史萊姆論壇

史萊姆論壇 (http://forum.slime.com.tw/)
-   一般電腦疑難討論區 (http://forum.slime.com.tw/f17.html)
-   -   中了病毒/木馬,可是確是由 Command.exe 開啟… (http://forum.slime.com.tw/thread163838.html)

NiGHTsC 2005-12-20 06:01 AM

中了病毒/木馬,可是確是由 Command.exe 開啟…
 
command.exe,每次一開機,就會自動開啟,
也沒辦法關掉,是系統檔,然後一上線,就會自已裝一些病毒或木馬的 exe 檔,
例如:wtf.exe,z00096.exe,shost.exe,sko.exe…等等。

請問有人可以告訴我到底中了什麼嗎?
我試了 SpyBot 和 PCC 2005,更新到最新版,
還是沒辦法,Windows Update 也更新了… :sxde45fty :sxde45fty
謝謝各位了…T_T

didi 2005-12-20 06:12 AM

是PCC 2005和泥說中毒的嗎

ps.幫偶多喝几杯tim hortons

Omar Lin 2005-12-20 09:40 AM

http://www.pandasoftware.com.tw/html/activescan.htm
先做線上埽毒,看看是說什麼病毒!

mini 2005-12-20 10:04 AM

windows 沒有內建 Command.exe 這個檔
先搜尋把他刪了
再掃毒

NiGHTsC 2005-12-20 03:24 PM

引用:

didi
是PCC 2005和泥說中毒的嗎

ps.幫偶多喝几杯tim hortons

不,是太明顯了,自已打開 cmd.exe,然後在 C 硬碟下做出?下載?複製?那些 wtf.exe 等等的檔,有些還是在 system32 或者 windows 夾子下的。

ps:剛剛買了一杯大杯VelouTim,橘子口味的,讚啦…:P[quote]怡紅公子
http://www.pandasoftware.com.tw/html/activescan.htm
先做線上埽毒,看看是說什麼病毒!
引用:

mini
windows 沒有內建 Command.exe 這個檔
先搜尋把他刪了
再掃毒

咦,沒有的啊,那命令視窗怎麼會有?
我有刪了,是在安全模式下…:D:D

真奇,PCC 2005 和 Spybot 1.3/Ad-Ware 6.0 竟然都找不到這些病毒/木馬…T_T
各位可以介紹幾個嗎?
Panda 聽說不錯…:p

NiGHTsC 2005-12-20 03:29 PM

引用:

怡紅公子
http://www.pandasoftware.com.tw/html/activescan.htm
先做線上埽毒,看看是說什麼病毒!

有,有掃了,可惜沒辦法一起消毒…T_T
這些是 Log,真多啊…@_@
-------------------------------------------------------------------------
Incident Status Location
Adware:Adware/Deskwizz Not desinfected C:\WINDOWS\DH.dll

Adware:Adware/ClkOptimizer Not desinfected C:\WINDOWS\System32\wuauclt.dll

Adware:Adware/CommAd Not desinfected C:\WINDOWS\TmlnaHRz\asappsrv.dll

Adware:Adware/CommAd Not desinfected C:\WINDOWS\TmlnaHRz\command.exe

Adware:adware/commad Not desinfected C:\WINDOWS\SYSTEM32\atmtd.dll

Adware:adware/sqwire Not desinfected C:\WINDOWS\SYSTEM32\tsuninst.exe

Adware:adware/qoologic Not desinfected C:\WINDOWS\SYSTEM32\wuauclt.dll

Spyware:spyware/virtumonde Not desinfected C:\WINDOWS\SYSTEM32\vtstt.dll

Adware:adware/popupsandbannersNot desinfected C:\WINDOWS\timessquare.exe

Adware:adware/dollarrevenue Not desinfected C:\WINDOWS\drsmartload.dat

Adware:adware/clkoptimizer Not desinfected Windows Registry
Adware:Adware/CommAd Not desinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7PGI1MNX\timessquare[1].exe

Adware:Adware/CommAd Not desinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\DO18WV4C\installer[1].exe

Adware:Adware/Zeno Not desinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\AQ6PX32G\inst_drca02[1].exe

Virus:W32/Sdbot.ftp Disinfected C:\WINDOWS\system32\i

Adware:Adware/Zeno Not desinfected C:\WINDOWS\system32\dwdsregt.exe

Adware:Adware/Sqwire Not desinfected C:\WINDOWS\system32\tsuninst.exe

Adware:Adware/ClkOptimizer Not desinfected C:\WINDOWS\system32\wuauclt.dll

Adware:Adware/ClkOptimizer Not desinfected C:\WINDOWS\system32\vgactl.cpl

Adware:Adware/Zeno Not desinfected C:\WINDOWS\system32\rodsregl.exe

Adware:Adware/CommAd Not desinfected C:\WINDOWS\Temp\cmdinst.exe

Adware:Adware/Sqwire Not desinfected C:\WINDOWS\Temp\tsinstall_4_0_4_0_b4.exe

Adware:Adware/CommAd Not desinfected C:\WINDOWS\timessquare.exe

Adware:Adware/CommAd Not desinfected C:\WINDOWS\TmlnaHRz\asappsrv.dll

Adware:Adware/CommAd Not desinfected C:\WINDOWS\TmlnaHRz\command.exe

Adware:Adware/Deskwizz Not desinfected C:\WINDOWS\DH.dll

Adware:Adware/Deskwizz Not desinfected C:\WINDOWS\z00096.exe

Possible Virus. Not desinfected C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\I3C7FNAJ\desk[1].exe[wtf.exe]

Possible Virus. Not desinfected C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\I3C7FNAJ\desk[2].exe[wtf.exe]

Possible Virus. Not desinfected C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\I3C7FNAJ\desk[3].exe[wtf.exe]

Adware:Adware/QoolAid Not desinfected C:\Documents and Settings\NiGHTsC\Local Settings\Temp\tm33623.exe

Adware:Adware/QoolAid Not desinfected C:\Documents and Settings\NiGHTsC\Local Settings\Temp\tm32337.exe

Adware:Adware/QoolAid Not desinfected C:\Documents and Settings\NiGHTsC\Local Settings\Temporary Internet Files\Content.IE5\MNCTIL2V\rcverlib[1].exe

Adware:Adware/Deskwizz Not desinfected C:\Documents and Settings\NiGHTsC\Local Settings\Temporary Internet Files\Content.IE5\4V6D8305\z00096[1].exe

Adware:Adware/Sqwire Not desinfected C:\Program Files\Common Files\riqz\riqzd\riqzc.dll
-------------------------------------------------------------------------

guest5 2005-12-20 03:46 PM

版上好像有免安裝的kaspersky跟AntiVirusKit免安裝的版本
先用這兩套掃~掃完之後~嘿~~要不要試試mcafee然後鎖住system32跟windows資料夾
mcafee就是這好用~呵


所有時間均為台北時間。現在的時間是 10:27 PM

Powered by vBulletin® 版本 3.6.8
版權所有 ©2000 - 2024, Jelsoft Enterprises Ltd.

『服務條款』

* 有問題不知道該怎麼解決嗎?請聯絡本站的系統管理員 *


SEO by vBSEO 3.6.1