Why does rising recommend Kingsoft drug overlord? It turned out to be an advertisement program"

Source: Internet
Author: User

EndurerOriginal
1Version

Open the free anti-virus web page of Rising's online website, and immediately pop up the Kingsoft drug overlord advertisement window. When rising finds the virus, the scanning result window is displayed, and the Kingsoft drug overlord advertisement window is displayed.

Is Rising recommending Kingsoft drug overlord?

A netizen's computer, working slowly, occasionally pops up an advertisement window, such:
/----------
Hxxp: // cg.9e3.com/register3.html
Hxxp: // photo.9158.com/tg/pic10.html
Hxxp: // vod.5617.com/5617/index.html
Hxxp: // dm21.fx120.net/120shop.htm
Hxxp: // www.cyworld.com.cn/event/markting/myminiroom/163_event.php? From = 49 & str_ad = linkid % 3d4365% 26 channelid % 3d200508
Hxxp: // my.chinahr.com/newaccount.aspx
Hxxp: // www.duduw.com/web/dudu-07.htm
Hxxp: // stbanner.allyes.com/sm/gmi/800600/index.php? Channelid = 201178 & linkid = 5794
----------/
Wait, the Yok search icon appears on the desktop, and the next boot is uninstalled ......

Restart your computer and select security mode with network connection.

Download hijackthis to the http://endurer.ys168.com to scan logs and find suspicious items:

/----------
Hijackthis_zww Chinese Version scan log v1.99.1
Saved at 0:09:39, Date:
Operating System: Windows XP SP2 (winnt 5.01.2600)
Browser: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Currently running process:
C:/Windows/system/java.exe

R3-urlsearchhook: Yok Search Class-{88351cef-bac0-4a9b-8380-31a173e2926f}-C:/program files/yok.com/supersearch/yok_supersearch.dll

O2-BHO: monitorurl class-{08a312bb-5409-49fc-9347-54bb7d069ac6}-C:/progra ~ 1/AD ~ 1/deskipn. dll

O2-BHO: wmpdrm-{0e674588-66b7-4e19-9d0e-2053b800f69f}-C:/Windows/system32/wmpdrm. dll

O2-BHO: myiehelper class-{tags}-C:/Documents and Settings/all users/Application Data/Microsoft/iehelper/iehelper2006814_4593.dll (file missing)

O2-BHO: cdnforie class-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll

O2-BHO: JMX. jmxcenter-{63799236-76bf-493c-a587-df479eba2d4b}-C:/Windows/system32/ejmx. dll

O2-BHO: Yok super search-{75fe2b5a-d3a4-4efa-ac11-adc9459688}-C:/program files/yok.com/supersearch/yok_supersearch.dll

O2-BHO: newweb controller-{9aceee31-1440-471b-aa46-72b061fe7d61}-C:/Windows/system32/winsc32.dll

O2-BHO: (No Name)-{D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF}-(no file)

O2-BHO: bhelper class-{F2E37336-BFDB-409B-8D0E-6F013C438B20}-C:/Windows/system/export o0611. dll

O2-BHO: wmhlprobj class-{F5824EFB-728A-4726-A5A5-85A68B20EDC3}-C:/progra ~ 1/CNNIC/CDN/wmhlpr. dll (file missing)

O3-IE Toolbar addition: Yok super search-{F869BB38-FFEF-4589-B986-610B7AD0ADA2}-C:/program files/yok.com/supersearch/yok_supersearch.dll

O4-startup Item HKLM // run: [C:/Windows/wd2_051117_wis205_mini.exe] C:/Windows/wd2_051117_wis205_mini.exe

O4-startup Item HKLM // run: [C:/Windows/setup_110017.exe] C:/Windows/setup_110017.exe

O4-startup Item HKLM // run: [C:/Windows/10045_setup.exe] C:/Windows/10045_setup.exe

O4-startup Item HKLM // run: [C:/Windows/101628.exe] C:/Windows/101628.exe

O4-startup Item HKLM // run: [spoolsv] C:/Windows/system32/spoolsv/spoolsv.exe-printer

O4-startup Item HKLM // run: [C:/Windows/newweb10317.exe] C:/Windows/newweb10317.exe

O4-startup Item HKLM // run: [C:/Windows/tshz168.exe] C:/Windows/tshz168.exe

O4-boot item HKLM // run: [C:/Windows/Setup-168.exe] C:/Windows/Setup-168.exe

O4-startup Item HKLM // run: [C:/Windows/yok_904_1007.exe] C:/Windows/yok_904_1007.exe

O4-startup Item HKLM // run: [msservice_v1.0] C:/Windows/system/java.exe

O4-startup Item HKLM // run: [desktop] C:/Windows/system32/rundll32.exe "C:/program files/deskadtop/run. dll", rundll

O4-startup Item HKLM // run: [cdnctr] C:/program files/CNNIC/CDN/cdnup.exe

O4-Global startup: IE-Bar.lnk = C:/program files/common files/ie-bar/iebar.exe

Add project in the right-click o8-ie menu: Yok super search-C:/program files/yok.com/supersearch/yoksch.htm

Add a project in the right-click o8-ie menu: Send the image with a colorful image bell-C:/program files/caishow tech/caishow/sendmms.htm

O9-Additional buttons in the browser: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll

O9-Additional "tool" menu items in the browser: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll

O9-Additional buttons in the browser: Yok super search-{F869BB38-FFEF-4589-B986-610B7AD0ADA2}-hxxp: // www.yok.com (file missing)

O10-unknown file in Winsock LSP: C:/Windows/system32/cdnns. dll
O10-unknown file in Winsock LSP: C:/Windows/system32/msplus. dll
O10-unknown file in Winsock LSP: C:/Windows/system32/msplus. dll

O11-Options Group: [cdnclient] accessing Chinese

O21-ssodl: delayrun-{5a6f2f95-3191-433b-8533-eb0b596a7bac}-C:/Windows/mongod0610. dll
----------/
Download lspfix. EXE and Rising Antivirus assistant from http://endurer.ys168.com.
Download winsockxpfix from http://www.miisoft.com/soft/22/2006/20060817014.html.

Uninstall: deskadtop, newweb, Yok super search, Chinese online

Find with WinRAR

/----------
C:/Windows/10045_setup.exe
C:/Windows/101628.exe
C:/Windows/newweb10317.exe
C:/Windows/setup_110017.exe
C:/Windows/Setup-168.exe
C:/Windows/tshz168.exe
C:/Windows/wd2_051117_wis205_mini.exe
C:/Windows/system32/quartz32.dll
C:/Windows/system32/SCIA. dll
C:/Windows/system32/msplus. dll
C:/Windows/system32/ijcj. dll
C:/Windows/system32/jjbi. dll
C:/Windows/system32/icif. dll
C:/Windows/system32/ejjf. dll
C:/Windows/system32/updatemodule. dll
C:/Windows/system32/winsc32.dll
C:/Windows/system32/spoolsv/spoolsv.exe
----------/
Package backup.

Delete an object:
/----------
C:/Windows/yok_904_1007.exe
C:/Windows/system32/msplus1.dll
C:/Windows/system32/winsc. dll
C:/Windows/system32/winsc64.dll
----------/

Decompress and run the "Rising anti-virus assistant", click "use rising free anti-virus", open the online free anti-virus webpage, And the Kingsoft drug overlord advertisement window is displayed immediately. Dizzy!

Scan the C:/windows and C:/Program Files folders. The results are as follows:
/----------
2:20:14 Rising anti-virus Assistant
Windows XP Service Pack 2 (5.1.2600)
File Name virus name
C:/Windows/system32/msicn/plugins/BM. dllTrojan. ourxin. e
C:/Windows/system32/msicn/plugins/AS. dllTrojan. ourxin. c
C:/Windows/system32/msicn/msibm. dllTrojan. Spy. Agent. BHS
C:/Windows/system32/1116/ntjdo/ntjcn. EmmTrojan. Spy. Agent. BHS
C:/Windows/system32/1116/ntjdo/plugins/CN. EmmTrojan. ourxin. e
C:/Windows/system32/1116/ntjdo/plugins/BT. EmmTrojan. ourxin. c
C:/Windows/system32/1116/tzt/xnqesn. EmmTrojan. ourxin. d
C: // Windows/system32/1116/tqppmtw. fyfTrojan. DL. Agent. kij
C:/Windows/system32/spoolsv/spoolsv.exeTrojan. DL. Agent. kij
C:/Windows/system32/wmpdrm. dllTrojan. ourxin. d
C:/Windows/system32/winsc32.dllTrojan. Clicker. qhost. I
C:/Windows/system32/updatemodule. dllTrojan. Clicker. Agent. Ads
C:/Windows/system32/ejjf. dllTrojan. DL. Direct. AA
C:/Windows/system32/icif. dllTrojan. DL. Direct. AA
C:/Windows/system32/jjbi. dllTrojan. DL. Direct. AA
C:/Windows/system32/ijcj. dllTrojan. DL. Direct. AA
C:/Windows/101628.exeTrojan. DL. adload. EI
C:/Windows/10045_setup.exeTrojan. startpage. bnx
C:/program files/common files/system/ddw.l. datTrojan. Inject. St
C:/program files/netmeeting/nmview. dllTrojan. Agent. DTE
C:/program files/netmeeting/CONF. dllTrojan. Agent. DTE
C:/program files/Xerox/fcbzc.exeTrojan. Inject. St
C:/program files/CNNIC/iebar_v2.exeTrojan. DL. qqhelper. EO
----------/

When rising finds out the scan result window, the Kingsoft drug overlord advertisement window is displayed!
We used the "Rising Antivirus assistant" to solve the problem.

Close all folder and browser program windows, run the lspfix.exe file, select the option "I know what I'm doing", and then set the cdnns in the left window. DLL and msplus. move the DLL to the right window (do not touch other files) and select "finish ".

Close all browser windows and folder windows, use hijackthis scan again, check the items in the previous column, and click [Fix] (fix ).

Clear temporary ie folders

Clear the C:/Documents and Settings/user/Local Settings/Temp folder

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.