EndurerOriginal
1Version
A netizen's computer, which was reported by rising boot scanning in the past two daysBackdoor. gpigeon. uql. For example:
-----------
Virus name processing result found date path file virus source
Backdoor. gpigeon. uqlCleared successfully iexplore. EXE> C:/program files/Internet Explorer/iexplore. EXE Local Machine
-----------/
Scan the log using hijackthis (which can be downloaded to the http://endurer.ys168.com) to discover n more suspicious items:
/---------
Logfile of hijackthis v1.99.1
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
R3-urlsearchhook: (No Name)-{BFCD2BAD-DE01-433E-A751-731B77EF84AD}-C:/Windows/system32/zzwcrh. dll (file missing)
R3-urlsearchhook: (No Name)-{808b6af8-f101-4af7-ac49-98d403b16fba}-C:/Windows/system32/uhxwtr. dll (file missing)
R3-urlsearchhook: (No Name)-{DB020387-4489-4B9B-AF88-1AF9357CAA18}-C:/Windows/system32/paiy. dll
R3-urlsearchhook: (No Name)-{E68EF228-54B9-4F82-96F3-55DDBE3855FE}-C:/Windows/system32/wqonu. dll
R3-urlsearchhook: (No Name)-{8446b2ee-c04c-4c5d-9706-2ffb46e89b62}-C:/Windows/system32/mihu. dll
R3-urlsearchhook: (No Name)-{59172c14-06b4-40c8-9a95-bc71c73bf5af}-C:/Windows/system32/ivaeye. dll (file missing)
R3-urlsearchhook: (No Name)-{EB6E4937-8C1D-4422-A928-A955BF4050A5}-C:/Windows/system32/gmuseq. dll (file missing)
R3-urlsearchhook: (No Name)-{E238864E-8FC0-4964-A119-8C219FD3FCA5}-C:/Windows/system32/qgungz. dll (file missing)
R3-urlsearchhook: (No Name)-{9cf077c6-e3ce-435b-b6ef-9ed2308051ea}-C:/Windows/system32/kmdlim. dll (File sing mis)
R3-urlsearchhook: (No Name)-{5b83669a-3ef7-4e7d-acc0-2de10faf1d8e}-C:/Windows/system32/fxai. dll (File sing mis)
R3-urlsearchhook: (No Name)-{717bb5f3-d783-44ad-a672-fbe9ff014212}-C:/Windows/system32/jzwz. dll (file missing)
R3-urlsearchhook: (No Name)-{2280d518-eafc-4e5f-8137-95459a65e71d}-C:/Windows/system32/bktql. dll (file missing)
R3-urlsearchhook: (No Name)-{B864F7E0-8EC6-4F40-A5D2-6DF6E7218916}-C:/Windows/system32/xnskic. dll (file missing)
R3-urlsearchhook: (No Name)-{7a68c18b-5050-49a1-89a2-ec2a4c9ad4d4}-C:/Windows/system32/aseuxe. dll (file missing)
R3-urlsearchhook: (No Name)-{9d0e044f-4c70-4ae0-99ce-dc3c730c6ad5}-C:/Windows/system32/tpuwa. dll (file missing)
R3-urlsearchhook: (No Name)-{0314b9fb-5711-49d8-aa91-51da09e0e725}-C:/Windows/system32/enkjvz. dll (file missing)
R3-urlsearchhook: (No Name)-{F3E2FC60-FB25-4050-8F98-6DC54343E838}-C:/Windows/system32/lrfpy. dll (file missing)
R3-urlsearchhook: (No Name)-{4fee26d2-50ea-452c-aa9c-7fe89eed2014}-C:/Windows/system32/ebofz. dll (File sing mis)
R3-urlsearchhook: (No Name)-{777a067d-4011-4af8-a862-6f90aa846768}-C:/Windows/system32/dwoaem. dll (file missing)
R3-urlsearchhook: (No Name)-{0fab0abe-5538-4f73-9413-a7b004f28ce5}-C:/Windows/system32/cjxl. dll (file missing)
R3-urlsearchhook: (No Name)-{9aa75677-9ec8-4c93-a03b-aef4bba47def}-C:/Windows/system32/pfzd. dll (File sing mis)
R3-urlsearchhook: (No Name)-{2ce8a22a-f345-4535-bac4-ad6ca18925e6}-C:/Windows/system32/joiu. dll (file missing)
R3-urlsearchhook: (No Name)-{BDAE40AF-1B93-40A7-8AA9-941CE8478922}-C:/Windows/system32/vrlr. dll (file missing)
R3-urlsearchhook: (No Name)-{0c4a6f76-f697-4c59-80f3-910344785973}-C:/Windows/system32/cfxmvw. dll (file missing)
R3-urlsearchhook: (No Name)-{AFC8634F-F67A-4F88-B950-54DBCE59D322}-C:/Windows/system32/nmgkm. dll (file missing)
R3-urlsearchhook: (No Name)-{8f1a07ae-48fd-4d67-b9ca-0418a9c093d6}-C:/Windows/system32/alihs. dll (file missing)
R3-urlsearchhook: (No Name)-{8a953ae5-b4cc-4691-baa7-078f533b2b55}-C:/Windows/system32/bbuh. dll (file missing)
R3-urlsearchhook: (No Name)-{5ee40808-b4ad-423b-94e5-d027ae6d6955}-C:/Windows/system32/ynam. dll (File sing mis)
R3-urlsearchhook: (No Name)-{FA1B1592-BE49-4036-8E17-5E004063BD7C}-C:/Windows/system32/jvvvfb. dll (file missing)
R3-urlsearchhook: (No Name)-{8f25af6b-6bd7-477a-8e4c-b7bcbc4027e1}-C:/Windows/system32/Nagi. dll (File sing mis)
R3-urlsearchhook: (No Name)-{0b5e2fa7-cd00-435e-8d5d-cc801a3024f1}-C:/Windows/system32/rmrb. dll (File sing mis)
R3-urlsearchhook: (No Name)-{3017565e-3424-4f08-bcd6-954553524e92}-C:/Windows/system32/zduiq. dll (file missing)
R3-urlsearchhook: (No Name)-{24011b59-f75b-4894-8324-d60f4d4d4ac4}-C:/Windows/system32/itjfge. dll (file missing)
R3-urlsearchhook: (No Name)-{09418925-370c-4806-a5ac-f35554aa4190}-C:/Windows/system32/jwqk. dll (File sing mis)
R3-urlsearchhook: (No Name)-{E354B57E-E92C-4168-912A-92FBA3F06E7A}-C:/Windows/system32/wxqk. dll (file missing)
R3-urlsearchhook: (No Name)-{7026fa9a-2acc-41a0-bfa5-f401bdb8a28e}-C:/Windows/system32/irhibw. dll (file missing)
R3-urlsearchhook: (No Name)-{D318DD44-FB1E-4CBF-85A4-F868AFE5505C}-C:/Windows/system32/AAHK. dll (file missing)
O2-BHO: Internet Explorer helper-{02c9b9ab-6372-46c5-b356-773faf3b6b1e}-C:/Windows/fonts/msshapi. dll (file missing)
O2-BHO: (No Name)-{0314b9fb-5711-49d8-aa91-51da09e0e725}-C:/Windows/system32/enkjvz. dll (file missing)
O2-BHO: (No Name)-{074c1100-60fc-447c-aaba-721645dc8b45}-C:/Windows/system32/fgrsc. dll (file missing)
O2-BHO: monitorurl class-{08a312bb-5409-49fc-9347-54bb7d069ac6}-C:/progra ~ 1/AD ~ 1/deskipn. dll
O2-BHO: (No Name)-{09418925-370c-4806-a5ac-f35554aa4190}-C:/Windows/system32/jwqk. dll (file missing)
O2-BHO: (No Name)-{0a476bef-93d7-4042-864a-43a9f6d00825}-C:/Windows/system32/qksjd. dll (file missing)
O2-BHO: (No Name)-{0b5e2fa7-cd00-435e-8d5d-cc801a3024f1}-C:/Windows/system32/rmrb. dll (file missing)
O2-BHO: (No Name)-{0c4a6f76-f697-4c59-80f3-910344785973}-C:/Windows/system32/cfxmvw. dll (file missing)
O2-BHO: (No Name)-{0c7c23ef-a848-485b-873c-0ed954731014}-(no file)
O2-BHO: wmpdrm-{0e674588-66b7-4e19-9d0e-2053b800f69f}-C:/Windows/system32/wmpdrm. dll (file missing)
O2-BHO: (No Name)-{0f23a638-9c94-4280-ab81-dda-b52d8c72}-C:/Windows/system32/zptw. dll
O2-BHO: (No Name)-{0fab0abe-5538-4f73-9413-a7b004f28ce5}-C:/Windows/system32/cjxl. dll (file missing)
O2-BHO: myiehelper class-{16b770a0-0e87-4278-b748-2460d64a8386}-C:/Documents and Settings/all users/Application Data/Microsoft/iehelper/iehelper_5001.dll
O2-BHO: (No Name)-{1fa33c54-8dbb-00005-968b-8d76c85012eb}-C:/Windows/system32/btim. dll (file missing)
O2-BHO: (No Name)-{2280d518-eafc-4e5f-8137-95459a65e71d}-C:/Windows/system32/bktql. dll (file missing)
O2-BHO: (No Name)-{24011b59-f75b-4894-8324-d60f4d4d4ac4}-C:/Windows/system32/itjfge. dll (File sing mis)
O2-BHO: winsearch-{27e96de0-8211-42cf-9a1e-fa6246a95b77}-C:/Windows/system32/winsearch. dll
O2-BHO: (No Name)-{2ce8a22a-f345-4535-bac4-ad6ca18925e6}-C:/Windows/system32/joiu. dll (file missing)
O2-BHO: (No Name)-{3017565e-3424-4f08-bcd6-954553524e92}-C:/Windows/system32/zduiq. dll (file missing)
O2-BHO: (No Name)-{47a5977b-52fb-46ec-9c79-c00004a1a0499}-C:/Windows/system32/dhsix. dll (file missing)
O2-BHO: (No Name)-{4fee26d2-50ea-452c-aa9c-7fe89eed2014}-C:/Windows/system32/ebofz. dll (file missing)
O2-BHO: (No Name)-{53d94615-275a-4f4b-93c5-600355c452f8}-C:/Windows/system32/llkd. dll (file missing)
O2-BHO: (No Name)-{57d87e3d-f83a-48c7-9883-9e4aef4e3c4e}-C:/Windows/system32/uilnhk. dll (file missing)
O2-BHO: (No Name)-{59172c14-06b4-40c8-9a95-bc71c73bf5af}-C:/Windows/system32/ivaeye. dll (file missing)
O2-BHO: (No Name)-{5b83669a-3ef7-4e7d-acc0-2de10faf1d8e}-C:/Windows/system32/fxai. dll (file missing)
O2-BHO: cdnforie class-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O2-BHO: (No Name)-{5ee40808-b4ad-423b-94e5-d027ae6d6955}-C:/Windows/system32/ynam. dll (file missing)
O2-BHO: Vision-{6671a431-5c3d-463d-a7cf-5587f9b7e191}-C:/progra ~ 1/mmsass ~ 1/mmsass ~ 1. dll
O2-BHO: stdup-{6a512bf7-ec78-4e8d-9841-6c02e8fa9838}-C:/Windows/system32/stdup. dll
O2-BHO: (No Name)-{7026fa9a-2acc-41a0-bfa5-f401bdb8a28e}-C:/Windows/system32/irhibw. dll (file missing)
O2-BHO: (No Name)-{717bb5f3-d783-44ad-a672-fbe9ff014212}-C:/Windows/system32/jzwz. dll (File sing mis)
O2-BHO: (No Name)-{777a067d-4011-4af8-a862-6f90aa846768}-C:/Windows/system32/dwoaem. dll (file missing)
O2-BHO: cpapview class-{77962960-536e-47ec-9ddb-52651519705f}-C:/Windows/system32/rundll32.dll (file missing)
O2-BHO: (No Name)-{7a68c18b-5050-49a1-89a2-ec2a4c9ad4d4}-C:/Windows/system32/aseuxe. dll (file missing)
O2-BHO: (No Name)-{808b6af8-f101-4af7-ac49-98d403b16fba}-C:/Windows/system32/uhxwtr. dll (File sing mis)
O2-BHO: (No Name)-{8446b2ee-c04c-4c5d-9706-2ffb46e89b62}-C:/Windows/system32/mihu. dll
O2-BHO: (No Name)-{8a953ae5-b4cc-4691-baa7-078f533b2b55}-C:/Windows/system32/bbuh. dll (file missing)
O2-BHO: (No Name)-{8f1a07ae-48fd-4d67-b9ca-0418a9c093d6}-C:/Windows/system32/alihs. dll (file missing)
O2-BHO: (No Name)-{8f25af6b-6bd7-477a-8e4c-b7bcbc4027e1}-C:/Windows/system32/Nagi. dll (file missing)
O2-BHO: (No Name)-{9aa75677-9ec8-4c93-a03b-aef4bba47def}-C:/Windows/system32/pfzd. dll (file missing)
O2-BHO: (No Name)-{9cf077c6-e3ce-435b-b6ef-9ed2308051ea}-C:/Windows/system32/kmdlim. dll (file missing)
O2-BHO: (No Name)-{9d0e044f-4c70-4ae0-99ce-dc3c730c6ad5}-C:/Windows/system32/tpuwa. dll (file missing)
O2-BHO: Yahoo bar-{A697BC46-BC93-4833-93F5-1E365011E88A}-C:/Windows/odbint. dll
O2-BHO: Java enhancer-{AF098F95-7CEA-407A-8552-3846737CC4B2}-C:/Windows/system32/funcwin. dll
O2-BHO: (No Name)-{AFC8634F-F67A-4F88-B950-54DBCE59D322}-C:/Windows/system32/nmgkm. dll (file missing)
O2-BHO: (No Name)-{B864F7E0-8EC6-4F40-A5D2-6DF6E7218916}-C:/Windows/system32/xnskic. dll (file missing)
O2-BHO: Flash 8 OCX-{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}-C:/Windows/system32/flash8.dll
O2-BHO: (No Name)-{BDAE40AF-1B93-40A7-8AA9-941CE8478922}-C:/Windows/system32/vrlr. dll (file missing)
O2-BHO: (No Name)-{BFCD2BAD-DE01-433E-A751-731B77EF84AD}-C:/Windows/system32/zzwcrh. dll (file missing)
O2-BHO: Count class-{CFF6E0CF-02FB-47F5-95A4-DD8610D59284}-C:/Windows/system32/bsnviewer. dll
O2-BHO: 51 navigation-{D271A289-57EB-4D0E-9131-A0CD25D4D1F8}-C:/Windows/system32/browsewmzero. dll
O2-BHO: (No Name)-{D318DD44-FB1E-4CBF-85A4-F868AFE5505C}-C:/Windows/system32/AAHK. dll (file missing)
O2-BHO: (No Name)-{DB020387-4489-4B9B-AF88-1AF9357CAA18}-C:/Windows/system32/paiy. dll
O2-BHO: (No Name)-{E238864E-8FC0-4964-A119-8C219FD3FCA5}-C:/Windows/system32/qgungz. dll (file missing)
O2-BHO: (No Name)-{E354B57E-E92C-4168-912A-92FBA3F06E7A}-C:/Windows/system32/wxqk. dll (file missing)
O2-BHO: (No Name)-{E68EF228-54B9-4F82-96F3-55DDBE3855FE}-C:/Windows/system32/wqonu. dll
O2-BHO: (No Name)-{EB6E4937-8C1D-4422-A928-A955BF4050A5}-C:/Windows/system32/gmuseq. dll (file missing)
O2-BHO: Update wnwb-{ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270}-C:/progra ~ 1/common ~ 1/wnwb/wnwbio. dll
O2-BHO: (No Name)-{F3E2FC60-FB25-4050-8F98-6DC54343E838}-C:/Windows/system32/lrfpy. dll (file missing)
O2-BHO: wmhlprobj class-{F5824EFB-728A-4726-A5A5-85A68B20EDC3}-C:/progra ~ 1/CNNIC/CDN/wmhlpr. dll
O2-BHO: (No Name)-{FA1B1592-BE49-4036-8E17-5E004063BD7C}-C:/Windows/system32/jvvvfb. dll (file missing)
O3-toolbar: copyso copy search-{40987a5c-6ab8-4977-8be9-a8889de2edcc}-C:/program files/copyso/copysoie. dll (File SING)
O3-toolbar: (No Name)-{6c3167d2-3fef-4cd4-b654-d3ae55b4128c}-(no file)
O4-HKLM/../run: [cdnctr] C:/program files/CNNIC/CDN/cdnup.exe
O4-HKLM/../run: [desktop] C:/Windows/system32/rundll32.exe "C:/program files/deskadtop/run. dll", rundll
O4-HKLM/../run: [spoolsv] C:/Windows/system32/spoolsv/spoolsv.exe-printer
O8-extra context menu item:> MMS sending <-res: // C:/progra ~ 1/mmsass ~ 1/mmsass ~ 1. dll/mms.htm
O8-extra context menu item: Visit the General website-C:/program files/CNNIC/CDN/cnnic.htm
O9-extra button: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O9-extra 'tool' menuitem: Chinese surfing-{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}-C:/progra ~ 1/CNNIC/CDN/cdnforie. dll
O9-extra button: (No Name)-{6671a433-5c3d-463d-a7cf-5587f9b7e191}-C:/progra ~ 1/mmsass ~ 1/mmsass ~ 1. dll
O9-extra 'tool' menuitem: color e genie settings-{6671a433-5c3d-463d-a7cf-5587f9b7e191}-C:/progra ~ 1/mmsass ~ 1/mmsass ~ 1. dll
O10-unknown file in Winsock LSP: C:/Windows/system32/cdnns. dll
O11-Options Group: [cdnclient] accessing Chinese
O21-ssodl: webwork-{4c611512-2c1d-44b2-a044-872ad2ad5a61}-C:/Windows/webwork. dll
O23-service: ebook (ebook)-unknown owner-C:/Windows/EXE
---------/
Uninstall: vision, stdup, webwork, winsearch, Chinese online, Desktop Media (adtop)
Stop and disable services: ebook (ebook)
Use WinRAR to find the file: C:/Windows/EXE. You cannot package it. Dizzy!
Download icesword to the http://endurer.ys168.com, copy C:/Windows/EXE to the desktop, You can package backup.
However, icesword cannot delete C:/Windows/EXE!
To the http://endurer.ys168.com to download the next Startup automatically delete file program/auto_del and run, drag C:/Windows/EXE from WinRAR window to the next start automatically delete file window, prompt file does not exist or folder, click "OK" to add "C:/Windows/EXE" to the list of files to be deleted, and click "delete" next time you start the file. Rising prompts auto_del.exe to modify the registry, allow and confirm.
Close all folder windows, use hijackthis to scan and repair the items listed above.
Clear temporary ie folders
Kaspersky reports C:/Windows/EXEBackdoor. win32.hupigon. cda.