1. Your OS , or other softwares installed may have security flaws
, so other people can install it on your computer , so first step
is to UPDATE your OS fixes , and UPDATE all other major softwares
installed on your computer
2. the hacker may already own OS account , you need to exam all
existing system accounts , delete all unknown accounts , and change
password for all existing accounts
3. if you have done the above , LOCATE the raidenftpd.exe , it
can not be renamed so you can surely find it .
4. the hacker may already disabled the log but you can still find
them , see the [DIR CONTAINS RAIDENFTPD.EXE]\virtualfs\[server
name]\laston.dat
5. collect all evidences , try to find the service that launches
raidenftpd.exe , shutdown and uninstall it , and finally delete
all raidenftpd files
what
are raidenftpd files ?
dupemaker.exe
raideneditor.exe
raidenftpd.dll
raidenftpd.exe
raidenftpd.svm
raidenftpdsvcinstaller.exe
rftpdservice.exe
rftpdservice.jpg
|
|