作者SDUM (Roger)
看板AntiVirus
标题[心得] 有装ThreatFire的人,请多加一条规则
时间Fri Jun 25 18:48:26 2010
最近,在大陆流行一个感染型病毒,伪装成QVOD的安装档案。
执行之後,会删除系统服务的重要dll档案,并替换成病毒的dll档案。
ThreatFire 内置的行为库,无法拦截。
请多加一条规则。
advanced tools -> custom rules settings -> New
-----------------------------------------------------
Rule Name:窜改 系统服务 的 重要dll档案
Rule Description:窜改 系统服务 的 重要dll档案
Rule:
When any process
tries to write or delete a file
named
appmgmts.dll
browser.dll
es.dll
framebuf.dll
mspmsnsv.dll
netman.dll
ntmssvc.dll
qmgr.dll
regsvc.dll
schedsvc.dll
ssdpsrv.dll
tapisrv.dll
upnphost.dll
xmlprov.dll
in C:\WINDOWS\system32
except when the source process is in the system process list
or the source process is in the trusted process list
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.114.222.131
1F:→ s109612044:请问这条规则comodo有没有... 06/26 00:04
2F:→ SDUM:COMODO 不需要 06/26 00:31