作者blman (我爱亦洁我爱亦洁)
看板AntiVirus
标题Re: [问题] papago里面一个档案被卡巴侦测为病毒=.=a
时间Tue Oct 23 22:53:49 2007
目前所知 PAPAGO! R12 & R15 两个版本会被防毒软体判为木马或广告软体。
PAPAGO! R12 的 Advertise_PC.exe
PAPAGO! R15 的 Advertise_PC.exe
PAPAGO! R15 的 TMC_PC.exe
Advertise_PC.exe 是 PAPAGO! 的广告软体。
TMC_PC.exe 是气候与交通等的更新程式。
网路有网友将这两个档发布给小红伞(AntiVir)分析,回报如下:
File ID Filename Size (Byte) Result
1108589 TMC_PC.exe 6.5 KB MALWARE
1108588 Advertise_PC.exe 6.5 KB MALWARE
The file 'TMC_PC.exe' has been determined to be 'MALWARE'. Our analysts named
the threat ADSPY/AdAgent.K. The term "ADSPY/" denotes adware or spyware. This
type of malware is able to change browser settings for example by
manipulating registry settings or by using of NTFS-streams. Very often
IEexploits are used to manipulate the browserhelp.dll.Detection is added to
our virus definition file (VDF) starting with version 6.39.00.160. Please
note that Avira's proactive heuristic detection module AHeAD detected this
threat up front without the latest VDF update as: HEUR/Malware.
The file 'Advertise_PC.exe' has been determined to be 'MALWARE'. Our analysts
named the threat ADSPY/AdAgent.I. The term "ADSPY/" denotes adware or
spyware. This type of malware is able to change browser settings for example
by manipulating registry settings or by using of NTFS-streams. Very often
IEexploits are used to manipulate the browserhelp.dll.Detection is added to
our virus definition file (VDF) starting with version 6.39.00.160. Please
note that Avira's proactive heuristic detection module AHeAD detected this
threat up front without the latest VDF update as: HEUR/Malware.
简单来说,这两个程式的操作手法不合正义程序,就是偷偷摸摸的,
所以防毒软体公司才会这麽明确的要判定为恶意程式。
例如,Advertise_PC.exe 不经过你的同意,就偷偷下载以下档案到你的电脑里,
http://www.papago.com.tw/mapcenter/ad10.bmp
http://www.papago.com.tw/mapcenter/ad20.bmp
http://www.papago.com.tw/mapcenter/ad40.bmp
http://www.papago.com.tw/mapcenter/ad_list.htm
http://www.papago.com.tw/mapcenter/ad_data.htm
以及 Advertise_PC.pdb
而 TMC_PC.exe 也不经过你的同意,偷偷下载以下档案到你的电脑里,
http://www.papago.com.tw/mapcenter/roadmsg.htm
http://www.papago.com.tw/mapcenter/weather.htm
http://www.papago.com.tw/mapcenter/weather2.htm
以及 TMC_PC.pdb
解决方法?有两个
方法一,将防毒软体将此两个档案设定为例外,即扫瞄时跳过这两个档。
但意谓着你要承受这两个程式可能带来的风险。
方法二,删掉这两个档,但也意谓着你无法使用气候与交通等更新功能。
但砍掉时发现执行 PAPAGO! 会要求你重装系统?!
那麽就把桌面的捷径砍掉,并进到 C:\Program Files\Maction\PAPAGO! R??\ 底下,
直接执行 PaPaGOR??.exe 就可以了,要方便一点的话,就拖拉这个档到桌面当捷径。
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 218.167.59.202
1F:推 adila:好文章怎麽没人推? 10/24 18:45
2F:推 Seattle995:推上天 10/24 23:59
3F:推 Seattle995:把C槽的.exe固定到开始功能表是可以的,但重开机後,病 10/25 00:18
4F:→ Seattle995:毒警告又跳出来,这时我直接按"no action",就可以继续 10/25 00:18
5F:→ Seattle995:使用了,不像以前会再重新安装太麻烦了,防毒软体是 10/25 00:18
6F:→ Seattle995:AVAST home edition,给大家参考看看! 10/25 00:19
7F:推 serein1010:推~正在烦恼这个问题..感谢 12/18 20:44
8F:推 pdpd:好文~~ 04/04 11:19