I have one more MDM under the Windows root directory on drive C. EXE file, which is automatically generated after each deletion and generates a process named SVCHOST. Since the process is in progress, all my folders are invisible, even if you select "show all files and folders" in the settings, turning off "Hide protected system files" is useless. what's going on?
I fell victim to this virus yesterday! Finally, the problem is solved (not formatting the hard disk, of course)
After the virus is detected, two files are generated under the root directory of each partition: Autorun. INF and ravmon.exe (this file is relatively large) and the property is hidden. mdm.exe, svchost.exe, and SVCHOST will be generated under c: \ windows. INI, (some will generate a skvp in c: \ windows \ system32. sys File) at the same time, it will add auto-start and addition System Service in the startup Item to achieve self-start. write at least three key values in the registry!
At this time, your computer may be "show all file options" invalid (my computer is like this). Now let's talk about how to clear it:
First, end the process svchost.exe (you must end the process SVCHOST. EXE first. If it is not completed, the key value in the registry or the key value in the startup item will be automatically restored in less than one minute ). Then you can enter the command prompt ("START" menu"Program"-->" Attachment "-->" command prompt "), and then run the following command