Today, Trojan. Win32.PcClient. bk, a member of the website, is obtained.
After the system is infected, create two files in the % system % file: AUTOEXEC. BAT and 1370.dll.
In the HKEY_LOCAL_MACHINESYSTEMCURRENTCONTROLSETSERVICES branch of the zookeeper table, add an animation and zookeeper messenger.
00001370.dllis inserted into winlogon.exeand iexplore.exe.
If the system crashes immediately and re-loads 0001370.dll, the virus still runs after re-installation, and 00001370. dll cannot be deleted.
SSM is a useful tool for post-paid. dll ). The following is the procedure for killing Trojan. Win32.PcClient. bk with SSM:
1. Add two rules in application rules of SSM to disable AUTOEXEC. BAT and 0001370. dll (see figure 1 ).
2/re-install the system (check the settings of SSM before re-upload, and ensure that they are automatically added ).
3/remove AUTOEXEC. BAT and 0001370.dll( limit 2) in the % system % file quota ).
4. Remove the sequence table sequence (sequence 3) added to the sequence ).
So far, this tricky post-attack will be destroyed by the bottom!
You can refer to the anti-trigger tool SMM for post-payment users/Trojans.