Clearance of cmdbcs.exe, wsttrs.exe, msccrt.exe, winform.exe, and upxdnd.exe
Trojan. psw. OnlineGames. XX Virus
Hacker and so on, this should be caused by downloading through the trojan Installer. These are basically some number-stealing Trojans.
Generally, Sreng logs are as follows:
Start the project (not necessarily all)
<Wsttrs> <c: \ windows \ wsttrs.exe> [Microsoft Corporation]
<SVC> <c: \ release E ~ 1 \ USERNAME \ locals ~ 1 \ temp \ byetmr.exe> [Microsoft Corporation]
<G1q> <c: \ w.e ~ 1 \ admini ~ 1 \ locals ~ 1 \ temp \ rundl132.exe> []
<Upxdnd> <c: \ docume ~ 1 \ USERNAME \ locals ~ 1 \ temp \ upxdnd.exe> [Microsoft Corporation]
<Winform> <c: \ windows \ winform.exe> [N/A]
<Ravshell> <c: \ windows \ system32 \ svch0st.exe> []
<Upxdnd> <c: \ docume ~ 1 \ USERNAME \ locals ~ 1 \ temp \ upxdnd.exe> [N/A]
<Cmdbcs> <c: \ windows \ cmdbcs.exe> [N/A]
<Mppps> <c: \ windows \ mppds.exe> [N/A]
<Nortonq> <c: \ windows \ nortonq.exe> []
<System> <c: \ Program Files \ common files \ System \ updaterun.exe> [N/A] 5 4 P e. c o m
<5cl3v> <c: \ docume ~ 1 \ USERNAME \ locals ~ 1 \ temp \ servicer.exe> []
<Mppdys> <c: \ windows \ mppdys.exe> []
<Mhsa> <c: \ docume ~ 1 \ USERNAME \ locals ~ 1 \ temp \ mhso.exe> []
<Msccrt> <c: \ windows \ msccrt.exe> []
<Wgs3> <c: \ windows \ wgs3.exe> []
<Wms3> <c: \ windows \ wms3.exe> []
<Twin> <c: \ windows \ system32 \ twunk32.exe> []
<Wsttrs> <REM c: \ windows \ wsttrs.exe> []
<Wsdttrs> <c: \ windows \ wsdttrs.exe> []
In fact, viruses are spread by exploiting browser vulnerabilities. when surfing the internet, you 'd better use the Firefox browser to browse the Web page. The biggest benefit of this browser is security! Firefox: http://www.54pe.com/html/caozuoxitong/20070311/9502.html
Completion of clearing body for cmdbcs.exe, wsttrs.exe, msccrt.exe, winform.exe, upxdnd.exe, etc.