy.dll | 2007-10-22 11:19:40 | Microsoft(R) Windows(R) Operating System | 5, 3, 2600, 2180 | Microsoft DirectMusic Interactive Engine | 著作權 (C) 2007 | 5, 3, 2600, 2180 | Microsoft Corporation |  | Microsoft DirectMusic Interactive Engine | miniDll.DLL
    C:/WINDOWS/system32/2b41.dll | 2007-10-22 11:21:46 | IEHpr Module | 1, 0, 0, 2 | IEHpr Module | Copyright 2007 | 1, 0, 0, 2 |  |  | IEHpr | IEHpr.DLL

C:/WINDOWS/system32/rundll32.exe * 1096 | 2004-8-8 4:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/WINDOWS/system32/wincheck071013.dll | 1987-10-13 9:31:38

C:/scktsrvr.exe * 1440 | 2006-2-11 9:40:34 | Borland Socket Server | 7.0 | Borland Socket Server | Copyright ? 1997-2001 Borland Software Corporation | 7.0.4.453 | Borland Software Corporation |  | SCKTSRVR | SCKTSRVR.EXE

C:/DOCUME~1/new/LOCALS~1/Temp/rundll.exe * 3280 | 2007-9-1 10:46:2
    C:/Documents and Settings/All Users/Application Data/Microsoft/Office/SYSTEM/loader.dll | 2007-10-22 9:35:58 | loader | 3.0.4 | system event loader | Microsoft.  All rights reserved. | 3.0.4 | Microsoft| ? | loader.dll | loader.dll

C:/Program Files/OCINS/idnsvr.exe * 4072 | 2007-10-22 9:37:22 |  | 2, 6, 0, 0 | 國際化網域名稱支援模組 | Copyright CNNIC 2006 - 2007 | 2, 6, 0, 0 | 中國互連網資訊中心(CNNIC) |  | idnsvr | idnsvr.exe
    C:/Program Files/OCINS/idnsvr.exe | 2007-10-22 9:37:22 |  | 2, 6, 0, 0 | 國際化網域名稱支援模組 | Copyright CNNIC 2006 - 2007 | 2, 6, 0, 0 | 中國互連網資訊中心(CNNIC) |  | idnsvr | idnsvr.exe

C:/WINDOWS/system32/rundll32.exe * 2300 | 2004-8-8 4:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/WINDOWS/system32/winsys16_071017.dll | 1987-10-22 9:39:30

C:/program files/internet explorer/iexplore.exe * 3852 | 2004-8-8 12:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
    C:/WINDOWS/system32/winsys32_071017.dll | 1987-10-22 9:41:22

C:/ah.exe * 14452 | 2007-10-6 19:54:54

C:/WINDOWS/system32/b4591.exe * 15012 | 2007-10-22 10:11:28 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows Progman Group Converter | Copyright Zhongsou(C) 2005 | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | GrpConv| ?

C:/WINDOWS/system32/rundll32.exe * 15192 | 2004-8-8 4:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/WINDOWS/system32/921.dll | 2007-10-22 11:21:46 |  Player 動態連結程式庫 | 1, 0, 0, 3 | Player 動態連結程式庫 |    著作權 (C) 2006 | 1, 0, 0, 3 |   | ? | Player | Player.dll

O2 - BHO CAdLogic Object - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:/Program Files/Common Files/CPUSH/cpush0.dll
O2 - BHO Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:/Documents and Settings/All Users/Application Data/Microsoft/PCTools/pctools.dll
O2 - BHO Invoke Class - {42A3A616-FF3C-4713-A5C2-4F1B566CEF51} - C:/WINDOWS/system32/2b41.dll
O2 - BHO IEAux Class - {7605CC7C-00FD-4A5F-BAFD-828342DE6279} - C:/PROGRA~1/OCINS/ieaux.dll
O2 - BHO ff Class - {B9751A53-4494-4d7c-9732-AE3058D8145F} - C:/WINDOWS/system32/2b41.dll
O2 - BHO Windows Browser - {C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} - C:/Documents and Settings/All Users/Application Data/Microsoft/OFFICE/USERDATA/a5eUwXqfYU.dll

O4 - HKCU/../Policies/Explorer/Run: [mscheck] rundll32.exe C:/WINDOWS/system32/wincheck071013.dll mymain
O4 - HKLM/../Run: [igfxpers] C:/WINDOWS/system32/igfxpers.exe
O4 - HKLM/../Run: [IdnSvr] C:/Program Files/OCINS/idnsvr.exe
O4 - HKLM/../Policies/Explorer/Run: [Userinit] rundll32.exe C:/WINDOWS/system32/winsys16_071017.dll start
O4 - HKLM/../Policies/Explorer/Run: [melove] C:/WINDOWS/system32/dream.exe
O4 - HKLM/../Policies/Explorer/Run: [dream] C:/WINDOWS/system32/dream.exe
O4 - HKLM/../Policies/Explorer/Run: [khy] rundll32 "C:/WINDOWS/Downlo~1/khy.dll",Run

O4 - Global Startup: scktsrvr.lnk -> c:/scktsrvr.exe

CmdProcAuto = d:/myplay.exe

C:/autorun.inf
/-----
[autorun]
OPEN=ah.exe
shellexecute=ah.exe
shell/Auto/command=ah.exe
shell=open
-----/
D:/autorun.inf
/-----
[autorun]
OPEN=ah.exe
shellexecute=ah.exe
shell/Auto/command=ah.exe
shell=open
-----/
E:/autorun.inf
/-----
[autorun]
OPEN=ah.exe
shellexecute=ah.exe
shell/Auto/command=ah.exe
shell=open
-----/
F:/autorun.inf
/-----
[autorun]
OPEN=ah.exe
shellexecute=ah.exe
shell/Auto/command=ah.exe
shell=open
-----/
O8 - IE右鍵菜單附加項 : &訪問通用網址 - C:/Program Files/OCINS/cnrbtn.html
O8 - IE右鍵菜單附加項 : 易趣購物 - C:/Program Files/AD4All/link1/eachlink.htm

O23 - 服務: 1ot8pminre (1ot8pminre) - C:/WINDOWS/system32/drivers/1ot8pminre.sys | 2004-8-8 4:0:0(自動)

O23 - 服務: acpidisk (acpidisk) - C:/WINDOWS/system32/drivers/acpidisk.sys | 2007-9-25 14:31:2(自動)

O23 - 服務: cnprov (cnprov) - system32/drivers/cnprov.sys | 中文上網官方版 | 2, 6, 0, 0 | 國際化網域名稱輔助模組 | Copyright (c) . All rights reserved. | 2.6.0.0 | 中國互連網絡資訊中心(CNNIC)| ? | cnprov.sys | cnprov.sys(引導)

O23 - 服務: idnaux (idnaux) - system32/drivers/idnaux.sys | CNNIC idnaux | 2, 6, 0, 0 | 國際化網域名稱支援模組 | Copyright ? 2005 | 2, 6, 0, 0 | 中國互連網絡資訊中心(CNNIC) |  | idnaux | idnaux.sys(自動)

O23 - 服務: lcyi7wceil (lcyi7wceil) - System32/DRIVERS/lcyi7wceil.sys(引導)

O23 - 服務: ms_2fax (ms_2fax) - C:/WINDOWS/system32/b4591.exe | 2007-10-22 10:11:28 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows Progman Group Converter | Copyright Zhongsou(C) 2005 | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | GrpConv| ?(自動)

O23 - 服務: mxdispdr (mxdispdr) - C:/WINDOWS/system32/drivers/mxdispdr.sys | 2007-9-30 20:18:14(自動)

O23 - 服務: sysloader (System Event loader) - "C:/Documents and Settings/All Users/Application Data/Microsoft/Office/SYSTEM/sysloader.exe" | 2007-10-17 10:18:48 | sysloader | 3.0.4 | system event loader | Microsoft.  All rights reserved. | 3.0.4 | Microsoft| ? | sysloader.exe | sysloader.exe(自動)

O23 - 服務: Yiqilai (一起來音樂助手) - "C:/Program Files/Yiqilai/wmp/YiqilaiLyrics.exe" | 2007-10-18 10:15:40 | YiqilaiLyrics | 1.0.1 | YiqilaiLyrics | Yiqilai.  All rights reserved. | 1.0.1 | Yiqilai| ? | YiqilaiLyrics.exe | YiqilaiLyrics.exe(自動)

檔案說明符 : c:/a.exe
屬性 : A---
擷取檔案版本資訊大小失敗!
建立時間 : 2007-10-22 16:56:33
修改時間 : 2007-10-22 16:57:6
訪問時間 : 2007-10-22 0:0:0
大小 : 102356 位元組 99.980 KB
MD5 : 7ed8ee6a124e1b69581b0e38435c123c
SHA1: A873CBFFC796E8D211684DE509BB951BBEAD3C64
CRC32: dbf1a17a

瑞星報為:Trojan.Clicker.Win32.PopHot.cg
Kaspersky已檢測到: 木馬程式 Trojan-Spy.Win32.Agent.afl 檔案: D:/test/a.exe.rar/a.exe/PE_Patch/UPack

d:/myplay.exe 與 c:/a.exe 相同

檔案說明符 : c:/ah.exe
屬性 : -SH-
擷取檔案版本資訊大小失敗!
建立時間 : 2007-10-18 16:10:4
修改時間 : 2007-10-6 19:54:54
訪問時間 : 2007-10-22 0:0:0
大小 : 18432 位元組 18.0 KB
MD5 : b329e5d20a1636f2a7eb7051a8ed55a1
SHA1: 4AAE08CB65BFBCC0F5F086AEDB3042ED16332F2F
CRC32: 8300cea6

瑞星報為:Trojan.DL.Win32.Autorun.yuz

Kaspersky 報為: Virus.Win32.AutoRun.og

檔案說明符 : C:/WINDOWS/system32/dream.exe 與 c:/ah.exe 相同。

檔案說明符 : c:/scktsrvr.exe
屬性 : ----
語言 : 英語(美國)
檔案版本 : 7.0.4.453
說明 : Borland Socket Server
著作權 : Copyright ? 1997-2001 Borland Software Corporation
備忘 :
產品版本 : 7.0
產品名稱 : Borland Socket Server
公司名稱 : Borland Software Corporation
合法商標 :
內部名稱 : SCKTSRVR
源檔案名稱 : SCKTSRVR.EXE
建立時間 : 2007-10-11 17:9:32
修改時間 : 2006-2-11 9:40:34
訪問時間 : 2007-10-22 0:0:0
大小 : 725504 位元組 708.512 KB
MD5 : c3ef0622b13655bc68cef169e52afb6a
SHA1: 9457F32E964F4040580D8B82B1AC512E96640673
CRC32: 30ec29d7

檔案說明符 : C:/Documents and Settings/All Users/Application Data/Microsoft/OFFICE/USERDATA/a5eUwXqfYU.dll
屬性 : A---
語言 : 英語(美國)
檔案版本 : 3, 0, 6, 0
說明 : MSN Browser
著作權 : Copyright 2006
備忘 :
產品版本 : 3, 0, 6, 0
產品名稱 : MSN Browser
公司名稱 : Microsoft Corporation
合法商標 :
內部名稱 : webbrowser
源檔案名稱 : webbrowser.DLL
建立時間 : 2007-10-22 9:41:59
修改時間 : 2007-10-22 9:42:0
訪問時間 : 2007-10-22 0:0:0
大小 : 170496 位元組 166.512 KB
MD5 : df8ff7499023477733bb020473625618
SHA1: F9117D64F0F47450FD49539EAC0CC826D1CC76F9
CRC32: 0e45cf62

主 題: RE: [?? Probable Spam] a5eUwXqfYU.dll [KLAB-3146835]
  寄件者: "" <newvirus@kaspersky.com>   
發送時間:2007-10-23 12:35:37

Hello,
a5eUwXqfYU.dll - not-a-virus:AdWare.Win32.IEHlpr.ai
This file is an Advertizing Tool, It's detection will be included in the next
update of extended databases set. See more info about
extended databases here: http://www.kaspersky.com/extraavupdates
Please quote all when answering.
--
Best regards, Denis Maslennikov
Virus analyst, Kaspersky Lab.

檔案說明符 : C:/WINDOWS/system32/2b41.dll
屬性 : A--R
語言 : 英語(美國)
檔案版本 : 1, 0, 0, 2
說明 : IEHpr Module
著作權 : Copyright 2007
備忘 :
產品版本 : 1, 0, 0, 2
產品名稱 : IEHpr Module
公司名稱 :
合法商標 :
內部名稱 : IEHpr
源檔案名稱 : IEHpr.DLL
建立時間 : 2001-2-3 11:22:36
修改時間 : 2007-10-22 11:21:46
訪問時間 : 2007-10-22 0:0:0
大小 : 53248 位元組 52.0 KB
MD5 : 7dd94ef20e40e0de728112675904811a
SHA1: B41E790374214A54C147CBA26736F0BA8E265022
CRC32: 2445c774

主 題: RE: [?? Probable Spam] 2b41.dll [KLAB-3146836]
  寄件者: "" <newvirus@kaspersky.com>   
發送時間:2007-10-23 12:44:09

Hello,

2b41.dll - not-a-virus:AdWare.Win32.BHO.ih
This file is an Advertizing Tool, It's detection will be included in the next
update of extended databases set. See more info about
extended databases here: http://www.kaspersky.com/extraavupdates
Please quote all when answering.
--
Best regards, Denis Maslennikov
Virus analyst, Kaspersky Lab.

檔案說明符 : C:/Documents and Settings/All Users/Application Data/Microsoft/Office/SYSTEM/sysloader.exe
屬性 : A---
語言 : 英語(美國)
檔案版本 : 3.0.4
說明 : system event loader
著作權 : Microsoft.  All rights reserved.
備忘 :
產品版本 : 3.0.4
產品名稱 : sysloader
公司名稱 : Microsoft
合法商標 :
內部名稱 : sysloader.exe
源檔案名稱 : sysloader.exe
建立時間 : 2007-10-17 10:18:48
修改時間 : 2007-10-17 10:18:48
訪問時間 : 2007-10-22 0:0:0
大小 : 357376 位元組 349.0 KB
MD5 : c18ceab29fac37d570190a12436d9c8b
SHA1: CB4744B9841B5F9C21CBA1039A46FCE1EAF6E3CD
CRC32: 348f2431

瑞星報為:Trojan.Win32.Inject.gh

主 題: RE:sysloader.exe [KLAB-3146870]
  寄件者: "" <newvirus@kaspersky.com>  
發送時間:2007-10-23 12:48:10

Hello.
New malicious software was found in the attached file. Trojan-Downloader.Win32.Agent.eky
It's detection will be included in the next update. Thank you for your help.
Please quote all when answering. Do not forget to include you registration data.
-----------------
Regards, Maslennikov Denis
Virus Analyst, Kaspersky Lab.

檔案說明符 : C:/WINDOWS/Downlo~1/khy.dll
屬性 : A--R
語言 : 中文(中國)
檔案版本 : 5, 3, 2600, 2180
說明 : Microsoft DirectMusic Interactive Engine
著作權 : 著作權 (C) 2007
備忘 : DirectMusic
產品版本 : 5, 3, 2600, 2180
產品名稱 : Microsoft(R) Windows(R) Operating System
公司名稱 : Microsoft Corporation
合法商標 :
內部名稱 : Microsoft DirectMusic Interactive Engine
源檔案名稱 : miniDll.DLL
建立時間 : 1987-10-22 14:46:33
修改時間 : 2007-10-22 11:19:40
訪問時間 : 2007-10-22 0:0:0
大小 : 49152 位元組 48.0 KB
MD5 : 3d6d8766c8436ea20457123a7363095d
SHA1: C93850C662823C02F596F80E129995EC93CF5CF1
CRC32: f5a4e191

主 題: RE: khy.dll [KLAB-3146872]
  寄件者: "" <newvirus@kaspersky.com>   發送時間:2007-10-23 12:49:41

Hello,

khy.dll - Trojan-Downloader.Win32.Agent.ekz
New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.
Please quote all when answering.
--
Best regards, Denis Maslennikov
Virus analyst, Kaspersky Lab.

檔案說明符 : C:/WINDOWS/system32/winsys16_071017.dll
屬性 : -SHR
擷取檔案版本資訊大小失敗!
建立時間 : 1987-10-18 9:34:39
修改時間 : 1987-10-22 9:39:30
訪問時間 : 2007-10-22 0:0:0
大小 : 24576 位元組 24.0 KB
MD5 : bd5ad170a8b0fec28e972b314c8668e0
SHA1: 408CB216C2A27187C841A0F9ACAF319BBBEC2D0D
CRC32: a9647ec5

瑞星報為:Trojan.Win32.Agent.zsq
Kaspersky已檢測到: 木馬程式 Trojan-Spy.Win32.Agent.aga 檔案: D:/test/winsys16_071017.dll.rar/winsys16_071017.dll

檔案說明符 : C:/WINDOWS/system32/wincheck071013.dll
屬性 : -SHR
擷取檔案版本資訊大小失敗!
建立時間 : 1987-10-13 9:31:37
修改時間 : 1987-10-13 9:31:38
訪問時間 : 2007-10-22 0:0:0
大小 : 27648 位元組 27.0 KB
MD5 : eb5929a3a390a519729d1e4dea37d34f
SHA1: 31A75B68CC4A03A7BE1A0265AB0DF271AF3F1887
CRC32: 697c1572

瑞星報為:Trojan.DL.Win32.MyDown.h

 

主 題: RE: wincheck071013.dll [KLAB-3146878]
  寄件者: "" <newvirus@kaspersky.com>  
發送時間:2007.10.23 13:12

Hello.
New malicious software was found in the attached file. Trojan.Win32.Delf.ajt
It's detection will be included in the next update. Thank you for your help.
Please quote all when answering. Do not forget to include you registration data.
-----------------
Regards, Maslennikov Denis
Virus Analyst, Kaspersky Lab.

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.