Encountering gray pigeon variants, Viking and N multi-Trojan (version 2nd)

Source: Internet
Author: User

EndurerOriginal

2006-09-08 th2Anti-Virus Software supplement
2006-09-071Version

A netizen's computer reported that backdoor. gpigeon. uql was detected.

Therefore, QQ is used for remote assistance.

Download hijackthis scan log from http://endurer.ys168.com and find the following suspicious items:

/-------------------------
Logfile of hijackthis v1.99.1
Scan saved at 11:22:51, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running Processes:

C:/program files/Microsoft/svhost32.exe
C:/program files/letscool/letscool.exe
C:/program files/zcom/zcomservice.exe
C:/program files/zcom/skin. dll
C:/program files/Internet Explorer/7sy.exe

R3-urlsearchhook: (No Name)-{BB936323-19FA-4521-BA29-ECA6A121BC78}-(no file)

F3-Reg: win. ini: load = C:/Windows/rundl132.exe

O2-BHO: Yahoo assistant-{406f94f0-504f-4a40-8dfd-58b0666abebd}-C:/progra ~ 1/Yahoo! /Assist ~ 1/assist/yasbar. dll

O2-BHO: (No Name)-{669751ed-d558-49ae-b01a-3b374cc7910e}-C:/Windows/system32/ssup. dll

O2-BHO: mangle class-{9a556b8f-fd02-420e-a1fd-9db33808254e}-C:/program files/mysec/secmouseaan. dll

O3-toolbar: My web honey (& M)-{102293e4-758b-4483-946b-714ebcec91b8}-C:/program files/mysec/secbaraan. dll

O2-BHO: (No Name)-{A9930D97-9CF0-42A0-A10D-4F28836579D5}-F:/music/kugoo3/kugoo3downxcontrol. ocx

O2-BHO: letscool system helper-{F0C15012-7DBD-4068-95A2-0A82DB03AC35}-C:/Windows/system32/coolbho. dll

O4-HKLM/../run: [MS] C:/program files/Microsoft/svhost32.exe

O4-HKLM/../run: [letscool] C:/program files/letscool/letscool.exe

O4-HKLM/../run: [stup.exe] C:/progra ~ 1/Tencent/adplus/stup.exe

O4-HKLM/../run: [_ RX] C:/Windows/rundll32.exe

O23-service: en-unknown owner-C:/Windows/hacker.com.cn.exe
-------------------------/

(For the following repair methods, refer to [system repair series] basic operation indexes.
Http://endurer.blogchina.com/2591241.html)

Stop and disable the service: systen

Download procview to http://endurer.ys168.com and terminate the process:
/-------------------------
C:/program files/Microsoft/svhost32.exe
C:/program files/letscool/letscool.exe
C:/program files/zcom/zcomservice.exe
C:/program files/zcom/skin. dll
C:/program files/Internet Explorer/7sy.exe
-------------------------/

Check the following folders with WinRAR and find:

C :/
============================================
Internt. HTA (Kaspersky reportsTrojan-PSW.Win32.QQPass.hn)
RAR. HTA (Kaspersky reportsTrojan-Downloader.JS.Small.cq)
Vidll. dll (indicated by KasperskyWorm. win32.viking. rThe rising report isWorm. Viking. AA)

C:/Documents and Settings/user/Local Settings/temp
============================================
G0ld.com (the Kaspersky report isWorm. win32.viking. r, Drweb reportsWin32.hllw. gavir.8The rising report isWorm. Viking. AA)
Qq42.161cmd.exe (the value of Kaspersky isTrojan. win32.delf. RF, Drweb reportsTrojan. PWS. spywoool)

C:/Program Files
============================================
Svhost32.exe (drweb reportsTrojan. PWS. lineage)

C:/program files/Internet Explorer
============================================
0sy.exe (Kaspersky reportsTrojan. win32.delf. RF, Drweb reportsTrojan. PWS. spywoool)
3sy.exe (Kaspersky reportsTrojan-PSW.Win32.Lineage.aih, Drweb reportsTrojan. PWS. lineage)
4sy.exe (Kaspersky reportsTrojan. psw. win32.lineage. PJ, Drweb reportsTrojan. PWS. lineage)
5sy.exe (Kaspersky reportsTrojan-PSW.Win32.Agent.ic)
6sy.exe (Kaspersky reportsTrojan-PSW.Win32.Agent.ic)
7sy.exe (Kaspersky reportsTrojan-PSW.Win32.Lineage.acw, Drweb reportsTrojan. PWS. lineage)

C:/program files/letscool
============================================
Letscool.exe (drweb reportsAdware. letscool)
Picdown.exe (drweb reportsTrojan. downloader.12193)

C:/program files/Microsoft
============================================
Svhost32.exe (drweb reportsTrojan. PWS. lineage)

C:/Windows
============================================
Rundll32.exe (the icon is similar to notepad. If Kaspersky isTrojan-PSW.Win32.Lineage.aih)
Rundl132.exe (Kaspersky reportsWorm. win32.viking. rThe rising report isWorm. Viking. AA, Drweb reportsWin32.hllw. gavir.8)

C:/Windows/system32
============================================
A.exe (drweb reportsTool. dialuppass.243)
Dllwm. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.acw, Drweb reportsTrojan. PWS. lineage)
Dllz. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.aih)
Hacker.com.cn.exe (Kaspersky reportsBackdoor. win32.hupigon. CGW, Drweb reportsBackdoor. pigeon.36)
Msdll. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.agl, Drweb reportsTrojan. PWS. lineage)
Nt.exe (Kaspersky reportsTrojan-Downloader.Win32.Small.dgc)
NT. dll (Kaspersky reportedTrojan-Downloader.Win32.Agent.apt)
Svhost32.exe (drweb reportsTrojan. PWS. lineage)
Upzgy.exe

After the backup is packaged, delete it.

Close all folder windows, use hijackthis to scan and repair the items listed above.

Uninstall: Yahoo assistant, letscool, zcom

Clear temporary ie folders

Clear the C:/Windows/Temp folder

Clear the C:/Documents and Settings/user/Local Settings/Temp folder

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.