查看: 2870|回复: 15
收起左侧

[一般话题] MS翻脸, 现在说:“我们很自豪我们的保护能力”

[复制链接]
jasonliul
头像被屏蔽
发表于 2013-10-11 17:52:26 | 显示全部楼层 |阅读模式
A couple of weeks ago, Holly Stewart, a senior program manager for Microsoft's Malware Protection Center, stated in an interview that the free Microsoft Security Essentials software tool it offers was designed to offer Windows PC users "baseline" protection against viruses and malware. The statement was treated by some PC users as an admission that Security Essentials was not good enough to stop malware threats.

Today, Microsoft decided to defend its malware policies via a new post on the Malware Protection Center blog. While the post did not mention the Microsoft Security Essentials interview, Dennis Batchelder, the partner group program manager for the company's Malware Protection Center, stated that it was "fully committed to protecting our consumer and business customers from malware."

Batchelder stated that in the past year the company has done a number of things to improve its malware-fighting features. He said, "We’ve developed early warning telemetry and faster signature delivery systems to respond to these threats." He also stated that Microsoft gets data from the owners of millions of PCs who have voluntarily provided access to their machines, which he says helps the center "identify and prioritize new malware files." Finally, Batchelder says the center has been sharing what it knows about malware threats with others in the industry.

Batchelder said that those efforts have helped to increase its malware protection results that have "less incorrect detections and less misses" by what he calls a "significant rate" between the last quarter of 2011 and the first half of 2013. He did not offer any specific numbers.

He closed his blog post by saying, "We are proud of the protection capabilities we provide for well over 150 million computers worldwide with our real-time antimalware products. We believe in Microsoft antimalware products and strongly recommend them to our customers, to our friends, and to our families."



原文
http://www.neowin.net/news/micro ... re-in-new-blog-post

评分

参与人数 1人气 +1 收起 理由
驭龙 + 1 感谢支持,欢迎常来: )

查看全部评分

墨家小子
发表于 2013-10-11 17:57:40 | 显示全部楼层
楼主你用mse不?你试试这个,运行它,然后你打开mse,看mse能不能删除它。记得虚拟机哦

样本地址:http://bbs.kafan.cn/thread-1579865-1-45.html

"We are proud of the protection capabilities we provide for well over 150 million computers worldwide with our real-time antimalware products. We believe in Microsoft antimalware products and strongly recommend them to our customers, to our friends, and to our families."
驭龙
发表于 2013-10-11 18:59:27 | 显示全部楼层
本帖最后由 驭龙 于 2013-10-11 19:12 编辑

兄弟,你这个不是原文,缺少很多内容,哈哈

http://bbs.kafan.cn/thread-1638578-1-1.html
驭龙
发表于 2013-10-11 18:59:51 | 显示全部楼层
本帖最后由 驭龙 于 2013-10-11 19:05 编辑
墨家小子 发表于 2013-10-11 17:57
楼主你用mse不?你试试这个,运行它,然后你打开mse,看mse能不能删除它。记得虚拟机哦

样本地址:http: ...


我来试这个样本。

@墨家小子  你的原帖被关闭,我发在这里吧

连动态签名服务和动态启发都没有出手,就被灭了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
墨家小子
发表于 2013-10-11 19:16:19 | 显示全部楼层
驭龙 发表于 2013-10-11 18:59
我来试这个样本。

@墨家小子  你的原帖被关闭,我发在这里吧

你解压出来,然后运行,模仿中毒环境之后,然后打开mse,是这样?
驭龙
发表于 2013-10-11 19:20:34 | 显示全部楼层
墨家小子 发表于 2013-10-11 19:16
你解压出来,然后运行,模仿中毒环境之后,然后打开mse,是这样?

解不了了,已经被特征码查杀,无法下载了,我现在在编辑帖子,呵呵,一会儿如果有时间,我虚拟机玩一下
墨家小子
发表于 2013-10-11 19:23:51 | 显示全部楼层
驭龙 发表于 2013-10-11 19:20
解不了了,已经被特征码查杀,无法下载了,我现在在编辑帖子,呵呵,一会儿如果有时间,我虚拟机玩一下

你先关闭mse,然后解压,然后双击,他就是建立启动项,隐藏解压文件夹,各种注入,运行之后,我才打开的mse,杀了一次又一次,杀不完
驭龙
发表于 2013-10-11 19:57:18 | 显示全部楼层
墨家小子 发表于 2013-10-11 19:23
你先关闭mse,然后解压,然后双击,他就是建立启动项,隐藏解压文件夹,各种注入,运行之后,我才打开的m ...


那我就不需要测了,问题在于MA不删除威胁的启动项,动态启发不删除样本本体,在样本有启动项的时候,必然是死循环,除非特征库完整更新,才能解决掉启动项和本体
驭龙
发表于 2013-10-11 20:19:21 | 显示全部楼层
墨家小子 发表于 2013-10-11 19:23
你先关闭mse,然后解压,然后双击,他就是建立启动项,隐藏解压文件夹,各种注入,运行之后,我才打开的m ...

@墨家小子  按照你的要求关闭实时监控,双击样本,之后开启实时监控,由于是已经完整入库,未见启动项残余,本体被特征码删除

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
墨家小子
发表于 2013-10-11 20:27:10 | 显示全部楼层
驭龙 发表于 2013-10-11 20:19
@墨家小子  按照你的要求关闭实时监控,双击样本,之后开启实时监控,由于是已经完整入库,未见启动项残余 ...

我的是九月六日的库,杀了一次又一次
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 11:55 , Processed in 0.138279 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表