看板 AntiVirus 關於我們 聯絡資訊
※ [本文轉錄自 ask 看板 #1FfolmNi ] 作者: pavlov (海風) 看板: ask 標題: [請問] 這隻蠕蟲要用甚麼軟體殺? 時間: Mon May 7 09:57:01 2012 下面節錄我電腦(Win7 64bit)安裝的小紅傘(Antivir)抓到的Malware紀錄, 已經試過使用 Anti-Malware+卡巴斯基2012從外部掃過一遍, 但小紅傘在每次開機的時候還是都會偵測到8個字元檔名的dll木馬 不慎其擾~ 有哪位高手有看過以下變種木馬pattern 懇請告知小弟要如何徹底刪掉母體程式 感恩!! Virus or unwanted program 'TR/Dropper.Gen [trojan]' detected in file 'C:\Users\Winston\AppData\Local\Temp\5qm1wxfx.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\ye-bjmpf.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\mpntnusb.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\fwjthnma.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\bfxt7mhp.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\jjqhpequ.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\yu3rtne9.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\2hifrtke.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\jmupm_te.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\vyry_dpg.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\sugm3oyv.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\fklrozw0.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\xnsf-hqk.dll. detected in file 'C:\Users\Winston\AppData\Local\Temp\o9lt4-gu.dll. -- ※ 發信站: 批踢踢實業坊(ptt.cc) ◆ From: 60.250.84.112 ※ 發信站: 批踢踢實業坊(ptt.cc) ※ 轉錄者: leoblack (140.109.49.244), 時間: 05/07/2012 10:39:43
chjimmy:猜測是登錄檔搭配自動執行製造的...要清要費一番功夫 05/07 11:18
pavlov:該怎麼查某個dll檔是在哪個路徑下的程式所製造出來的呢? 05/07 12:45