EndurerOriginal
2006-09-08 th2Anti-Virus Software supplement
2006-09-071Version
A netizen's computer reported that backdoor. gpigeon. uql was detected.
Therefore, QQ is used for remote assistance.
Download hijackthis scan log from http://endurer.ys168.com and find the following suspicious items:
/-------------------------
Logfile of hijackthis v1.99.1
Scan saved at 11:22:51, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running Processes:
C:/program files/Microsoft/svhost32.exe
C:/program files/letscool/letscool.exe
C:/program files/zcom/zcomservice.exe
C:/program files/zcom/skin. dll
C:/program files/Internet Explorer/7sy.exe
R3-urlsearchhook: (No Name)-{BB936323-19FA-4521-BA29-ECA6A121BC78}-(no file)
F3-Reg: win. ini: load = C:/Windows/rundl132.exe
O2-BHO: Yahoo assistant-{406f94f0-504f-4a40-8dfd-58b0666abebd}-C:/progra ~ 1/Yahoo! /Assist ~ 1/assist/yasbar. dll
O2-BHO: (No Name)-{669751ed-d558-49ae-b01a-3b374cc7910e}-C:/Windows/system32/ssup. dll
O2-BHO: mangle class-{9a556b8f-fd02-420e-a1fd-9db33808254e}-C:/program files/mysec/secmouseaan. dll
O3-toolbar: My web honey (& M)-{102293e4-758b-4483-946b-714ebcec91b8}-C:/program files/mysec/secbaraan. dll
O2-BHO: (No Name)-{A9930D97-9CF0-42A0-A10D-4F28836579D5}-F:/music/kugoo3/kugoo3downxcontrol. ocx
O2-BHO: letscool system helper-{F0C15012-7DBD-4068-95A2-0A82DB03AC35}-C:/Windows/system32/coolbho. dll
O4-HKLM/../run: [MS] C:/program files/Microsoft/svhost32.exe
O4-HKLM/../run: [letscool] C:/program files/letscool/letscool.exe
O4-HKLM/../run: [stup.exe] C:/progra ~ 1/Tencent/adplus/stup.exe
O4-HKLM/../run: [_ RX] C:/Windows/rundll32.exe
O23-service: en-unknown owner-C:/Windows/hacker.com.cn.exe
-------------------------/
(For the following repair methods, refer to [system repair series] basic operation indexes.
Http://endurer.blogchina.com/2591241.html)
Stop and disable the service: systen
Download procview to http://endurer.ys168.com and terminate the process:
/-------------------------
C:/program files/Microsoft/svhost32.exe
C:/program files/letscool/letscool.exe
C:/program files/zcom/zcomservice.exe
C:/program files/zcom/skin. dll
C:/program files/Internet Explorer/7sy.exe
-------------------------/
Check the following folders with WinRAR and find:
C :/
============================================
Internt. HTA (Kaspersky reportsTrojan-PSW.Win32.QQPass.hn)
RAR. HTA (Kaspersky reportsTrojan-Downloader.JS.Small.cq)
Vidll. dll (indicated by KasperskyWorm. win32.viking. rThe rising report isWorm. Viking. AA)
C:/Documents and Settings/user/Local Settings/temp
============================================
G0ld.com (the Kaspersky report isWorm. win32.viking. r, Drweb reportsWin32.hllw. gavir.8The rising report isWorm. Viking. AA)
Qq42.161cmd.exe (the value of Kaspersky isTrojan. win32.delf. RF, Drweb reportsTrojan. PWS. spywoool)
C:/Program Files
============================================
Svhost32.exe (drweb reportsTrojan. PWS. lineage)
C:/program files/Internet Explorer
============================================
0sy.exe (Kaspersky reportsTrojan. win32.delf. RF, Drweb reportsTrojan. PWS. spywoool)
3sy.exe (Kaspersky reportsTrojan-PSW.Win32.Lineage.aih, Drweb reportsTrojan. PWS. lineage)
4sy.exe (Kaspersky reportsTrojan. psw. win32.lineage. PJ, Drweb reportsTrojan. PWS. lineage)
5sy.exe (Kaspersky reportsTrojan-PSW.Win32.Agent.ic)
6sy.exe (Kaspersky reportsTrojan-PSW.Win32.Agent.ic)
7sy.exe (Kaspersky reportsTrojan-PSW.Win32.Lineage.acw, Drweb reportsTrojan. PWS. lineage)
C:/program files/letscool
============================================
Letscool.exe (drweb reportsAdware. letscool)
Picdown.exe (drweb reportsTrojan. downloader.12193)
C:/program files/Microsoft
============================================
Svhost32.exe (drweb reportsTrojan. PWS. lineage)
C:/Windows
============================================
Rundll32.exe (the icon is similar to notepad. If Kaspersky isTrojan-PSW.Win32.Lineage.aih)
Rundl132.exe (Kaspersky reportsWorm. win32.viking. rThe rising report isWorm. Viking. AA, Drweb reportsWin32.hllw. gavir.8)
C:/Windows/system32
============================================
A.exe (drweb reportsTool. dialuppass.243)
Dllwm. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.acw, Drweb reportsTrojan. PWS. lineage)
Dllz. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.aih)
Hacker.com.cn.exe (Kaspersky reportsBackdoor. win32.hupigon. CGW, Drweb reportsBackdoor. pigeon.36)
Msdll. dll (indicated by KasperskyTrojan-PSW.Win32.Lineage.agl, Drweb reportsTrojan. PWS. lineage)
Nt.exe (Kaspersky reportsTrojan-Downloader.Win32.Small.dgc)
NT. dll (Kaspersky reportedTrojan-Downloader.Win32.Agent.apt)
Svhost32.exe (drweb reportsTrojan. PWS. lineage)
Upzgy.exe
After the backup is packaged, delete it.
Close all folder windows, use hijackthis to scan and repair the items listed above.
Uninstall: Yahoo assistant, letscool, zcom
Clear temporary ie folders
Clear the C:/Windows/Temp folder
Clear the C:/Documents and Settings/user/Local Settings/Temp folder