EndurerOriginal
1Version
A netizen's computer, which was reported by rising boot scanning in the past two days, found backdoor. gpigeon. uql. For example:
/------------
Virus name processing result found date path file virus source
Backdoor. gpigeon. uqlCleared successfully iexplore. EXE> C:/program files/Internet Explorer/iexplore. EXE Local Machine
------------/
Scan the log using hijackthis (which can be downloaded to the http://endurer.ys168.com) to find a suspicious item:
/------------
O23-service: Program-unknown owner-C:/Windows/h.com.cn.exe
------------/
(For the following repair methods, refer to [system repair series] basic operation indexes.
Http://endurer.blogchina.com/2591241.html)
Stop and disable services: Programs
Use WinRAR to find: C:/Windows/h.com.cn.exe
After the backup is packaged, delete it.
Close all files and folders, use hijackthis to scan and fix the o23 items listed above.
Clear temporary ie folders
Use WinRAR to check C:/, C:/Windows, C:/Windows/debug, C:/Windows/Downloaded Program Files, C:/Windows/system32, and C: /Windows/temp, C:/Documents and Settings/ABC/Local Settings/temp, C:/program files, C:/program files/Internet Explorer, D:/, etc, suspicious files discovered:
/-------------
Ipdetect.exe.rar
Msdos.exe (Kaspersky reportsTrojan-Spy.Win32.Delf.dq)
New.exe (Kaspersky reportsTrojan-Downloader.Win32.Small.bxa)
7hqoy. dll (Kaspersky reportedRootkit. win32.vanti. e)
-------------/
Also, package the backup and delete it.