EndurerOriginal
2006-11-131Version
Last night, rising, a netizen's computer, repeatedly reported TrojansTrojan. psw. wowar. qqThe file is C:/Windows/system32/dllms. dll. Click the Clear button, and rising will prompt you to delete the file at next startup. Let me check it.
Download hijackthis scan log from http://endurer.ys168.com and find the following suspicious items:
/--------
Logfile of hijackthis v1.99.1
Scan saved at 22:03:23, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running Processes:
C:/program files/Microsoft/svhost32.exe
O4-HKLM/../run: [MS] C:/program files/Microsoft/svhost32.exe
O4-HKLM/../run: [loadie] C:/Windows/rund1132.exe
--------/
Process Termination: C:/program files/Microsoft/svhost32.exe
Use WinRAR to manually check and find the following suspicious files:
C:/Windows:
Rund1132.exe
Csrss.exe
Svchost.exe
C:/Windows/system32:
Dllreg. dll
Rxdll. dll (indicated by KasperskyTrojan-PSW.Win32.Nilage.asg)
Xydll. dll (indicated by KasperskyTrojan-PSW.Win32.Delf.ps)
C:/program files/MicrosoftBelow:
Svhost32.exe
C:/program file/Internet ExplorerBelow:
Csrss.exe
Rundll32.exe (the value of Kaspersky isTrojan-PSW.Win32.Nilage.asg)
Services.exe (Kaspersky reportsTrojan-PSW.Win32.Nilage.asg)
After the backup is packaged, delete it.
Clear temporary ie folders
Restart the computer and check again. The C:/Windows/system32/dllms. dll member has been cleared by rising.