查看: 2187|回复: 6
收起左侧

[讨论] 一次上报样本给迈克菲的经历

[复制链接]
wangyuhe
发表于 2018-4-28 12:21:38 | 显示全部楼层 |阅读模式
昨天在样本区发现迈克菲miss pony,pony2两个样本,遂上传。昨天晚上9.30上传,今天凌晨2.00收到回信,好像是给了解决方法,让我手动添加到本地病毒库里(邮箱附件),然后说准备更新入库。不过今天中午升级依旧不能查杀,看来入库还是慢,比不上ESET,卡巴,不过官方的态度还是蛮不错的,写了很多,客服态度也很好。
McAfee Labs Sample Analysis,

ID Number:  10589066   Identified: Generic.TRA

Synopsis:

Thank you for submitting your suspicious file(s) for analysis. Attached is an EXTRA.DAT file for extra detection.

Solution:

The attached EXTRA.DAT file will detect the following submitted files:

Filename            MD5 digest                                                      
--------            ----------                                                      
pony2.exe           058bf1e8af9fc7cd82505d497fe65ebd                                 
pony.exe            233f9fd4175c6f3428956ba2599075e7                                 

The EXTRA.DAT file should be copied into the directory where the other DAT files reside (ex: C:\Program Files\Common Files\McAfee\Engine).
Additional information, including steps to deploy EXTRA.DAT files, is available in the following location:
  

Support:

McAfee Labs accepts file samples for analysis and possible inclusion into AV signature DAT updates.
Additional information for submitting samples to McAfee is available in the following location:


Product related questions and comments can be addressed via Technical Support and Customer Services, including:
* Assistance with detection and cleaning or removal of malware
* Product installation and update questions
* Product usage questions

Please use the following links to reach our Technical Support group:
Business Customers:

Home Customers:


Regards,
McAfee Labs: McAfee Labs

McAfee Labs:

McAfee Labs Blog:


*Disclaimer*
McAfee Labs researchers subject EXTRA.DAT files to a careful automatic test suite to verify their detection, and in order to reduce the possibility of "false alarm" detections or other issues and to improve their overall reliability. Note, however, that the McAfee Quality Assurance team has NOT tested or approved these files for release. McAfee makes no warranty that these files will be free from errors or other interruptions or that they will meet your requirements. To the maximum extent permitted by applicable law, MCAFEE DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT WITH RESPECT TO THESE FILES.  Some states and jurisdictions do not allow limitations on implied warranties, so the above limitation may not apply to you. The foregoing provisions shall be enforceable to the maximum extent permitted by applicable law.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
马云波波波 + 1 赞一个!

查看全部评分

飞碟1234
头像被屏蔽
发表于 2018-4-28 13:32:47 | 显示全部楼层
这算是官方的惯例,先给你一个extra.dat,手动添加,这样救急使,然后等官方入库更新。就可以根本解决问题。但是咖啡的入库流程实在是慢,没兴趣折腾了。
jone_jys
头像被屏蔽
发表于 2018-4-28 16:03:42 | 显示全部楼层
大公司流程多,通病。
这样的好处是处理比较完善,但是效率太低了。

下面提到的误报,我连续上报好几封邮件才解除。
https://bbs.kafan.cn/forum.php?m ... ;extra=#pid41854667
wangyuhe
 楼主| 发表于 2018-4-28 16:26:23 | 显示全部楼层
欧阳宣
头像被屏蔽
发表于 2018-4-30 22:22:22 | 显示全部楼层
这件事两三年前我天天要重复四五次,绝大部分情况下没有什么后续
kxmp
发表于 2018-4-30 22:51:40 | 显示全部楼层
然后入库了之后你才发现其实只是普通的hash拉黑
wangyuhe
 楼主| 发表于 2018-5-1 07:50:10 来自手机 | 显示全部楼层
好吧ヽ(  ̄д ̄;)ノ
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-25 16:48 , Processed in 0.144065 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表