查看: 5867|回复: 7
收起左侧

[砖头] 反驳红伞报HEUR/Crypted 和HEUR/Malware不是报壳的说法

[复制链接]
The EQs
发表于 2007-3-8 23:38:41 | 显示全部楼层 |阅读模式
声明:此帖只是讨论技术,而不是口水贴

记得以前有很多人说过红伞是见壳就报的,自己也不相信,不过在经历了红伞这么多误报之后,不得不相信这句话。。。就拿以前的一个例子来说,GB论坛换服务器的时候,升级了一个新版本,然后升级后的GB升级文件被红伞用启发式报HEUR/Malware了,偶去多引擎页面扫了扫,只有红伞一个报,其余都未报,看了一下,上面写了加了ASPACK,还有一个例子就是红伞支持者之一的周X在样本区发的20层北斗的样本,按照正常的话,只要杀软能脱壳就能准确报出这个木马的名字,但是红伞呢?直接报HEUR/Crypted(大家自己可以查查crypted的具体意思是什么),另外nod32官方论坛的有个人是这样说的“Can't beat the package”。。。,大家也可以测试一下误报的东西都有没有加壳。。。
ohmyivan
发表于 2007-3-8 23:58:24 | 显示全部楼层
不关心,反正小红伞目前杀马杀毒最强,这就够了,懒得搞什么研究.
mofunzone
发表于 2007-3-9 00:02:20 | 显示全部楼层
就目前测试结果,只有skvp+北斗产生的crypted是加壳的原因,还有几个不常用的壳类似ntpacker,岁月加壳,木马帝国加壳的这几个有问题,已经联系雨伞了,剩下的crypted倒是没什么问题
不过就算报壳了,一般的软件也不会这么写吧
ly250094040
发表于 2007-3-9 00:41:46 | 显示全部楼层
此类帖子严禁口水和辱骂

违者直接思过
ly250094040
发表于 2007-3-9 00:43:15 | 显示全部楼层
这段时间这类帖子实在太乱了。。。。


打个预防针先
曲中求
发表于 2007-3-9 01:07:21 | 显示全部楼层
Description:
HEUR/Crypted


HEUR/Crypted is a heuristic detection routine designed to detect common malware characteristics. Avira AntiVir recognizes unknown malware proactively using its AHeAD technology. To achieve this, Avira performs innovative structural analyzing.

On the basis of the composition of a file, the sequence of significant code sequences or based on particular behavior patterns,
the heuristics can determine with a high probability whether it is dealing with a harmful or virulent file.

HEUR/Crypted in particular signals files that have a suspicious structure of the program. Usually such files are protected by encryption mechanisms and are often manipulated afterwards to hide the real functionality.

Please note that cracks or the cracked program files themselves as well as key generators are often modified with similar techniques. Therefore Avira AntiVir's AHeAD heuristics may detect such files as well. The user should keep in mind that trojans are often disguised as such software.


In the unlikely occurrence of a false positive we would kindly ask for your help, by sending the file to our virus lab.

A heuristic detection might be a false identification if one or more of the following are true:
- The program is in use for a very long time and is known to the user
- The program was installed by the user himself
- The program is from a trustworthy source


Please note that even old programs can get infected or replaced by malware without your knowledge. Besides that trustworthy sources might have become compromised themselves.

In order to enhance detection and reduce the rate of false positives we recommend that you send the file to our virus lab for further analysis.

[ 本帖最后由 曲中求 于 2007-3-9 01:10 编辑 ]
rs-z
发表于 2007-3-9 01:16:28 | 显示全部楼层

回复 #6 曲中求 的帖子

原來如此
jessonguo
发表于 2007-3-9 01:44:07 | 显示全部楼层
原帖由 曲中求 于 2007-3-9 01:07 发表
Description:
HEUR/Crypted


HEUR/Crypted is a heuristic detection routine designed to detect common malware characteristics. Avira AntiVir recognizes unknown malware proactively using its A ...


学习了 多谢曲版了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-9-20 06:12 , Processed in 0.121857 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表