{"id":7714,"date":"1969-12-31T18:00:00","date_gmt":"1970-01-01T00:00:00","guid":{"rendered":"http:\/\/the-4400.cn\/wp\/?p=11"},"modified":"1969-12-31T18:00:00","modified_gmt":"1970-01-01T00:00:00","slug":"win32wormmagistr%e7%9a%84%e6%89%8b%e5%8a%a8%e6%a3%80%e6%b5%8b%e5%92%8c%e6%b8%85%e9%99%a4","status":"publish","type":"post","link":"https:\/\/www.bohu.net\/blog\/7714\/","title":{"rendered":"Win32\/Worm.Magistr\u7684\u624b\u52a8\u68c0\u6d4b\u548c\u6e05\u9664"},"content":{"rendered":"<p>\u524d\u51e0\u5929\u5355\u4f4d\u7684\u673a\u5668\u4e2d\u4e86\u6bd2,\u7531\u4e8e\u6ca1\u6709\u4f7f\u7528\u6740\u6bd2\u8f6f\u4ef6,\u624b\u5de5\u5904\u7406\u7684,\u4e0b\u9762\u7b80\u5355\u8bf4\u4e00\u4e0b.<br \/>\n\u672c\u673a\u51e0\u4e4e\u6ca1\u6709\u611f\u89c9,\u76f4\u5230\u5c40\u57df\u7f51\u4e2d\u6709\u90e8\u5206\u673a\u5668\u65e0\u6cd5\u4e0a\u7f51,CMD\u4e2d\u8fd0\u884c arp -a ,\u53d1\u73b0\u5c40\u57df\u7f51\u4e2d\u673a\u5668\u7684\u7f51\u5173\u90fd\u6307\u5411\u4e86\u975e\u7f51\u5173\u7684\u4e2d\u6bd2\u673a\u5668.<br \/>\n\u8fd9\u4e5f\u662f\u8be5\u75c5\u6bd2\u6700\u8ba8\u538c\u7684\u5730\u65b9,\u4f2a\u9020\u7f51\u5173,\u8fdb\u884carp\u6b3a\u9a97.<br \/>\n\u4ee5\u4e0b\u662f\u7b80\u5355\u7684\u67e5\u6740\u548c\u68c0\u6d4b\u65b9\u6cd5.<br \/>\n\u75c5\u6bd2\u540d : Worm.Magistr<br \/>\n\u4e2d\u6587\u540d : \u9a6c\u5409\u65af<br \/>\n\u7c7b\u578b : \u75c5\u6bd2<br \/>\n\u5371\u9669\u7ea7\u522b : \u8f83\u5371\u9669<\/p>\n<p>\u75c5\u6bd2\u662f\u7531C\u8bed\u8a00\u7f16\u5199\u7684\u611f\u67d3\u578b\u75c5\u6bd2\uff0c\u611f\u67d3\u540e\u7f00\u540d\u4e3aEXE\u768432\u4f4dPE\u53ef\u6267\u884c\u7a0b\u5e8f\uff0c\u75c5\u6bd2\u6e90\u7684\u5927\u5c0f\u4e3a40KB\u3002<br \/>\n\u75c5\u6bd2\u6e90\u6587\u4ef6\u4e3aboot.exe\uff0c\u7531\u7528\u6237\u4eceU\u76d8\u4e0a\u63d0\u53d6\u3002<br \/>\n\u75c5\u6bd2\u68c0\u67e5\uff1a<br \/>\n\u68c0\u67e5\u9a71\u52a8\u5668\u6839\u76ee\u5f55\u4e0b\u662f\u5426\u6709boot.exe\u3002<br \/>\n\u7531\u4e8e\u4e00\u4e9b\u75c5\u6bd2\u6587\u4ef6\u662f\u9690\u85cf\u7684,\u624b\u52a8\u68c0\u6d4b\u9700\u8981\u4f7f\u7528 AVG Anti-Rootkit \u68c0\u67e5\u662f\u5426\u5b58\u5728\u201cC:\\WINNT\\linkinfo.dll\u201d\u3002<br \/>\n\u662f\u5426\u7f51\u7edc\u51fa\u73b0\u5f02\u5e38,\u7279\u522b\u662f\u5c40\u57df\u7f51\u4e2d\u5176\u4ed6\u673a\u5668\u7684\u7f51\u7ba1\u88ab\u6b3a\u9a97\u4e3a\u4e2d\u6bd2\u673a\u5668\u7684ip.<\/p>\n<p> \u63a8\u8350\u5de5\u5177\u94fe\u63a5:<\/p>\n<p>AVG Anti-Rootkit Free<br \/>\n\u4e13\u6740\u5de5\u5177\u5730\u5740 :  http:\/\/free.grisoft.com\/doc\/downloads-products\/us\/frt\/0?prd=arw<\/p>\n<p>BitComet AntiARP \u662f\u4e00\u4e2a\u9632\u62a4ARP\u653b\u51fb\u7684\u5c0f\u5de5\u5177\uff0c\u4f5c\u4e3a\u670d\u52a1\u8fd0\u884c\uff0c\u4e0d\u9700\u8981\u4efb\u4f55\u8bbe\u7f6e\u5373\u53ef\u81ea\u52a8\u9632\u62a4ARP\u653b\u51fb\u3002http:\/\/www.bitcomet.com\/tools\/antiarp\/index-zh.htm<\/p>\n<p> \u75c5\u6bd2\u4e13\u6740\u53ca\u76f8\u5173\u94fe\u63a5:<br \/>\n            \u5fae\u8f6f\u4e13\u6740\u5de5\u5177: http:\/\/go.microsoft.com\/fwlink\/?linkid=37020&#038;name=Win32\/Magistr<br \/>\n             &#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u51e0\u5929\u5355\u4f4d\u7684\u673a\u5668\u4e2d\u4e86\u6bd2,\u7531\u4e8e\u6ca1\u6709\u4f7f\u7528\u6740\u6bd2\u8f6f\u4ef6,\u624b\u5de5\u5904\u7406\u7684,\u4e0b\u9762\u7b80\u5355\u8bf4\u4e00\u4e0b. \u672c\u673a\u51e0\u4e4e\u6ca1\u6709\u611f\u89c9,\u76f4\u5230\u5c40\u57df\u7f51\u4e2d\u6709\u90e8 &hellip; <a href=\"https:\/\/www.bohu.net\/blog\/7714\/\" class=\"more-link\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">\u201cWin32\/Worm.Magistr\u7684\u624b\u52a8\u68c0\u6d4b\u548c\u6e05\u9664\u201d<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[161],"class_list":["post-7714","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-free"],"_links":{"self":[{"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/posts\/7714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/comments?post=7714"}],"version-history":[{"count":0,"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/posts\/7714\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/media?parent=7714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/categories?post=7714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bohu.net\/blog\/wp-json\/wp\/v2\/tags?post=7714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}