Beat a machine dog, such as comint32.sys, fat32.sys, and tk71ov01. sys.
Original endurer
2008-03-13 1st
(Continued: beat a bot like comint32.sys, fat32.sys, and tk71ov01. sys)
First, download fileinfo, bat_do to the http://purpleendurer.ys168.com to extract, package, and delete suspicious files in the log.
Then, clean up the startup items of the virus.
Download hijackthis to the http://endurer.ys168.com, scan and fix o22 items.
Use Registry Editor Regedit to delete o23 and o24 items.
Some Virus File Information:
File Description: C:/Windows/system32/Drivers/rzedsig. sys
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 10:59:42
Modification time: 10:59:44
Access time:
Size: 23392 bytes, 22.864 KB
MD5: e19143eace55115a128fd79a3e0d0b79
Sha1: 4158bce7d3664a535f6710e466d95eed6d13c232
CRC32: 1658d0c5
Rising news:Rootkit. win32.mnless. ca
File Description: C:/Windows/system32/lbrhx. dll
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time: 23:54:26
Access time:
Size: 95232 bytes, 93.0 KB
MD5: fcd29b11dda-f23297c26cdf5e0d03d8
Sha1: a78cbfeed2604d09feecf6b75318e2b83ed473bf
CRC32: d95592c8
C:/Windows/system32/gsiyo. dll
C:/Windows/system32/jzpfr. dll is the same as above.
File Description: C:/Windows/system32/fikce. dll
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time: 23:54:26
Access time:
Size: 116224 bytes, 113.512 KB
MD5: aeefad4dd429f4439aa49cbdbe9cf373
Sha1: aacc41cc6650cfa8e1f36bf21b7009d17259d4c1
CRC32: b8b5a634
C:/Windows/system32/xacuw. dll same as above
C:/Windows/system32/uwzbt. dll
C:/Windows/system32/prulo. dll
C:/Windows/system32/zbegy. dll
C:/Windows/system32/psumo. dll
C:/Windows/system32/ybdvx. dll
C:/Windows/system32/gjlof. dll
C:/Windows/system32/svxar. dll
C:/Windows/system32/lnqhk. dll
C:/Windows/system32/cehjb. dll
C:/Windows/system32/qsuxo. dll
C:/Windows/system32/uwzqt. dll
C:/Windows/system32/suxzr. dll
C:/Windows/system32/svxzr. dll
C:/Windows/system32/lnphj. dll same as above
C:/Windows/system32/xzcew. dll
C:/Windows/system32/dgilc. dll
C:/Windows/system32/xzbtv. dll
C:/Windows/system32/zcehy. dll
C:/Windows/system32/acfhz. dll
C:/Windows/system32/cegja. dll
C:/Windows/system32/vxaru. dll
C:/Windows/system32/dfizc. dll
C:/Windows/system32/oqtkn. dll
C:/Windows/system32/hjmog. dll
C:/Windows/system32/jlnqh. dll
C:/Windows/system32/zcewy. dll
C:/Windows/system32/qtvyp. dll
C:/Windows/system32/iknph. dll
C:/Windows/system32/ikmpg. dll
C:/Windows/system32/loqtk. dll same as above
C:/Windows/system32/rtwyq. dll
C:/Windows/system32/yadfx. dll
C:/Windows/system32/acfwz. dll
C:/Windows/system32/suwoq. dll
C:/Windows/system32/zbevy. dll
C:/Windows/system32/fhkbe. dll
C:/Windows/system32/vyadu. dll
C:/Windows/system32/begya. dll
C:/Windows/system32/qtvnp. dll
C:/Windows/system32/vxacu. dll
C:/Windows/system32/qsvmp. dll
C:/Windows/system32/uxzrt. dll
C:/Windows/system32/jmogi. dll
C:/Windows/system32/knphj. dll
C:/Windows/system32/bdgia. dll
C:/Windows/system32/wzbev. dll
C:/Windows/system32/kmprj. dll
C:/Windows/system32/nqskm. dll
C:/Windows/system32/dgiac. dll same as above
File Description: C:/Windows/system32/ehjld. dll
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time: 23:54:26
Access time:
Size: 99840 bytes, 97.512 KB
MD5: 7d11286043e917709b6fda-dcc88d07b
Sha1: ff3913ca8cd568b03cb22d89c60efa3db74cda88
CRC32: 5bdd1b86
C:/Windows/system32/ehjmd. dll
C:/Windows/system32/dfikc. dll
C:/Windows/system32/fikme. dll
C:/Windows/system32/svxpr. dll same as above