本帖最后由 kyqm 于 2011-8-7 19:03 编辑
Shadow Defender 是否会被误认为是鬼影?
重装系统出现个怪事
装完系统后装上个Shadow Defender(论坛上星空打包的),然后用金山的鬼影专杀扫描一遍,发现有四个文件染毒
我想可能是装杂七杂八软件时染上了毒吧,退出Shadow Defender重启之后又再次用鬼影专杀扫描一遍,好了,没毒了。
然后把Shadow Defender加上保护,再扫一遍,悲剧了,又发现四个病毒
我不知道,到底是真的Shadow Defender被病毒感染,还是Shadow Defender修改了MBR或者哪个敏感地方导致报毒?
请专家,高手,网友一起分析一下。
补充一下,我用的是Eset Smart Security ,扫描系统内存及C:,没发现病毒。
——————————————————————————————————————————————————————
日志文件:
2,0110807,,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kisknl,,删除注册表成功,,0,,000000000000000000,,0
2,0110807,,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kisknl,,删除注册表成功,,0,,000000000000000000,,0
2,0110807,,diskpt.sys,,恶意驱动,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\pchsvc.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\6to4.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\ias.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,diskpt.sys,,恶意驱动,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\pchsvc.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\6to4.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\ias.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kisknl,,删除注册表成
——————————————————————————————————————————————————————
换个思路,再找一台机子,装SD,也用专杀扫一遍,看看是否会重现问题,
哪位朋友也试试看?
我用家里另一台电脑尝试了一下,SD没有保护时没扫出鬼影,SD加上保护后,扫除了5个病毒
日志为
2,0110807,,免疫:,,C:\Documents and Settings\Administrator\Local Settings\Temp\tmp.tmp,,0,,000000000000000000,,0
2,0110807,,免疫:,,C:\WINDOWS\system32\xp-b1393be4.exe,,0,,000000000000000000,,0
2,0110807,,免疫:,,C:\WINDOWS\system32\b3b4da\393be4.exe,,0,,000000000000000000,,0
2,0110807,,免疫:,,C:\WINDOWS\system32\1ea28c\ed3dc2.exe,,0,,000000000000000000,,0
2,0110807,,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kisknl,,删除注册表成功,,0,,000000000000000000,,0
2,0110807,,diskpt.sys,,恶意驱动,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\pchsvc.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\regsvc.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\6to4.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,C:\WINDOWS\system32\ias.dll,,重启删除,,21,,000000000000000000,,0
2,0110807,,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kisknl,,删除注册表成功,,0,,000000000000000000,,0
但是两台机子软件差不多,所以担心这个例子没有代表性
哪位有空也帮忙测试一下。 |