查看: 5948|回复: 27
收起左侧

[技术原创] Hitman Pro之云的初体验(*^__^*)

[复制链接]
悠柚
发表于 2009-7-25 14:00:42 | 显示全部楼层 |阅读模式
首先是官方的介绍

Hitman Pro 3 - the all-in-one tool against malicioussoftware


Hitman Pro 3 is a fast all-in-one tool to locate, identify and removeviruses, spyware, trojans, rootkits and other malware. Hitman Pro 3 willquickly show if your PC is infected with malicious software.
Research shows that many computers are infected,even if they have an up-to-date security suite installed, and that acombination of different anti malware programs would be required to preventinfection.
Hitman Pro 3 uses innovative cloud computing techniques to detect and removepotential malware threats with minimal impact on system performance.


Advantages of Hitman Pro 3


  • Recognizes     and removes viruses, trojans, rootkits, spyware and other malware.
  • Revolutionary     innovation in scanning technique to distinguish between malicious and safe     software without signatures.
  • Short scan     time - searches the system within a few minutes.
  • No extra     system load.
  • Impossible to     make false positives on important systems files thanks to     "profiling" and whitelisting.
  • Multi-vendor     identification of malware in our real-time "Scan Cloud".
  • Automatically     restores common system alterations made by malicious software.
  • Creates a check     point in System Restore before removing malicious software.
  • Removes     resistant threats using native NT boot-time deleter.
  • Removes     references to malicious software (like shortcuts and registry entries).
  • Free malware     scan.
  • Free online     support in English, German and Dutch.

How does Hitman Pro 3 work?



The Hitman Pro 3 executable can be downloaded and run straight from a USBFlash Drive, CD/DVD, local or network attached hard drive and will quicklyreveal the presence of any malware.
It will scan your PC in a few minutes and detect files that are potentiallymalware using a Behavioral Scan.
The actual identification of these potential malware files is then done on theHitman Pro servers - the "Scan Cloud".

To understand how Hitman Pro 3 works we first need to describe a fewfundamental characteristics of malicious software and your Windows PC.

Like everything else, malicious software always has a purpose. The malwarewriter only wants one thing: money. The traditional virus that cripples ordestroys your PC is now quite rare. To make money the virus needs to be run andstay resident on the PC. This way the malicious software can steal yourpersonal data, show pop-ups, or install fake software programs. The softwarecan even turn your PC into a zombie as part of a botnet, using your PC to sendspam or be part of a cyber attack. Of course, all this is going on without younoticing anything. To keep doing this, the malicious software needs to startautomatically and protect itself from being removed by security software.

  
On a single Windows PC there are thousands of files with a limited  number of these files being "executables" and "associated data  files", which have file extensions like EXE, DLL, SYS, etc. They belong  to for example a word processor, a spreadsheet program or a photo editing  program.
  To work properly, the malicious program must be an executable file.
  
  Hitman Pro 3 looks for executables like drivers and other automatically  starting software programs. These are active in memory, communicate with the  internet and potentially try to make themselves invisible. From an average of  400,000 files on your PC typically only 2000 are interesting enough for  Hitman Pro 3 to classify. Hitman tries to determine:

  
  • where a       file comes from
  • how it got       on your PC
  • which       publisher created it
  • what       purpose it has
  • whether it       can be uninstalled appropriately
  • if it is       visible for the user and through Windows API's
  • if it's       communicating with unreliable computers on the internet
  • if it's       compressed or encrypted
  • if it has       anomalies commonly found in malicious software
  • what people       say about the file on security related websites
  
These are just a few of the details that Hitman Pro 3 collects,  understands and associates. This method is what we call the Behavioral Scan.

  
Hitman Pro 3 uses as manycharacteristics of safe and malicious software as possible. After classifyingonly a handful remain interesting enough for further investigation. Each fileis fingerprinted and sent to our Scan Cloud. This cloud determines if a file issafe, unsafe or unknown.
Unknown files on your PC are physically sent to the Scan Cloud where the filesare scanned, in just seconds, by trusted anti-malware software from our trustedpartners.
Purpose
Hitman Pro 3 does not leave a program running in the backgroundthat continuously checks incoming e-mail and downloaded files for malware.Therefore you need to scan your PC regularly to ensure your PC is not infected.
Hitman Pro 3 can be used in combination with any other security suite. Scanningyour PC for malware with Hitman Pro 3 will always be free so if you alreadyhave a security suite on your PC, it is an ideal program to make sure yoursecurity suite has not missed anything.
Behavioral Scan
The Behavioral Scan in Hitman Pro 3 does not need to monitoryour system constantly to discover suspicious behavior. Most behavioralblocking programs need to monitor continuously. Hitman Pro 3 uses the knowledgefrom multiple anti-malware partners to identify the files on your system, whichmakes it exceptionally usable for non-technical computer users, who cannotanswer incoherent questions about for example new system services or registryentries. In addition, Hitman Pro 3 knows upfront which files are notinteresting and which belong to the operating system. This is done by checkingthe (valid) digital signatures on executable files and a white list containingsignatures of known safe files. Hitman Pro 3 has signatures of all importantfiles from Windows 2000 to Windows 7 (RC). After a quick check, these files areautomatically detected as safe.

云扫描很流行的东西,基于行为分析的扫描TForMamutu
体验开始!

[ 本帖最后由 悠柚 于 2009-7-25 14:50 编辑 ]

评分

参与人数 1经验 +33 收起 理由
一凡 + 33 熟悉的记忆啊,版区有你更精彩。虽然是一款

查看全部评分

悠柚
 楼主| 发表于 2009-7-25 14:34:28 | 显示全部楼层
首先是安装包的模样还算漂亮吧
ok,双击运行,主界面(不用安装,很绿色就是在C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe新建了一个备份,以便下次扫描

那几个引擎很让人遐想连篇帅锅也还算养眼
点击setting,可以修改设置
自动上传可疑文件进行云扫描,这个是重点
不过不是免费的,30天试用,please click“License Information”
选择“Active free license”

设置完后,点击“Next”
接受协议
当然选择接受
直接扫描,貌似是全盘

上传到云服务器
1mb小水管,速度还行,扫描速度很快(基于云的关系?)

不知怎么的两个上传失败
把vdisk的上传工具报成了可疑,不过提示不会删除
直接出现界面倒计时10秒
还扫了6个trace,界面没显示啊
5个引擎,啊不算上G Data的两个,a2的两个,应该是7个引擎,一个毒也没扫出来(可能是我的电脑比较干净
随手找了样本区的一个毒,eset可以检测出来,由于不能自定义扫描,只能再来一次,我把样本放到了system32下面,这个貌似会被扫描到,看看效果

[ 本帖最后由 悠柚 于 2009-7-25 14:52 编辑 ]
悠柚
 楼主| 发表于 2009-7-25 14:39:14 | 显示全部楼层
扫到了,正在上传
不过最后被prevx扫出来了
不管了,也算检测成功了

点评:完全基于云的扫描器,网速过慢可能会效果打折,不过感觉还行,大家可以用用,体验一下真正的“云”的实力
附上下载地址(支持win7哦!
http://files.surfright.nl/HitmanPro35.exe 32bit
http://files.surfright.nl/HitmanPro35_x64.exe 64bit
程序不大,推荐用迅雷下载(因为我用dta下载了几次都失败了,换迅雷一切正常

[ 本帖最后由 悠柚 于 2009-7-25 14:46 编辑 ]

评分

参与人数 1人气 +1 收起 理由
danny007 + 1 辛苦辛苦。。那么多引擎= =

查看全部评分

悠柚
 楼主| 发表于 2009-7-25 14:42:22 | 显示全部楼层
截图好累
alexchen2008
发表于 2009-7-25 14:45:14 | 显示全部楼层
辛苦了,前排支持一下。

人气恢复了给你加人气。

[ 本帖最后由 alexchen2008 于 2009-7-25 14:47 编辑 ]
Evighet
发表于 2009-7-25 14:50:06 | 显示全部楼层
前排围观~
人民
发表于 2009-7-25 14:56:01 | 显示全部楼层
只为看一下我的下载速度

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
luxiao200888
发表于 2009-7-25 14:58:54 | 显示全部楼层
云扫描快?!

至少panda不快
悠柚
 楼主| 发表于 2009-7-25 15:01:41 | 显示全部楼层

回复 8楼 luxiao200888 的帖子

还是很快的,第一次扫描9m,第二次就只有3m了 ,看来有记忆功能
fengtaks
发表于 2009-7-25 15:10:15 | 显示全部楼层

回复 1楼 悠柚 的帖子

这个貌似只能“全盘云”,以前装过,安装后自扫,选择跳过就会一直提示可能存在威胁,呵呵,来自荷兰的“一抹橙”啊~
不过我相对于现在的桌面图标,还是喜欢以前的那个“快递工”



[ 本帖最后由 fengtaks 于 2009-7-25 15:12 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-18 04:48 , Processed in 0.136602 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表