Solution: Gray pigeon variants, rootkit. win32.vanti, win32.delf, win32.small, etc.

Source: Internet
Author: User

EndurerOriginal
1Version

A netizen's computer, which was reported by rising boot scanning in the past two days, found backdoor. gpigeon. uql. For example:
/------------
Virus name processing result found date path file virus source
Backdoor. gpigeon. uqlCleared successfully iexplore. EXE> C:/program files/Internet Explorer/iexplore. EXE Local Machine
------------/

Scan the log using hijackthis (which can be downloaded to the http://endurer.ys168.com) to find a suspicious item:

/------------
O23-service: Program-unknown owner-C:/Windows/h.com.cn.exe
------------/
(For the following repair methods, refer to [system repair series] basic operation indexes.
Http://endurer.blogchina.com/2591241.html)

Stop and disable services: Programs

Use WinRAR to find: C:/Windows/h.com.cn.exe

After the backup is packaged, delete it.

Close all files and folders, use hijackthis to scan and fix the o23 items listed above.

Clear temporary ie folders

Use WinRAR to check C:/, C:/Windows, C:/Windows/debug, C:/Windows/Downloaded Program Files, C:/Windows/system32, and C: /Windows/temp, C:/Documents and Settings/ABC/Local Settings/temp, C:/program files, C:/program files/Internet Explorer, D:/, etc, suspicious files discovered:

/-------------
Ipdetect.exe.rar
Msdos.exe (Kaspersky reportsTrojan-Spy.Win32.Delf.dq)
New.exe (Kaspersky reportsTrojan-Downloader.Win32.Small.bxa)
7hqoy. dll (Kaspersky reportedRootkit. win32.vanti. e)
-------------/

Also, package the backup and delete it.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.