查看: 44228|回复: 231
收起左侧

[分享] 【绝版】Malwarebytes Anti-Malware(MBAM)终身版若干问题解释

  [复制链接]
东方石
发表于 2014-3-28 21:15:28 | 显示全部楼层 |阅读模式
本帖最后由 东方石 于 2014-3-30 20:20 编辑

【版权声明】转载请注明作者为东方石,卡饭论坛原帖地址http://bbs.kafan.cn/thread-1702745-1-1.html


美国安软Malwarebytes从2014年4月底改授权为1年期,MBAM终身版停止发售,将成绝版。


以上支持支付宝付款,结算价格约126元人民币,我有幸搭上末班车购买到lifetime/1PC版。

MBAM有免费扫描版,收费版带监控,暂无官方简中版,论坛有汉化文件,破解情况未明。

在此以大家最为关心的五个问题为主线,收集、摘引官方文档及其它英文资料并整合如下:

1. Does Malwarebytes Anti-Malware replace antivirus software?
Malwarebytes Anti-Malware is not meant to be a replacement for antivirus software. Malwarebytes Anti-Malware is a complementary but essential program which detects and removes zero-day malware and "Malware in the Wild". This includes malicious programs and files, such as virus droppers, worms, trojans, rootkits, dialers, spyware, and rogue applications that many antivirus programs do not detect or cannot fully remove. That being said, there are many infections that Malwarebytes Anti-Malware does not detect or remove which any antivirus software will, such as file infectors. It is important to note that Malwarebytes Anti-Malware works well and should run alongside antivirus software without conflicts. In some rare instances, exclusions may need to be set for your specific antivirus product to achieve the best possible system performance.

MBAM does not target script files. That means MBAM will not target JS, HTML, VBS, BAT, CMD, PDF, PHP, etc. It also does not target documents such as; DOC, DOCx, XLS, XLSx, PPT, PPS, ODF, etc. As an adjunct anti malware solution, MBAM leaves that to the traditional anti virus application to deal with.

Until MBAM, v1.75 MBAM could not access files in archives but with v1.75 came that ability so it can unarchive a Java Jar (which is a PKZip file) but it won't target the .CLASS files within. Same goes with CHM files (which is a PKZip file) but it doesn't target the HTML files within. MBAM v1.75 specifically will deal with; ZIP, RAR, 7z, CAB and MSI for archives. And self-Extracting; ZIP, 7z, RAR and NSIS executables (aka; SFX files).

MBAM specifically targets binaries that start with the first two characters being; MZ. They can be; EXE, CPL, SYS, DLL, SCR and OCX. Any of these files type can be renamed to be anything from TXT, JPG, CMD and BAT and they will still be targeted just as long as the binary starts with 'MZ'.

Today's cyber criminals build software designed to slip past antivirus programs undetected. Malwarebytes Anti-Malware Premium crushes these threats with innovative technologies designed to defend you while keeping your online experience fast and hassle free.

2. Why is Malwarebytes now charging an annual license fee for its products?
As more and more people have come to rely on us for malware protection and cleanup, our costs in bandwidth, hosting fees, infrastructure, salaries of our researchers, QA department, and more have grown immensely. Though our company is about more than just making money, we are a company and we do have to make money to pay our staff to continue doing what they love, which is fight malware. The subscription model will help us to be sustainable for the future while staying true to our roots that we will always make malware cleanup free for everyone (in our free version).

3. I have a lifetime license, am I still covered?
If you previously purchased Malwarebytes Anti-Malware PRO, Malwarebytes will continue to honor your lifetime license for 2.0 and beyond. Your update to Malwarebytes Anti-Malware Premium is free. You will be able to transfer your lifetime license to a newer computer whenever you decide to upgrade or if you reformat your computer, but lifetime licenses are not transferable between users.

4. How many computers may I install a license on?
Malwarebytes actively enforces a one license-key & ID per computer policy. The reason behind this is that we offer a one time payment of lifetime licenses which include our Real Time Protection Module, IP Protection, scheduled updates and scans as well as software upgrades. However, we do offer discounts at the point of sale when you purchase multiple copies. Licenses are transferable from old machines to new ones.

5. Can I install the license on a system with multiple operating systems on it?
The Malwarebytes Anti-Malware consumer version license applies to physical systems. If you have multiple operating systems installed on your personal computer or laptop, you may use the same license on each operating system installed on the same physical system.

简要翻译并概括如下:

1、MBAM定位辅杀,不查病毒,专治木马,专防漏洞,应与传统杀软并用。

2、改变授权收费方式是因业务急剧扩张,公司运转需要更好的资金保障。

3、终身版授权支持最新2.0版及今后新版本的更新激活使用,永不过期。

4、1PC授权限用于一台电脑,但不绑定硬件,转移授权需先卸载再新装。

5、电脑数以硬件计而非OS,1PC授权可支持同一硬盘上的多系统同时使用。




本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 6人气 +6 收起 理由
rufeng + 1 加油!东方石
binkwong + 1 精品文章
HEMM + 1 版区有你更精彩: )
aiping + 1 版区有你更精彩: )
驭龙 + 1 版区有你更精彩: )

查看全部评分

东方石
 楼主| 发表于 2014-3-30 13:24:58 | 显示全部楼层
zandalong 发表于 2014-3-30 12:49
这货可有监控?有监控为什么会和杀软没有冲突?

请看以下这段:
1. Does Malwarebytes Anti-Malware replace antivirus software?
Malwarebytes Anti-Malware is not meant to be a replacement for antivirus software. Malwarebytes Anti-Malware is a complementary but essential program which detects and removes zero-day malware and "Malware in the Wild". This includes malicious programs and files, such as virus droppers, worms, trojans, rootkits, dialers, spyware, and rogue applications that many antivirus programs do not detect or cannot fully remove. That being said, there are many infections that Malwarebytes Anti-Malware does not detect or remove which any antivirus software will, such as file infectors. It is important to note that Malwarebytes Anti-Malware works well and should run alongside antivirus software without conflicts. In some rare instances, exclusions may need to be set for your specific antivirus product to achieve the best possible system performance.

MBAM does not target script files. That means MBAM will not target JS, HTML, VBS, BAT, CMD, PDF, PHP, etc.
It also does not target documents such as; DOC, DOCx, XLS, XLSx, PPT, PPS, ODF, etc. As an adjunct anti malware solution, MBAM leaves that to the traditional anti virus application to deal with.

Until MBAM, v1.75 MBAM could not access files in archives but with v1.75 came that ability so it can unarchive a Java Jar (which is a PKZip file) but it won't target the .CLASS files within. Same goes with CHM files (which is a PKZip file) but it doesn't target the HTML files within. MBAM v1.75 specifically will deal with; ZIP, RAR, 7z, CAB and MSI for archives. And self-Extracting; ZIP, 7z, RAR and NSIS executables (aka; SFX files).

MBAM specifically targets binaries that start with the first two characters being; MZ
They can be; EXE, CPL, SYS, DLL, SCR and OCX. Any of these files type can be renamed to be anything from TXT, JPG, CMD and BAT and they will still be targeted just as long as the binary starts with 'MZ'.

Today's cyber criminals build software designed to slip past antivirus programs undetected. Malwarebytes Anti-Malware Premium crushes these threats with innovative technologies designed to defend you while keeping your online experience fast and hassle free.

也就是说,MBAM是专门且只扫描和监控传统杀软所不查杀或不擅长的那部分危害文件,例如木马,而感染性病毒这类传统杀软所擅长的领域,MBAM是不参与的,这也就是为什么有人说MBAM查杀很高、有人说这货查杀巨低的原因,如果样本包都是传统感染性病毒(例如针对DOC和PDF的宏病毒),那么MBAM的查杀率几乎为零,但只要样本包都是木马(例如fakeAV等),那么MBAM的查杀就高的吓人。也就是以上的差别领域查杀设计,使得MBAM在开启监控(免费版只有扫描功能,收费版可实时监控)时,也可以和其他传统杀软的监控并行,而且根据官方的意思,也不光是可以,更是应该和推荐。当然,在某些情况下,也是需要一定排除设置的。
东方石
 楼主| 发表于 2014-4-1 22:04:09 | 显示全部楼层
zandalong 发表于 2014-4-1 21:44
今天试用了下,但有几个问题。
1.Malwarebytes Anti-Malware有本地监控,按你所说,因为它所监控的东 ...
官方这段话说得蛮清楚了:Malwarebytes Anti-Malware is a complementary but essential program which detects and removes zero-day malware and "Malware in the Wild". This includes malicious programs and files, such as virus droppers, worms, trojans, rootkits, dialers, spyware, and rogue applications that many antivirus programs do not detect or cannot fully remove. That being said, there are many infections that Malwarebytes Anti-Malware does not detect or remove which any antivirus software will, such as file infectors. It is important to note that Malwarebytes Anti-Malware works well and should run alongside antivirus software without conflicts. In some rare instances, exclusions may need to be set for your specific antivirus product to achieve the best possible system performance. 关于怎么做到的,下面这段可以参考:
MBAM does not target script files. That means MBAM will not target JS, HTML, VBS, BAT, CMD, PDF, PHP, etc. It also does not target documents such as; DOC, DOCx, XLS, XLSx, PPT, PPS, ODF, etc. As an adjunct anti malware solution, MBAM leaves that to the traditional anti virus application to deal with. Until MBAM, v1.75 MBAM could not access files in archives but with v1.75 came that ability so it can unarchive a Java Jar (which is a PKZip file) but it won't target the .CLASS files within. Same goes with CHM files (which is a PKZip file) but it doesn't target the HTML files within. MBAM v1.75 specifically will deal with; ZIP, RAR, 7z, CAB and MSI for archives. And self-Extracting; ZIP, 7z, RAR and NSIS executables (aka; SFX files). MBAM specifically targets binaries that start with the first two characters being; MZ. They can be; EXE, CPL, SYS, DLL, SCR and OCX. Any of these files type can be renamed to be anything from TXT, JPG, CMD and BAT and they will still be targeted just as long as the binary starts with 'MZ'.
概括的说,就是根据文件类型来区分,如果危害文件隐藏了真实文件类型,MBAM也会通过二进制代码的开头来辨别出来。事实上,现在传统杀软也大都可以查杀木马等威胁的,不过一方面没有MBAM擅长,毕竟后者是专门做这个的,比如很多杀软查了杀不掉,MBAM就可以清除掉,但这不是最重要的,重要的是另一方面,从样本区的实际体验可以发现,很多其他杀软不报的木马,特别是网马和fakeAV之类的,MBAM都报了,而且不是误报,例如我看到过很多次几乎所有其他杀软扫出来都是干净文件,但MBAM先报了,过了一段时间后,其他杀软才入库,说明MBAM在查杀引擎上肯定有独到的技术的,只不过不为我们熟知而已。

评分

参与人数 1经验 +5 收起 理由
zandalong + 5 版区有你更精彩: )

查看全部评分

东方石
 楼主| 发表于 2014-4-4 10:35:41 | 显示全部楼层
本帖最后由 东方石 于 2014-4-4 10:41 编辑
zandalong 发表于 2014-3-30 12:49
这货可有监控?有监控为什么会和杀软没有冲突?

今天又找到了一份Malwarebytes官方在2013年5月发布的兼容列表,需要指出的是,开头那段英文说明的意思是:
MBAM兼容绝大多数其它杀软,列表仅为经官方实机测试的,并不意味着不在列表中的杀软就不兼容。截图如下:


完整文档见附件:

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +5 收起 理由
zandalong + 5 感谢解答: )

查看全部评分

东方石
 楼主| 发表于 2014-8-15 19:52:44 | 显示全部楼层
【序列号找回渠道】通过本帖提供的cleverbridge销售平台购买MBAM后,如若发生误删注册邮件等误操作致使授权信息丢失的情况,可以通过https://www.cleverbridge.com/?scope=ccinfo找回key,只要在该页面中输入购买当时所填的注册邮箱即可,事实上,通过cleverbridge网站购买的任何软件,其序列号找回都可以通过该网页实现。
kerlee
发表于 2014-3-28 21:28:56 | 显示全部楼层
好像记得这货挺犀利的
yaoogle007
发表于 2014-3-28 21:36:26 | 显示全部楼层
你又买了个了?我要是买了就没那么多电脑装了。。。。
东方石
 楼主| 发表于 2014-3-28 21:39:04 | 显示全部楼层
yaoogle007 发表于 2014-3-28 21:36
你又买了个了?我要是买了就没那么多电脑装了。。。。

这货专注做传统杀软不做的事,而且没有主防,兼容性很好,可以完美搭配任何安软和任意组合,算是给自己多一种选择

评分

参与人数 1经验 +5 收起 理由
zandalong + 5 感谢解答: )

查看全部评分

Dust-;羅錠
发表于 2014-3-28 21:39:25 | 显示全部楼层
本帖最后由 Dust-;羅錠 于 2014-3-28 23:56 编辑

我试了一下高级版,不得不说,这东西在windows 8.1下很卡啊,时不时就卡住了,特别是点击右键扫描,它没有扫描程序,要到主界面扫描,每次扫描都要卡上几秒钟,还有打开自我防护也要卡上一会。

网页防护误报太犀利了,QQ,QQ音乐的外连ip都被拦截了。查杀实在不怎么样。

终上所述,不知道有没有windows 8.1的原因,反正就是很糟糕啊,查杀不高就算了,但主要是很卡,这点受不了。

评分

参与人数 1经验 +5 收起 理由
zandalong + 5 感谢支持,欢迎常来: )

查看全部评分

Miostartos
发表于 2014-3-28 21:41:58 | 显示全部楼层
Dust-;羅錠 发表于 2014-3-28 21:39
我试了一下高级版,不得不说,这东西在windows 8.1下很卡啊,时不时就卡住了,特别是点击右键扫描,它没有 ...

这玩意扫描一直都这样
要卡一卡的
FREE也是
算老毛病了吧。。貌似是因为每次扫描都要先扫描内存的原因
东方石
 楼主| 发表于 2014-3-28 21:42:05 | 显示全部楼层
Dust-;羅錠 发表于 2014-3-28 21:39
我试了一下高级版,不得不说,这东西在windows 8.1下很卡啊,时不时就卡住了,特别是点击右键扫描,它没有 ...

我这边还好,占用挺小的,蛮流畅的,查杀的话,请留意主楼中关于第一个问题给出的资料,因为MBAM是不扫描不监控传统杀软的查杀对象的,所以这样的比较没有意义,这个是专注做辅杀的,也是最近几年北美最流行的一款辅助安软
Dust-;羅錠
发表于 2014-3-28 21:52:00 | 显示全部楼层
东方石 发表于 2014-3-28 21:42
我这边还好,占用挺小的,蛮流畅的,查杀的话,请留意主楼中关于第一个问题给出的资料,因为MBAM是不扫描 ...

可惜了,我还对它成为真正杀软抱有期望的,毕竟我用Dr.Web,我试了一下,Dr.Web预防性保护会在它处理病毒的时候拦截,虽然预防性保护除了有规则的前两项,其他算是鸡肋。

我也买了一份,纯粹是看见是终生的忍不住,比如OSS我也买了...不过现在试了2.0也是有点不值,看看以后能不卡就好了。

我最喜欢Dr.Web,就是喜欢它的命名和修复,入库命名很正确,不像BD等其他杀软,虽然入库快,但是命名就是基本上随便写了,而且现在Dr.Web上报的话输入序列号,分析入库速度已经很快了,基本上当天就可以回复,再不济第二天也可以了,所以我是越来越喜欢它了。今天一冲动买了Malwarebytes Anti-Malware,和以前的OP,看来都要存起来了。
Miostartos
发表于 2014-3-28 21:54:04 | 显示全部楼层
现在正在严重纠结到底买还是不买。。。手上没什么余粮
勇者无敌
头像被屏蔽
发表于 2014-3-28 21:58:41 | 显示全部楼层
Dust-;羅錠 发表于 2014-3-28 21:52
可惜了,我还对它成为真正杀软抱有期望的,毕竟我用Dr.Web,我试了一下,Dr.Web预防性保护会在它处理病毒 ...

OP可以不存起来啊,和蜘蛛一起用,俄系双剑合璧,我也喜欢蜘蛛,但和我喜欢的ZAP冲突导致网速很慢
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-7-8 18:50 , Processed in 0.149788 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表