EndurerOriginal
2006-12-30 th1Version
Today, I received a help email containing the logs scanned by hijakcthis.
Suspicious items found in log:
/==============
Logfile of hijackthis v1.99.1
Scan saved at 6:54:09, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running Processes:
C:/Windows/system32/scvhsot.exe
O4-HKLM/../run: [qqkav] C:/Windows/system32/scvhsot.exe
===============/
And
Trojan.dl.multi.wfg(sss.exe, scvhost. EXE)
Http://endurer.bokee.com/5980310.html
Http://blog.csdn.net/Purpleendurer/archive/2006/12/22/1454383.aspx
Similar.
The recommended solution is as follows:
Press CTRL + ALT + DEL to open the task manager and terminate the process: scvhsot.exe
Use WinRAR to check all hard disk partitions from disk D and delete autorun.infand sss.exeor sxs.exe
Use WinRAR to open C:/Windows/system32 and delete the file: scvhsot.exe
Fixed with hijackthis: O4-HKLM/../run: [qqkav] C:/Windows/system32/scvhsot.exe