查看: 9951|回复: 32
收起左侧

[原创] 终于搞定了臭名远扬的Lcass.exe了!!

[复制链接]
傻猪猪米走鸡
发表于 2007-5-31 22:03:16 | 显示全部楼层 |阅读模式
报了!报了!真的报了!终于报了……
D:\firefox下载的文件\桌面.rar ?RAR ?桌面\Lcass.exe - Win32/VB.AGS 木马
不知道大家有没有留意过这个被感染的文件——Lcass.exe。
很久很久以前就已经有了,当然也不是化石……只是上一年的事……

不知有多少人上报过这个了,可是今天才总算报了……
回顾一下,这是来自 lanvin  的帖子:

去打印了个东西带回来的宝贝



有3个旧的  1个比较新,过了好多

其中因为看到了 风野胤  的回复:

偶有些崩溃
那个很老的lcass
nod还是不报
我继续上报
我就不信了


于是我愤怒了,直接上去Wild sercuety论坛上面跟Marcos吵了起来,原帖如下(我就是Galaxykiss了):
Galaxykiss
Infrequent Poster
Join Date: Mar 2007
Posts: 2


Please check this sample.
this sample was packed by ASPack v2.12 .give me an inbox add so that I can sand it to u,Mr.Marcos!
In my opinion, ASPack v2.12 is always a weakpoint of nod32.Somehow,there are few samples, which packed by ASPack v2.12, can be check.What's more,only a little samples would add into the database.
It's no worst than no one responded the user's samples upload.Trust me truely, I was argueing with the rest of antivirus software users all the time.I say lots of advantages about nod32.But they can just stop me by one point, that's no one will give the users responding. I can stand that no one give me responding, but I can stand no matter how many times I sant virus samples to ESET and no one would be add in the database.
Sorry to say that ,but you'd better fix this weakpoint.

Marcos
Eset Moderator
Join Date: Nov 2002
Posts: 3,823


Re: Please check this sample.
We are not aware of any problems with ASPack 2.12. If you have some samples that you are positive they are functional, send them to samples[at]eset.com with this thread's url in its subject.


Marcos
Eset Moderator
Join Date: Nov 2002
Posts: 3,823


Re: Please check this sample.
The file you have sent us is actually packed with ASPack, but NOD32 does not have a problem with it at all.




一开始之后更新的两个病毒库都没有添加进去,还回复我的文件没问题,现在倒好,终于良心发现了。终于能查了。

下面是我发给他的短消息:

Marcos
Eset Moderator
Join Date: Nov 2002
Posts: 3,823


Re: I have sant the sample I mentioned yesterday.
Quote:
Originally Posted by Galaxykiss
hello,
have u recieve the sample , I did what u ask me to do.
the email subject with the url:http://www.wilderssecurity.com/showthread.php?t=176116
Hope u to reply me soon ,thanks a lot.



Hello,

I replied yesterday directly to that thread. No problem with that file were found that would prevent NOD32 for scanning the ASPacked file internally.


Marcos

一下是我打烂沙盘问到底(粤语方言)的回复:
Galaxykiss
Infrequent Poster
Join Date: Mar 2007
Posts: 2


Re: I have sant the sample I mentioned yesterday.
Quote:
Originally Posted by Marcos
Quote:
Originally Posted by Galaxykiss
hello,
have u recieve the sample , I did what u ask me to do.
the email subject with the url:http://www.wilderssecurity.com/showthread.php?t=176116
Hope u to reply me soon ,thanks a lot.



Hello,

I replied yesterday directly to that thread. No problem with that file were found that would prevent NOD32 for scanning the ASPacked file internally.


Marcos



hello,it's good to see your message.
What about the file itself?Was it infected any virus?
and Do u know a virus call Black-Day?It's a powerful virus but nod couldn't detected. Can I sent it to u?
thanks a lot.


现在大家感受到我的用心良苦吧……
现在看来,在怎么说到底,ESET还是会以用户为重的。所以我看到了曙光……
我现在附上样本,大家看看……

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +1 收起 理由
东海林将司 + 1 版区有你更精彩: )

查看全部评分

傻猪猪米走鸡
 楼主| 发表于 2007-5-31 22:04:56 | 显示全部楼层
沙发了,跟自己说自己辛苦了……
努力没有白费啊……
即使可能只能弥补冰山一角……
东海林将司
发表于 2007-5-31 22:14:01 | 显示全部楼层
赞一个
kfanty
发表于 2007-5-31 22:21:13 | 显示全部楼层
谢谢楼主,NOD有你更精彩!
风野胤
发表于 2007-5-31 22:23:18 | 显示全部楼层
的确是值得撒花的事情
我记得这个病毒已经很久了
现在在不断换邮箱上报那个末日阴影中
The EQs
发表于 2007-5-31 22:27:43 | 显示全部楼层
eset在对Auto病毒处理的很及时。。。基本上上报过后下次就会升级。。。。但是在很多老病毒上处理非常慢。。。。。
傻猪猪米走鸡
 楼主| 发表于 2007-5-31 22:31:41 | 显示全部楼层
eq你帮我报这个啦,我是报了很多次都不行的……
我知道这个你也报过……
密码:infected

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ljj
发表于 2007-5-31 22:50:26 | 显示全部楼层
跟着大大们沾光啊!
傻猪猪米走鸡
 楼主| 发表于 2007-5-31 23:02:05 | 显示全部楼层
我也正在学……
hlm444
发表于 2007-5-31 23:15:47 | 显示全部楼层
学习啊
学习  继续努力
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 08:32 , Processed in 0.118942 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表