楼主: piratk
收起左侧

[技术原创] 【重新总结版】围巾(viking)前各大杀软的表现,亲测!

[复制链接]
piratk
头像被屏蔽
 楼主| 发表于 2007-4-26 21:46:29 | 显示全部楼层
原帖由 154161 于 2007-4-26 21:39 发表
我的红伞可以


你这图没有说明问题啊!!

还有啊……

到底norton能不能清除啊?

很想知道……
飞天法宝
发表于 2007-4-26 22:33:15 | 显示全部楼层
这个其实我感觉即使删除也误所谓了,只要能发现并处理掉就好,我们找没染毒的再下
buycard
发表于 2007-4-26 22:39:12 | 显示全部楼层
在论坛混了不少日子,90%的人不知道什么“杀毒”,以为删了就好了
The EQs
发表于 2007-4-26 22:45:27 | 显示全部楼层

fprot的说明。。。可以借鉴一下

You'll keep your promise do you?  

If you detect something in the first instance you don't have to clean it since your realtime monitor wouldn't allow to start it. I assume you understand that.

The problem is if you install a AV on an already infected system - there you have to clean of course. Or - and this is most likely the major case - if the AV updated virus signatures and detects *now* malware what it didn't before.

There are several different types of "cleaning". The most difficult is parasitic virus cleaning (depending on the virus type) and removing code-injecting trojans (for example code injection into winlogon.exe)

Normal "stupid" malware you can just terminate and delete. There's no "cleaning" needed except maybe a registry key.

Next problem is that some viruses (parasitic viruses, that means they attach their code to other existing "innocent" executables) corrupt files. Such files you cannot clean once they are corrupted. Most of the Vendors adding a ".DAM" (for damaged) for such virus samples. You can only delete such samples.

Next problem is spyware. Usually they add hell a lot of registry keys or change them. Most of the AV programs only restoring the settings when infected by widely known spyware. You can maybe use some generic registry fixer.

Another problem are heuristic detections. If you detect something via heuristic you might not know which registry key it creates. A simple trick helps there: Remember the executable name (for example WIN32X.EXE) and search the registry for autostarts with this name. If it exists then you can delete it. HOWEVER... Some Malware creates names similar to real applications. For instance the Quicktime Updater is a known victim of this. So you cannot just browse for registry keys in autostart. ( Example: Application X.EXE has a registry autostart and is NOT DETECTED. However, X.EXE loads QTUpdater.Exe and that is the malware file AND detected via Heuristic. If you delete now QTUpdater.EXE from the autostart you just deleted the REAL (non-malicious!) Updater for Quicktime. )
jpzy
发表于 2007-4-26 23:13:16 | 显示全部楼层
原帖由 154161 于 2007-4-26 21:39 发表
我的红伞可以

,报出来的病毒名就不是Viking,下面似乎也没有清除病毒的项目!
piratk
头像被屏蔽
 楼主| 发表于 2007-4-26 23:26:30 | 显示全部楼层
原帖由 飞天法宝 于 2007-4-26 22:33 发表
这个其实我感觉即使删除也误所谓了,只要能发现并处理掉就好,我们找没染毒的再下


错错错……

有的文件再也无法下载怎么办?

感染了就删除?大错特错……
jushua
发表于 2007-4-27 04:30:05 | 显示全部楼层
norton NIS 2007可以修复,很自动化,有些用户可能不会留意。修复后文件减少了几十k. 不想提供截图,浪费时间。
不要那么没信任感。
xiaop000
发表于 2007-4-27 08:20:20 | 显示全部楼层
不能修复是很郁闷的,一旦中毒跟没杀软差不多,文件都给删了,一样都得重装
windlau78
头像被屏蔽
发表于 2007-4-27 08:52:18 | 显示全部楼层
原帖由 154161 于 2007-4-26 21:39 发表
我的红伞可以

红伞基本上不具备修复功能,一般都是删掉。
smty
发表于 2007-4-27 09:22:10 | 显示全部楼层
NOD32可以清除“部分”变种的维金和熊猫感染的文件,过去曾经给别人清除过,当时的维金变种好像是.ch,.j看来还是不能清除。
感觉卡巴斯基的清除能力比较强,红伞能够清除病毒的情况,目前还没遇到过。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-13 23:15 , Processed in 0.097091 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表