EndurerOriginal
1Version
A netizen said that his computer has been working very slowly recently and asked me to help with the remote maintenance via QQ.
Download hijackthis to the http://endurer.ys168.com to scan logs and find suspicious items:
/------
Logfile of hijackthis v1.99.1
Scan saved at 15:11:51, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
O4-HKLM/../run: [ltnward] C:/Windows/system32/ltnward.exe
------/
Use pe_xscan to scan logs and find suspicious items:
/------
Pe_xscan by Purple endurer
2007-1-26 15:39:30
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
O4-HKLM/../run: [ltnward] C:/Windows/system32/ltnward.exe
O24-[]-{0ae234e0-34e0-ae22-e0ae-4e0e24e0ae22} = C:/program files/common files/Microsoft shared/msinfo/34e0ae22. dll
------/
WinRAR found C:/Windows/system32/ltnward.exe, to the http://purpleendurer.ys168.com to download fileinfo extraction information:
/------
File Description: C:/Windows/system32/ltnward.exe
Attribute: ---
Language: Chinese (China)
File version: 1, 0, 0, 1
Note: ltnward Application
Copyright: Copyright (c) 2006
Note:
Product Version: 1, 0, 0, 1
Product Name: ltnward Application
Company Name:
Legal trademark:
Internal name: ltnward
Source File Name: ltnward.exe
Creation Time: 13:49:49
Modification time: 22:15:32
Access time:
Size: 31744 bytes, 31.0 KB
MD5: a312a56cad6bfc547fd510443f81d89a
------/
After a Google search, we found that ltnward.exe had another culprit: ltnwardl. dll, but I did not find it.
Check the killing record of rising. Sure enough, ltnwardl. dll has been killed:
/------
Virus name Discovery Date scan method path file virus source
Trojan. DL. Agent. CJYScreensaver scan C:/Windows/system32 ltnwardl. dll> pecompact2x
------/
No C:/program files/common files/Microsoft shared/msinfo/34e0ae22. dll found
Fixed with hijackthis: O4-HKLM/../run: [ltnward] C:/Windows/system32/ltnward.exe
Use Registry Editor to delete:
O24-[]-{0ae234e0-34e0-ae22-e0ae-4e0e24e0ae22} = C:/program files/common files/Microsoft shared/msinfo/34e0ae22. dll
The corresponding registry key.
Clear C:/Windows/prefetch
Clear C:/Windows/temp
Clear temporary ie folders