EndurerOriginal
1Version
A netizen's computer recently reported by rising:
/---
Virus name processing result scan method path file virus source
Trojan. DL. getou.Clear successfully manually scan iexplore. EXE> C:/program files/Internet Explorer/iexplore. EXE Local Machine
---/
Let me check it out.
Pe_xscan is used to scan and suspicious items are found:
/---
Pe_xscan by Purple endurer
2007-3-6 10:50:43
Windows XP Service Pack 1 (5.1.2600)
Administrator user group
[System process] * 0
C:/Windows/system32/lgsym. dll |
C:/program files/lljagent/kxagents.exe * 1980 | 10:59:52 | kxagentservice | 1, 2, 0, 0 | kxagentservice | copyright (c) 2005 smartdove | 1, 2, 0, 0 | smartdove | kxagentservice | kxagents.exe
C:/program files/lljagent/kxagents.exe | 10:59:52 | kxagentservice | 1, 2, 0, 0 | kxagentservice | copyright (c) 2005 smartdove | 1, 2, 0, 0 | smartdove | kxagentservice | kxagents.exe
C:/program files/lljagent/zlib1.dll | zlib | 1.2.1 | zlib data compression library | (c) 1995-2003 Jean-Loup gailly & Mark Adler | 1.2.1 |? |? | Zlib1.dll | zlib1.dll
C:/Windows/explorer. EXE * 424 | MICROSOFT (r) Windows (r) Operating System | 6.00.2800.1106 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2800.1106 (xpsp1.020828-1920) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/lgsym. dll |
C:/Windows/iexpl0re.exe * 1312 | 7:53:42
C:/Windows/iexpl0re.exe | 7:53:42
C:/Windows/system32/lgsym. dll |
C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe * 388 | 7:53:48
C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe | 7:53:48
C:/program files/Internet Explorer/iexplore.exe * 1644 | MICROSOFT (r) Windows (r) Operating System | 6.00.2800.1106 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2800.1106 (xpsp1.020828-1920) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/lgsym. dll |
O4-hkcr/../run: [kavshell] C:/Windows/system32/svch0st.exe
O4-hkcr/../run: [lch9ku087gfj] C:/Windows/iexpl0re.exe
O4-hkcr/../run: [1xbi5t4lx] C:/Windows/rundl13a.exe
O4-HKLM/../run: [kisskobaby] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/wl.exe
O4-HKLM/../run: [whereou] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe
O23-service: ie_winservername (Windows createrie)-C:/Windows/winlllgon.exe (automatically started)
---/
Download hijackthis from the http://endurer.ys168.com, download bat_do from the http://purpleendurer.ys168.com, and download Dr. Web cureit backup.
(For the following repair operations, refer:
[System repair series] basic operation index
Http://endurer.blogchina.com/2591241.html)
Restart your computer to safe mode.
Use bat_do to package and back up suspicious files.
Scan with Dr. Web cureit. The results are as follows:
========================================================== ============================================
Dr. Web (r) platform for Windows v4.33.2 (4.33.2.10060)
Copyright (c) Igor Daniloff, 1992-2006
Log generated on:, 11:35:35 [hcnybgs2] [administrator]
Command-line: "C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/rarsfx0/cureit.exe "/LNG/INI: cureit_xp.ini
Operating System: Windows XP Professional x86 (build 2600), Service Pack 1
========================================================== ============================================
Engine version: 4.33 (4.33.5.10110)
Engine API version: 2.01
[Scan path] C:/Documents ents and settings/Administrator/Local Settings/temp/my.exe
> C:/Documents and Settings/Administrator/Local Settings/temp/my.exe infectedTrojan. PWS. lineage-Will be cured after reboot
[Scan path] C:/Windows/winlllgon.exe
C:/Windows/winlllgon.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/xin1_12.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/111_12.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/11000012.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/1%2%.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/ehtnr4ca/12[1).exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/tm4ytsrs/xi1_1).exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/tm4ytsrs/1[1).exe infectedBackdoor. webdor-Deleted
> C:/Documents and Settings/Administrator/Local Settings/temp/my.exe infectedTrojan. PWS. lineage-Will be cured after reboot
[Scan path] C:/Windows
C:/Windows/winllgon.exe infectedBackdoor. webdor-Deleted
C:/Windows/rundl132.exe infectedTrojan. PWS. wsgame-Deleted
C:/Windows/rundl13a.exe infectedTrojan. PWS. wsgame-Deleted
C:/Windows/system32/rav26.dll infectedTrojan. PWS. Soul-Deleted
Unfortunately, C:/Windows/system32/lgsym. dll does not respond. You can only manually delete lgsym. dll.
Use hijackthis to repair items O4 and o23 in pe_xscan.
Run the system tool in the attachment: Clear the disk.
Clear C:/Windows/prefetch
Check the rising version and find that the last upgrade date is July 22, March 2!
Restart your computer and upgrade rising ......