EndurerOriginal
2006-10-19 th1Version
A netizen's computer, once I open IE, will pop up a message box such as the advertisement window and work contact, asking me to help me.
Download hijackthis scan log from http://endurer.ys168.com and find the following suspicious items:
/----------
Logfile of hijackthis v1.99.1
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running Processes:
C:/Windows/pop.exe
O2-BHO: raobject class-{46f194eb-b7db-4b7a-bd42-5ff39fd17664}-C:/progra ~ 1/pcast/hbcast. dll
O2-BHO: bhoimp class-{70aff2cb-9da2-499c-8d15-900729fce83d}-C:/Windows/system32/yhbo. dll (file missing)
O2-BHO: (No Name)-{B3D16F27-E86C-4A68-9E74-D09147C8D929}-C:/Windows/system32/apphelper. dll
O2-BHO: System helper-{B88DBC3F-41FB-40AE-AFB0-4220E842B710}-C:/Windows/system32/flash9.dll (file missing)
O2-BHO: subconscious intruder-{EBBC6E6D-7B65-46be-B509-86CED2D17876}-C:/Windows/system32/inte32.dll (file missing)
O4-HKLM/../run: [update] C:/program files/common files/updat/update.exe
O4-HKLM/../run: [richmedia] C:/Windows/system32/rundll32.exe "C:/progra ~ 1/pcast/hbcast. dll ", waitwindows
O4-HKLM/../run: [realtpsk] C:/Windows/system/realsched.exe
O4-hkcu/../run: [msnnt] C:/Windows/winampf.exe
----------/
Uninstall: Desktop Media/richmedia, Yahoo assistant, and Chinese Internet access
Check C:/, C:/Windows, C:/Windows/system32 with WinRAR and find the following suspicious files:
/----------
1001live.exe (the value of Kaspersky isTrojan-Dropper.Win32.Agent.awb)
7075cafi.exe (the value of Kaspersky isTrojan-Dropper.Win32.Agent.awb)
01394067. exe
ACSS. dll (from linkmedia tech)
199019002. EXE (Kaspersky reportsNot-a-virus: adwarewin32.hengbang. t)
Apphelper. dll (the value of Kaspersky isTrojan-ClickerWin32.BHO.f)
Downloads
Cert.exe (Kaspersky reportsTrojan-Dropper.Win32.Delf.zg)
Ie.exe (Kaspersky reportsTrojan-Spy.Win32.Agent.ct)
Drsmartload.exe
Pop.exe
Nbvgj.exe (Kaspersky indicatesTrojan-Clocker.Win32.costrat.n)
Realsched.exe
Safehelper12.dll
Sdmagent.exe
TL. dll
Setup147.exe
Winampf.exe (Kaspersky indicatesTrojan-Downloader.Win32.Small.dts)
Vtglx.exe
Zhang02.exe (Kaspersky reportsTrojan-Downloader.Win32.Adload.fu)
Acss.exe
Vp_vm.dll
Ss10cmd.exe
----------/
After the backup is packaged, delete it.
Close all folder windows, use hijackthis to scan and repair the items listed above.
Clear temporary ie folders