作者yangzhe (Eko.沒事塗塗抹抹)
看板AntiVirus
標題[問題] AdwCleaner誤報?
時間Fri Jun 15 06:27:04 2018
平常就有定期用AdwCleaner掃電腦的習慣
今天早上進行掃描時,有抓到以下兩個感染
***** [ Registry ] *****
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP-NoScope
雖然我印象中,最近並沒有下載奇怪的東西和逛詭異的網站
最近用過的一些AntiMalware也沒有抓出這兩個感染(包含MBAM、Zemana和Hitmanpro)
但姑且還是讓AdwCleaner做了清理和重開機
後來上了Malwarebytes的官方論壇,才發現有些人也跟我遇到相同的問題
不少網友都感覺這是誤報,想請教下版上先進們的意見。
------------------------------------------------------------------------------
附上AdwCleaner的log:
-------------------------------
Malwarebytes AdwCleaner 7.2.0.0
-------------------------------
Build: 06-05-2018
Database: 2018-06-14.1
-------------------------------
Mode: Clean
-------------------------------
Start: 06-15-2018
Duration: 00:00:00
OS: Windows 10 Pro(1803版,有更到最新)
Cleaned: 2
Failed: 0
[ Services ]
No malicious services cleaned.
[ Folders ]
No malicious folders cleaned.
[ Files ]
No malicious files cleaned.
[ DLL ]
No malicious DLLs cleaned.
[ WMI ]
No malicious WMI cleaned.
[ Shortcuts ]
No malicious shortcuts cleaned.
[ Tasks ]
No malicious tasks cleaned.
[ Registry ]
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP
Deleted
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
FirewallRules|WMI-ASYNC-In-TCP-NoScope
[ Chromium (and derivatives) ]
No malicious Chromium entries cleaned.
[ Chromium URLs ]
No malicious Chromium URLs cleaned.
[ Firefox (and derivatives) ]
No malicious Firefox entries cleaned.
[ Firefox URLs ]
No malicious Firefox URLs cleaned.
[+] Delete Tracing Keys
[+] Reset Winsock
還請各位多多協助!
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 36.238.186.244
※ 文章網址: https://www.ptt.cc/bbs/AntiVirus/M.1529015226.A.ECE.html
→ fatstan: 像是誤報 有人反應復原之後就掃不到了 06/15 09:40
那慘了...我沒多想就先把它移除掉了...
這兩條感覺是防火牆的規則,少了它們會怎麼樣嗎?
※ 編輯: yangzhe (36.238.186.244), 06/15/2018 12:43:32
※ 編輯: yangzhe (36.238.186.244), 06/15/2018 13:21:17
→ brianuser: 他這規則預設沒開所以應該是沒影響 06/15 13:54
→ brianuser: 嗯…希望我沒搞錯 06/15 13:55
感謝建議,如果沒有影響的話那就還好
※ 編輯: yangzhe (36.238.186.244), 06/15/2018 15:15:04