EndurerOriginal
2006.11.101Version
A netizen's computer has been running very slowly recently. Let me check it out.
Via QQ Remote Assistance.
Download hijackthis scan log from http://endurer.ys168.com and find the following suspicious items:
/----------
Logfile of hijackthis v1.99.1
Scan saved at 10:18:40, on
Platform: Windows XP (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
R3-urlsearchhook: (No Name)-{BB936323-19FA-4521-BA29-ECA6A121BC78}-(no file)
F3-Reg: win. ini: load =? Why?
O4-HKLM/../run: [logfeil] Regedit-s c:/$ ntuninstallq8875736 $/winsys. Cer
O18-Protocol: koboo-{7dee9d05-fa0a-4416-a6f3-6537d0eab6a6}-C:/Windows/system32/mbprot. dll
O18-Protocol: mbox-{7dee9d05-fa0a-4416-a6f3-6537d0eab6a6}-C:/Windows/system32/mbprot. dll
O23-service: Windows ddosserver (ddosserver)-unknown owner-C:/Windows/system32/jgdr.exe
----------/
C:/$ ntuninstallq8875736 $/winsys. CER is a very old virus. For details, refer:
Another batch of viruses were killed (version 3rd)
Http://endurer.bokee.com/3938079.html
C:/Windows/system32/jgdr.exe uses the IE web page icon, which is quite confusing. Kaspersky reportsBackdoor. win32.hupigon. CCE, Dr. Web reports:Backdoor. pigeon.341, Rising:Backdoor. gpigeon. gqs.
Stop and disable services: Windows ddosserver (ddosserver)
Use WinRAR to find and delete the following files:
C:/Windows/system32/jgdr.exe
C:/Windows/system32/mbprot. dll
Delete a folder: C:/$ ntuninstallq8875736 $
Use hijackthis to fix the suspicious items listed above.
Clear temporary ie folders