How many admin accounts appear inexplicably in XP are backdoor viruses?

Updated on healthy 2024-02-09
26 answers
  1. Anonymous users2024-02-05

    Your virus is a Trojan horse.

    1. Only redo the system.

    2 Then press F8 on the first restart

    3. Enter Safe Mode.

    4Open My Computer -> the Tools of the title bar.

    Internet Options -> View - > Advanced Options, in the drop-down button on the Show all files button, then click OK at the bottom.

    5 Open My Computer Right-click on d; Disk and then click Open in the drop-down menu Be sure to do this (because you're double-clicking on the d; The virus on the disk is written into the registry again, and the system is doing it in vain).

    6 You will see an executable file and an autorun file to delete them.

    7. Then repeat steps 5-6 to delete e; f;g;etc.

    8 Then start over and it's OK.

    Good luck.

  2. Anonymous users2024-02-04

    Depending on your situation, your computer must have become a broiler. If you have more administrator accounts, you can use Control Panel - > Performance Maintenance - > Management Tools - > Computer Management - > Local Users and Groups - > Users, in the list on the right there are all users in your computer, you can right-click on the extra users and choose to delete or put a checkmark before the user has been deactivated in the properties, you can close (deactivate) the extra users. If you are using Rising Ransomware, there is a vulnerability scan that can be used to turn off the system's sharing by disabling the default sharing.

    Another way: set the system to show the suffix status (My Computer -> Tools -> Folder Options -> View -> Hide the tick of the extension of known file types) Create a new txt file and type:"

    net share admin$ /del

    net share ipc$ /del

    net share c$ /del

    net share d$ /del

    net share e$ /del

    net share f$ /del

    net share g$ /del

    net share h$ /del

    Just enter the content in the quotation marks. The letters before $ represent your hard drive letter, mine is assigned to h so to h).

    After saving, change the suffix to. bat, double-click on the batch file and delete all the hard disk shares.

    Add this batch file to the beginning of the system shortcut, and the default sharing will be automatically turned off every time you turn on the computer in the future.

  3. Anonymous users2024-02-03

    Scold. If you are not a ** server.

    As long as it is turned off or blocked by a firewall, 445, the general rookie of the port can't hack you. If you're a master, you'll be hacked no matter what. But there is no need for the master to hack you.

    Reinstall the lower system. Hit the full patch. Shut down those ports. Antivirus software is just one way to fix the problem. Defending yourself is the last word!

    That's right. Kill soft recommend nod32...It's too ruthless.

    The sharing issue you mentioned is normal. A lot of machines are like that. You can make a batch and put it in the startup. Every time you turn on the computer, you can automatically turn off the sharing.

    net share ipc$ /delete

    net share admin$ /delete

    net share c$ /delete

    net share d$ /delete

    net share e$ /delete

    If you have several hard disk partitions, write a few lines of such commands, and do not copy this line. )

    Save as a note suffix! Then drag this batch file to the "Program" "Startup" item, so that it will run every time you boot up, that is, close the share with the net command. If you need to open a share or shares one day, just re-process the batch file (delete the corresponding command line).

  4. Anonymous users2024-02-02

    Those are certainly rookies.

    Since there is a back door where you can see.

    It is a middle pigeon. It was double-opened 3389.

    Kill poison in safe mode.

  5. Anonymous users2024-02-01

    It's basically letting the invasion go. And there must be a *BAT file, which is executed every time I enter, performs sharing setting net shareFind this app. Delete it. All operations are operated in safe mode.

    To defend. It's best to use an on-premises security policy. Block the port you want to block.

    But if you've already let the control go. I don't know which port is connected. Let's say port 3389.

    is the default. Then hackers who know a little bit better. Will directly change this port to something else, such as 4527 or something.

    That way you won't be able to find out. You're directly under cmd. Enter netstat -a -b to see the process as well as the port.

    And then judge. No, it won't. Reinstallation is recommended. Scold.

  6. Anonymous users2024-01-31

    There's nothing strange about it, it's okay to disable it!

    All hard disks are shared, which is the default of the system!

    As my brother said, you can also use the net share command to do batch processing!

  7. Anonymous users2024-01-30

    Let's restore. Restore to the last correct configuration (remember the backup).

  8. Anonymous users2024-01-29

    Poisoning is normal in daily life, and it is unlikely to be hacked, so you can try to find the operation records on the account, and delete those accounts if there is no problem after a detailed check. If you're really afraid, redo the system!

  9. Anonymous users2024-01-28

    Make a clean system, shut down the computer from time to time every day, and do a good job of anti-virus measures--- this rookie advice, hehe.

  10. Anonymous users2024-01-27

    You can't install two kinds of antivirus software on one computer, which will cause conflicts.

    There are many reasons why your computer has been hacked, such as not patching all vulnerabilities in time, not turning off the sharing function, not closing certain dangerous ports, etc.

  11. Anonymous users2024-01-26

    The most complete solution to the reinstallation system.

  12. Anonymous users2024-01-25

    A suspicion of a virus comes to your door.

    Install antivirus software Rising Antivirus.

    Be careful to sail the ship of ten thousand years.

  13. Anonymous users2024-01-24

    Your system is encoded incorrectly, it should be set to unicode

  14. Anonymous users2024-01-23

    It's a virus, reinstallation doesn't solve the problem, you need to repartition, that is, the hard disk is full, and then install, or the problem can't be removed, the speed will be slower and slower.

  15. Anonymous users2024-01-22

    System volume information is the system folder that already exists.

    Of course, there are also viruses in it. If you don't kill it with antivirus, you can rest assured.

  16. Anonymous users2024-01-21

    The folder you mentioned is the system folder, not a virus, first upgrade the virus database of the antivirus software to the latest, and then restart the computer to enter the safe mode to kill the virus once.

  17. Anonymous users2024-01-20

    This is the system label information folder, which cannot be deleted, and it is not a virus.

  18. Anonymous users2024-01-19

    Upgrade the kill software to the latest version, full antivirus, and then cooperate with 360 to kill the Trojan, and then Windows Cleanup Assistant and Trojan Scavenger to kill the horse, you can do it, if you are not at ease, then trouble to go to the next Trojan removal master.

  19. Anonymous users2024-01-18

    Go to safe mode to kill, in that mode a lot of things don't load, including viruses, then it's easier to kill viruses.

  20. Anonymous users2024-01-17

    This is not a virus. That's what every computer has. Attributes are hidden by the system. Higher level. is important information for the system. Don't delete it.

  21. Anonymous users2024-01-16

    Kill with 360 Security Guard in safe mode.

  22. Anonymous users2024-01-15

    In the Tools Folder Options view.

    To display all files, you need to modify two places:

    1.Displays all files and folders.

    2.Uncheck the "Hide protected system files" checkbox.

    Because this folder is the folder used by XP System Restore and is a system file, you need to display the protected system files to see them.

    This folder cannot be deleted, but because it is used as a system restore folder and retains files from previous D drives, there is a possibility that there are virus files.

    Delete the files in this folder.

    Or, right-click on "My Computer", select "Properties" System Restore", and set the D drive to turn off System Restore.

  23. Anonymous users2024-01-14

    It is recommended that the landlord install Tencent PC Manager to protect computer security, Tencent PC Manager is a free security software, which can effectively prevent and solve common security risks on the computer, and is also China's first two-in-one security software with anti-virus and optimized management functions.

    Tencent PC Manager has functions such as cloud scanning and killing Trojans, system acceleration, vulnerability fixing, real-time protection, network speed protection, computer clinic, etc., and has pioneered the pioneering function of "management + antivirus" two-in-one.

    Relying on the butler cloud detection and killing and the second-generation self-developed anti-virus engine "Eagle Eye", the little red umbrella, the housekeeper system repair engine and the Kingsoft cloud detection and killing engine line cover, the ability in security protection and virus detection and killing has reached the same level as the world's first-class anti-software killing.

  24. Anonymous users2024-01-13

    Tencent Computer Manager is Liang Mu's professional anti-virus software that adopts the "4+1" core "core" anti-virus engine, in addition to its own butler cloud anti-virus engine, Eagle Eye's second-generation anti-virus engine and system repair engine, it also integrates the Kingsoft anti-virus engine, and the anti-virus engine of the world-renowned anti-virus software Xiaohong Umbrella, and the anti-virus ability is good. Ascending cavity.

    I've been using it for a while, and my computer has always been healthy.

    If the landlord is interested, you can use it to see

  25. Anonymous users2024-01-12

    This system is safe, don't worry!

  26. Anonymous users2024-01-11

    These English are just a reminder that your system is poisoned! You need to install antivirus software! I don't know what antivirus software you use!

    It is recommended that you change it and kill it all! It's best to kill it in safe mode as well, it's more thorough! As for the antivirus software on the Internet, I won't talk about it, each has its own advantages!

    It depends on which one you prefer?

Related questions
11 answers2024-02-09

When you're in a bad mood, sometimes it's because people think too much. Always thinking about something that will happen in the future puts a strain on one's psyche. Why think about something you can't do? >>>More

38 answers2024-02-09

I feel this way sometimes, maybe because it's so lonely, but in fact, each of you should have a close friend who can tell him the secrets of your own heart. Maybe it's like the guy upstairs said - it's time to fall in love! >>>More

16 answers2024-02-09

It doesn't matter if he doesn't matter to you either. Take a step back and open the sky. and don't get along with others for a lifetime. >>>More

27 answers2024-02-09

1. There may be something important that you haven't done and don't want to do it, which causes you to be restless, 2. It may also be due to the weather, 3. It may be that you have a sensitive personality and have more emotional elements (most of the girls may have a week before the menstrual holiday, and the mood will sway with the advent of that).

9 answers2024-02-09

There are three types of Tenpay account freezing:

1. Due to the system detecting that there is a security risk in your account, in order to ensure the safety of the funds in the account, it is temporarily frozen. According to your account login, transactions, etc., the system will temporarily clear the fiber and freeze the funds in your account if it detects that it is not your own operation! >>>More