遭遇 NinSys74.Sys,B674A2D4.EXE,42AE09E4.DLL,msavp.dll,avpdj,avpwl.dll等
来源:互联网 发布:韩春雨事件 知乎 编辑:程序博客网 时间:2024/05/04 19:10
遭遇 NinSys74.Sys,B674A2D4.EXE,42AE09E4.DLL,msavp.dll,avpdj.dll,avpwl.dll等
endurer 原创
2007-10-12 第1版
昨天中午又帮两位网友清理电脑病毒。
先回忆一下其中一位的。
网友的电脑上装有瑞星2007杀毒软件,不过是已经过期的下载版。
下载 pe_xscan 的 log 中发现如下可疑项:
/===
pe_xscan 07-08-30 by Purple Endurer
2007-10-11 13:45:14
Windows XP Service Pack 2(5.1.2600)
管理员用户组
[System Process] * 0
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/csrss.exe * 656 | 2006-11-8 18:57:2 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Client Server Runtime Process | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CSRSS.Exe | CSRSS.Exe
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/winlogon.exe * 680 | 2006-11-8 18:57:2 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/services.exe * 724 | 2006-11-8 18:57:2 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/lsass.exe * 736 | 2006-11-8 18:57:2 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/svchost.exe * 936 | 2006-11-8 18:57:2 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
C:/WINDOWS/system32/msavp.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/Explorer.EXE * 1648 | 2007-6-13 21:21:56 | Microsoft(R) Windows(R) Operating System | 6.00.2900.3156 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/msavp.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/PROGRAM FILES/RISING/RAV/RavStub.exe * 2012 | 2007-10-4 19:39:36 | RavStub Application | 19, 0, 0, 4 | Rising RavStub | Copyright (c) 1998-2005 Rising Corp. | 19, 0, 0, 4 | Beijing Rising Technology Co., Ltd. | | RavStub | RavStub.exe
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/RUNDLL32.EXE * 340 | 2006-11-8 18:57:2 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/ctfmon.exe * 1904 | 2006-11-8 18:57:2 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/42AE09E4.DLL | 2007-10-10 22:11:46 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/Program Files/Tencent/QQ/TIMPlatform.exe * 3232 | 2007-7-19 16:34:46 | QQ | 7,0,208,1651 | TIMPlatform | Copyright ? 2005 ━ 2007 TENCENT Inc. All Rights Reserved | 7,0,365,1701 | TENCENT | | TIMPlatform | TIMPlatform.exe
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/Program Files/Tencent/QQ/QQ.exe * 3512 | 2007-7-19 16:27:2 | QQ | 7,0,365,1701 | QQ | Copyright (C) 1998 - 2007 TENCENT Inc. All Rights Reserved | 7,0,365,1701 | TENCENT | | COMQQD | QQ.exe
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/msavp.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/IEXPLORE.EXE * 3948 | 2006-11-8 18:57:2 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
C:/WINDOWS/system32/avpdj.dll | 2007-9-30 20:47:10
C:/WINDOWS/system32/avpwl.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpwm.dll | 2007-9-30 20:47:0
C:/WINDOWS/system32/avpms.dll | 2007-9-30 20:47:8
C:/WINDOWS/system32/avpdh.dll | 2007-9-30 20:47:8
C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys | 2007-10-10 22:10:38
C:/WINDOWS/system32/msavp.dll | 2007-9-30 20:47:8
O2 - BHO - {00000AA9-A363-466E-BEF5-9BB68697AA7F} -
O4 - HKCU/../Run: [bgswitch] C:/WINDOWS/system32/bgswitch.exe
O4 - HKLM/../Run: [DiskMan32] C:/WINDOWS/DiskMan32.exe
O4 - HKLM/../Run: [AVPSrv] C:/WINDOWS/AVPSrv.exe
O4 - HKLM/../Run: [KVP] C:/WINDOWS/system32/drivers/svchost.exe
O23 - 服务: 29055CF4 (29055CF4) - C:/WINDOWS/system32/B674A2D4.EXE -d | 2007-10-7 12:11:18 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)
O24 - ShlExecHook: [] - {A263206E-55FF-4BF9-A503-880D801F3226} = C:/Program Files/Internet Explorer/PLUGINS/WinSys74.Sys
O24 - ShlExecHook: [] - {AAF3B135-E338-491A-B3CB-9D75DA02C5D1} = C:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys
===/
另外还有一个服务:
O23 - 服务: ptac (Windows ptac RunThem) - C:/WINDOWS/System32/svchost.exe -k netsvcs | 2006-11-8 18:57:2 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe(自动)
Google了一下,没有发现相关的信息。
处理方法都是差不多的,重启到带网络连接的安全模式,到 http://purpleendurer.ys168.com 下载 bat_do 和 FileInfo,用来提取可疑文件信息并打包,延时删除。
下载 DrWeb CureIt! 扫描,用卡卡安全助手清理残留启动项。
重启电脑后,用卡卡安全助手检查没有发现残留启动项,下载瑞星2008,卸载瑞星2007,重启电脑再装瑞星2008,重启电脑,把瑞星2008升级到最新版本再扫描,又发现一些病毒,主要是在系统还原文件夹中。
原来忙得忘记禁用系统还原功能,清理C盘了~
附部分文件信息:
文件说明符 : C:/WINDOWS/system32/42AE09E4.DLL
属性 : A---
语言 : 英语(美国)
文件版本 :
说明 :
版权 : (C) Microsoft Corporation. All rights reserved.
备注 :
产品版本 :
产品名称 : Microsoft(R) Windows(R) Operating System
公司名称 : Microsoft Corporation
合法商标 :
内部名称 :
源文件名 :
创建时间 : 2007-9-30 21:0:57
修改时间 : 2007-10-10 22:11:46
访问时间 : 2007-10-11 0:0:0
大小 : 36864 字节 36.0 KB
MD5 : c216dd38c3734f71e1630db8f6fc3f18
HSA1: 9132DFB817623CC51A6A77F86C569DB9993D7CB8
文件说明符 : C:/WINDOWS/system32/B674A2D4.EXE
属性 : A---
语言 : 英语(美国)
文件版本 :
说明 :
版权 : (C) Microsoft Corporation. All rights reserved.
备注 :
产品版本 :
产品名称 : Microsoft(R) Windows(R) Operating System
公司名称 : Microsoft Corporation
合法商标 :
内部名称 :
源文件名 :
创建时间 : 2007-9-30 20:47:15
修改时间 : 2007-10-7 12:11:18
访问时间 : 2007-10-11 0:0:0
大小 : 16944 字节 16.560 KB
MD5 : 1e2a3451e003fde987841bc38448f15c
HSA1: B72A28A2B94EABDEE58C024649709AB4F73B0D99
文件说明符 : c:/Program Files/Internet Explorer/PLUGINS/SysWin75.Jmp
属性 : A---
获取文件版本信息大小失败!
创建时间 : 2007-9-30 20:47:0
修改时间 : 2007-9-30 20:47:2
访问时间 : 2007-10-11 0:0:0
大小 : 32360 字节 31.616 KB
MD5 : 509c0946db538572e2bc5588328adac2
HSA1: C6E2062C353A78D01A743B413762D2A60ECAB690
文件说明符 : c:/Program Files/Internet Explorer/PLUGINS/NinSys74.Sys
属性 : ASH-
获取文件版本信息大小失败!
创建时间 : 2007-10-7 12:10:55
修改时间 : 2007-10-10 22:10:38
访问时间 : 2007-10-11 0:0:0
大小 : 45178 字节 44.122 KB
MD5 : 379798cd3eccc1597e46820daed03d17
HSA1: F5DA9AB853BDDB510A63C57EF1A493509B1F2676
文件说明符 : c:/Program Files/Internet Explorer/PLUGINS/NysWin75.Jmp
属性 : A---
获取文件版本信息大小失败!
创建时间 : 2007-10-7 12:10:55
修改时间 : 2007-10-10 23:13:18
访问时间 : 2007-10-11 0:0:0
大小 : 32379 字节 31.635 KB
MD5 : c702d3c8959dcca8a0a55aef00358a97
HSA1: 249CCE7D1FDA11E43E6B7EB8AE17D87376373CE1
文件说明符 : c:/Program Files/Internet Explorer/PLUGINS/NinSys74.Tao
属性 : ASH-
获取文件版本信息大小失败!
创建时间 : 2007-10-10 23:13:16
修改时间 : 2007-10-10 23:13:18
访问时间 : 2007-10-11 0:0:0
大小 : 45179 字节 44.123 KB
MD5 : 74e350f6a1f0d0b11047a932277def16
HSA1: E60983A06033A4FA81EDA8D9D448AF98061AF371
没时间逐一测试杀软的反应了
- 遭遇 NinSys74.Sys,B674A2D4.EXE,42AE09E4.DLL,msavp.dll,avpdj,avpwl.dll等
- 遭遇PegeFile.pif,IEXPLORE32.Sys,WinSys64.Sys,NewTemp.dll,avpdj.dll等1
- 遭遇EBUIITI.SYS,QBNLWVQCIMQBOS.DLL,JSRLDZLVYUNXEO.DLL,JSRLDZLVYUNXEO.DLL等
- 遭遇 kapjazy.dll,yhpri.dll,WinSys64.Sys,nwiztlbu.exe,myplayer.com 等1
- 遭遇 kapjazy.dll,yhpri.dll,WinSys64.Sys,nwiztlbu.exe,myplayer.com 等2
- 遭遇conme.exe,abbhelp.dll,MintRoot.sys,AntiVirus.sys,mtlrd.sys等1
- 遭遇conme.exe,abbhelp.dll,MintRoot.sys,AntiVirus.sys,mtlrd.sys等2
- 遭遇HBInject.exe,HBmhly.dll,sys07003.dll,zsqf.dll,ytfa.dll,ytfb.dll,ytfc.dll等
- 遭遇scvhost.exe,kcohj1ba.sys,4f4.exe,w509v.sys,8g4.dll,307b.dll等
- 遭遇Cli5.exe,DNFchin.exe,362.VBS,svhot.exe,userdata.dll,oshajf.sys等
- 遭遇6to4.dll,pcidump.sys,WmiSvc.sys,updater.exe等
- 遭遇vchelp.exe,videodevice.dll,swchost.exe,IEXPLORE32.Sys等1
- 遭遇vchelp.exe,videodevice.dll,swchost.exe,IEXPLORE32.Sys等2
- 遭遇 h.sys,GuiHelp.sys,iesuper.dll,jfrwdh.dll,pedadt.dll等
- 遭遇scvhost.exe,qsetup.exe,dsound.dll,hnetcfg.dll,olepro32.dll等1
- 遭遇scvhost.exe,qsetup.exe,dsound.dll,hnetcfg.dll,olepro32.dll等2
- 遭遇HBKernel32.sys,53u1ttMe.2ys,HBTL.dll,HBSO2.dll,bcejnmfd.dll等1
- 遭遇HBKernel32.sys,53u1ttMe.2ys,HBTL.dll,HBSO2.dll,bcejnmfd.dll等2
- Cisco无线AP在复杂企业环境下配置
- 集成的故事 - IHE
- VB 部件的注册
- 用Struts+Spring+Hibernate组装WEB应用
- windows 系统文件中的i386
- 遭遇 NinSys74.Sys,B674A2D4.EXE,42AE09E4.DLL,msavp.dll,avpdj,avpwl.dll等
- sql培训内容(精简)
- windows xp 注册表
- 经典LINUX程序员面试题
- Eclipse插件FatJar安装与使用
- C# 中访问修饰符
- 用 BinaryWrite 向浏览器输出内容
- Ejb3.0开发指南
- 关于创建文件(夹)与删除文件(夹)的例子。