【建議】★ 最新病毒透過 MSN大量傳播中 , 請勿任意接受來路不名的檔案



贊助商連結


頁 : 1 2 [3] 4

hpo14
2005-02-03, 10:52 AM
我都開全部自動接收.. = =
不過線在沒在線上.....晚點在上線看看唄.
(祈禱我同學沒中才好)

贊助商連結


skeepy
2005-02-03, 11:04 AM
回yuping:我也想更新,但不是我能控制的,現在用的是公司電腦。
回softbrian:有裝,感謝提醒已將該選項取消.

天氣預報
2005-02-03, 11:28 AM
只接收自己不按執行也會中嗎?

kaspersky
2005-02-03, 11:31 AM
Kaspersky 在 02/03 am10:02 分的病毒碼巳經可以掃除新的 msn 變種病毒......

天氣預報
2005-02-03, 11:45 AM
Win32.Bropia.B(CA), Win32/Bropia.196608!Worm, W32/Bropia.B (F-Secure) , WORM_BROPIA.D (Trend), W32/Bropia.worm.d (McAfee), W32/Bropia-C (Sophos), W32.Spybot.Worm (Symantec), IM-Worm.Win32.VB.c (Kaspersky)

Norton的有點怪
http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html
2003年就掃得到?
還是說它把類似特徵的都放一起?

titanfu
2005-02-03, 11:45 AM
那...只有掃到.pif...對系統其他地方的設定有處理嗎???
我測試檢查之後 系統的確多了 winhost.exe 這檔案跟設定 還有啟動等等
引用前面的文章...
Winhost.exe 這個是????????????????
我檢查兩台XP...一台有去跑.pif 一台沒跑.... 下面的情況真的有出現跟存在呢~

When run, this memory-resident worm drops a copy of itself in the root folder (usually C:\) using any of the following file names:

* Bedroom-thongs.pif
* Hot.pif
* LMAO.pifROFL.pif
* LOL.scrWebcam.pif
* Naked_drunk.pif
* New_webcam.pif
* Underware. Pif

Removing autostart entries from the registry prevents the malware from executing at startup.

1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
3. In the right panel, locate and delete the entry:
win32 = "winhost.exe"
4. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>RunServices
5. In the right panel, locate and delete the entry:
win32 = "winhost.exe"
6. In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Ole
7. In the right panel, locate and delete the entry:
win32 = "winhost.exe"
8. Close Registry Editor.

Fabian C
2005-02-03, 11:51 AM
今天我也有收到,雖然知道是病毒,
但Windows Messenger對於這種怪怪的副檔名,不允許儲存。
防毒軟體連用的機會都沒有...

propc
2005-02-03, 11:56 AM
現在officescan norton 卡巴斯基皆能掃到病毒。

天氣預報
2005-02-03, 12:54 PM
變種到J了
http://securityresponse.symantec.com/avcenter/venc/data/w32.bropia.j.html

sintyan
2005-02-03, 01:20 PM
每天一早到公司就是先更新office scan病毒碼,
今天一早就把office scan病毒碼更新到2.390
卡巴斯基測不到,
好在沒事沒事,不然..............準備提頭見課長囉!
待在IT部裡,防毒還不夠機警,是會丟工作地!
感謝各位大大提供的資訊!