EndurerOriginal
2006-09-052Version
1Version
There is a netizen's computer, occasionally pop up hxxp: // www.71791.com and other advertising windows.
Use hijackthis (which can be downloaded to the http://endurer.ys168.com) to scan logs and detect suspicious items:
/-----------
Logfile of hijackthis v1.99.1
Scan saved at 21:32:36, on
Platform: Windows XP SP1 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running Processes:
C:/Windows/system32/realplayer.exe
O2-BHO: sohudaiehelper-{0ca51d02-7739-43ea-8d9a-1e8ad4327b03}-C:/program files/P4P/sodaie. dll (file missing)
O2-BHO: shdocvwhlp class-{BE442802-3911-46E0-B227-076B15A4EAD3}-C:/Windows/system32/mskey16.dll
O4-HKLM/../run: [WebService] systems.exe
O4-HKLM/../run: Your realplayer.exe] C:/Windows/system32/realplayer.exe
O4-hkcu/../run: Your realplayer.exe] C:/Windows/system32/realplayer.exe
O6-hkcu/software/policies/Microsoft/Internet Explorer/Control Panel present
O7-hkcu/software/Microsoft/Windows/CurrentVersion/policies/system, disableregedit = 1
O16-DPF: {28e0fa88-aba8-4937-a247-3031f1a11165} (installer class)-hxxp: // pi.51.net/download/diybar2.cab
O16-DPF: {6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89}-hxxp: // kuaiso.com/toolsbar/kuaiso.cab
O16-DPF: {98a62e3f-a8c5-4ef0-8a00-c70cf9d18a89} (loadercore class)-hxxp: // tb.sogou.com/dlloader.cab
O23-service: remote managements instrumenta (remss_ser)-unknown owner-C:/Windows/system32/netstart.exe
-----------/
Restart your computer to safe Mode
Stop and disable services: remote managements instrumenta (remss_ser)
Process terminated: C:/Windows/system32/realplayer.exe
Find the file with WinRAR:
/-----------
C:/autoexec. HTA
C:/Windows/systems.exe (drweb reportsTrojan. click.1363The rising report isTrojan. startpage. Tal)
C:/Windows/system32/brlmon. dll
C:/Windows/system32/realplayer.exe (the value of Kaspersky isTrojan-Downloader.Win32.Agent.aqr)
C:/Windows/system32/netstart.exeTrojan. startpage. BOA)
-----------/
After the backup is packaged, delete it.
Close all browsers and folders, use hijackthis to scan and fix the items listed above.
Clear temporary ie folders
Clear C:/Documents ents and settings/user/Local Settings/temp (where user is the user name)