想請教各位大大
這幾天我用家裡的桌上型電腦,插入隨身碟或讀卡機或iPOD等USB裝置DEVICE
都無法讀取,出現"已超過在單一系統中可存放的秘密最大數目"的訊息
我是有用NOD32掃毒,但掃完後仍是如此
有什麼解法嗎,還是說要重灌系統或M/B硬體問題,要維修或換M/B?
開啟"磁碟管理"時,發現磁碟區那邊完全是空白的,
雖然檔案總管還看得到,
google了很久,還去下載了一堆 anti-spyware, anti-malware...的來掃還是一樣,
就在要放棄的時候,突然想起來還沒用小紅傘做 Full System Scan,
掃了之後就抓到3隻木馬,選擇 delete 之後,
小紅傘便要求立刻重新開機,且立即倒數計時30秒,還不給 cancel 的按鈕...
重新開機後便完全恢復正常,隨身碟插上後也都可以開啟了
最可怕的是這幾隻木馬是看不見的,即使檔案總管開啟顯示所有檔案的選項,
或是用 total commander,依舊是看不到,
這在小紅傘是被稱為 Hidden Object,其定義為
http://forum.avira.com/wbb/index.php?page=Thread&threadID=84658
A hidden object refers to a registry entry or file or folder that is invisible to the operating system. This includes rootkits which are used to hide malware. These are dangerous. But keep in mind that not all hidden objects are dangerous as there are legal programs which hide their own files and registry entries.
但要記得在 Configuration 中,開啟 Search for Rootkits before scan,
不然小紅傘好像就會掃不到 Hidden Object,
以下 Log 檔內容提供給有遇到相同問題的人做參考
Starting search for hidden objects.
c:\windows\system32\drivers\ovfsthdovnrvekaohntmpubjgoywisjltrwklr.sys
[INFO] The file is not visible.
[DETECTION] Is the TR/PCK.Tibs.ZC Trojan
[NOTE] The file was deleted!
c:\windows\system32\ovfsthklyxexrqjxddkckrtqsietqyntwhlbpv.dll
[INFO] The file is not visible.
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[INFO] No SpecVir entry was found!
c:\windows\system32\ovfsthdeytympargxytkhomyxirqesabrvimuw.dat
[INFO] The file is not visible.
c:\windows\system32\ovfsthqjfcnpdxahjofakobcutvjllajfsvasn.dll
[INFO] The file is not visible.
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[INFO] No SpecVir entry was found!
c:\windows\system32\ovfsthxfptkynvnecgfoenowkbnjcbfwlyyubw.dll
[INFO] The file is not visible.
[DETECTION] Is the TR/Tibs.ZB Trojan
[INFO] No SpecVir entry was found!
c:\windows\system32\ovfsthuiqhegoodclhbwobllypkkwamprvyspv.dat
[INFO] The file is not visible.
內文搜尋

X