Infected by a trojan. The trojan created an open UDP port at 123.
Then another TCP at 135( I think... but this port is used by Netbios).
Then it creates a folder Recycler/S-5-3-42-2819952290-8240758988-879315005-3665/jwgkvsq.vmx
Size is 159KB. It also creates an autorun.inf file with the size of 58KB.
Services stared using the svhost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
By using services.msc I identified a few services that use svhost.exe
Service name:
1)Help and Support from the services menu.
2)COM+ Event System
3)Windows Management Instrumentation
4)Themes
5)System Event Notification
This is which i have disabled during startup so it should be the source of infection.
6)DHCP Client
7)Computer Browser
8)Secondary Logon
9)Server
【诗巫景Ho-KaLiu】诗巫灯会2017
-
配合诗巫旅游年,由诗巫市议会主催,诗巫中华工商总会主办的灯会兼美食节,从10月3日至26日在诗巫第一及第二期广场举行。
关于美食节我就不多说。不过这次的灯会别出心裁,值得一提。
据说这灯会的设计及创作是交由一间来自中国,在马来西亚投资的亚洲太平洋马戏杂技艺术有限公司负责,总共花费了大约30万零吉的重本!建设工...
7 years ago
1 comment:
Hi,
You might want to check up the following forum:
http://en.kioskea.net/forum/affich-43800-avg-windows-update-failure
They recommended the following:
http://www.simplysup.com/tremover/download.html
SFC
Post a Comment