[Practice] manually clear Remote Control Trojans

Source: Internet
Author: User

 

First of all, we maintained a server for the general manager last week and found that the server had been hacked. After basic security is completed, a sethc backdoor and abnormal services are found.

(Who claimed the backdoor consciously)

After finding it, del will be generated automatically. Finally, cacls c: \ windows \ system32 \ sethc.exe/D everyone

Then an abnormal service is found.


The cause is that the executable file named svchost.exe-k netsvcs and the service name is windows audio ..

Click "stop" to disable the service. I did not expect the service to be disabled due to a daemon.

Open the Registry HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services

Find Audiosrv and delete it. It is still automatically created. Then, right-click the permission and allow only administrator access. Then, empty the executable file directory.

Then restart the server and find that the service can be deleted, that is, the trojan is removed. Then delete it. netstat-an finds that the connection is normal.

 

From: network security technology blog (http://www.safe121.com)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.