EndurerOriginal
1Version
Today, a friend said his computer could not be connected to the crowd to play games. Let me help you. The friend's computer system was newly installed with Win 2000, without any patches. It was installed with Kingsoft drug overlord and Kingsoft network hacker. Start lianzhongProgramThe Kingsoft website will pop up the inquiry window, the friend does not understand this stuff, so if he chooses not to allow, he will not be able to play the game.
During system patching, hijackthis is used to scan logs and detect suspicious startup items:
O4-HKLM/../run: [file mapping services] hp-1003.exe
O4-HKLM/../runservices: [file mapping services] hp-1003.exe
Search finds that this hp-1003.exe is located in C:/Windows/system32 and has read-only, hidden, and system attributes. Online scanning of Kaspersky reported backdoor. win32.sdbot. AFG, and rising reported backdoor. sdbot. kxe.
In Windows 2000, the task manager cannot terminate the virus process, use icesword to terminate the process, and delete the file.