EndurerOriginal
2006-11-071Version
A user's computer browser was hijacked by www.ting789.com and sent a log scanned by hijackthis.
The following suspicious items are found in the log:
/---------
F3-Reg: win. ini: load = C:/Windows/mobsync.exe
O4-startup Item HKLM // run: [mobsync] C:/Windows/mobsync.exe
O4-startup: 0a5021.exe
O4-Global startup: 0a5021.exe
O21-ssodl: dlmon-{590498a3-4131-4d8f-ba4b-36791a0803b1 }-
C:/Windows/system32/dlmain. dll (file missing)
---------/
Repair suggestions:
Restart to safe Mode
Set the system to display all files and folders without hiding extensions of known file types
Find the following files:
/---------
C:/Windows/mobsync.exe
C:/Windows/system32/dlmain. dll
0a5021.exe (search by the Start menu)
---------/
The files found with compression software (such as WinRAR, WinZip) Packaging backup, after all the repair work is completed as an e-mail attachment sent to the endurer@163.com.
Close all browser windows and folder windows, use hijackthis scan again, check the suspicious items listed above, and click [Fix] (fix) (if you know something is safe, can not be processed ):
Clear temporary ie folders
This web site has previously caused great harm, see:
Questions about hxxp: // www.ting789.com/index.htmplease discuss here (endurer modification)
http://forum.ikaka.com/topic.asp? Board = 67 & artid = 6552776