刚装上费尔 一查杀 看到 好多问题 日志显示如下 请大家帮我看看什么 情况 谢谢!!
Date,Virus Name,Virus Type,User,Filename,Scan Type
2008-7-29 18:50:43,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\Filup.exe->C:\Program Files\Common Files\Filseclab\mdcoder.dll,Realtime scan
2008-7-29 18:50:36,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\unrar.dll,Realtime scan
2008-7-29 18:50:35,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\unzip32.dll,Realtime scan
2008-7-29 18:50:34,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\w32tools.dll,Realtime scan
2008-7-29 18:50:30,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\twsupd.dll,Realtime scan
2008-7-29 18:50:29,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\mdcoder.dll,Realtime scan
2008-7-29 18:50:29,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\FilUp.exe,Realtime scan
2008-7-29 18:50:28,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\FilMsg.exe,Realtime scan
2008-7-29 18:49:37,非法的写操作,可疑程序,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\common_update_cn.exe->C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{CA3ECDCB-2D7D-42F5-9E97-0493DBAF4E00}_APP\fapiconv.dll,Realtime scan
2008-7-29 18:46:48,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios9.com,Realtime scan
2008-7-29 18:46:48,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios8.com,Realtime scan
2008-7-29 18:46:48,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios7.com,Realtime scan
2008-7-29 18:46:48,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios6.com,Realtime scan
2008-7-29 18:46:47,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios5.com,Realtime scan
2008-7-29 18:46:47,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios4.com,Realtime scan
2008-7-29 18:46:47,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios3.com,Realtime scan
2008-7-29 18:46:46,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios2.com,Realtime scan
2008-7-29 18:46:33,非法的写操作,可疑程序,Administrator,C:\Program Files\Common Files\Filseclab\CertReg.exe->C:\WINDOWS\system32\mbios1.com,Realtime scan
2008-7-29 12:19:13,HTML.Shell.PoliKey.C,病毒,Administrator,5.(未注册),Manual scan
2008-7-29 12:17:01,HTML.Shell.PoliKey.C,病毒,Administrator,4.(未注册),Manual scan
2008-7-29 12:14:39,Heuri.Suspicious.ERNM,启发式扫描,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\TWIEX12FD\emb-1.exe,Manual scan
2008-7-29 12:14:37,Heuri.Suspicious.ERNM,启发式扫描,Administrator,C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\TWIEX12E5\emb-1.exe,Manual scan
2008-7-29 12:01:09,Adware.IEhlpr.grva,广告程序,Administrator,1.(未注册),Manual scan
2008-7-29 12:00:25,Backdoor.PcShare.an.wm,木马,Administrator,0.(未注册),Manual scan
2008-7-29 11:41:08,注册表监控,错误的值,Administrator,HKEY_CLASSES_ROOT\inifile\shell\open\command[]=C:\WINDOWS\System32\NOTEPAD.EXE %1,Realtime scan
2008-7-29 11:41:08,注册表监控,错误的类型,Administrator,HKEY_CLASSES_ROOT\txtfile\shell\open\command[]=C:\WINDOWS\notepad.exe %1,Realtime scan
[ 本帖最后由 behind411 于 2008-7-30 18:21 编辑 ] |