EndurerComments
1Version
For example:
I am in the middleBackdoor. gpigeon. IIRRising Star 2007 can be used to make the difference. After the attack is completed, restart the system.
Virus files: C:/program files/Internet Explorer/iyune.exe-> backdoor. gpigeon. IIR
The following suspicious items are found in the log of hijackthis attached to the email:
/--------
Hijackthis_zww Chinese Version scan log v1.99.1
Saved on 16:57:48, date
Operating System: Windows XP SP2 (winnt 5.01.2600)
Browser: Internet Explorer v7.00 (7.00.5730.0011)
O23-NT Service: cker.com.cn-unknown owner-C:/Windows/winr.exe
--------/
Although hijackthis has not been updated for a long time, it can still identify IE 7 ^_^
Repair suggestions:
(For the following operations, refer to [System Restoration series] basic operation indexes.
Http://endurer.bokee.com/2591241.html)
Restart your computer to safe Mode
Disable System Restoration
Stop and disable the service: cker.com.cn
Use WinRAR to find the file C:/Windows/winr.exe, package the backup, and delete it.
Scan and fix with hijackthis:
O23-NT Service: cker.com.cn-unknown owner-C:/Windows/winr.exe
Clear temporary ie folders and C:/Windows/prefetch folders
Restart the computer to the normal mode, the file cker.com.cn compressed package as an e-mail attachment to the endurer@163.com