[求救] win32/conficker.AA worm @ server2003 …
1. 敘述問題:
系統會自動藉由網路連線建立每日工作排程 生成confickerAA
(如此圖)http://attui.pixnet.net/album/photo/108289697
NOD32掃描確定無病毒
已經安裝MS08-067更新
上網嘗試過confickerAA NOD32官網的清除方式+網友教學 (ex.defender)
但均無法阻止自動排程 也掃不出異常
應該有某個程式在幫病毒開門
只是找不出....
其他過去病毒存在紀錄(圖均可放大)
http://attui.pixnet.net/album/photo/108289692
http://attui.pixnet.net/album/photo/108289693
http://attui.pixnet.net/album/photo/108289694
http://attui.pixnet.net/album/photo/108289695
http://attui.pixnet.net/album/photo/108289696
http://attui.pixnet.net/album/photo/108289697
想請問如何清除已經刪除的"服務" @_@?
2. 系統資料:
Windows Server 2003 R2 SP2
3. 分析報告:
Combofix報告:
2003無法使用combofix efix........
Hijackthis :
http://sun.cis.scu.edu.tw/~92a39/upload/37393.txt
SRENG :
http://sun.cis.scu.edu.tw/~92a39/upload/37394.txt
目前有懷疑這兩個檔案 但是不知道怎麼清除..
[ulkeqr / ulkeqr][Stopped/Disabled]
<C:\WINDOWS\system32/svchost.exe -k
ulkeqr-->%SystemRoot%\System32\nvqiuy.dlL><N/A>
[xgqgbk / xgqgbk][Stopped/Disabled]
<C:\WINDOWS\system32\SVCHOST.EXE -k
xgqgbk-->%SystemRoot%\System32\hyudlu.fsl><N/A>
本機是固定ip
有灌SQL2005 + FTP server +ERP程式..
--
http://tw.youtube.com/watch?v=iB3ikC9rOLs
Randy Pausch (October 23, 1960 – July 25, 2008)
--
※ 發信站: 批踢踢實業坊(ptt.cc)
◆ From: 61.221.173.34
※ 編輯: Attui 來自: 61.221.173.34 (11/21 12:12)
推
11/21 12:15, , 1F
11/21 12:15, 1F
→
11/21 12:15, , 2F
11/21 12:15, 2F
→
11/21 12:26, , 3F
11/21 12:26, 3F
推
11/21 12:42, , 4F
11/21 12:42, 4F
→
11/21 12:43, , 5F
11/21 12:43, 5F
推
11/21 15:58, , 6F
11/21 15:58, 6F
噓
10/09 17:44, , 7F
10/09 17:44, 7F
噓
10/09 17:45, , 8F
10/09 17:45, 8F
噓
10/09 17:47, , 9F
10/09 17:47, 9F
噓
10/09 17:49, , 10F
10/09 17:49, 10F
噓
10/09 17:50, , 11F
10/09 17:50, 11F
噓
10/09 17:52, , 12F
10/09 17:52, 12F
噓
10/09 17:53, , 13F
10/09 17:53, 13F
噓
10/09 17:55, , 14F
10/09 17:55, 14F
噓
10/09 18:57, , 15F
10/09 18:57, 15F
噓
10/09 18:59, , 16F
10/09 18:59, 16F
噓
10/09 19:00, , 17F
10/09 19:00, 17F
噓
10/09 19:02, , 18F
10/09 19:02, 18F
噓
10/09 19:04, , 19F
10/09 19:04, 19F
噓
10/09 19:05, , 20F
10/09 19:05, 20F
噓
10/09 19:07, , 21F
10/09 19:07, 21F
噓
10/09 19:08, , 22F
10/09 19:08, 22F
噓
10/09 19:10, , 23F
10/09 19:10, 23F
噓
10/09 19:11, , 24F
10/09 19:11, 24F
噓
10/09 19:13, , 25F
10/09 19:13, 25F
噓
10/09 19:15, , 26F
10/09 19:15, 26F
噓
10/09 19:16, , 27F
10/09 19:16, 27F
噓
10/09 19:18, , 28F
10/09 19:18, 28F
噓
10/09 19:19, , 29F
10/09 19:19, 29F
噓
10/09 19:21, , 30F
10/09 19:21, 30F
噓
10/09 19:22, , 31F
10/09 19:22, 31F
噓
10/09 19:24, , 32F
10/09 19:24, 32F
噓
10/09 19:26, , 33F
10/09 19:26, 33F
噓
10/09 19:27, , 34F
10/09 19:27, 34F
噓
10/09 19:29, , 35F
10/09 19:29, 35F