又遇Trojan.PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

又遇Trojan.PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

endurer 原创 2008-06-13 第1

 

一位朋友说最近他的电脑中的瑞星杀毒软件和防火墙软件的实时监控图标不见了,电脑反应很慢,请偶帮忙检修。

下载 pe_xscan 扫描 log 并分析,发现如下可疑项:

pe_xscan 08-04-26 by Purple Endurer
2008-6-12 12:20:52
Windows XP Service Pack 2(5.1.2600)
MSIE:6.0.2900.2180
管理员用户组
正常模式

[System Process] * 0    C:/WINDOWS/system32/SysDaJcHv.dll | 2008-6-4 2:40:4 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32    C:/WINDOWS/system32/msosptfs01.dll | 2008-6-5 10:3:24    C:/WINDOWS/system32/msoscqet01.dll | 2008-6-9 2:20:9    C:/WINDOWS/system32/msosfasq01.dll | 2008-6-9 2:24:37    C:/WINDOWS/system32/msosping01.dll | 2008-6-5 10:3:15    C:/WINDOWS/system32/msoscqit00.dll | 2008-6-1 3:29:26    C:/WINDOWS/system32/msosjtio00.dll | 2008-6-1 3:32:36    C:/WINDOWS/system32/msosfmsq01.dll | 2008-6-2 7:58:15    C:/WINDOWS/system32/msosjtfo01.dll | 2008-6-9 2:24:57    C:/WINDOWS/system32/msosdrop00.dll | 2008-6-1 3:33:9    C:/WINDOWS/system32/ytewcxzsw.dll | 2008-6-8 2:8:22    C:/WINDOWS/system32/wwwwww.dll | 2008-6-9 2:18:42    C:/WINDOWS/system32/qqqqqq.dll | 2008-6-9 8:29:38    C:/WINDOWS/system32/gggggg.dll | 2008-6-10 0:11:23    C:/WINDOWS/system32/kduonz.dll | 2008-6-10 0:11:30    C:/WINDOWS/system32/oooooo.dll | 2008-6-10 6:57:29    C:/WINDOWS/system32/cccccc.dll | 2008-6-11 0:0:15    C:/WINDOWS/system32/eeeeee.dll | 2008-6-11 0:56:8    C:/WINDOWS/system32/mmmmmm.dll | 2008-6-11 2:29:38    C:/WINDOWS/system32/tttttt.dll | 2008-6-11 7:26:26    C:/WINDOWS/system32/xxxxxx.dll | 2008-6-12 0:14:16    C:/Program Files/Internet Explorer/PLUGINS/DosSys08.Sys | 2008-6-5 10:3:32 C:/WINDOWS/system32/winlogon.exe* 1020 | 2004-8-23 8:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE    C:/WINDOWS/system32/SysDaJcHv.dll | 2008-6-4 2:40:4 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32    C:/WINDOWS/system32/msosptfs01.dll | 2008-6-5 10:3:24    C:/WINDOWS/system32/msoscqet01.dll | 2008-6-9 2:20:9    C:/WINDOWS/system32/msosfasq01.dll | 2008-6-9 2:24:37    C:/WINDOWS/system32/msosping01.dll | 2008-6-5 10:3:15    C:/WINDOWS/system32/msoscqit00.dll | 2008-6-1 3:29:26    C:/WINDOWS/system32/msosjtio00.dll | 2008-6-1 3:32:36    C:/WINDOWS/system32/msosfmsq01.dll | 2008-6-2 7:58:15    C:/WINDOWS/system32/msosjtfo01.dll | 2008-6-9 2:24:57    C:/WINDOWS/system32/msosdrop00.dll | 2008-6-1 3:33:9    C:/WINDOWS/system32/ytewcxzsw.dll | 2008-6-8 2:8:22    C:/WINDOWS/system32/wwwwww.dll | 2008-6-9 2:18:42    C:/WINDOWS/system32/qqqqqq.dll | 2008-6-9 8:29:38    C:/WINDOWS/system32/gggggg.dll | 2008-6-10 0:11:23    C:/WINDOWS/system32/kduonz.dll | 2008-6-10 0:11:30    C:/WINDOWS/system32/oooooo.dll | 2008-6-10 6:57:29    C:/WINDOWS/system32/cccccc.dll | 2008-6-11 0:0:15    C:/WINDOWS/system32/eeeeee.dll | 2008-6-11 0:56:8    C:/WINDOWS/system32/mmmmmm.dll | 2008-6-11 2:29:38    C:/WINDOWS/system32/tttttt.dll | 2008-6-11 7:26:26 C:/WINDOWS/system32/ctfmon.exe* 956 | 2004-8-23 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE    C:/WINDOWS/system32/SysDaJcHv.dll | 2008-6-4 2:40:4 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32    C:/WINDOWS/system32/msosptfs01.dll | 2008-6-5 10:3:24    C:/WINDOWS/system32/msoscqet01.dll | 2008-6-9 2:20:9    C:/WINDOWS/system32/msosfasq01.dll | 2008-6-9 2:24:37    C:/WINDOWS/system32/msosping01.dll | 2008-6-5 10:3:15    C:/WINDOWS/system32/msoscqit00.dll | 2008-6-1 3:29:26    C:/WINDOWS/system32/msosjtio00.dll | 2008-6-1 3:32:36    C:/WINDOWS/system32/msosfmsq01.dll | 2008-6-2 7:58:15    C:/WINDOWS/system32/msosjtfo01.dll | 2008-6-9 2:24:57    C:/WINDOWS/system32/msosdrop00.dll | 2008-6-1 3:33:9    C:/WINDOWS/system32/ytewcxzsw.dll | 2008-6-8 2:8:22    C:/WINDOWS/system32/wwwwww.dll | 2008-6-9 2:18:42    C:/WINDOWS/system32/qqqqqq.dll | 2008-6-9 8:29:38    C:/WINDOWS/system32/gggggg.dll | 2008-6-10 0:11:23    C:/WINDOWS/system32/kduonz.dll | 2008-6-10 0:11:30    C:/WINDOWS/system32/oooooo.dll | 2008-6-10 6:57:29    C:/WINDOWS/system32/cccccc.dll | 2008-6-11 0:0:15    C:/WINDOWS/system32/eeeeee.dll | 2008-6-11 0:56:8    C:/WINDOWS/system32/mmmmmm.dll | 2008-6-11 2:29:38    C:/WINDOWS/system32/tttttt.dll | 2008-6-11 7:26:26    C:/WINDOWS/system32/xxxxxx.dll | 2008-6-12 0:14:16    C:/Program Files/Internet Explorer/PLUGINS/DosSys08.Sys | 2008-6-5 10:3:32 C:/WINDOWS/system32/svchost.exe* 1028 | 2004-8-23 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe    C:/WINDOWS/system32/SysDaJcHv.dll | 2008-6-4 2:40:4 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32    C:/WINDOWS/system32/msosptfs01.dll | 2008-6-5 10:3:24    C:/WINDOWS/system32/msoscqet01.dll | 2008-6-9 2:20:9    C:/WINDOWS/system32/msosfasq01.dll | 2008-6-9 2:24:37    C:/WINDOWS/system32/msosping01.dll | 2008-6-5 10:3:15    C:/WINDOWS/system32/msoscqit00.dll | 2008-6-1 3:29:26    C:/WINDOWS/system32/msosjtio00.dll | 2008-6-1 3:32:36    C:/WINDOWS/system32/msosfmsq01.dll | 2008-6-2 7:58:15    C:/WINDOWS/system32/msosjtfo01.dll | 2008-6-9 2:24:57    C:/WINDOWS/system32/msosdrop00.dll | 2008-6-1 3:33:9    C:/WINDOWS/system32/ytewcxzsw.dll | 2008-6-8 2:8:22    C:/WINDOWS/system32/wwwwww.dll | 2008-6-9 2:18:42    C:/WINDOWS/system32/qqqqqq.dll | 2008-6-9 8:29:38    C:/WINDOWS/system32/gggggg.dll | 2008-6-10 0:11:23    C:/WINDOWS/system32/kduonz.dll | 2008-6-10 0:11:30    C:/WINDOWS/system32/oooooo.dll | 2008-6-10 6:57:29    C:/WINDOWS/system32/cccccc.dll | 2008-6-11 0:0:15    C:/WINDOWS/system32/eeeeee.dll | 2008-6-11 0:56:8    C:/WINDOWS/system32/mmmmmm.dll | 2008-6-11 2:29:38    C:/WINDOWS/system32/tttttt.dll | 2008-6-11 7:26:26    C:/WINDOWS/system32/xxxxxx.dll | 2008-6-12 0:14:16 C:/WINDOWS/explorer.exe* 3728 | 2004-8-23 8:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE    C:/WINDOWS/system32/SysDaJcHv.dll | 2008-6-4 2:40:4 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32    C:/WINDOWS/system32/msosptfs01.dll | 2008-6-5 10:3:24    C:/WINDOWS/system32/msoscqet01.dll | 2008-6-9 2:20:9    C:/WINDOWS/system32/msosfasq01.dll | 2008-6-9 2:24:37    C:/WINDOWS/system32/msosping01.dll | 2008-6-5 10:3:15    C:/WINDOWS/system32/msoscqit00.dll | 2008-6-1 3:29:26    C:/WINDOWS/system32/msosjtio00.dll | 2008-6-1 3:32:36    C:/WINDOWS/system32/msosfmsq01.dll | 2008-6-2 7:58:15    C:/WINDOWS/system32/msosjtfo01.dll | 2008-6-9 2:24:57    C:/WINDOWS/system32/msosdrop00.dll | 2008-6-1 3:33:9    C:/WINDOWS/system32/ytewcxzsw.dll | 2008-6-8 2:8:22    C:/WINDOWS/system32/wwwwww.dll | 2008-6-9 2:18:42    C:/WINDOWS/system32/qqqqqq.dll | 2008-6-9 8:29:38    C:/WINDOWS/system32/gggggg.dll | 2008-6-10 0:11:23    C:/WINDOWS/system32/kduonz.dll | 2008-6-10 0:11:30    C:/WINDOWS/system32/oooooo.dll | 2008-6-10 6:57:29    C:/WINDOWS/system32/cccccc.dll | 2008-6-11 0:0:15    C:/WINDOWS/system32/eeeeee.dll | 2008-6-11 0:56:8    C:/WINDOWS/system32/mmmmmm.dll | 2008-6-11 2:29:38    C:/WINDOWS/system32/tttttt.dll | 2008-6-11 7:26:26    C:/WINDOWS/system32/xxxxxx.dll | 2008-6-12 0:14:16    C:/Program Files/Internet Explorer/PLUGINS/DosSys08.Sys | 2008-6-5 10:3:32 O2 - BHO - {398C9B84-4EF7-47B5-9862-DE29543B3C42} - C:/Program Files/Internet Explorer/PLUGINS/DosSys08.Sys O4 - HKLM/../Run: [ytewcxzsw] C:/WINDOWS/ssssss.exe O4 - HKLM/../Run: [juejwcx] C:/WINDOWS/juejwcx.exe O4 - HKLM/../Run: [anistio] C:/WINDOWS/anistio.exE O4 - HKLM/../Run: [isscs32] C:/WINDOWS/isscs32.exe O4 - HKLM/../Run: [dionpis] C:/WINDOWS/dionpis.exe O4 - HKLM/../Run: [hefcndy] C:/WINDOWS/hefcndy.exe O4 - HKLM/../Run: [fmsbbqi] C:/WINDOWS/fmsbbqi.exe O4 - HKLM/../Run: [bincdwsa] C:/WINDOWS/bincdwsa.exe O4 - HKLM/../Run: [dbhlp32] C:/WINDOWS/dbhlp32.exe O4 - HKLM/../Run: [fmsjhif] C:/WINDOWS/fmsjhif.exe O4 - HKLM/../Run: [qrdkntbd] C:/WINDOWS/rktdwvur.exe O4 - HKLM/../Run: [ptshell] C:/WINDOWS/ptshell.exe O4 - HKLM/../Run: [tciocp64] C:/WINDOWS/tciocp64.exe O4 - HKLM/../Run: [mfchlp64] C:/WINDOWS/mfchlp64.exe O4 - HKLM/../Run: [WINSvr64] C:/WINDOWS/WINSvr64.exe O4 - HKLM/../Run: [wrew2ds] C:/WINDOWS/wrew2ds.exe O4 - HKLM/../Run: [isndntio] C:/WINDOWS/isndntio.exe {D92688DA-7FAB-4AB4-8AC9-5EADE1E3C8E4}_234225_user.job O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/restrictions 存在 IE或Internet选项可能受到限制 O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Control Panel 存在 IE或Internet选项可能受到限制 O20 - AppInit_DLLs = SysDaJcHv.dll,msosptfs01.dll,wipicdec.dll,msoscqet01.dll,nicozftp01.dll,rgvxyr.dll,msosmhap00.dll,msosdohs01.dll,msosmnsf01.dll,msosfasq01.dll,msosping01.dll,msosmhfp00.dll,msoscqit00.dll,msosjtio00.dll,msosfmsq01.dll,msosjtfo01.dll,msosdrop00.dll,ytewcxzsw.dll,wwwwww.dll,obrrrz.dll,qqqqqq.dll,gggggg.dll,kduonz.dll,oooooo.dll,cccccc.dll,eeeeee.dll,mmmmmm.dll,tttttt.dll,xxxxxx.dll O23 - 服务: 71BFE972 (71BFE972) - C:/WINDOWS/system32/25847834.EXE -d (自动) O23 - 服务: cqet (cqet) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp88.tmp (自动) O23 - 服务: cqit (cqit) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp7.tmp | 2008-6-1 9:27:57(自动) O23 - 服务: dohs (dohs) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp9.tmp | 2008-6-2 7:57:49(自动) O23 - 服务: drop (drop) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp13.tmp | 2008-6-1 9:29:51(自动) O23 - 服务: fasq (fasq) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp92.tmp (自动) O23 - 服务: fmsq (fmsq) - C:/DOCUME~1/user/LOCALS~1/Temp/tmpF.tmp | 2008-6-1 9:28:15(自动) O23 - 服务: IIS Manager (IIS Manager ) - C:/DOCUME~1/user/LOCALS~1/Temp/1.tmp (手动) O23 - 服务: jtfo (jtfo) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp94.tmp | 2008-6-9 2:22:16(自动) O23 - 服务: jtio (jtio) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp11.tmp | 2008-6-3 7:45:41(自动) O23 - 服务: mhap (mhap) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp1.tmp (自动) O23 - 服务: mhfp (mhfp) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp1.tmp (自动) O23 - 服务: mnsf (mnsf) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp9.tmp | 2008-6-2 7:57:49(自动) O23 - 服务: msfpfis64 (msfpfis64) - C:/WINDOWS/system32/drivers/msosmsfpfis64.sys | 2008-6-1 3:29:16(自动) O23 - 服务: msp2p32 (msp2p32) - C:/WINDOWS/system32/drivers/msosmsp2p32.sys | 2008-6-1 3:28:25(自动) O23 - 服务: NPF (Netgroup Packet Filter) -  system32/drivers/npf.sys | WinPcap Netgroup Packet Filter Driver | 3, 1, 0, 27 | npf | Copyright ? 2005 CACE Technologies. Copyright ? 2003-2005 NetGroup, Politecnico di Torino. | 3, 1, 0, 27 | CACE Technologies | | NPF + TME | npf.sys(手动) O23 - 服务: ping (ping) - C:/DOCUME~1/user/LOCALS~1/Temp/tmpD.tmp | 2008-6-2 0:6:28(自动) O23 - 服务: ptfs (ptfs) - C:/DOCUME~1/user/LOCALS~1/Temp/tmpB.tmp | 2008-6-1 9:28:5(自动) O23 - 服务: zftp (zftp) - C:/DOCUME~1/user/LOCALS~1/Temp/tmp5.tmp | 2008-6-2 0:6:23(自动) O24 - ShlExecHook: [] - {398C9B84-4EF7-47B5-9862-DE29543B3C42} = C:/Program Files/Internet Explorer/PLUGINS/DosSys08.Sys  O26 - IFEO: 360rpt.exe -> ntsd -d O26 - IFEO: 360safe.exe -> ntsd -d O26 - IFEO: 360safebox.exe -> ntsd -d O26 - IFEO: 360tray.exe -> ntsd -d O26 - IFEO: avp.exe -> TASKMAN.EXE O26 - IFEO: CCenter.exe -> ntsd -d O26 - IFEO: KPPMain.exe -> ntsd -D O26 - IFEO: KWatch.exe -> ntsd -d O26 - IFEO: QQDoctor.exe -> ntsd -D O26 - IFEO: QQKav.exe -> ntsd -D O26 - IFEO: Rav.exe -> TASKMAN.EXE O26 - IFEO: RavMon.exe -> ntsd -D O26 - IFEO: RavMonD.exe -> ntsd -D O26 - IFEO: RavStub.exe -> TASKMAN.EXE O26 - IFEO: RavTask.exe -> TASKMAN.EXE O26 - IFEO: rfwcfg.exe -> TASKMAN.EXE O26 - IFEO: rfwmain.exe -> TASKMAN.EXE O26 - IFEO: rfwProxy.exe -> TASKMAN.EXE O26 - IFEO: rfwsrv.exe -> TASKMAN.EXE O26 - IFEO: rfwstub.exe -> TASKMAN.EXE O26 - IFEO: runiep.exe -> TASKMAN.EXE O26 - IFEO: safeboxTray.exe -> ntsd -D O26 - IFEO: tqat.exe -> ntsd -d

这与以前的《遭遇 Trojan-PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等》相似,但在实际处理时要复杂一些~

(未完待续)

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

紫郢剑侠

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值