起舞荧光草歌曲:backdoor.win32.rbot.gen何处来的

来源:百度文库 编辑:查人人中国名人网 时间:2024/04/27 22:41:23
重装系统之后,安装了木马克星和卡巴斯基之后,查杀硬盘,无毒。GHOST了系统。

上网,到百度知道,没一分钟
木马克星提示:
新建:winnt\o
新建:winnt\system32\mssetup32.exe

卡巴提示:mssetup32.exe感染backdoor.win32.rbot.gen

GHOST还原系统。上网冲浪,涛声依旧,刚点了sohu.com的几个目录,没打开其它的网,
上面的现象又出现了。

再查杀系统光盘,无毒
现在问大家:backdoor.win32.rbot.gen 是从何处来的。如何找到它的栖身之地。

英文解释,自己看吧,这个程序来自于IRC漏洞,
去windows升级一下就好了
Backdoor.Rbot is a family of Trojan programs for Windows, which offer the user remote access to victim machines. The Trojans are controlled via IRC, and have the following functions:

monitor networks for interesting data packets (i.e. those containing passwords to FTP servers, and e-payment systems such as PayPal etc.)
scan networks for machines which have unpatched common vulnerabilties (RPC DCOM, UPnP, WebDAV and others); for machines infected by Trojan programs (Backdoor.Optix, Backdoor.NetDevil, Backdoor.SubSeven and others) and by the Trojan components of worms (I-Worm.Mydoom, I-Worm.Bagle); for machines with weak system passwords
conduct DoS attacks
launch SOCKS and HTTP servers on infected machines
send the user of the program detailed information about the victim machine, including passwords to a range of computer games

RPC漏洞!升级windows

哇,这个后门好厉害啊,也许不是病毒,是其中的一点代码之类的吧