EndurerOriginal
1Version
Today, I received an email from a netizen, not indicating what went wrong with the computer. Only the hijackthis log is available.
The following suspicious items are found in the log:
Hijackthis_zww Chinese Version scan log v1.99.1
Saved on 21:09:06, Date:
Operating System: Windows XP SP2 (winnt 5.01.2600)
Browser: Internet Explorer v6.00 SP2 (6.00.2900.2180)
O2-BHO: (No Name)-{7e853d72-626a-48ec-a868-ba8d5e23e045}-(no file)
O4-startup Item HKLM // run: [winform] E:/Windows/winform.exe
O4-startup Item HKLM // run: [cmdbcs] E:/Windows/cmdbcs.exe
O4-startup Item HKLM // run: [wsttrs] E:/Windows/wsttrs.exe
O4-startup Item hkcu // run: [System Boot Check] C:/Windows/baba.exe
O4-startup Item hkcu // run: [set] E:/Windows/servicea.exe
O4-startup Item hkcu // run: [6] E:/Windows/iexpl0ra.exe
O4-startup Item hkcu // run: [c] E:/Windows/c0nima.exe
O4-startup Item hkcu // run: [gf73z81wd] E:/docume ~ 1/Meng/locals ~ 1/temp/servicer.exe
O4-startup Item hkcu // run: [2 zgemexrk] E:/docume ~ 1/Meng/locals ~ 1/temp/c0nime.exe
O23-NT Service: Internet-unknown owner-E:/Windows/nntv.exe
O23-NT Service: workstation-unknown owner-E:/Windows/services.exe
The startup items in the O4 group are similar to those found in the computers of netizens worm. Viking. pk in the previous days. See:
I only reminded you yesterday that today some netizens have clicked on the web site in QQ information, which is Worm. Viking. PK.
Http://endurer.bokee.com/6174316.html
Http://blog.csdn.net/Purpleendurer/archive/2007/03/20/1535711.aspx
Http://blog.i0778.com /? 1314/action_viewspace_itemid_2810.html
Repair suggestions:
(For the following repair operations, refer to [system repair series] basic operation indexes.
Http://endurer.blogchina.com/2591241.html)
Restart your computer to safe Mode
Stop and disable the service:
Internet
Workstation
Find the file with WinRAR:
E:/Windows/winform.exe
E:/Windows/cmdbcs.exe
E:/Windows/wsttrs.exe
C:/Windows/baba.exe
E:/Windows/servicea.exe
E:/Windows/iexpl0ra.exe
E:/Windows/c0nima.exe
E:/docume ~ 1/Meng/locals ~ 1/temp/servicer.exe
E:/docume ~ 1/Meng/locals ~ 1/temp/c0nime.exe
E:/Windows/nntv.exe
E:/Windows/services.exe
After the backup is packaged, delete it.
Use hijackthis to fix the suspicious items listed above
Clear temporary ie folders
Clear C:/Windows/prefetch
Restart the computer, the E:/Windows/services.exe and other files as e-mail attachments to the endurer@163.com.