Board logo

标题: 救命啊~~~~ [打印本页]

作者: Wildflower    时间: 2004-5-25 10:17     标题: 救命啊~~~~

Dein PC ist akut mit dem Generic.RPC/DCOM-Worm-TCP445 infiziert.
Bitte sorge umgehend dafür das Dein PC gesäubert wird. Dein Netzzugang kann ansonsten gesperrt werden. Nähere Infos zu dem Virus durch klicken auf den Virusnamen.
Virusname: Generic.RPC/DCOM-Worm-TCP445
Festgestellt am: 2004-05-20 00:50:24
Zuletzt gesehen am: 2004-05-25 05:00:03
Erfasst durch: Router-ACL

可是用杀毒软件根本查不到这个病毒

更奇怪的是我是22号换的全新的硬盘,是全新的,为什么还会有病毒??

哪位高手来救命啊??
作者: blackskin    时间: 2004-5-25 11:13

系统要经常升级,这样才能避免这些Worm

This outline is intended for Rice University users whose personal or
home computers are infected with one of the RPC/DCOM worms. These
worms propagate by exploiting a known security bug in Windows NT, 2000
and XP. For specific information on the RPC/DCOM exploit, see

https://www.owlnet.rice.edu/cgi-rice/fom?file=365

If your dial-up account was deactivated due to worm infection, and
dial-up is your only means to access the Internet, you must print out
these instructions and take them home with you. You will also need
several pieces of software and additional instructions as indicated
below. Please read these instructions first and copy the required
files and programs to floppy disks or a CD-R.

(1) If your computer uses Windows ME or XP, you must disable the
"System Restore" function. Instructions are available here:

  http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

Print out a copy of those instructions and take them home with you if
your home computer is infected.

(2) Download and install appropriate patches for your operating system
from Microsoft.

For Windows 2000/NT, these two patches must be applied:

  http://www.microsoft.com/technet/security/bulletin/MS03-007.asp
  http://www.microsoft.com/technet/security/bulletin/MS03-039.asp
  (Scroll down to "Patch Availability".)

For Windows XP Home/Pro, a single patch is required:

  http://support.microsoft.com/default.aspx?scid=kb;en-us;826939
  (Scroll down to "Download the 826939 package now.")

If given the choice between 32-bit and 64-bit updates, always choose
the 32-bit version.

If you use your dial-up account to connect to the Internet, and your
dial-up account was deactivated to prevent the virus from propagating,
then you must download the patch utilities on campus and take them home
on a floppy disk or CD-R.

For convenience, I've mirrored the above patches here:

Windows NT/2000:

  ftp://updates.rice.edu/pub/antiv ... mswindows/MS03-007/

  ftp://updates.rice.edu/pub/antiv ... mswindows/MS03-039/

Windows XP:

  ftp://updates.rice.edu/pub/antiv ... mswindows/KB826939/

However, this site is only accessible from the Rice network, Rice dialup
or Rice VPN.  If you use a non-Rice connection, you must go to the
Microsoft site.

(3) Download and run the McAfee Stinger application:

  http://vil.nai.com/vil/stinger/

Perform a full scan with the Stinger utility. This will remove most
RPC/DCOM worms from your operating system. Restart your computer when
the full scan is complete.

As above, if your home computer is infected and your dial-up account
has been deactivated, you must put the Stinger application on a floppy
disc or CD-R and take it home with you.

(4) Install and update antivirus software. Rice University has
licensed McAfee VirusScan for your use. Visit
http://www.rice.edu/IT/hwsw/virus/ for details and a download link.

VirusScan will not fit on a floppy disc; if you do not have network
access at home, you will need to copy the software to a recordable
CD. If you need help making a recordable CD, please contact IT (at
http://problem.rice.edu/) for assistance.

(5) Apply current virus signature updates to McAfee VirusScan. You can
get them from http://www.rice.edu/IT/hwsw/virus/ ; you will also need
to put them on a CD if you do not have network access at home.

(6) Perform a full antivirus scan with the fully-updated version of
VirusScan. If VirusScan finds infected files, instruct it to delete
them.

(7) Restart your computer. It should now be clean and protected from
further infection by RPC/DCOM infector worms. Notify Rice IT via
problem@rice.edu or http://problem.rice.edu/ if you need to reactivate
your dial-up or VPN account. Please mention that you have applied both
required patches and cleaned your computer with Stinger.

(8) Keep your system updated! Security patching and updates are the
first line of defense to protect your Microsoft operating system from
worm and virus infection. Without security updates, future worms and
viruses will infect your computer, and we may have to temporarily lock
accounts again to prevent the spread of infection.
作者: Wildflower    时间: 2004-5-25 11:38

我不明白的是为什么病毒是在20号被FESTGESTELLT的,可是我的硬盘是22号装的,里面不应该有病毒啊
作者: blackskin    时间: 2004-5-25 11:45

那可能是老硬盘上的毒吧
作者: Wildflower    时间: 2004-5-25 12:10

我的老硬盘TOTAL KAPUTT了,都已经扔了,不在电脑里啊
作者: blackskin    时间: 2004-5-25 12:21

Originally posted by Wildflower at 2004-5-25 12:10:
我的老硬盘TOTAL KAPUTT了,都已经扔了,不在电脑里啊

那你在装新硬盘之前用的什么硬盘???
管理员有可能是22号才查日志文件,把你封了~~~~~
而其实你是20号中的毒~~~~~~
作者: ∮紫Suki风∮    时间: 2004-5-25 12:23

换一台算了!!!!!这样简单又快捷!!!!
作者: Wildflower    时间: 2004-5-25 12:44

Originally posted by blackskin at 2004-5-25 13:21:
那你在装新硬盘之前用的什么硬盘???
管理员有可能是22号才查日志文件,把你封了~~~~~
而其实你是20号中的毒~~~~~~


这么说吧,我的硬盘是18号晚上坏的,19号把它拆下来去检查,确定已经不能用了之后就没再装上去,一直到22号之前我都没开过电脑,就这样

不过我朋友用她的电脑用我的帐户上网来着,因为她也是因为这个病毒被封了的,可是不应该有病毒在我的电脑里啊,难道网线里还能有病毒??
作者: blackskin    时间: 2004-5-25 12:51

Originally posted by Wildflower at 2004-5-25 12:44:
这么说吧,我的硬盘是18号晚上坏的,19号把它拆下来去检查,确定已经不能用了之后就没再装上去,一直到22号之前我都没开过电脑,就这样

不过我朋友用她的电脑用我的帐户上网来着,因为她也是因为这个病毒被封了 ...

那可能是你朋友的电脑有毒,因为她用你的帐号,所以管理员就把这个帐号给封了,以为是你中毒了~~~~
作者: ∮紫Suki风∮    时间: 2004-5-25 13:00

怎么现在都是被一些病毒困扰啊!!!!!!!
作者: Wildflower    时间: 2004-5-25 13:12

Originally posted by blackskin at 2004-5-25 13:51:
那可能是你朋友的电脑有毒,因为她用你的帐号,所以管理员就把这个帐号给封了,以为是你中毒了~~~~


但是现在我的帐户还没有被封,而且今天早上我5点用我自己的电脑上网还是显示有病毒啊

Zuletzt gesehen am: 2004-05-25 05:00:03




欢迎光临 人在德国 社区 (http://rs238848.rs.hosteurope.de/bbs/) Powered by Discuz! 7.2