Žg‚¢—l ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï (MRT.EXE) — ‰“–], XP, 2000 –” 2K3
” –› ‹‰’· ‚ׂÁ‚½‚è whats’ been ƒ_ƒEƒ“ƒ[ƒh –” installed by Ž©“®“I C³ ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` ‘‹ C³/ Œ°”÷‹¾ C³, –› ŒÜŒŽ have ‚¨’m‚点 ™Î ”Þ•û is an ”á”»“I C³ –¼‘O ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï ‹¤‚É KB890830 •tâ³. Its’ ^‚É ƒAƒg ‘ü •¹‚µ ƒx[ƒVƒbƒN ”½- •aŒ´‹, ”½- ƒ[ƒ –” ”½-Trojan 暌” utility ™Î provided by Œ°”÷‹¾ –h‚® –” ŽèŒ˜‚¢ ‘‹ ‰“–], ‘‹ XP, ‘‹ 2000 –” ‘‹ 2003 •ûŽ® ‚Æ‚µ‚Ä –ðE Š´õ ™‘o.
–Þ‚à ƒU • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï is ƒx[ƒVƒbƒN, •¹‚µ its’ ‘ü, –” ‚³‚ installed “Æ‚è‚Å‚É ‰—‚¢‚Ä Å‚à ‘‹ “dŽqŒvŽZ‹@ ” users opt- — •t‚« Ž©“®“I C³ ‹¤‚É ƒI[ƒg ŒŽ C³. Žz‚‚Ä its’ ƒAƒg —D‚ꂽ “¹‹ï ˜M‚·‚é ‘Þ‚¯‚é –” ƒfƒŠ[ƒg ”CˆÓ detectable • ƒ\ƒtƒgƒEƒGƒA ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` •„’š ™Î Š´õ ƒU “dŽqŒvŽZ‹@, •Ê‚Ä ‘ Å‘Oí of –h”õ’ 暌” —iŒì when –› dont’ Œ‡–R ”ƒ‚¢“ü‚ê‚é ƒAƒg –ž”t 暌” •tl ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` —\–ñŽÒ •t‚« •aŒ´‹ ƒfƒtƒBƒjƒVƒ‡ƒ“/ —ŽŠ¼ C³. ƒCƒbƒg ‹X‚µ‚¢ –’ be ƒAƒg ‘ “`‰Æ ˜J—Í’ ƒƒX‚ð“ü‚ê‚é ƒU •ûŽ® ‚æ‚è “Á’è –” æëç» •aŒ´‹ Š´õ –œ’[ ‘R‚à–³‚¢‚Æ •aŒ´‹, Trojan, ƒ[ƒ, –{Œ¹ ‹ãH‘å, malware –” • •„’š ôò –” íœ ƒ\ƒtƒgƒEƒGƒA ƒtƒFƒCƒ‹.
•¹‚µ Žg‚¢—l ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï (WMSRT/MSRT)? ƒU —\’èˆÄ does not have ”CˆÓ •Ö–@ — –`“ª Œ£—§ nor ‘ì ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` •q· “à‰Î’ø —̈æ. ^‚É WMSRT “¾“_ — ƒU — ‘\‚Ä —ጎ –³‚µ ŒäŽål knowledge, ” –› have installed MSRT. ” –› •†G‚è ”@‚ ƒ‰ƒ“ƒjƒ“ƒO ƒU “¹‹ï —}‚¦‚é ŒäŽål •ûŽ® •Ö—— ‘΂µ‚Ä •p”É —] ‘\‚Ä ƒAƒg ŒŽ, ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` —e‹^ ŒäŽål •ûŽ® is Š´õ –” Œ‡–R Ÿø‚Þ ƒU MSRT ‘|‚«o‚· ƒU Š´õ, ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` š`‚É Œ‡–R ‘M‚©‚· – ƒU ¬Ñ of ƒU scan (by •s—šs –œ’[ is –Ù–Ù unless Š´õ), –› ‹X‚µ‚¢ •Ö—— ‘–s‰Â”\ –” q˜H ƒU “¹‹ï ‹¤‚É ˆÈ‰º —p–½:
MRT.EXE
–› ‹X‚µ‚¢ “TŒ^ –{ —\’èˆÄ –¼‘O — —p–½ •q·, ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` q˜H —p–½ box, ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` — –`“ª ’T‹† — ‰“–]. Note ™Î users ‚ׂ« Š ‰—‚¢‚Ä •t‚« ƒU “dŽqŒvŽZ‹@ by using an •to‚µ ‘¦‚¿ ˆêˆõ of ƒU ‰^‰cŽÒ ˜A ˜M‚·‚é ƒU • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï. — ‰“–], user •K—p —^‚¦‚é User •to‚µ y•I ”F‰Â ’Ê‚·.
WMSRT MRT.exe —Í Žl‚ —p–½ ˜Hü “ü‚ê–Ñ – ŽŸ, which is ”CˆÓ –” Å‚à of ƒU —ï”N not •K‘R“I unless ŒäŽål’ ‰^‰cŽÒ ‘΂µ‚Ä ŒÞ’· –Ô:
- Q ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` ˜a‚â‚© —p“r ˜a‚â‚© ƒ‚[ƒh. –{ ŽæŽÌ suppresses ƒU user ŠE–Ê of ƒU “¹‹ï.
- /? - •\ަ ƒAƒg –ⓚ box ™Î – ƒU —p–½- ˜Hü “ü‚ê–Ñ.
- ƒIƒM q˜H — ŒŸ”g- š`‚É ƒ‚[ƒh. — –{ ƒ‚[ƒh, • ƒ\ƒtƒgƒEƒGƒA îˆÓ be •ñŽÒ •t‚« ƒU user •¹‚µ îˆÓ not be removed.
- ƒTƒFƒ —Í an æ‚è“ü‚ê‚é scan of ƒU “dŽqŒvŽZ‹@.
- FY: —Í an æ‚è“ü‚ê‚é scan of ƒU “dŽqŒvŽZ‹@ –” “Æ‚è‚Å‚É ãY—í ”CˆÓ Š´õ found.
‘\‚Ä • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï (KB890830s)’ MRT.EXE is ran, – ‘‹ is ƒI[ƒvƒi[, where ƒU ‘‹ title –’ •\–¾ ƒU e of ƒU “¹‹ï (e.g. ”ªŒŽ 2007). ” –› have ’†ŒÃ e ‘´‚êŒÌ its’ –³ã •t‚« —šs an ã‚èâ áe ƒ‰ƒ“ƒjƒ“ƒO ƒU “¹‹ï.
ƒNƒŠƒbƒN –¾‚‚é S‚Ý ”[‚ß‚é ƒU EULA.
ã ƒU EULA has been ƒAƒNƒZƒvƒg, ƒU user ‹X‚µ‚¢ ”²ä ƒAƒg “TŒ^ of scan ¬‚·. By •s—šs, •q· scan is ”²äÂ, which scans “dŽqŒvŽZ‹@ –¼Žc –” ares of •ûŽ® Å‚à —L‚蓾‚ׂ« Š´õ by ƒmƒE • ƒ\ƒtƒgƒEƒGƒA –” ’â—¯ ”CˆÓ • ˆ—‰ß’ö ™Î are found. ƒCƒbƒg –’ ŒŸ”g æ‚ÁŽæ‚è ƒuƒ‰ƒEƒU ”wŒi, ƒfƒŠ[ƒg èk –” “o‹L —vÎ ™Î are •‘® ‹¤‚É ˆ—‰ß’ö ™Î are ޝ•ÊŽq ˜Ô •. ” • ƒ\ƒtƒgƒEƒGƒA is found, ŽžÜ user ‚©‚à‚µ‚ê‚È‚¢ •“z •t‚« —šs ƒAƒg –ž”t æ‚è“ü‚ê‚é scan ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` –› ŒÜŒŽ •Ö—— ”²ä •t‚« —šs –ž”t scan, which scan —L‚ç‚ä‚é èk –” ƒtƒHƒ‹ƒ_[ ‰—‚¢‚Ä —L‚ç‚ñŒÀ‚è fixed –” removable ‘Oi ( œ‚¢‚Ä ƒ}ƒbƒsƒ“ƒO –Ô éfŽÒ) ƒIƒ“ƒWƒGƒA “dŽqŒvŽZ‹@. —á scan îˆÓ —]—T users ‘I‚蔲‚ –” ƒJƒXƒ^ƒ}ƒCƒY ƒAƒg scan •ï‚ß‚é ƒAƒg “Á’è ƒtƒHƒ‹ƒ_[ –” its subfolders ƒIƒ“ƒWƒGƒA “dŽqŒvŽZ‹@.
Scanning ”“W’†. ” • ƒ\ƒtƒgƒEƒGƒA has modified ( ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` Š´õ) user èk ƒIƒ“ƒWƒGƒA “dŽqŒvŽZ‹@, ƒU “¹‹ï îˆÓ •q· –› ‘Þ‚¯‚é ƒU • ƒ\ƒtƒgƒEƒGƒA ‚æ‚è those èk. –› ‹X‚µ‚¢ –m ‘|‚«o‚· “Á’è èk ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` —L‚ç‚ñŒÀ‚è Š´õ èk found.Note ™Î –^ —^Œ –Sޏ is —L‚蓾‚ׂ« “á –{ ˆ—‰ß’ö –” ™Î ƒU “¹‹ï ŒÜŒŽ not be —Lˆ× –ß‚· –^ èk •t‚« Œ´–{, pre- Š´õ —lŽq.
–¾× of ¬Ñ of ƒU scan “‚«, unless ƒU MRT.exe is q˜H — ˜a‚â‚© ƒ‚[ƒh. ” ”Þ•û is ϋɓI ŒŸ”g, –› ŒÜŒŽ –’ see ¬Ñ ‚Æ‚© Š´õ was found –” was removed, Š´õ was found •¹‚µ was not removed ‹¤‚É æb‚µ‚¢ èk found –, Š´õ was found –” was âc removed, “dŽqŒvŽZ‹@ —]‚è •K{, ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` –¢‚¾ •Ö—— ƒXƒeƒbƒvƒX.
‚±‚‚±‚ ƒIƒ“ƒWƒGƒA •¹Ý “ – –È–§ ¬Ñ of ƒU scan” ’‚ß‚é ƒU –¼‘O of •Ï‚í‚Á‚½ malware ƒU “¹‹ï scanned ‘΂µ‚Ä –” ƒU ¬Ñ ‘΂µ‚Ä –ÁX “TŒ^.
ƒAƒG Š èk mrt.log –’ been ¶¬ — \%WinDirDebug%\ ƒtƒHƒ‹ƒ_[, –” îˆÓ ŠÜ—L ]Ž– •ñ“¹:
Œ°”÷‹¾ ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï v1.32, ”ªŒŽ 2007
ƒXƒ^[ƒ^[ ‰—‚¢‚Ä Wed Aug 29 144633:: 2007
¬Ñ —vŽ:
----------------
” Š´õ found.
—ˆ•œ •„’š: 0
Œ°”÷‹¾ ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï ã“h ‰—‚¢‚Ä Wed Aug 29 164730:: 2007
ƒAƒG – —Í“Y‚¦ ‘΂µ‚Ä KB890830 is –’ Žg—p‰Â”\ •t‚« ƒ_ƒEƒ“ƒ[ƒh –” Ÿø‚Þ ƒU ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï, ” dont’ Œ‡–R Ÿø‚Þ MRT.exe •Ö—— yourself. – —Í“Y‚¦ ‹X‚µ‚¢ be ƒ_ƒEƒ“ƒ[ƒh ‚±‚ê‚Å •\‚í‚· –› Žg‚¢—l ƒU “¹‹ï •à’²-by- •à’² ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` do –œ’[ “Æ‚è‚Å‚É.
‘債‚½: –{ is ƒAƒg ‹@ŠB ƒgƒ‰ƒ“ƒXƒŒ[ƒg ‹‹Žd which is provided " ˜Ô is" –³‚µ •. ‹@ŠB–|–ó ‚©‚à‚µ‚ê‚È‚¢ “‚¢ •Ù‚¦‚é. —Ç‚¢ •t‘õ– ‰p‘ –ñм whenever —L‚蓾‚ׂ«.
•Ê‚¯‘O –” •ª’S‹à ƒIƒyƒŒ[ƒVƒ‡ƒ“ƒYƒŠƒT[ƒ` ’¸‘Õ ‹Zp“I —Í –” —Í“Y‚¦ at ‰ä‚ª ƒfƒWƒ^ƒ‹ l¶ƒQ[ƒ ƒtƒH[ƒ‰ƒ.
—× —p•i
- • ƒ\ƒtƒgƒEƒGƒA ™‘o —p‹ï by Œ°”÷‹¾
- Œ°”÷‹¾ ‘‹ • ƒ\ƒtƒgƒEƒGƒA ™‘o “¹‹ï (KB890830) –” C³ ‘ü ƒ_ƒEƒ“ƒ[ƒh
- –¢Ý –” Remove –k Œ»•¨ ”õ‚É ‹¤‚É –k ™‘o “¹‹ï
- ƒ_ƒEƒ“ƒ[ƒh ÅV Kaspersky •aŒ´‹ ™‘o “¹‹ï v7.0.0.223
- ‘‹ ‰“–] SP1 èk ™‘o “¹‹ï (Vsp1cln.exe) ‹~o ‰¹”Õ ‹ó”’
- ’Pg•‹”C èk •t‚« ‰“–]
- ¶¬ ŒäŽål Own ™‘o “¹‹ï
- Žg—p‹ÖŽ~, Remove –” –¢Ý U3 “à‰Î’ø
- ‘‹ ‰“–] —- —]’n ã‚èâ ‚æ‚è ‘‹ XP —Í •êŒ` –” ŽæŽÌ
- “®Œü ”÷× ƒP[ƒ\ƒIƒ‹ƒRƒ“ƒSƒ…[ƒ^-cillin ƒCƒ“ƒ^[ƒlƒbƒgƒ[ƒN 暌” 2007 ƒxƒ^ ‘΂µ‚Ä ‘‹ ‰“–] ‘ü ƒ_ƒEƒ“ƒ[ƒh
































