Table of Contents
0x00 Foreword
0x01 Emergency Scenario
0x02 Event Analysis
0x03 Preventive measures
Home Operation and Maintenance Safety How to solve Windows worm virus

How to solve Windows worm virus

May 17, 2023 pm 07:22 PM
window

0x00 Foreword

Worm virus is a very old computer virus. It is a self-contained program (or a set of programs) that usually spreads through the network. Every time it invades a new computer computer, it replicates itself on this computer and automatically executes its own programs.

Common worms: Panda Burning Incense Virus, Shock Wave/Shock Wave Virus, Conficker Virus, etc.

0x01 Emergency Scenario

One morning, the administrator found at the egress firewall that the internal network server continued to initiate active connections to overseas IPs. The internal network environment was unable to connect to the external network, and there was no way to figure it out.

0x02 Event Analysis

For the intranet IP of the server seen on the egress firewall, first disconnect the virus-infected host from the intranet, then log in to the server and open D-shield_web scan Check the port connection status and you can find that the local area initiates a large number of active connections to the external network IP:
How to solve Windows worm virus

Through the port exception and tracking the process ID, you can find that the exception is caused by svchost.exe windows Caused by the service main process, svchost.exe sends requests to port 445 of a large number of remote IPs:
How to solve Windows worm virus

Here we speculate that the system process may be infected by a virus, and use Kaspersky virus to check and kill it Tool, scan and kill all files, and find an exception in c:\windows\system32\qntofmhz.dll:
How to solve Windows worm virus

Use multi-engine online virus scanning (http://www.virscan.org /) Scan the file:

How to solve Windows worm virus

Confirm that the server is infected with the conficker worm virus, download the conficker worm killing tool to check the server, and successfully remove the virus.
How to solve Windows worm virus

1、发现异常:出口防火墙、本地端口连接情况,主动向外网发起大量连接
2、病毒查杀:卡巴斯基全盘扫描,发现异常文件
3、确认病毒:使用多引擎在线病毒对该文件扫描,确认服务器感染conficker蠕虫病毒。
4、病毒处理:使用conficker蠕虫专杀工具对服务器进行清查,成功清除病毒。
Copy after login

0x03 Preventive measures

In government and hospital intranets, there are still some very old infectious viruses. How to protect computers from virus infection , summarizing several preventive measures:

1、安装杀毒软件,定期全盘扫描
2、不使用来历不明的软件,不随意接入未经查杀的U盘
3、定期对windows系统漏洞进行修复,不给病毒可乘之机
4、做好重要文件的备份,备份,备份。
Copy after login

The above is the detailed content of How to solve Windows worm virus. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. Best Graphic Settings
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
Will R.E.P.O. Have Crossplay?
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)