Encounter my.exe, svch0st.exe, iexpl0re.exe, rundl13a.exe, lgsym. dll, etc.

Source: Internet
Author: User

EndurerOriginal

1Version

A netizen's computer recently reported by rising:

/---
Virus name processing result scan method path file virus source
Trojan. DL. getou.Clear successfully manually scan iexplore. EXE> C:/program files/Internet Explorer/iexplore. EXE Local Machine
---/

Let me check it out.

Pe_xscan is used to scan and suspicious items are found:

/---
Pe_xscan by Purple endurer
2007-3-6 10:50:43
Windows XP Service Pack 1 (5.1.2600)
Administrator user group

[System process] * 0
C:/Windows/system32/lgsym. dll |
C:/program files/lljagent/kxagents.exe * 1980 | 10:59:52 | kxagentservice | 1, 2, 0, 0 | kxagentservice | copyright (c) 2005 smartdove | 1, 2, 0, 0 | smartdove | kxagentservice | kxagents.exe
C:/program files/lljagent/kxagents.exe | 10:59:52 | kxagentservice | 1, 2, 0, 0 | kxagentservice | copyright (c) 2005 smartdove | 1, 2, 0, 0 | smartdove | kxagentservice | kxagents.exe
C:/program files/lljagent/zlib1.dll | zlib | 1.2.1 | zlib data compression library | (c) 1995-2003 Jean-Loup gailly & Mark Adler | 1.2.1 |? |? | Zlib1.dll | zlib1.dll
C:/Windows/explorer. EXE * 424 | MICROSOFT (r) Windows (r) Operating System | 6.00.2800.1106 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2800.1106 (xpsp1.020828-1920) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/Windows/system32/lgsym. dll |
C:/Windows/iexpl0re.exe * 1312 | 7:53:42
C:/Windows/iexpl0re.exe | 7:53:42
C:/Windows/system32/lgsym. dll |
C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe * 388 | 7:53:48
C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe | 7:53:48
C:/program files/Internet Explorer/iexplore.exe * 1644 | MICROSOFT (r) Windows (r) Operating System | 6.00.2800.1106 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2800.1106 (xpsp1.020828-1920) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/lgsym. dll |

O4-hkcr/../run: [kavshell] C:/Windows/system32/svch0st.exe
O4-hkcr/../run: [lch9ku087gfj] C:/Windows/iexpl0re.exe
O4-hkcr/../run: [1xbi5t4lx] C:/Windows/rundl13a.exe
O4-HKLM/../run: [kisskobaby] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/wl.exe
O4-HKLM/../run: [whereou] C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/my.exe

O23-service: ie_winservername (Windows createrie)-C:/Windows/winlllgon.exe (automatically started)
---/

Download hijackthis from the http://endurer.ys168.com, download bat_do from the http://purpleendurer.ys168.com, and download Dr. Web cureit backup.

(For the following repair operations, refer:
[System repair series] basic operation index
Http://endurer.blogchina.com/2591241.html)

Restart your computer to safe mode.

Use bat_do to package and back up suspicious files.

Scan with Dr. Web cureit. The results are as follows:

========================================================== ============================================
Dr. Web (r) platform for Windows v4.33.2 (4.33.2.10060)
Copyright (c) Igor Daniloff, 1992-2006
Log generated on:, 11:35:35 [hcnybgs2] [administrator]
Command-line: "C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/rarsfx0/cureit.exe "/LNG/INI: cureit_xp.ini
Operating System: Windows XP Professional x86 (build 2600), Service Pack 1
========================================================== ============================================
Engine version: 4.33 (4.33.5.10110)
Engine API version: 2.01

[Scan path] C:/Documents ents and settings/Administrator/Local Settings/temp/my.exe
> C:/Documents and Settings/Administrator/Local Settings/temp/my.exe infectedTrojan. PWS. lineage-Will be cured after reboot
[Scan path] C:/Windows/winlllgon.exe
C:/Windows/winlllgon.exe infectedBackdoor. webdor-Deleted

C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/xin1_12.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/111_12.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/11000012.16.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/8 hapgzkv/1%2%.exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/ehtnr4ca/12[1).exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/tm4ytsrs/xi1_1).exe infectedBackdoor. webdor-Deleted
C:/Documents and Settings/LocalService/Local Settings/Temporary Internet Files/content. ie5/tm4ytsrs/1[1).exe infectedBackdoor. webdor-Deleted
> C:/Documents and Settings/Administrator/Local Settings/temp/my.exe infectedTrojan. PWS. lineage-Will be cured after reboot
[Scan path] C:/Windows
C:/Windows/winllgon.exe infectedBackdoor. webdor-Deleted
C:/Windows/rundl132.exe infectedTrojan. PWS. wsgame-Deleted
C:/Windows/rundl13a.exe infectedTrojan. PWS. wsgame-Deleted
C:/Windows/system32/rav26.dll infectedTrojan. PWS. Soul-Deleted

Unfortunately, C:/Windows/system32/lgsym. dll does not respond. You can only manually delete lgsym. dll.

 

Use hijackthis to repair items O4 and o23 in pe_xscan.

 

Run the system tool in the attachment: Clear the disk.

 

Clear C:/Windows/prefetch

 

Check the rising version and find that the last upgrade date is July 22, March 2!

 

Restart your computer and upgrade rising ......

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.