引用:
作者: 明心皓月
請問Plunderer大大
不用防毒軟體.難不成 您是用 " 硬體 "
|
非也, 而是傳說中的 "裸奔"
看我的工作管理員及 hijackthis 日誌就知道了, 夠簡單
Scan saved at 12:36:20, on 2007/12/11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\cFosSpeed\spd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\cFosSpeed\cFosSpeed.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Internet\Opera\opera.exe
E:\Utility\HiJackThis\HijackThis.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\Phonetic\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: 傳送至 OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: 傳送至 OneNote(E) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - ESC Trusted Zone:
http://*.update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{987F457C-C13D-415D-AF2A-42F5C939761C}: NameServer = 168.95.192.1,168.95.1.1
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
--
End of file - 2388 bytes
網站照樣上, 軟體照樣下, 並非我一定不會中毒, 而是:
1. 可疑的程式處理程序逃不過我的眼睛
2. 路由上網, 外界很難攻進
3. Firefox 或 Opera 瀏覽, 對惡意網站幾乎免疫
4. 即使中毒, 10 分鐘即可自己搞定, 萬一系統被破壞, Ghost 還原更快
但裝防毒軟體及防火牆, 拖慢系統速度累積起來就不知浪費多少時間
5.自誇的說, 對病毒及防毒軟體都有相當程度的了解了....病毒是 "日新月異", 防毒軟體是 "了無新意", 所以呢, 該中還是會中...若非要裝個維護安全的軟體, 我會裝 HIPS 軟體
6.以上純屬個人意見, 不鼓勵他人效法