Recently, my computer was infected with viruses, which took me a lot of time. This virus is a trojan. ProgramIt creates many executable files on the disk, modifies the registry, and mounts these files. In addition, it attaches a module to the explorer process. If you just delete the program on the hard disk, the virus will recur after a while, because the real behind-the-scenes black hands are not cleared.
After two or three days of hard work, I went online to check information, used various analysis and scanning tools, and finally solved the problem by mmaqandao. This software has a function that is to detect suspicious modules, I discovered the real behind-the-scenes hacker with this function.
After this virus event, I have more anti-virus experience. Nowadays, many viruses are transmitted through the web page, so it is very dangerous to browse the Web page as an administrator. If you use a non-Administrator identity to browse the Web page, you can prevent many viruses, because non-Administrators cannot modify the registry or write files on drive C. In addition, if you think some suspicious programs can run as non-Administrators. The virus that I encountered this time expands the file by creating an executable file in Local Settings \ Temp and then executing it, according to some information on the Internet, this is also a common method of virus. Therefore, I have set the permission for this directory to deny the permission of the current user to execute on this directory.
As the saying goes, good food is always wise. Using these anti-virus methods can greatly reduce the chance of poisoning in the future.