PCDVD數位科技討論區

PCDVD數位科技討論區 (https://www.pcdvd.com.tw/index.php)
-   系統組件 (https://www.pcdvd.com.tw/forumdisplay.php?f=19)
-   -   卡巴斯基爛死了害我裝備被盜 (https://www.pcdvd.com.tw/showthread.php?t=647782)

chingmaio 2006-08-28 08:14 PM

引用:
作者B.Fox
恕刪...
以前我在幾個禮拜前遇過的來說
當時我剛試用NOD32
他就刪掉了EvID4226Patch.exe
這檔案有沒有木馬我不知道
我只知道用過的人應該不少
而且我也知道這檔案我要留著
不然以後無法破解SP2連線數限



EvID4226Patch.exe可以更改連線數.
所以.判定為惡意程式.
這也是XP更新時,將連線數改成10的原因之一....

不過..
有不少類似的程式,nod都是判定成惡意程式.
有用p2p的應該覺得很麻煩吧... :nonono:

野口隆史 2006-08-28 08:20 PM

引用:
作者chingmaio
EvID4226Patch.exe可以更改連線數.
所以.判定為惡意程式.
這也是XP更新時,將連線數改成10的原因之一....

不過..
有不少類似的程式,nod都是判定成惡意程式.
有用p2p的應該覺得很麻煩吧... :nonono:

是駭客工具...不是惡意程式..
NOD32的REPORT寫的很清楚明白...
惡意程式是有潛在的危險,兩者性質上差很多..

lutic 2006-08-28 09:02 PM

其實防毒軟體只能算是被動的防毒方式
靠的是大家覺得把有問題的檔案回報之後 再做更新病毒碼的動作
小弟之前也有收過朋友從nsn上傳來的網址 下載的檔案卡巴掃不到
回報卡巴後 馬上就收到回信說是後門程式...

很多人收到病毒都不會回報 等到出問題才在說防毒軟體爛 怎樣怎樣的...
如果大家都把病毒回報 就不會出現這樣多的不知名病毒了 不是嗎

honglun 2006-08-28 09:03 PM

引用:
作者Ann383
本人ㄉ習慣下載東西一定會掃毒,下載下來的檔案用卡巴掃不到
也因此我的裝備被盜最後用諾噸線上掃毒才查出來

有沒有專門防木馬的防毒軟體 是中文介面?



到下面那網頁中掃掃看.

http://www.microsoft.com/taiwan/ath...ety_center.mspx

野口隆史 2006-08-29 04:47 AM

我這次直接在信裡說明了哪些軟體會報,哪些軟體不會報
Kaspersky這次讓我等了很久
依舊是簡潔有利的回答...
引用:
Hello
There are nothing milicious has been detected

Regards, Chugunov Evgeniy
Virus Analyst, Kaspersky Lab.
Ph.: +7(095) 797-8700


ANTIVIR也回應了
大意是說在我附加的檔案裡頭有發現新的病毒
不過病毒類型似乎變了?!
並會下次特徵碼更新的時候會加入
引用:
Dear Sir or Madam,


Thank you for your recent inquiry.

We found a new virus in the attachment you have sent us.
The signature will be integrated in one of our next updates.
The signature of the virus will be detected as TR/AXW.A.

野口隆史 2006-08-29 04:58 AM

MCAFEE也回信了,不過我看的似懂非懂,沒辦法翻譯...
請英文達人幫個忙...
引用:
AVERT Labs - Beaverton

Current Scan Engine Version:4.4.00

Current DAT Version:4838

Thank you for your submission.


Analysis ID: 2500510

File Name Findings
Detection
Type Extra
--------------------|------------------------------|------------------------
----|------------|-----
dtr.dll |inconclusive |
| |no
hook.dll |inconclusive |
| |no
n[|t+|forxp.exe |inconclusive |
| |no
n[|tnt.ini |inconclusive |
| |no

inconclusive [dtr.dll hook.dll n[|t+|forxp.exe
n[|tnt.ini]


Upon analysis the file submitted does not appear to
contain one of the
100,000 known
threats in the AutoImmune database. The file may
contain a new malware
threat, or no
code capable of being infected. Your submission is
being forwarded to an
AVERT
Researcher for further analysis. You will be contacted
by AVERT through
e-mail with
the results of that analysis.


To find detailed information about viruses and other
malware, please review
AVERT’s
Virus Information Library:


http://vil.mcafeesecurity.com


In order to get the fastest possible response, you may
wish to submit future

virus-samples to:


https://www.webimmune.net/default.asp


In most cases it can respond almost instantly with a
solution. This may also
be the
best option if you are having a problem with gateway
scanners stripping your
sample
submission.


If you believe your computer is infected, but are
unsure which files should
be
submitted to AVERT for review, please visit:


http://vil.mcafeesecurity.com/vil/submit-sample.aspx


For other virus-related information, please review the
AVERT homepage at:


http://www.mcafee.com/us/threat_center/default.asp


Support –


Virus Research accepts file-samples for analysis and
possible inclusion into
AV
signature DAT sets. We are also prepared to answer
general virus questions.
All
product-related questions and comments can be
addressed through technical
support and
customer service, including:


* Product installation and update questions

* Product usage questions

* Specific operating system/version questions

* Assistance with detection and cleaning or removal of
viruses or trojans


Use the following link to update your DAT and scan
engine to the most
current version:

http://www.mcafee.com/apps/download...updates/dat.asp


Use the following links to reach online technical
support for McAfee
products -

Corporate Customers:


http://www.mcafeesecurity.com/us/support/


Single User/Retail Customers:


http://www.mcafeehelp.com


Note –


Due to the prevalence of network gateway AV products,
it is important that
all
submissions be zipped and the zip file
password-protected (password -
infected). Some
products will reject an email that contains a virus
that is not sent in this
way. In
addition, often we receive a file that appears not to
have been infected, to
find
later that the file was infected when it left the
sender, and was cleaned
somewhere
along the line.


Regards,




McAfee AVERT tm

A division of McAfee, Inc

chaotommy 2006-08-29 05:21 AM

引用:
作者野口隆史
MCAFEE也回信了,不過我看的似懂非懂,沒辦法翻譯...
請英文達人幫個忙...

廢話部份就不用管了
這個才是重要部份

Upon analysis the file submitted does not appear to
contain one of the100,000 known threats in the AutoImmune database.

送過去的檔案 在他們的 (100,000個病毒) 病毒資料庫(AutoImmune data 自動防禦資料庫 :confused: ) 沒有符合的資料

The file may contain a new malware threat, or no code capable of being infected. Your submission is being forwarded to an AVERT Researcher for further analysis. You will be contacted by AVERT through e-mail with
the results of that analysis.

這個檔案可能是一個新的 malware 或者是沒有攻擊能力.
他們會把這個檔案轉給 AVERT Researcher 做更進一步的研究
如果有更新(或者是有結果)的消息 會再EMAIL給你


(爛爛的翻譯... 將就一下吧 :shy: )

joe7569 2006-08-29 09:05 AM

我記得這加速器很久以前就有
當初作者也有說很多防毒軟體會誤判
他說跟他寫的程式語法有關係
不知道可信度如何

野口隆史 2006-08-29 10:54 AM

先感謝chaotommy 兄的翻譯

MCAFEE又回信了..
MCAFEE好像也不是很肯定這個檔案到底有什麼問題...
引用:
A.V.E.R.T. Sample Analysis
Issue Number:2500510
Virus Research Analyst: Brant Yaeger

AVERT Labs, Beaverton

Thank you for submitting your suspicious file.

Synopsis -

These files are being considered for inclusion in future DAT sets.

In order to get the fastest possible response, you may wish to submit
virus-samples to http://www.webimmune.net. In most cases it can respond
almost instantly with a solution.

Please note our policies for submissions:

All submissions must be in password-protected ZIP files (password -
infected) containing 30 files or less or being less than 3MB total unpacked
size. Please send only one ZIP file per submission, and one submission per
day. This allows submissions to be initially analyzed by our automated
systems, so they can be processed by our researchers more quickly.

Please resubmit any relevant files according to the guidelines listed above.

We cannot accept samples of virus source-code. We cannot compile possible
virus source code to analyze, because to do so would be a serious breach of
AV ethics. Also, in order to create detection for any new malware, we need
a copy of the malware itself to ensure that we have a complete sample, for
proper detection and cleaning capability.

Support -

Virus Research accepts file-samples for analysis and possible inclusion into
AV signature DAT sets. We are also prepared to answer general virus
questions.

All product-related questions and comments can be addressed through
technical support and customer service, including:

* Product installation and update questions
* Product usage questions
* Specific operating system/version questions
* Assistance with detection and cleaning or removal of viruses or trojans

Use the following link to reach online technical support for McAfee
products.

Corporate Customers:
https://mysupport.mcafeesecurity.com/

Single User/Retail Customers:
http://www.mcafeehelp.com

Regards,

Brant Yaeger
Virus Research Analyst
McAfee AVERT
A division of McAfee, Inc.

ASA-05

ninjaboy 2006-08-29 10:58 AM

引用:
作者leewayne
也許此一時彼一時吧!
敝人也是被站上一窩蜂大推卡巴而從 Norton 2006 轉到卡巴,
結果.........
結果.........
上個月中一堆病毒,其中有兩個根本看的到而解不了,
最後連開機都成了問題............
只好把硬碟拔下,到另一台有安裝 Norton2006 的系統上解毒,
但不太敢批卡巴,因為一定會有人跳出來說「卡巴是無誤的,是使用者自己不會用。」
有圖為證:底下這兩隻毒,卡巴根本就是直接放行,全無警告:
http://www.taiker.net/files/snap023.JPG
由於該發信人的 ID 是「學生家長」,所以不疑有他便點了附加檔,
卡巴連警告也沒,就直接放行,結果卡巴無解,只有拆硬碟到另一台電腦解。
不過,卡巴能拿第一,應該還是有它專精的一面,所以還要再多論據來評論卡巴才好。


下次看到.scr的盡量別去執行,因為基本上都是病毒


所有的時間均為GMT +8。 現在的時間是03:12 PM.

vBulletin Version 3.0.1
powered_by_vbulletin 2025。