遭遇RootKit.Win32.GameHack,Trojan.PSW.Win32.QQPass,Trojan-PSW.Win32.OnLineGames等1

遭遇RootKit.Win32.GameHack,Trojan.PSW.Win32.QQPass,Trojan-PSW.Win32.OnLineGames等1

endurer 原创
2008-03-19 第1

一位网友今天说他的电脑中了QQ盗号木马,按QQ医生的提示重启电脑也不能解决,请偶帮忙清理。

下载 pe_xscan 扫描 log 并分析,发现如下可疑项(进程模块中重复的部分有省略):

/===
pe_xscan 08-03-03 by Purple Endurer
2008-3-19 12:15:38
Windows XP Service Pack 2(5.1.2600)
管理员用户组
正常模式
[System Process] * 0
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
   C:/WINDOWS/system32/rzysdhbx.dll | 2008-3-19 9:4:6
C:/WINDOWS/System32/winlogon.exe* 524 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/WINDOWS/system32/winnet.dll | 2004-8-17 12:0:0 | DllProgram Dynamic Link Library | 1, 0, 0, 1 | DllProgram DLL | 版权所有 (C) 2008 | 1, 0, 0, 1 | | | DllProgram | DllProgram.DLL
C:/WINDOWS/System32/services.exe* 576 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
C:/WINDOWS/System32/lsass.exe* 588 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
C:/WINDOWS/System32/svchost.exe* 756 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
C:/WINDOWS/System32/alg.exe* 220 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Application Layer Gateway Service | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | ALG.exe | ALG.exe
   C:/WINDOWS/System32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/System32/sve.dll | 2008-3-19 9:5:10
C:/WINDOWS/EXPLORER.EXE* 1296 | 2007-6-13 21:21:56 | Microsoft(R) Windows(R) Operating System | 6.00.2900.3156 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/msosiocp.dll | 2008-3-19 8:48:36
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/rzysdhbx.dll | 2008-3-19 9:4:6
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/Setup/en_1072.bin | 2008-3-19 8:48:36
C:/WINDOWS/SOUNDMAN.EXE* 2288 | 2006-3-2 7:22:4 | Realtek Sound Manager | 5, 1, 0, 52 | Realtek Sound Manager | Copyright (c) 2001-2004 Realtek Semiconductor Corp. | 5, 1, 0, 52 | Realtek Semiconductor Corp. | | ALSMTray | ALSMTray.exe
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
C:/WINDOWS/System32/ctfmon.exe* 2968 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
C:/QQ/TXPlatform.exe * 3904 | 2007-11-18 9:53:40 | TM2008 | 1, 0, 170, 201 | TM2008 | Copyright (C) 1998-2007 TENCENT Inc. All Rights Reserved | 1, 0, 170, 0 | Tencent| ? | |
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
C:/QQ/QQ.exe * 492 | 2008-2-19 14:15:12 | QQ | 8,0,714,1791 | QQ | Copyright (C) 1998 - 2008 TENCENT Inc. All Rights Reserved | 8,0,714,1791 | TENCENT | | COMQQD | QQ.exe
   C:/WINDOWS/system32/ej.dll | 2008-3-19 9:5:14
   C:/WINDOWS/system32/sve.dll | 2008-3-19 9:5:10
   C:/WINDOWS/system32/yfntgmtzx.dll | 2008-3-19 9:4:26 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/WINDOWS/system32/yfmsdkqwd.dll | 2008-3-19 9:3:50 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32
   C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys | 2008-3-19 8:58:22
   C:/WINDOWS/system32/dbclue.dll | 2008-3-19 9:5:20
   C:/WINDOWS/system32/rnuhoj.dll | 2008-3-19 9:4:50
   C:/WINDOWS/system32/rzysdhbx.dll | 2008-3-19 9:4:6
O2 - BHO - {D29DCEE0-457B-45A2-A92D-741B95B7723B} - C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys
O4 - HKLM/../Run: [igzwzslm] C:/WINDOWS/gwsmhxuq.exe
O4 - HKLM/../Run: [LotusHlp] C:/WINDOWS/LotusHlp.exe
O4 - HKLM/../Run: [SHAProc] C:/WINDOWS/SHAProc.exe
O4 - HKLM/../Run: [igzwzslm] C:/WINDOWS/gwsmhxuq.exe
O4 - HKLM/../Run: [LotusHlp] C:/WINDOWS/LotusHlp.exe
O4 - HKLM/../Run: [SHAProc] C:/WINDOWS/SHAProc.exe
O4 - HKLM/../Run: [upxdnd] C:/WINDOWS/upxdnd.exe
O4 - HKLM/../Run: [msccrt] C:/WINDOWS/msccrt.exe
O4 - HKLM/../Run: [cmdbcs] C:/WINDOWS/cmdbcs.exe
O4 - HKLM/../Run: [DbgHlp32] C:/WINDOWS/DbgHlp32.exe
O4 - HKLM/../Run: [Kvsc3] C:/WINDOWS/Kvsc3.exE
O4 - HKLM/../Run: [WSockDrv32] C:/WINDOWS/WSockDrv32.exe
O20 - AppInit_DLLs = mhtd.dll,qnefnaib.dll,ej.dll,uixauh.dll,hjiq.dll,kiluw.dll,dsfg.dll,yqhs.dll,oaijihzeuyouhz.dll,jemnaw.dll,cuhad.dll,laixuhz.dll,rfhx.dll,mnauygniqaixnaij.dll,oqnauhc.dll,xjxr.dll,utiemnaw.dll,sve.dll,wininat.dll,gnolnait.dll,zadnew.dll,htwx.dll,awf.dll,duygnef.dll,gmx.dll,nadgnohiac.dll,agzg.dll,qlihzouhgnfe.dll,bchib.dll,tzm.dll,r2.dll,bauhgnem.dll,eohsom.dll,fyom.dll,sauhad.dll,ijougiemnaw.dll,taijoad.dll,lnaixnauhqq.dll,idtj.dll,vhqq.dll,atgnehz.dll,rsqq.dll,tsqc.dll,vauyiqvlnaix.dll,wQ.dll,fmxh.dll,cty.dll,pahzij.dll,jz.dll,bz.dll,pyomielnux.dll,slcs.dll,xptyj.dll,umqj.dll,xqjy.dll,fifeei.dll,shqein.dll,xy2.dll,wtiemnaw.dll,uyomielnux.dll,vlihzouhgnfe.dll,2ty.dll,nauhgnem.dll,auhad.dll,rj.dll,hz.dll,naijihzeuyouhz.dll,xhqq.dll,jmx.dll,dgzg.dll,gsqq.dll,fz.dll,gnaixnauhuoyizqq.dll,gnolnait.dll,jsqc.dll,dqncj.dll,eve.dll,2nauygniqaixnaij.dll,niluw.dll,ijougiemnaw.dll,xhtd.dll,QQ.dll,sfhx.dll,gnaixnauhqq.dll,3auhad.dll,oadnew.dll,iemnaw.dll,qcsct.dll,oadgnohiac.dll,iqnauhc.dll,aixauh.dll
O23 - 服务: B302EC43 (B302EC43) - C:/WINDOWS/system32/75D23BE4.EXE -d(自动)
O23 - 服务: drop (drop) - C:/DOCUME~1/donghe/LOCALS~1/Temp/tmp74.tmp (自动)
O23 - 服务: fpids32 (fpids32) - C:/WINDOWS/system32/drivers/msosfpids32.sys | 2008-3-19 9:5:32(自动)
O23 - 服务: mhfp (mhfp) - C:/DOCUME~1/donghe/LOCALS~1/Temp/tmp53.tmp(自动)
O23 - 服务: msert (msert) - system32/drivers/mselk.sys(自动)
O23 - 服务: RemoteStorage (Windows Accounts Driver) - C:/WINDOWS/system32/winnet.exe | 2004-8-17 12:0:0(自动)
O24 - ShlExecHook: [] - {D29DCEE0-457B-45A2-A92D-741B95B7723B} = C:/Program Files/Internet Explorer/PLUGINS/Ns_Sys55.Sys
O24 - ShlExecHook: [B] - {50632D5C-B71B-4ba0-B012-3DC6F15C011B} = C:/WINDOWS/system32/msosiocp.dll
O24 - ShlExecHook: [Microsoft] - {5E907A48-400E-4EA8-9792-FFAE052D59E9} = C:/WINDOWS/system32/pedadt.dll
===/
 (未完待续)
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

紫郢剑侠

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值