Results (
Thai) 1:
[Copy]Copied!
Please refer to the below information and suggestion.As you many know, svchost.exe is a Utility Process to manage DLL, and one svchost could manage many of DLLs.If we go through hacking cases, there are the cases by fortifying svchost.exe (or creating hacking tool by naming svchost.exe), copying DLL to a specific Script or running this sort of Script by using a command. We believe that the hacker would directly access to DB and update the value through running a specific program (DLL, Exe file, or Script). Please search the svchost.exe, and check the latest revised/update date or created date.And we suggest your IT team to check suspicious file(s) detected if there are any recently created or revised.In addition, we suggest your IT team to check :1) Credential Information a. if there would be any issue managing credential information (User/Password) for DB access. b. If there is any User you didn't create c. Whether there are any unnecessary User existsPlease change the current Password of the activated accounts and remove unnecessary users. If there is osql utility, please remove it, too.2) Porta. if TCP, UDP Port which are not used are currently openb. if some Ports are abnormally open Please block the Ports. For those Ports abnormally open, please check the program using the ports. We highly recommend to change the IPs of servers. 3) GMTool or other management/operation tools Please find any possibilities if these tools are leaked.4) Check every single Login User information and remove those accounts not in use.Change the password for the users in use. Tick the both values of Success, Fail of Audit privilege use of Local Policies of secpol.msc. By doing this, you can check all the events of Login attempts.If you've been through from 1) to 4) and now you can believe that you've done and complete all of them, please reinstall all the programs of servers including OS. After that, please ask us to deliver necessary files to reinstall Ran Online. Note :Please prevent server environment clean from hacking tool or back-door tools.Also, could you tell us whether you've been running Anti-virus program? Looking forward to hearing from you regarding what you've been doing up to now and the plans you are to do to respond this case, such as c2 audit mode.
Being translated, please wait..