Today, I found that the computer was abnormal. I only needed to open the folder on the left side of the Windows resource manager, and the cmd.exe crashed. I checked that w32.downadup. Autorun virus was detected. Although the latest version of Rising antivirus software is installed on the machine, the virus cannot be detected at all. Symantec can detect it, but the Organization's confidential computers do not allow the installation of foreign anti-virus software. They can only use rising. After searching online, you can download the anti-virus software package on Symantec's website. Run the following command to delete the virus:
Symantec w32.downadup removal tool 1.1.0.5
Process: svchost.exe, thread: 00000454 (terminated)
Process: svchost.exe, thread: 00000b64 (terminated)
Process: svchost.exe, thread: 00000bb0 (terminated)
Process: svchost.exe, thread: 0000093c (terminated)
Process: svchost.exe, thread: 00000bbc (terminated)
Process: svchost.exe, thread: 00000bc0 (terminated)
Process: svchost.exe, thread: 000000f0 (terminated)
Process: svchost.exe (terminated)
G: \ recycler \ S-5-3-42-2819952290-8240758988-879315005-3665 \ javasgkvsq. vmx: w32.downadup. B (unrepairable) (deleted)
Registry: HKLM \ System \ CurrentControlSet \ Services \ bits: Start (value set to 0x00000003 (3 ))
Registry: HKLM \ System \ CurrentControlSet \ Services \ ersvc: Start (value set to 0x00000002 (2 ))
Registry: HKLM \ System \ CurrentControlSet \ Services \ wscsvc: Start (value set to 0x00000002 (2 ))
Registry: HKLM \ System \ CurrentControlSet \ Services \ wuauserv: Start (value set to 0x00000002 (2 ))
W32.downadup has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 356394
The number of deleted threat files: 1
The number of threat processes terminated: 1
The number of threat threads terminated: 7
The number of registry entries fixed: 4
The tool initiated a system reboot.