EndurerOriginal
1Version
Open the free anti-virus web page of Rising's online website, and immediately pop up the Kingsoft drug overlord advertisement window. When rising finds the virus, the scanning result window is displayed, and the Kingsoft drug overlord advertisement window is displayed.
Is Rising recommending Kingsoft drug overlord?
A netizen's computer, working slowly, occasionally pops up an advertisement window, such:
/----------
Hxxp: // cg.9e3.com/register3.html
Hxxp: // photo.9158.com/tg/pic10.html
Hxxp: // vod.5617.com/5617/index.html
Hxxp: // dm21.fx120.net/120shop.htm
Hxxp: // www.cyworld.com.cn/event/markting/myminiroom/163_event.php? From = 49 & str_ad = linkid % 3d4365% 26 channelid % 3d200508
Hxxp: // my.chinahr.com/newaccount.aspx
Hxxp: // www.duduw.com/web/dudu-07.htm
Hxxp: // stbanner.allyes.com/sm/gmi/800600/index.php? Channelid = 201178 & linkid = 5794
----------/
Wait, the Yok search icon appears on the desktop, and the next boot is uninstalled ......
Restart your computer and select security mode with network connection.
Download hijackthis to the http://endurer.ys168.com to scan logs and find suspicious items:
/----------
Hijackthis_zww Chinese Version scan log v1.99.1
Saved at 0:09:39, Date:
Operating System: Windows XP SP2 (winnt 5.01.2600)
Browser: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Currently running process:
C:/Windows/system/java.exe
R3-urlsearchhook: Yok Search Class-{88351cef-bac0-4a9b-8380-31a173e2926f}-C:/program files/yok.com/supersearch/yok_supersearch.dll
O2-BHO: monitorurl class-{08a312bb-5409-49fc-9347-54bb7d069ac6}-C:/progra ~ 1/AD ~ 1/deskipn. dll
O2-BHO: wmpdrm-{0e674588-66b7-4e19-9d0e-2053b800f69f}-C:/Windows/system32/wmpdrm. dll
O2-BHO: myiehelper class-{tags}-C:/Documents and Settings/all users/Application Data/Microsoft/iehelper/iehelper2006814_4593.dll (file missing)
O2-BHO: cdnforie class-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O2-BHO: JMX. jmxcenter-{63799236-76bf-493c-a587-df479eba2d4b}-C:/Windows/system32/ejmx. dll
O2-BHO: Yok super search-{75fe2b5a-d3a4-4efa-ac11-adc9459688}-C:/program files/yok.com/supersearch/yok_supersearch.dll
O2-BHO: newweb controller-{9aceee31-1440-471b-aa46-72b061fe7d61}-C:/Windows/system32/winsc32.dll
O2-BHO: (No Name)-{D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF}-(no file)
O2-BHO: bhelper class-{F2E37336-BFDB-409B-8D0E-6F013C438B20}-C:/Windows/system/export o0611. dll
O2-BHO: wmhlprobj class-{F5824EFB-728A-4726-A5A5-85A68B20EDC3}-C:/progra ~ 1/CNNIC/CDN/wmhlpr. dll (file missing)
O3-IE Toolbar addition: Yok super search-{F869BB38-FFEF-4589-B986-610B7AD0ADA2}-C:/program files/yok.com/supersearch/yok_supersearch.dll
O4-startup Item HKLM // run: [C:/Windows/wd2_051117_wis205_mini.exe] C:/Windows/wd2_051117_wis205_mini.exe
O4-startup Item HKLM // run: [C:/Windows/setup_110017.exe] C:/Windows/setup_110017.exe
O4-startup Item HKLM // run: [C:/Windows/10045_setup.exe] C:/Windows/10045_setup.exe
O4-startup Item HKLM // run: [C:/Windows/101628.exe] C:/Windows/101628.exe
O4-startup Item HKLM // run: [spoolsv] C:/Windows/system32/spoolsv/spoolsv.exe-printer
O4-startup Item HKLM // run: [C:/Windows/newweb10317.exe] C:/Windows/newweb10317.exe
O4-startup Item HKLM // run: [C:/Windows/tshz168.exe] C:/Windows/tshz168.exe
O4-boot item HKLM // run: [C:/Windows/Setup-168.exe] C:/Windows/Setup-168.exe
O4-startup Item HKLM // run: [C:/Windows/yok_904_1007.exe] C:/Windows/yok_904_1007.exe
O4-startup Item HKLM // run: [msservice_v1.0] C:/Windows/system/java.exe
O4-startup Item HKLM // run: [desktop] C:/Windows/system32/rundll32.exe "C:/program files/deskadtop/run. dll", rundll
O4-startup Item HKLM // run: [cdnctr] C:/program files/CNNIC/CDN/cdnup.exe
O4-Global startup: IE-Bar.lnk = C:/program files/common files/ie-bar/iebar.exe
Add project in the right-click o8-ie menu: Yok super search-C:/program files/yok.com/supersearch/yoksch.htm
Add a project in the right-click o8-ie menu: Send the image with a colorful image bell-C:/program files/caishow tech/caishow/sendmms.htm
O9-Additional buttons in the browser: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O9-Additional "tool" menu items in the browser: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O9-Additional buttons in the browser: Yok super search-{F869BB38-FFEF-4589-B986-610B7AD0ADA2}-hxxp: // www.yok.com (file missing)
O10-unknown file in Winsock LSP: C:/Windows/system32/cdnns. dll
O10-unknown file in Winsock LSP: C:/Windows/system32/msplus. dll
O10-unknown file in Winsock LSP: C:/Windows/system32/msplus. dll
O11-Options Group: [cdnclient] accessing Chinese
O21-ssodl: delayrun-{5a6f2f95-3191-433b-8533-eb0b596a7bac}-C:/Windows/mongod0610. dll
----------/
Download lspfix. EXE and Rising Antivirus assistant from http://endurer.ys168.com.
Download winsockxpfix from http://www.miisoft.com/soft/22/2006/20060817014.html.
Uninstall: deskadtop, newweb, Yok super search, Chinese online
Find with WinRAR
/----------
C:/Windows/10045_setup.exe
C:/Windows/101628.exe
C:/Windows/newweb10317.exe
C:/Windows/setup_110017.exe
C:/Windows/Setup-168.exe
C:/Windows/tshz168.exe
C:/Windows/wd2_051117_wis205_mini.exe
C:/Windows/system32/quartz32.dll
C:/Windows/system32/SCIA. dll
C:/Windows/system32/msplus. dll
C:/Windows/system32/ijcj. dll
C:/Windows/system32/jjbi. dll
C:/Windows/system32/icif. dll
C:/Windows/system32/ejjf. dll
C:/Windows/system32/updatemodule. dll
C:/Windows/system32/winsc32.dll
C:/Windows/system32/spoolsv/spoolsv.exe
----------/
Package backup.
Delete an object:
/----------
C:/Windows/yok_904_1007.exe
C:/Windows/system32/msplus1.dll
C:/Windows/system32/winsc. dll
C:/Windows/system32/winsc64.dll
----------/
Decompress and run the "Rising anti-virus assistant", click "use rising free anti-virus", open the online free anti-virus webpage, And the Kingsoft drug overlord advertisement window is displayed immediately. Dizzy!
Scan the C:/windows and C:/Program Files folders. The results are as follows:
/----------
2:20:14 Rising anti-virus Assistant
Windows XP Service Pack 2 (5.1.2600)
File Name virus name
C:/Windows/system32/msicn/plugins/BM. dllTrojan. ourxin. e
C:/Windows/system32/msicn/plugins/AS. dllTrojan. ourxin. c
C:/Windows/system32/msicn/msibm. dllTrojan. Spy. Agent. BHS
C:/Windows/system32/1116/ntjdo/ntjcn. EmmTrojan. Spy. Agent. BHS
C:/Windows/system32/1116/ntjdo/plugins/CN. EmmTrojan. ourxin. e
C:/Windows/system32/1116/ntjdo/plugins/BT. EmmTrojan. ourxin. c
C:/Windows/system32/1116/tzt/xnqesn. EmmTrojan. ourxin. d
C: // Windows/system32/1116/tqppmtw. fyfTrojan. DL. Agent. kij
C:/Windows/system32/spoolsv/spoolsv.exeTrojan. DL. Agent. kij
C:/Windows/system32/wmpdrm. dllTrojan. ourxin. d
C:/Windows/system32/winsc32.dllTrojan. Clicker. qhost. I
C:/Windows/system32/updatemodule. dllTrojan. Clicker. Agent. Ads
C:/Windows/system32/ejjf. dllTrojan. DL. Direct. AA
C:/Windows/system32/icif. dllTrojan. DL. Direct. AA
C:/Windows/system32/jjbi. dllTrojan. DL. Direct. AA
C:/Windows/system32/ijcj. dllTrojan. DL. Direct. AA
C:/Windows/101628.exeTrojan. DL. adload. EI
C:/Windows/10045_setup.exeTrojan. startpage. bnx
C:/program files/common files/system/ddw.l. datTrojan. Inject. St
C:/program files/netmeeting/nmview. dllTrojan. Agent. DTE
C:/program files/netmeeting/CONF. dllTrojan. Agent. DTE
C:/program files/Xerox/fcbzc.exeTrojan. Inject. St
C:/program files/CNNIC/iebar_v2.exeTrojan. DL. qqhelper. EO
----------/
When rising finds out the scan result window, the Kingsoft drug overlord advertisement window is displayed!
We used the "Rising Antivirus assistant" to solve the problem.
Close all folder and browser program windows, run the lspfix.exe file, select the option "I know what I'm doing", and then set the cdnns in the left window. DLL and msplus. move the DLL to the right window (do not touch other files) and select "finish ".
Close all browser windows and folder windows, use hijackthis scan again, check the items in the previous column, and click [Fix] (fix ).
Clear temporary ie folders
Clear the C:/Documents and Settings/user/Local Settings/Temp folder