作者yangzhe (Eko.没事涂涂抹抹)
看板AntiVirus
标题[问题] AdwCleaner误报?
时间Fri Jun 15 06:27:04 2018
平常就有定期用AdwCleaner扫电脑的习惯
今天早上进行扫描时,有抓到以下两个感染
***** [ Registry ] *****
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP-NoScope
虽然我印象中,最近并没有下载奇怪的东西和逛诡异的网站
最近用过的一些AntiMalware也没有抓出这两个感染(包含MBAM、Zemana和Hitmanpro)
但姑且还是让AdwCleaner做了清理和重开机
後来上了Malwarebytes的官方论坛,才发现有些人也跟我遇到相同的问题
不少网友都感觉这是误报,想请教下版上先进们的意见。
------------------------------------------------------------------------------
附上AdwCleaner的log:
-------------------------------
Malwarebytes AdwCleaner 7.2.0.0
-------------------------------
Build: 06-05-2018
Database: 2018-06-14.1
-------------------------------
Mode: Clean
-------------------------------
Start: 06-15-2018
Duration: 00:00:00
OS: Windows 10 Pro(1803版,有更到最新)
Cleaned: 2
Failed: 0
[ Services ]
No malicious services cleaned.
[ Folders ]
No malicious folders cleaned.
[ Files ]
No malicious files cleaned.
[ DLL ]
No malicious DLLs cleaned.
[ WMI ]
No malicious WMI cleaned.
[ Shortcuts ]
No malicious shortcuts cleaned.
[ Tasks ]
No malicious tasks cleaned.
[ Registry ]
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP-NoScope
[ Chromium (and derivatives) ]
No malicious Chromium entries cleaned.
[ Chromium URLs ]
No malicious Chromium URLs cleaned.
[ Firefox (and derivatives) ]
No malicious Firefox entries cleaned.
[ Firefox URLs ]
No malicious Firefox URLs cleaned.
[+] Delete Tracing Keys
[+] Reset Winsock
还请各位多多协助!
--
※ 发信站: 批踢踢实业坊(ptt.cc), 来自: 36.238.186.244
※ 文章网址: https://webptt.com/cn.aspx?n=bbs/AntiVirus/M.1529015226.A.ECE.html
1F:→ fatstan: 像是误报 有人反应复原之後就扫不到了 06/15 09:40
那惨了...我没多想就先把它移除掉了...
这两条感觉是防火墙的规则,少了它们会怎麽样吗?
※ 编辑: yangzhe (36.238.186.244), 06/15/2018 12:43:32
※ 编辑: yangzhe (36.238.186.244), 06/15/2018 13:21:17
2F:→ brianuser: 他这规则预设没开所以应该是没影响 06/15 13:54
4F:→ brianuser: 嗯…希望我没搞错 06/15 13:55
感谢建议,如果没有影响的话那就还好
※ 编辑: yangzhe (36.238.186.244), 06/15/2018 15:15:04