作者leoblack (自我放逐的开始只好自己)
看板AntiVirus
标题Fw: [请问] 这只蠕虫要用甚麽软体杀?
时间Mon May 7 10:39:43 2012
※ [本文转录自 ask 看板 #1FfolmNi ]
作者: pavlov (海风) 看板: ask
标题: [请问] 这只蠕虫要用甚麽软体杀?
时间: Mon May 7 09:57:01 2012
下面节录我电脑(Win7 64bit)安装的小红伞(Antivir)抓到的Malware纪录,
已经试过使用 Anti-Malware+卡巴斯基2012从外部扫过一遍,
但小红伞在每次开机的时候还是都会侦测到8个字元档名的dll木马 不慎其扰~
有哪位高手有看过以下变种木马pattern
恳请告知小弟要如何彻底删掉母体程式
感恩!!
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\Users\Winston\AppData\Local\Temp\5qm1wxfx.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\ye-bjmpf.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\mpntnusb.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\fwjthnma.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\bfxt7mhp.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\jjqhpequ.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\yu3rtne9.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\2hifrtke.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\jmupm_te.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\vyry_dpg.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\sugm3oyv.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\fklrozw0.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\xnsf-hqk.dll.
detected in file 'C:\Users\Winston\AppData\Local\Temp\o9lt4-gu.dll.
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 60.250.84.112
※ 发信站: 批踢踢实业坊(ptt.cc)
※ 转录者: leoblack (140.109.49.244), 时间: 05/07/2012 10:39:43
1F:推 chjimmy:猜测是登录档搭配自动执行制造的...要清要费一番功夫 05/07 11:18
2F:推 pavlov:该怎麽查某个dll档是在哪个路径下的程式所制造出来的呢? 05/07 12:45