The gray pigeon graypigeon_hacker.com.cn
Original endurer
1st
A netizen's computer would move his mouse to open a window and perform other operations, which may be remotely controlled by others. Please help check.
The super patrol inspection system service installed in the computer of Netizens found a service item named graypigeon_hacker.com.cn, which is obviously gray.
You can use pe_xscan to scan the image as follows:
O23-service: graypigeon_hacker.com.cn (graypigeon_hacker.com.cn)-C:/Windows/hacker.com.cn.exe | 8:54:42 (automatic)
Disable the service.
Download bat_do and fileinfo to the http://purpleendurer.ys168.com.
Use fileinfo to extract file information:
File Description: C:/Windows/hacker.com.cn.exe
Attribute :----
Digital Signature: No
PE file: Yes
An error occurred while obtaining the file version information!
Creation Time: 3:19:59
Modification time: 8:54:42
Size: 761344 bytes, 743.512 KB
MD5: 036e0927559d7363faedbd5e9d4ae842
Sha1: c8204641bda5b92028d2bb2ecb2f6b27f1ae48aa
CRC32: 4167ee90
Delayed deletion after backup is packaged with bat_do.
Restart your computer to delete the service.