<?xml version="1.0" encoding="GB2312"?>  
<rss version="2.0" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> 
  
<channel> 
<title><![CDATA[欢迎光临endurer@bokee]]></title> 
<link>http://endurer.bokee.com/index.html</link> 
<description><![CDATA[<table border=0><tr><td style="filter:Glow(color:yellow,stength:2,enabled=1);"><b style="font-size:20pt;color:purple;"> 
<nobr>共同关注我们的电脑和网络安全……</nobr><br/>读万卷书，行万里路……</b></td></tr></table>]]></description> 
<dc:language>zh-cn</dc:language> 
<dc:creator>endurer@163.com</dc:creator> 
<dc:date>2008-09-03T23:48:43Z</dc:date> 
<admin:generatorAgent rdf:resource="http://blog.bokee.com.com" /> 

<item> 
<title><![CDATA[BaiDu/百毒不死，害人不止]]></title> 
<link>http://endurer.bokee.com/6794653.html</link> 
<description><![CDATA[今天一同事说他的电脑关机时卡住了，请偶帮忙看看。 <br /><br />运行卡卡安全助手检查启动项，发现BHO有个BaiDu的东东，卸载~ <br /><br />问题解决~ <br /><br />估计是同事装什么软件时不小心给装上去了。 <br /><br />BaiDu这个LJ网站从问世开始就一直使用背后阴谋和流氓伎俩，先是XX搜霸和XX超级搜霸，在被网络协会评为十大流氓软件后，还是恶习不改，到处放百毒工具条（BaiduBar.Tool），为网马入侵用户电脑开后门~ <br /><br />BaiDu在US上市，是一家美资公司，帮美国人赚钱的，所以对它没有什么爱国热情可言~ <br /><br />只是<font style="FONT-SIZE: small; LINE-HEIGHT: 1.3em" color="#ff0000"><b><wbr />BaiDu不死，害人不止</b></font>~]]></description> 
<guid isPermaLink="false">6794653@http://endurer.bokee.com/</guid> 
<dc:subject>系统维护</dc:subject> 
<dc:date>2008-09-04T21:31:30Z</dc:date> 
</item> 
<item> 
<title><![CDATA[BaiDu/百毒不死，害人不止]]></title> 
<link>http://endurer.bokee.com/6794050.html</link> 
<description><![CDATA[<div>今天一同事说他的电脑关机时卡住了，请偶帮忙看看。 </div><div>&amp;shy;</div><div>运行卡卡安全助手检查启动项，发现BHO有个BaiDu的东东，卸载~ </div><div>&amp;shy;</div><div>问题解决~ </div><div>&amp;shy;</div><div>估计是同事装什么软件时不小心给装上去了。 </div><div>&amp;shy;</div><div>BaiDu这个LJ网站从问世开始就一直使用背后阴谋和流氓伎俩，先是XX搜霸和XX超级搜霸，在被网络协会评为十大流氓软件后，还是恶习不改，到处放百毒工具条（BaiduBar.Tool），为网马入侵用户电脑开后门~ </div><div>&amp;shy;</div><div>BaiDu在US上市，是一家美资公司，帮美国人赚钱的，所以对它没有什么爱国热情可言~ </div><div>&amp;shy;</div><div>只是<font color="#ff0000" size="3"><b>BaiDu不死，害人不止</b></font>~</div>]]></description> 
<guid isPermaLink="false">6794050@http://endurer.bokee.com/</guid> 
<dc:subject>系统维护</dc:subject> 
<dc:date>2008-09-03T23:48:42Z</dc:date> 
</item> 
<item> 
<title><![CDATA[s.exe,4f4.exe,8g4.dll,fh8.dll]]></title> 
<link>http://endurer.bokee.com/6793249.html</link> 
<description><![CDATA[<p>文件说明符 : C:\WINDOWS\system32\s.exe<br />属性 : A--R<br />数字签名:否<br />PE文件:是<br />语言 : 中文(中国)<br />文件版本 : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br />说明 : Windows Progman Group Converter<br />版权 : Copyright Zhongsou(C) 2005<br />产品版本 : 5.1.2600.2180<br />产品名称 : Microsoft(R) Windows(R) Operating System<br />公司名称 : Microsoft Corporation<br />内部名称 : GrpConv<br />创建时间 : 2008-8-8 12:9:38<br />修改时间 : 2008-7-26 9:48:34<br />大小 : 98304 字节 96.0 KB<br />MD5 : e989fd3e1b34e9beb26c6d9744143b5e<br />SHA1: BA27F06F5C76B7DD78D80414ADC9DC97E2647BC0<br />CRC32: 443ca0a9</p><div id="nombre">文件 s.exe 接收于 2008.09.02 07:56:02 (CET)</div><p><table id="tableado" style="DISPLAY: block" cellspacing="0" cellpadding="0" border="0"><tbody><tr><td>反病毒引擎</td><td>版本</td><td style="TEXT-ALIGN: center">最后更新</td><td>扫描结果</td></tr><tr><td>AhnLab-V3</td><td>2008.9.2.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>AntiVir</td><td>7.8.1.23</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Authentium</td><td>5.1.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Avast</td><td>4.8.1195.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>AVG</td><td>8.0.0.161</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>BitDefender</td><td>7.2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>CAT-QuickHeal</td><td>9.50</td><td style="TEXT-ALIGN: center">2008.08.29</td><td>-</td></tr><tr><td>ClamAV</td><td>0.93.1</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>DrWeb</td><td>4.44.0.09170</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eSafe</td><td>7.0.17.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eTrust-Vet</td><td>31.6.6062</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Ewido</td><td>4.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>F-Prot</td><td>4.4.4.56</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>F-Secure</td><td>7.60.13501.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Fortinet</td><td>3.14.0.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>GData</td><td>19</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Ikarus</td><td>T3.1.1.34.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.Jhee.V</td></tr><tr><td>K7AntiVirus</td><td>7.10.435</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>McAfee</td><td>5374</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Microsoft</td><td>1.3807</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan:Win32/Jhee.V</td></tr><tr><td>NOD32v2</td><td>3406</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Norman</td><td>5.80.02</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>PCTools</td><td>4.4.2.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Prevx1</td><td>V2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Malware Downloader</td></tr><tr><td>Rising</td><td>20.60.02.00</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Sophos</td><td>4.33.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Sunbelt</td><td>3.1.1592.1</td><td style="TEXT-ALIGN: center">2008.08.30</td><td>-</td></tr><tr><td>Symantec</td><td>10</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>TheHacker</td><td>6.3.0.8.069</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>TrendMicro</td><td>8.700.0.1004</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">TROJ_JHEE.BU</td></tr><tr><td>VBA32</td><td>3.12.8.4</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>ViRobot</td><td>2008.9.1.1359</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>VirusBuster</td><td>4.5.11.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Webwasher-Gateway</td><td>6.6.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr></tbody></table></p><p><table id="tablaInformacion" cellspacing="0" cellpadding="0" width="550" border="0"><tbody><tr><th>附加信息</th></tr><tr class=""><td>File size: 98304 bytes</td></tr><tr class="odd"><td>MD5...: e989fd3e1b34e9beb26c6d9744143b5e</td></tr><tr class=""><td>SHA1..: ba27f06f5c76b7dd78d80414adc9dc97e2647bc0</td></tr><tr class="odd"><td>SHA256: 106ab625564ca6909f70cc3e935530043046c5435275f642c48cdf66a2e02a68</td></tr><tr class=""><td>SHA512: be682cd2432cf677db5a1511f8626a2f898e12ec56bd0ca438ab4a38aa143bf1<br />717e21d0aab5f47121e39bfbc88a9dd8ea8c2b0a1dd6e9573c74880fdae52240</td></tr><tr class="odd"><td>PEiD..: Armadillo v1.71</td></tr><tr class=""><td>TrID..: File type identification<br />Win64 Executable Generic(59.6%)<br />Win32 Executable MS Visual C++ (generic) (26.2%)<br />Win32 Executable Generic (5.9%)<br />Win32 Dynamic Link Library (generic) (5.2%)<br />Generic Win/DOS Executable (1.3%)</td></tr><tr class="odd"><td>PEInfo: PE Structure information<br /><br />( base data )<br />entrypointaddress.: 0x40777e<br />timedatestamp.....: 0x488a8272 (Sat Jul 26 01:48:34 2008)<br />machinetype.......: 0x14c (I386)<br /><br />( 4 sections )<br />name viradd virsiz rawdsiz ntrpy md5<br />.text 0x1000 0xea15 0xf000 6.56 bc21b827dc08dc0a38b7f037cbacd830<br />.rdata 0x10000 0x20a0 0x3000 3.53 5d06b741269a1ab50e725000971ad5b4<br />.data 0x13000 0x5da8 0x4000 1.80 cf3cbe4050c51c06a50c399959f21f72<br />.rsrc 0x19000 0x3a8 0x1000 1.01 d4e889dabc877175e20b2ef2f4be76dd<br /><br />( 2 imports ) <br />&amp;gt; KERNEL32.dll: GetModuleHandleA, GetEnvironmentVariableA, SetStdHandle, IsBadCodePtr, IsBadReadPtr, ReadFile, Sleep, GetLastError, GetModuleFileNameA, GetShortPathNameA, CreateProcessA, CreateDirectoryA, LoadLibraryA, GetProcAddress, FreeLibrary, GetWindowsDirectoryA, GetVersionExA, CloseHandle, CreateToolhelp32Snapshot, Process32First, Process32Next, OpenProcess, MultiByteToWideChar, WideCharToMultiByte, RtlUnwind, RaiseException, GetCommandLineA, GetVersion, ExitProcess, HeapFree, HeapAlloc, HeapReAlloc, TerminateProcess, GetCurrentProcess, LCMapStringA, LCMapStringW, GetCPInfo, HeapSize, GetACP, GetOEMCP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, VirtualFree, WriteFile, VirtualAlloc, IsBadWritePtr, SetFilePointer, FlushFileBuffers, GetStringTypeA, GetStringTypeW<br />&amp;gt; ADVAPI32.dll: ControlService, RegQueryInfoKeyA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, DeleteService, StartServiceA, QueryServiceStatus, CreateServiceA, ChangeServiceConfig2A, RegCreateKeyA, RegSetValueExA, RegCloseKey, OpenSCManagerA, OpenServiceA, CloseServiceHandle, DeregisterEventSource, GetUserNameA, CreateProcessAsUserA, OpenProcessToken<br /><br />( 0 exports ) <br /></td></tr><tr class=""><td>Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=09D2F541009E3A18805B016D663C340007832D56</td></tr><tr class="odd"><td>ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=e989fd3e1b34e9beb26c6d9744143b5e</td></tr></tbody></table></p><p>文件说明符 : C:\WINDOWS\system32\4f4.exe<br />属性 : ---R<br />数字签名:否<br />PE文件:是<br />语言 : 中文(中国)<br />文件版本 : 7, 0, 6000, 381<br />说明 : Windows Update Automatic Updates<br />版权 : Copyright Zhongsou(C) 2005<br />产品版本 : 7, 0, 6000, 381<br />产品名称 : Microsoft(R) Windows(R) Operating System<br />公司名称 : Microsoft Corporation<br />内部名称 : wuauclt<br />创建时间 : 2008-8-14 19:39:15<br />修改时间 : 2008-8-18 9:23:23<br />大小 : 114688 字节 112.0 KB<br />MD5 : 7d9d179ed12d26eff1a7c5d2aadc1884<br />SHA1: 42608AD8247C89CD6C52697AF082FBCA213FA5CC<br />CRC32: c44ee596</p><div id="nombre">文件 4f4.exe 接收于 2008.09.02 07:51:50 (CET)</div><p><table id="tableado" style="DISPLAY: block" cellspacing="0" cellpadding="0" border="0"><tbody><tr><td>反病毒引擎</td><td>版本</td><td style="TEXT-ALIGN: center">最后更新</td><td>扫描结果</td></tr><tr><td>AhnLab-V3</td><td>2008.9.2.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>AntiVir</td><td>7.8.1.23</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Authentium</td><td>5.1.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Avast</td><td>4.8.1195.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Win32:Trojan-gen {Other}</td></tr><tr><td>AVG</td><td>8.0.0.161</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>BitDefender</td><td>7.2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Generic.667569</td></tr><tr><td>CAT-QuickHeal</td><td>9.50</td><td style="TEXT-ALIGN: center">2008.08.29</td><td>-</td></tr><tr><td>ClamAV</td><td>0.93.1</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>DrWeb</td><td>4.44.0.09170</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eSafe</td><td>7.0.17.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eTrust-Vet</td><td>31.6.6062</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Ewido</td><td>4.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>F-Prot</td><td>4.4.4.56</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>F-Secure</td><td>7.60.13501.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.BHO.gdt</td></tr><tr><td>Fortinet</td><td>3.14.0.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>GData</td><td>19</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.BHO.gdt</td></tr><tr><td>Ikarus</td><td>T3.1.1.34.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.Jhee.V</td></tr><tr><td>K7AntiVirus</td><td>7.10.435</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.BHO.gdt</td></tr><tr><td>McAfee</td><td>5374</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Microsoft</td><td>1.3807</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan:Win32/Jhee.V</td></tr><tr><td>NOD32v2</td><td>3406</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">a variant of Win32/BHO.NCY</td></tr><tr><td>Norman</td><td>5.80.02</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>PCTools</td><td>4.4.2.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Prevx1</td><td>V2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Malicious Software</td></tr><tr><td>Rising</td><td>20.60.02.00</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Trojan.Win32.BHO.fef</td></tr><tr><td>Sophos</td><td>4.33.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Sunbelt</td><td>3.1.1592.1</td><td style="TEXT-ALIGN: center">2008.08.30</td><td>-</td></tr><tr><td>Symantec</td><td>10</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>TheHacker</td><td>6.3.0.8.069</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>TrendMicro</td><td>8.700.0.1004</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>VBA32</td><td>3.12.8.4</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>ViRobot</td><td>2008.9.1.1359</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>VirusBuster</td><td>4.5.11.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Webwasher-Gateway</td><td>6.6.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr></tbody></table></p><p><table id="tablaInformacion" cellspacing="0" cellpadding="0" width="550" border="0"><tbody><tr><th>附加信息</th></tr><tr class=""><td>File size: 114688 bytes</td></tr><tr class="odd"><td>MD5...: 7d9d179ed12d26eff1a7c5d2aadc1884</td></tr><tr class=""><td>SHA1..: 42608ad8247c89cd6c52697af082fbca213fa5cc</td></tr><tr class="odd"><td>SHA256: 923b711004868c4b93fda6ded1c75b05097d0ad7901c18a3b9cf4fac21392c06</td></tr><tr class=""><td>SHA512: b7873b2bb3169c353aba5657da10e6685adf71bbfac998f330819ed01684757d<br />c829419cf9105695c7d4aac685a2127868e610e623bc9fba2f31d322dfb9aaff</td></tr><tr class="odd"><td>PEiD..: Armadillo v1.71</td></tr><tr class=""><td>TrID..: File type identification<br />Win64 Executable Generic (59.6%)<br />Win32 Executable MS Visual C++ (generic) (26.2%)<br />Win32 Executable Generic (5.9%)<br />Win32 Dynamic Link Library (generic) (5.2%)<br />Generic Win/DOS Executable (1.%)</td></tr><tr class="odd"><td>PEInfo: PE Structure information<br /><br />( base data )<br />entrypointaddress.: 0x40d7ce<br />timedatestamp.....: 0x48a8cf0b (Mon Aug 18 01:23:23 2008)<br />machinetype.......: 0x14c (I386)<br /><br />( 4 sections )<br />name viradd virsiz rawdsiz ntrpy md5<br />.text 0x1000 0x148a5 0x15000 6.58 9540ea1874c6abf2d0412723de0fd4ef<br />.rdata 0x16000 0x2636 0x3000 3.92 d3825aad0a09cace49691d3fb795bdfa<br />.data 0x19000 0x4068 0x2000 3.46 f23487b12d7926a9080d896434f01aac<br />.rsrc 0x1e000 0x420 0x1000 1.11 7e1601bbdaf4774922a6674fbd7eb714<br /><br />( 4 imports ) <br />&amp;gt; KERNEL32.dll: ReadFile, CreateFileA, DeviceIoControl, GetModuleHandleA, lstrlenA, MultiByteToWideChar, WideCharToMultiByte, LocalFree, SetEndOfFile, SetStdHandle, IsBadCodePtr, Sleep, GetLastError, GetModuleFileNameA, CreateDirectoryA, GetFileAttributesA, DeleteFileA, CreateProcessA, WaitForSingleObject, CloseHandle, SetFileAttributesA, CopyFileA, GetPrivateProfileStringA, LoadLibraryA, GetProcAddress, GetVersionExA, FreeLibrary, GetWindowsDirectoryA, IsBadReadPtr, GetStringTypeW, GetStringTypeA, FlushFileBuffers, SetFilePointer, IsBadWritePtr, VirtualAlloc, RtlUnwind, RaiseException, GetCommandLineA, GetVersion, ExitProcess, HeapFree, HeapAlloc, HeapReAlloc, TerminateProcess, GetCurrentProcess, LCMapStringA, LCMapStringW, GetCPInfo, HeapSize, GetACP, GetOEMCP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, VirtualFree, WriteFile<br />&amp;gt; ADVAPI32.dll: RegisterServiceCtrlHandlerA, RegEnumValueA, SetServiceStatus, StartServiceCtrlDispatcherA, ControlService, DeleteService, StartServiceA, QueryServiceStatus, CreateServiceA, ChangeServiceConfig2A, RegCreateKeyA, RegSetValueExA, OpenSCManagerA, OpenServiceA, CloseServiceHandle, DeregisterEventSource, RegQueryInfoKeyA, RegOpenKeyExA, RegCloseKey<br />&amp;gt; ole32.dll: CoUninitialize, CoGetClassObject, StringFromCLSID, CoInitialize<br />&amp;gt; OLEAUT32.dll: -<br /><br />( 0 exports ) <br /></td></tr><tr class=""><td>Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=1A741BE600E22A09C07901CE1AE8BF0084B630EB</td></tr></tbody></table><br />文件说明符 : C:\WINDOWS\system32\8g4.dll<br />属性 : ---R<br />数字签名:否<br />PE文件:是<br />语言 : 英语(美国)<br />文件版本 : 6, 0, 2900, 3395<br />说明 : Internet Extensions for Win32<br />版权 : Copyright 2007<br />备注 : <br />产品版本 : 6, 0, 2900, 3395<br />产品名称 : Microsoft(R) Windows(R) Operating System<br />公司名称 : Microsoft Corporation<br />内部名称 : wininet.dll<br />创建时间 : 2008-8-16 7:28:49<br />修改时间 : 2008-8-18 9:24:6<br />大小 : 53248 字节 52.0 KB<br />MD5 : 8b0f13a77904747fa97c94ca9d385820<br />SHA1: DEEA688792B17F0963627910AEFCDEEF1C29A93A<br />CRC32: 5f208cad</p><p>文件 8g4.dll 接收于 2008.09.02 08:03:07 (CET) 结果: <span id="porcentaje"><span style="COLOR: red">7</span>/36 (19.45%)</span></p><p><table id="tableado" style="DISPLAY: block" cellspacing="0" cellpadding="0" border="0"><tbody><tr><td>反病毒引擎</td><td>版本</td><td style="TEXT-ALIGN: center">最后更新</td><td>扫描结果</td></tr><tr><td>AhnLab-V3</td><td>2008.9.2.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>AntiVir</td><td>7.8.1.23</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">ADSPY/Bho.aeu</td></tr><tr><td>Authentium</td><td>5.1.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Avast</td><td>4.8.1195.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>AVG</td><td>8.0.0.161</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>BitDefender</td><td>7.2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Adware.BDSearch.1</td></tr><tr><td>CAT-QuickHeal</td><td>9.50</td><td style="TEXT-ALIGN: center">2008.08.29</td><td>-</td></tr><tr><td>ClamAV</td><td>0.93.1</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>DrWeb</td><td>4.44.0.09170</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Adware.Sogou.119</td></tr><tr><td>eSafe</td><td>7.0.17.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eTrust-Vet</td><td>31.6.6062</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Ewido</td><td>4.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>F-Prot</td><td>4.4.4.56</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>F-Secure</td><td>7.60.13501.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Fortinet</td><td>3.14.0.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>GData</td><td>19</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Ikarus</td><td>T3.1.1.34.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">AdWare.Bdsearch.1</td></tr><tr><td>K7AntiVirus</td><td>7.10.435</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>McAfee</td><td>5374</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Microsoft</td><td>1.3807</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>NOD32v2</td><td>3406</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Norman</td><td>5.80.02</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>PCTools</td><td>4.4.2.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Adware.WSearch.O</td></tr><tr><td>Prevx1</td><td>V2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Rising</td><td>20.60.10.00</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Sophos</td><td>4.33.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">DesktopMedia</td></tr><tr><td>Sunbelt</td><td>3.1.1592.1</td><td style="TEXT-ALIGN: center">2008.08.30</td><td>-</td></tr><tr><td>Symantec</td><td>10</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>TheHacker</td><td>6.3.0.8.069</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>TrendMicro</td><td>8.700.0.1004</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>VBA32</td><td>3.12.8.4</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>ViRobot</td><td>2008.9.1.1359</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>VirusBuster</td><td>4.5.11.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Webwasher-Gateway</td><td>6.6.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Ad-Spyware.Bho.aeu</td></tr></tbody></table></p><p><table id="tablaInformacion" cellspacing="0" cellpadding="0" width="550" border="0"><tbody><tr><th>附加信息</th></tr><tr class=""><td>File size: 53248 bytes</td></tr><tr class="odd"><td>MD5...: 8b0f13a77904747fa97c94ca9d385820</td></tr><tr class=""><td>SHA1..: deea688792b17f0963627910aefcdeef1c29a93a</td></tr><tr class="odd"><td>SHA256: 5f98c4e22ab2101045c5f6f50fd03e2b43603b277389ddfeae1b6ab77ab5642d</td></tr><tr class=""><td>SHA512: e5f314dbe88bdf68a89a4676cd3459abd8b1c88b42e19318f4489b7a4e57bc5b<br />3fbf105077ec0c123c6732fa5c8292927518bd3791ce3d3f8627f20d66de4c4a</td></tr><tr class="odd"><td>PEiD..: Armadillo v1.xx - v2.xx</td></tr><tr class=""><td>TrID..: File type identification<br />DirectShow filter (52.6%)<br />Windows OCX File (32.2%)<br />Win32 Executable MS Visual C++ (generic) (9.8%)<br />Win32 Executable Generic (2.2%)<br />Win32 Dynamic Link Library (generic) (1.9%)</td></tr><tr class="odd"><td>PEInfo: PE Structure information<br /><br />( base data )<br />entrypointaddress.: 0x10007153<br />timedatestamp.....: 0x48a8ced7 (Mon Aug 18 01:22:31 2008)<br />machinetype.......: 0x14c (I386)<br /><br />( 5 sectins )<br />name viradd virsiz rawdsiz ntrpy md5<br />.text 0x1000 0x6846 0x7000 6.12 bf6c802cab768d06827795f8a039bd62<br />.rdata 0x8000 0x1f42 0x2000 5.09 70d66633da7462cc773003a3c24c6e86<br />.data 0xa000 0x2250 0x1000 1.78 24134641bcf54f63f31c909833171a5e<br />.rsrc 0xd000 0xed0 0x1000 4.09 d331bda4646b0bb8d6cc9254ce2dea02<br />.reloc 0xe000 0xef2 0x1000 5.15 2be4cafb06c52c0d0369dbfad86010c7<br /><br />( 8 imports ) <br />&amp;gt; MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br />&amp;gt; MSVCRT.dll: memcmp, strlen, strcpy, memset, _access, realloc, malloc, free, _EH_prolog, strcat, strrchr, strncpy, strncmp, __dllonexit, _onexit, _except_handler3, _terminate@@YAXXZ, _initterm, _adjust_fdiv, __1type_info@@UAE@XZ, __CxxFrameHandler, _purecall, _mbslwr, memcpy, sprintf<br />&amp;gt; KERNEL32.dll: InterlockedDecrement, LocalAlloc, LocalFree, GetModuleHandleA, DeviceIoControl, CreateFileA, CreateDirectoryA, GetTempFileNameA, GetDriveTypeA, SearchPathA, GetFileAttributesA, WaitForSingleObject, SetFileAttributesA, GetVolumeInformationA, OpenMutexA, GetWindowsDirectoryA, GetSystemDirectoryA, CreateProcessA, CloseHandle, GetVersionExA, GetProcessHeap, GetLogicalDrives, lstrcatA, lstrcpyA, LoadLibraryA, GetProcAddress, HeapDestroy, IsDBCSLeadByte, lstrcpynA, lstrcmpiA, LoadLibraryExA, GetLastError, FindResourceA, LoadResource, SizeofResource, FreeLibrary, WideCharToMultiByte, GetShortPathNameA, lstrlenA, MultiByteToWideChar, GetModuleFileNameA, InitializeCriticalSection, DeleteCriticalSection, LeaveCriticalSection, InterlockedIncrement, EnterCriticalSection, CopyFileA, lstrlenW<br />&amp;gt; USER32.dll: CharNextA<br />&amp;gt; ADVAPI32.dll: RegEnumValueA, RegCreateKeyExA, RegDeleteValueA, RegCloseKey, RegOpenKeyExA, RegEnumKeyExA, RegSetValueExA, RegQueryInfoKeyA, RegDeleteKeyA, RegCreateKeyA, RegQueryValueA, RegSetValueA, RegSetKeySecurity, RegUnLoadKeyA, RegNotifyChangeKeyValue, CloseServiceHandle, OpenServiceA, OpenSCManagerA, QueryServiceStatus, RegQueryValueExA<br />&amp;gt; ole32.dll: CoTaskMemAlloc, CoTaskMemRealloc, CoCreateInstance, CoTaskMemFree<br />&amp;gt; OLEAUT32.dll: -, -, -, -, -, -, -<br />&amp;gt; MSVCP60.dll: _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, __1_Winit@std@@QAE@XZ, __0_Winit@std@@QAE@XZ, __1Init@ios_base@std@@QAE@XZ, __0Init@ios_base@std@@QAE@XZ, _substr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QBE_AV12@II@Z, __8std@@YA_NABV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@0@PBD@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, __0_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@ABV01@@Z, __Hstd@@YA_AV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@0@ABV10@0@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __Hstd@@YA_AV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@0@ABV10@PBD@Z, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z<br /><br />( 4 exports ) <br />DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer<br /></td></tr></tbody></table></p><p>文件说明符 : C:\WINDOWS\system32\fh8.dll<br />属性 : ---R<br />数字签名:否<br />PE文件:是<br />语言 : 中文(中国)<br />文件版本 : 4, 1, 0, 3936<br />说明 : MS DTC administrative component<br />版权 :&amp;nbsp;&amp;nbsp;&amp;nbsp; 版权所有 (C) 2006<br />产品版本 : 4, 1, 0, 3936<br />产品名称 : Microsoft Distributed Transaction Coordinator<br />公司名称 : Microsoft Corporation<br />内部名称 : msdtcui<br />创建时间 : 2008-8-16 7:28:49<br />修改时间 : 2008-8-18 9:24:8<br />大小 : 679936 字节 664.0 KB<br />MD5 : 5cc9d394a169a062f7ff5a083e1d2f16<br />SHA1: DA8F216AFD1A4E61DDD93B447BB697520D0AC697<br />CRC32: 5e40c01c</p><div id="nombre">文件 fh8.dll 接收于 2008.09.02 08:12:20 (CET) 结果: <span id="porcentaje"><span style="COLOR: red">20</span>/36 (55.56%)</span></div><p><table id="tableado" style="DISPLAY: block" cellspacing="0" cellpadding="0" border="0"><tbody><tr><td>反病毒引擎</td><td>版本</td><td style="TEXT-ALIGN: center">最后更新</td><td>扫描结果</td></tr><tr><td>AhnLab-V3</td><td>2008.9.2.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>AntiVir</td><td>7.8.1.23</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">TR/Agent.49152</td></tr><tr><td>Authentium</td><td>5.1.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Avast</td><td>4.8.1195.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Win32:Agent-GRW</td></tr><tr><td>AVG</td><td>8.0.0.161</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Generic_r.D</td></tr><tr><td>BitDefender</td><td>7.2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Adware.BDSearch.1</td></tr><tr><td>CAT-QuickHeal</td><td>9.50</td><td style="TEXT-ALIGN: center">2008.08.29</td><td style="COLOR: red">AdWare.BHO.cox (Not a Virus)</td></tr><tr><td>ClamAV</td><td>0.93.1</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>DrWeb</td><td>4.44.0.09170</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Adware.Sogou.120</td></tr><tr><td>eSafe</td><td>7.0.17.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eTrust-Vet</td><td>31.6.6062</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Ewido</td><td>4.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>F-Prot</td><td>4.4.4.56</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>F-Secure</td><td>7.60.13501.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">AdWare.Win32.BHO.cox</td></tr><tr><td>Fortinet</td><td>3.14.0.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Adware/DesktopMedia</td></tr><tr><td>GData</td><td>19</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Win32:Agent-GRW</td></tr><tr><td>Ikarus</td><td>T3.1.1.34.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Virus.Win32.Agent.GRW</td></tr><tr><td>K7AntiVirus</td><td>7.10.435</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Win32.Malware.1</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">not-a-virus:AdWare.Win32.BHO.cox</td></tr><tr><td>McAfee</td><td>5374</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">potentially unwanted program Adware-DesktopMedia</td></tr><tr><td>Microsoft</td><td>1.3807</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Adware:Win32/Rugo</td></tr><tr><td>NOD32v2</td><td>3406</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Norman</td><td>5.80.02</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>PCTools</td><td>4.4.2.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Prevx1</td><td>V2</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">Worm</td></tr><tr><td>Rising</td><td>20.60.10.00</td><td style="TEXT-ALIGN: center">2008.09.02</td><td style="COLOR: red">AdWare.Win32.Mnless.ahb</td></tr><tr><td>Sophos</td><td>4.33.0</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>Sunbelt</td><td>3.1.1592.1</td><td style="TEXT-ALIGN: center">2008.08.30</td><td style="COLOR: red">Adware.Bdsearch</td></tr><tr><td>Symantec</td><td>10</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>TheHacker</td><td>6.3.0.8.069/td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>TrendMicro</td><td>8.700.0.1004</td><td style="TEXT-ALIGN: center">2008.09.02</td><td>-</td></tr><tr><td>VBA32</td><td>3.12.8.4</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">AdWare.Win32.BHO.cox</td></tr><tr><td>ViRobot</td><td>2008.9.1.1359</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Adware.BHO.679936.D</td></tr><tr><td>VirusBuster</td><td>4.5.11.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Webwasher-Gateway</td><td>6.6.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Ad-Spyware.BDSearch.1.45</td></tr></tbody></table></p><p><table id="tablaInformacion" cellspacing="0" cellpadding="0" width="550" border="0"><tbody><tr><th>附加信息</th></tr><tr class=""><td>File size: 679936 bytes</td></tr><tr class="odd"><td>MD5...: 5cc9d394a169a062f7ff5a083e1d2f16</td></tr><tr class=""><td>SHA1..: da8f216afd1a4e61ddd93b447bb697520d0ac697</td></tr><tr class="odd"><td>SHA256: f230b2961b14d6f817312d09786e3b8270eb85571e0f6acfff0e6a9aed56f6ab</td></tr><tr class=""><td>SHA512: d73fbdd486596eda659f1f05e9f532496a02f18625ca4c1801cc18811c88024a<br />2127f14f1f7d2163749c364f920b729ebedd2704792146bdd1e78e97e1759fbb</td></tr><tr class="odd"><td>PEiD..: -</td></tr><tr class=""><td>TrID..: File type identification<br />Win32 Executable MS Visual C++ (generic) (53.1%)<br />Windows Screen Saver (18.4%)<br />Win32 Executable Generic (12.0%)<br />Win32 Dynamic Link Library (generic) (10.6%)<br />Generic Win/DOS Executable (2.8%)</td></tr><tr class="odd"><td>PEInfo: PE Structure information<br /><br />( base data )<br />entrypointaddress.: 0x10044883<br />timedatestamp.....: 0x48a8ce36 (Mon Aug 18 01:19:50 2008)<br />machinetype.......: 0x14c (I386)<br /><br />( 5 sections )<br />name viradd virsiz rawdsiz ntrpy md5<br />.text 0x1000 0x79f76 0x7a000 6.62 daa7ab1749d0349d0d49b08f790012dd<br />.rdata 0x7b000 0xc4ce 0xd000 4.73 470ce27f912cec8a2fb64d136a712951<br />.data 0x88000 0x52e2c 0xd000 2.61 31fa3a006582c503094bbf1d8a2c44ce<br />.rsrc 0xdb000 0x1258 0x2000 3.01 9f55d89a8fd45e9f03a4f5db7ab987b7<br />.reloc 0xdd000 0xe674 0xf000 5.83 a465aad81a0719d36866c17035df8794<br /><br />( 9 imports ) <br />&amp;gt; WS2_32.dll: -, -, -<br />&amp;gt; ole32.dll: CoTaskMemRealloc, CLSIDFromString, CLSIDFromProgID, CoGetClassObject, OleLockRunning, CoTaskMemAlloc, StringFromGUID2, OleUninitialize, OleInitialize, CreateStreamOnHGlobal, CoCreateInstance, CoUninitialize, CoInitialize, CoTaskMemFree<br />&amp;gt; WININET.dll: InternetOpenA, InternetReadFile, GetUrlCacheEntryInfoA, InternetCrackUrlA, DeleteUrlCacheEntry, InternetConnectA, InternetCloseHandle, HttpOpenRequestA, HttpSendRequestA<br />&amp;gt; urlmon.dll: URLDownloadToFileA<br />&amp;gt; KERNEL32.dll: RaiseException, InitializeCriticalSection, DeleteCriticalSection, GetLocalTime, CloseHandle, UnmapViewOfFile, MapViewOfFile, CreateFileMappingA, OpenFileMappingA, ReleaseMutex, FlushViewOfFile, WaitForSingleObject, CreateMutexA, FindClose, FindFirstFileA, GetLastError, GetSystemTimeAsFileTime, SetErrorMode, MultiByteToWideChar, GetShortPathNameA, GetTempFileNameA, GetTempPathA, CopyFileA, Sleep, SetFileAttributesA, GetWindowsDirectoryA, DeleteFileA, GetVolumeInformationA, GetSystemDirectoryA, FindNextFileA, lstrcmpA, lstrcatA, lstrcpyA, CreateDirectoryA, GetVersionExA, SetProcessWorkingSetSize, GetCurrentProcess, GetTickCount, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, EnterCriticalSection, LeaveCriticalSection, FlushInstructionCache, HeapFree, GetProcessHeap, HeapAlloc, WideCharToMultiByte, InterlockedDecrement, lstrlenA, GetCurrentThreadId, GlobalUnlock, GlobalLock, GlobalAlloc, lstrlenW, MulDiv, InterlockedIncrement, GetModuleFileNameA, SetEvent, GetModuleHandleA, FreeLibrary, SizeofResource, LoadResource, LoadLibraryExA, lstrcmpiA, lstrcpynA, IsDBCSLeadByte, GetProcAddress, LoadLibraryA, CreateThread, OpenEventA, CreateProcessA, WaitForMultipleObjects, CreateEventA, Module32Next, Module32First, CreateToolhelp32Snapshot, GetCurrentDirectoryA, Process32Next, Process32First, ReadFile, CreateFileA, TerminateProcess, DeviceIoControl, VirtualAlloc, VirtualFree, SetFilePointer, WriteFile, SetEndOfFile, GetStdHandle, QueryPerformanceCounter, HeapSize, GetCurrentProcessId, SetUnhandledExceptionFilter, IsBadWritePtr, HeapCreate, FlushFileBuffers, HeapDestroy, TlsGetValue, TlsSetValue, TlsFree, SetLastError, TlsAlloc, GetOEMCP, GetCPInfo, LCMapStringW, LCMapStringA, RemoveDirectoryA, GetCommandLineA, HeapReAlloc, VirtualQuery, GetSystemInfo, VirtualProtect, GetFileAttributesA, GetDriveTypeA, FileTimeToLocalFileTime, FileTimeToSystemTime, ExitProcess, RtlUnwind, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, UnhandledExceptionFilter, GetStringTypeA, GetStringTypeW, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, IsBadReadPtr, IsBadCodePtr, GetTimeZoneInformation, SetStdHandle, GetLocaleInfoW, CompareStringA, CompareStringW, SetEnvironmentVariableA, LocalFree, FindResourceA, GetFullPathNameA<br />&amp;gt; USER32.dll: GetForegroundWindow, SetForegroundWindow, SystemParametersInfoA, MapWindowPoints, ShowWindow, UpdateWindow, PeekMessageA, GetMessageA, TranslateMessage, DispatchMessageA, EnumWindows, AdjustWindowRectEx, FindWindowExA, PostMessageA, CreateAcceleratorTableA, CharNextA, GetParent, GetClassNameA, RedrawWindow, IsWindow, GetDlgItem, SetFocus, GetFocus, IsChild, GetWindow, DestroyAcceleratorTable, BeginPaint, EndPaint, GetDesktopWindow, InvalidateRgn, InvalidateRect, FillRect, SetCapture, ReleaseCapture, GetSysColor, CreateWindowExA, CallWindowProcA, RegisterWindowMessageA, RegisterClassExA, GetWindowTextLengthA, GetWindowTextA, DefWindowProcA, SetActiveWindow, LoadCursorA, GetClassInfoExA, KillTimer, SetTimer, SetWindowPos, MoveWindow, SetWindowTextA, SendMessageA, GetWindowLongA, SetWindowLongA, DestroyWindow, PostQuitMessage, wsprintfA, SetWindowRgn, ReleaseDC, GetWindowRect, GetClientRect, GetSystemMetrics, LoadImageA, UnregisterClassA, GetDC<br />&amp;gt; GDI32.dll: CreateRectRgn, GetPixel, RestoreDC, CreateSolidBrush, GetStockObject, GetObjectA, GetDeviceCaps, BitBlt, CreateCompatibleBitmap, DeleteDC, SelectObject, CreateCompatibleDC, CombineRgn, SaveDC, DeleteObject<br />&amp;gt; ADVAPI32.dll: RegOpenKeyA, RegQueryValueExA, InitializeSecurityDescriptor, RegSetValueExA, RegCreateKeyA, GetUserNameA, RegCreateKeyExA, RegEnumValueA, RegDeleteKeyA, RegDeleteValueA, RegOpenKeyExA, RegQueryInfoKeyA, RegEnumKeyExA, SetSecurityDescriptorDacl, RegCloseKey<br />&amp;gt; OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -<br /><br />( 8 exports ) <br />Always, CallByControl, GetPlayerVersion, HxcDown, HxcUpdate, RunAD, Stop, playAdh<br /></td></tr><tr class=""><td>Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=52B62B9300B9F45560080A686AD6A100F0A85D5F</td></tr></tbody></table><br /><br />&amp;nbsp;</p>]]></description> 
<guid isPermaLink="false">6793249@http://endurer.bokee.com/</guid> 
<dc:subject>安全资讯</dc:subject> 
<dc:date>2008-09-02T22:34:19Z</dc:date> 
</item> 
<item> 
<title><![CDATA[遭遇scvhost.exe,kcohj1ba.sys,4f4.exe,w509v.sys,8g4.dll,307b.dll等]]></title> 
<link>http://endurer.bokee.com/6792445.html</link> 
<description><![CDATA[<p>遭遇scvhost.exe,kcohj1ba.sys,4f4.exe,w509v.sys,8g4.dll,307b.dll等</p><p><font color="#800080">endurer</font> 原创<br />2008-09-01 第<strong><font color="#ff0000">1</font></strong>版</p><p>今天开会时，需要播放课件，为此准备了两台本本，不料作为备用的那台本本，开机后就不定期的弹出消息框，提示加载307b.dll出错。明显是中标了。</p><p>这消息框势必会影响课件地播放，必须立即处理。</p><p>该本本装有Kingsoft Internet Security 2008，不过病毒库是8月17日的，暂时无法连网升级。</p><p>用金山清理专家扫描，没有发现可疑的东东。</p><p>后来发现该电脑中居然装有瑞星卡卡安全助手，不过是4.x的版本。用它检查开机启动项，马上发现了可疑的东东，用pe_xscan 扫描并分析如下：</p><p>/===<br />pe_xscan 08-08-01 by Purple Endurer <br />2008-9-1 13:40:48 <br />Windows XP Service Pack 2(5.1.2600) <br /MSIE:7.0.5730.13 <br />管理员用户组 <br />正常模式 <br /><br />O2 - BHO BHO Class - {1307E689-5CA1-4a15-9583-F2350790290D} =&amp;nbsp;<font color="#ff0000">C:\WINDOWS\system32\oqxovy.dll</font><font color="#008000">|</font> 2008-8-17 6:41:44 <br />O2 - BHO Invoke Class - {6B76DDAB-898D-4e5b-917C-2B697C2EA7A4} =&amp;nbsp;<font color="#ff0000">C:\WINDOWS\system32\8g4.dll</font><font color="#008000">|</font> 2008-8-15 23:28:49 <br />O4 - HKLM\..\Policies\Explorer\Run: [307b] rundll32 &amp;nbsp;<font color="#ff0000">C:\WINDOWS\Downlo~1\307b.dll</font>&amp;quot;,Run</p><p>307ac.job<br />307b.job<br />307dc.job<br />307sc.job<br /><br />O9 - IE工具栏扩展按钮HKLM：知识库 - {06926B30-424E-4f1c-8EE3-543CD96573DC} - <font color="#ff0000">hxxp://blank.la/?h</font><br />O9 - IE工具菜单扩展项HKLM： - {06926B30-424E-4f1c-8EE3-543CD96573DC} - <font color="#ff0000">hxxtp://blank.la/?h</font><br />O23 - 服务: 9bi9m8 (9bi9m8) - &amp;nbsp;<font color="#ff0000">System32\DRIVERS\9bi9m8.sys</font>(引导) <br />O23 - 服务: ADProt (ADProt) -&amp;nbsp;<font color="#ff0000">C:\WINDOWS\system32\drivers\ADProt.sys</font>(系统) <br />O23 - 服务: kcohj1ba (kcohj1ba) - &amp;nbsp;<font color="#ff0000">system32\drivers\kcohj1ba.sys</font>(引导) <br />O23 - 服务: oboqyy (Logical Disk Manager Amdinistrative oboqyy) -&amp;nbsp;<font color="#ff0000">c:\root\yxyeaholes\scvhost.exe</font><font color="#008000">|</font> 2008-7-11 3:14:2(自动) <br />O23 - 服务: OSEvent (OSEvent) -&amp;nbsp;<font color="#ff0000">C:\WINDOWS\system32\s.exe</font><font color="#008000">|</font> 2008-8-8 4:9:38(自动) <br />O23 - 服务: ThinkpadSer (ThinkpadSer) -&amp;nbsp;<font color="#ff0000">C:\WINDOWS\system32\4f4.exe</font><font color="#008000">|</font> 2008-8-14 11:39:15(自动) <br />O23 - 服务: w509v (w509v) - &amp;nbsp;<font color="#ff0000">system32\drivers\w509v.sys</font>(引导)</p><p>===/</p><p>把这些东东都清理了，重启电脑，果然不再弹出那个消息框了。</p><p>文件说明符 : C:\root\yxyeaholes\scvhost.exe<br />属性 : A---<br />数字签名:否<br />PE文件:是<br />语言 : 中文(中国)<br />文件版本 : 1.0.0.0<br />产品版本 : 1.0.0.0<br />创建时间 : 2008-7-11 11:14:2<br />修改时间 : 2008-7-11 11:14:2<br />大小 : 478720 字节 467.512 KB<br />MD5 : 84e9c475ffe13cb7c8fd60f5b2995f00<br />SHA1: BAD9CFAE6813748DF9EB9BC0AD6C5728A267D2B2<br />CRC32: cdee47b1</p><p>文件 scvhost.exe 接收于 2008.09.01 15:25:39 (CET)</p><table id="tableado" style="DISPLAY: block" cellspacing="0" cellpadding="0" border="0"><tbody><tr><td>反病毒引擎</td><td>版本</td><td style="TEXT-ALIGN: center">最后更新</td><td>扫描结果</td></tr><tr><td>AhnLab-V3</td><td>2008.8.29.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Win-Trojan/Xema.variant</td></tr><tr><td>AntiVir</td><td>7.8.1.23</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">TR/Spy.Gen</td></tr><tr><td>Authentium</td><td>5.1.0.4</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">W32/Banload.E.gen!Eldorado</td></tr><tr><td>Avast</td><td>4.8.1195.0</td><td style="TEXT-ALIGN: center">2008.08.31</td><td style="COLOR: red">Win32:Trojan-gen {Other}</td></tr><tr><td>AVG</td><td>8.0.0.161</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Downloader.Generic7.AGRS</td></tr><tr><td>BitDefender</td><td>7.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Generic.662130</td></tr><tr><td>CAT-QuickHeal</td><td>9.50</td><td style="TEXT-ALIGN: center">2008.08.29</td><td style="COLOR: red">TrojanDownloader.Delf.mpl</td></tr><tr><td>ClamAV</td><td>0.93.1</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>DrWeb</td><td>4.44.0.09170</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>eSafe</td><td>7.0.17.0</td><td style="TEXT-ALIGN: center">2008.08.31</td><td>-</td></tr><tr><td>eTrust-Vet</td><td>31.6.6062</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Ewido</td><td>4.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>F-Prot</td><td>4.4.4.56</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">W32/Banload.E.gen!Eldorado</td></tr><tr><td>F-Secure</td><td>7.60.13501.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan-Downloader.Win32.Delf.mpl</td></tr><tr><td>Fortinet</td><td>3.14.0.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>GData</td><td>19</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan-Downloader.Win32.Delf.mpl</td></tr><tr><td>Ikarus</td><td>T3.1.1.34.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan-Downloader.Win32.Delf.asz</td></tr><tr><td>K7AntiVirus</td><td>7.10.435</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Win32.Malware.1</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan-Downloader.Win32.Delf.mpl</td></tr><tr><td>McAfee</td><td>5373</td><td style="TEXT-ALIGN: center">2008.08.29</td><td style="COLOR: red">Generic Downloader.x</td></tr><tr><td>Microsoft</td><td>1.3807</td><td style="TEXT-ALIGN: center">2008.08.25</td><td>-</td></tr><tr><td>NOD32v2</td><td>3404</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">probably a variant of Win32/TrojanDownloader.Delf.ATB</td></tr><tr><td>Norman</td><td>5.80.02</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td style="TEXT-ALIGN: center">2008.08.31</td><td>-</td></tr><tr><td>PCTools</td><td>4.4.2.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan-Downloader.Delf!sd6</td></tr><tr><td>Prevx1</td><td>V2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Cloaked Malware</td></tr><tr><td>Rising</td><td>20.60.01.00</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Win32.Undef.dru</td></tr><tr><td>Sophos</td><td>4.33.0</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>Sunbelt</td><td>3.1.1592.1</td><td style="TEXT-ALIGN: center">2008.08.30</td><td style="COLOR: red">Trojan-Downloader.Delphi.Gen</td></tr><tr><td>Symantec</td><td>10</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan Horse</td></tr><tr><td>TheHacker</td><td>6.3.0.6.069</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>TrendMicro</td><td>8.700.0.1004</td><td style="TEXT-ALIGN: center">2008.09.01</td><td>-</td></tr><tr><td>VBA32</td><td>3.12.8.4</td><td style="TEXT-ALIGN: center">2008.08.31</td><td style="COLOR: red">Trojan-Downloader.Win32.Delf.mpl</td></tr><tr><td>ViRobot</td><td>2008.9.1.1359</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Win32.Downloader.478720.B</td></tr><tr><td>VirusBuster</td><td>4.5.11.0</td><td style="TEXT-ALIGN: center">2008.08.31</td><td>-</td></tr><tr><td>Webwasher-Gateway</td><td>6.6.2</td><td style="TEXT-ALIGN: center">2008.09.01</td><td style="COLOR: red">Trojan.Spy.Gen</td></tr></tbody></table><p>&amp;nbsp;</p><p><table id="tablaInformacion" cellspacing="0" cellpadding="0" width="550" border="0"><tbody><tr><th>附加信息</th></tr><tr class=""><td>File size: 478720 bytes</td></tr><tr class="odd"><td>MD5...: 84e9c475ffe13cb7c8fd60f5b2995f00</td></tr><tr class=""><td>SHA1..: bad9cfae6813748df9eb9bc0ad6c5728a267d2b2</td></tr><tr class="odd"><td>SHA256: 6925307afc3957989c289dcbcba3eeb220e75d503bc91b4bd6c625a2ba48dbf6</td></tr><tr class=""><td>SHA512: 219b328dc82b6d208444b825d18a4c71758a65ccfa21f291e0bc26d458bf11e9<br />75e5282071dfd603ad54550f72df417ec095702300f6a88a742c99d1ad486f2a</td></tr><tr class="odd"><td>PEiD..: -</td></tr><tr class=""><td>TrID..: File type identification<br />Win32 Executable Borland Delphi 7 (69.1%)<br />Win32 Executable Borland Delphi 6 (27.0%)<br />Win32 Executable Delphi generic (1.5%)<br />Win32 Executable Generic (0.8%)<br />Win32 Dynamic Link Library (generic) (0.7%)</td></tr><tr class="odd"><td>PEInfo: PE Structure information<br /><br />( base data )<br />entrypointaddress.: 0x463f40<br />timedatestamp.....: 0x2a425e19 (Fi Jun 19 22:22:17 1992)<br />machinetype.......: 0x14c (I386)<br /><br />( 8 sections )<br />name viradd virsiz rawdsiz ntrpy md5<br />CODE 0x1000 0x62fd0 0x63000 6.54 e67f1df4e269a7be7237114c94c9974a<br />DATA 0x64000 0x13b8 0x1400 4.11 dc6afc04a81f1b4d2e6fe22b921b4345<br />BSS 0x66000 0x1141 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br />.idata 0x68000 0x2776 0x2800 5.01 d0b43b14609d2a068b5d2753a50f0afa<br />.tls 0x6b000 0x10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br />.rdata 0x6c000 0x18 0x200 0.20 59ae59073dbfc82e5e0222fb77af1a75<br />.reloc 0x6d000 0x7204 0x7400 6.66 d8a0e4ffedfa836b07ffcabfcec0d94d<br />.rsrc 0x75000 0x6800 0x6800 4.31 22b9293e6ea466a14872f8b94f2578e2<br /><br />( 18 imports ) <br />&amp;gt; kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle<br />&amp;gt; user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA<br />&amp;gt; advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey<br />&amp;gt; oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen<br />&amp;gt; kernel32.dll: TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA<br />&amp;gt; advapi32.dll: ReportEventA, RegisterEventSourceA, RegQueryValueExA, RegOpenKeyExA, RegCloseKey, DeregisterEventSource<br />&amp;gt; kernel32.dll: lstrcpyA, WriteFile, WinExec, WaitForSingleObject, VirtualQuery, VirtualAlloc, SuspendThread, Sleep, SizeofResource, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, ReadFile, MultiByteToWideChar, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalSize, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetVersionExA, GetVersion, GetUserDefaultLCID, GetTickCount, GetThreadLocale, GetSystemInfo, GetStringTypeExA, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetExitCodeThread, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetComputerNameA, GetCPInfo, GetACP, FreeResource, InterlockedIncrement, InterlockedExchange, InterlockedDecrement, FreeLibrary, FormatMessageA, FindResourceA, FindFirstFileA, FindClose, FileTimeToLocalFileTime, FileTimeToDosDateTime, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateThread, CreateFileA, CreateEventA, CompareStringA, CloseHandle<br />&amp;gt; version.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA<br />&amp;gt; gdi32.dll: UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, Rectangle, RectVisible, RealizePalette, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionA, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateEnhMetaFileA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, CloseEnhMetaFile, BitBlt<br />&amp;gt; user32.dll: CreateWindowExA, mouse_event, WindowFromPoint, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursorPos, SetCursor, SetClipboardData, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostThreadMessageA, PostQuitMessage, PostMessageA, PeekMessageA, OpenClipboard, OffsetRect, OemToCharA, MsgWaitForMultipleObjects, MessageBoxA, MessageBeep, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMessageTime, GetMessageExtraInfo, GetMessageA, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, EmptyClipboard, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, CloseClipboard, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharUpperBuffA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout<br />&amp;gt; kernel32.dll: Sleep<br />&amp;gt; oleaut32.dll: SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit<br />&amp;gt; ole32.dll: CreateStreamOnHGlobal, IsAccelerator, OleDraw, OleSetMenuDescriptor, CoTaskMemFree, ProgIDFromCLSID, StringFromCLSID, CoCreateInstance, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID<br />&amp;gt; oleaut32.dll: GetErrorInfo, GetActiveObject, SysFreeString<br />&amp;gt; advapi32.dll: StartServiceCtrlDispatcherA, SetServiceStatus, RegisterServiceCtrlHandlerA, OpenServiceA, OpenSCManagerA, DeleteService, CreateServiceA, CloseServiceHandle<br />&amp;gt; comctl32.dll: ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create<br />&amp;gt; shell32.dll: ShellExecuteA<br />&amp;gt; URLMON.DLL: URLDownloadToFileA<br /><br />( 0 exports ) <br ></td></tr><tr class=""><td>Prevx info: <a href="http://info.prevx.com/aboutprogramtext.asp?PX5=A1F493E60054DB824ECA07D058F4F400F6E383C7">http://info.prevx.com/aboutprogramtext.asp?PX5=A1F493E60054DB824ECA07D058F4F400F6E383C7</a></td></tr></tbody></table></p><p>&amp;nbsp;</p>]]></description> 
<guid isPermaLink="false">6792445@http://endurer.bokee.com/</guid> 
<dc:subject>系统维护</dc:subject> 
<dc:date>2008-09-01T21:45:21Z</dc:date> 
</item> 
<item> 
<title><![CDATA[译＞10个不应犯的常见安全错误]]></title> 
<link>http://endurer.bokee.com/6787540.html</link> 
<description><![CDATA[<p>10 common security mistakes that should never be made<br />10个不应犯的常见安全错误</p><p>&amp;nbsp;Author: Chad Perrin<br />作者：Chad Perrin</p><p>&amp;nbsp;翻译：<font color="#800080">endurer</font> 2008-08-25 第1版</p><p>&amp;nbsp;Category: Security, Authentication, Encryption, Risk Management, Privacy<br />分类：安全，认证，加密，风险管理，隐私</p><p>Tags: Password, Security, Chad Perrin<br />标签：密码，安全，Chad Perrin</p><p>英文来源：<a href="http://blogs.techrepublic.com.com/security/?p=542&amp;tag=nl.e101"><u><font color="#0000ff">http://blogs.techrepublic.com.com/security/?p=542&amp;amp;tag=nl.e101</font></u></a></p><p /><p class="entry"><em>Read about ten very basic, easily avoided security mistakes that should never be made — but are among the most common security mistakes people make.</em></p><p class="entry">一起来阅读了解10个不应犯的非常基本、易于避免的——却是人们犯的最多的常见安全错误罢。</p><p class="entry">《endurer注：1、Read about：读知(阅后得知)》</p><p class="entry" /><div class="entry"><hr /></div><div class="entry">The following is a list of ten security mistakes I see all the time. They’re not just common, though — they’re also extremely basic, elementary mistakes, that anyone with a modicum of security knowledge should know better than to make.</div><div class="entry">&amp;nbsp;</div><div class="entry">以下是我一直在看的10个安全错误列表。然而它们不仅是常见的—它们也非常基本的，初级的错误，即任何具有一点点的安全知识的人都应该知道，更不要说犯了。</div><div class="entry">&amp;nbsp;</div><div class="entry">《endurer注：1、all the time：一直》<br /></div><p class="entry" /><div class="entry"><ol><li><strong>Sending sensitive data in unencrypted email:</strong> Stop sending me passwords, PINs, and account data via unencrypted email. Please. I understand that a lot of customers are too stupid or lazy to use encryption, but I’m not. Even if you’re going to give <em>them</em> what <em>they</em> want, in the form of unencrypted sensitive data sent via email, that doesn’t mean you can’t give <em>me</em> what <em>I</em> want — secure communications when sending sensitive data.<br /><br /><strong>使用未加密的电子邮件发送敏感数据</strong>：通过未加密的电子邮件发送口令、帐号数据的，请停下来。我理解许多客户太蠢或太懒而不使用加密，但我不是这样。即使你们以通过以电子邮件以非加密敏感数据的方式，把他们想要的东东发给他们，这不意味着你不能我所需要的——在发送敏感数据时使通信安全。<br /></li><li><strong>Using “security” questions whose answers are easily discovered:</strong> Social security numbers, mothers’ maiden names, first pets, and birthdays do not constitute a secure means of verifying identity. Requiring an end user to compromise his or her password by specifying a question like that as a means of resetting the password basically ensures that the password itself is useless in preventing anyone that is willing to do a little homework from gaining unauthorized access.<br /><br /><strong>使用答案很容易发现的“安全”问题</strong>：社会安全号码，母亲的婚前姓名，第1个宠物，以及生日，并不构成一个核实身份的安全手段。要求最终用户指定一个那样的问题，作为一种重置密码的手段，以妥协处理他或她的密码，基本可以确信的是，密码本身在防范为获得未经授权的访问而愿意花点功夫的人时没有用。<br /><br />《endurer注：1、be willing to：愿意,乐意》<br /><br /></li><li><strong>Imposing password restrictions that are too strict:</strong> The number of cases I’ve seen where some online interface to a system that offers the ability to manage one’s finances — such as banking Web sites — impose password restrictions that actually make the interface less secure is simply unacceptable. Six-character numeric passwords are dismayingly common, and the examples only go downhill from there. See a previous article, <a href="http://blogs.techrepublic.com.com/security/?p=528" target="_blank"><u><font color="#0000ff">“How does bad password policy like this even happen?</font></u></a>” for another example in more detail.<br /><br /><strong>密码限制过头了</strong>：我曾数次看到一个提供管理一个人财务的功能的系统的在线接口——如银行网站——实际上使接口缺少安全的强制密码限制是明显不能接受的。六位数字密码是令人惊愕地相同，并且该例只会变坏。看前一篇文章，《像这样的坏密码如何会出现呢？》来获得其它例子的详情。<br /><br />《endurer注：1、go downhill：变坏(每况愈下,衰退)》<br /><br /></li><li><strong>Letting vendors define “good security”:</strong> I’ve said before that <a href="http://blogs.techrepublic.com.com/security/?p=282" target="_blank"><u><font color="#0000ff">there’s no such thing as a vendor you can trust</font></u></a>. Hopefully you were listening. Ultimately, the only security a corporate vendor really cares about protecting is the security of its own profits and market share. While this sometimes prompts a vendor to improve the security of its products and services, it sometimes prompts exactly the opposite. As such, you must question a vendor’s definition of “good security”, and you must not let vendors tell you what’s important to you.<br /><br /><strong>让供应商来定义“良好的安全”</strong>：此前我说过没有您可以信任的供应商。希望您正在听。最终，公司供应商真正关心保护的惟一安全是其自身利益和市场占有率的安全。虽然这有时会提醒供应商来改善其安全产品和服务，但它有时会提示了相反一面。如此一来，你必须质疑供应商“良好的安全”的定义，你不能让供应商告诉你什么是对你最重要的。<br /><br />《endurer注：1、no such thing：没有的事<br />2、market share：市场占有率》<br /><br /></li><li><strong>Underestimating required security expertise:</strong> People in positions of authority in corporations often fail to understand the necessity for specific security expertise. This applies not only to nontechnical managers, but to technical IT managers as well. In fact, standards working groups such as the one that produced the <abbr title="Wired Equivalent Privacy" />WEP</abbr /> standard often include a lot of very smart technologists, but not a single cryptographer, despite the fact they intend to develop security standards that rely explicitly on cryptographic algorithms.<br /><br /><strong>低估所需要安全专业技术</strong>：企业的掌权者常常不明白特定安全技术的必要性。不仅非技术性的管理人员如此，而且技术性的IT管理人员也是这样。事实上，在标准工作组，如一个产生了WEP标准的，往往包括了很多很聪明的技术人员，而不仅仅有一个译解密码者，尽管事实上他们打算制定的安全标准，很晃显地依赖加密算法。<br /></li><li><strong>Underestimating the importance of review:</strong> Even those with security expertise specific to what they’re trying to accomplish should have their work checked by others with that expertise as well. Peer review is regarded in the security community as something akin to a holy grail of security assurance, and nothing can really be considered secure without being subjected to significant, punishing levels of testing by security experts from outside the original development project.<br /><br /><strong>低估审查的重要性</strong>：即使那些有安全技术专长的人，需要将他们正试图完成的工作，交由其他同样具有该专长的人检查。在安全团体中，同行审查被视为是类似于圣杯的安全保证，并且没有什么东东，未经相当数量的来自外部独立发展计划的安全专家的惩治水平测试，就真地被视为安全。<br /><br />《endurer注：1、akin to：类似(近于,的同族)<br />2、peer review：同行审查<br />3、Holy Grail：〈宗〉圣杯，圣盘<br />4、be subjected to：使经受,使遭受》<br /></li><li><strong>Overestimating the importance of secrecy:</strong> Many security software developers who make the mistake of underestimating the importance of review couple that with overestimation of the importance of secrecy. They justify a lack of peerreview with hand-waving about how important it is to keep security policies secret. As Kerckoffs’ Principle — one of the most fundamental in security research — points out, however, any system whose security relies on the design of the system itself being kept secret is not a system with strong security.<br /><br /><strong>高估保密的重要性</strong>：一些犯了低估复审的重要性的安全软件开发者同时高估保密的重要性。他们摇手以要保持安全政策的秘密是何等重要为由来为缺乏同行审查作开脱。然而，作为kerckoffs 的原则——最根本的安全性研究之一——指出，任何本身安全依赖于系统设计保密的系统，不是一个强健安全的系统。<br /><br />《endurer注：1、couple with：接在一起(耦合)<br />2、Kerckhoffs 提出的密码系统的设计准则:数据的安全性应该依赖于密钥，而不是密码算法的保密。》<br /></li><li><strong>Requiring easily forged identification:</strong> Anything that involves faxing signatures, or sending photocopies or scans of ID cards, is basically just a case of security theater — putting on a great show without actually providing the genuine article (security, in this case) at all. It is far too easy to forge such second-generation (or worse) low quality copies. In fact, for things like signatures and ID cards, the only way for a copy to serve as useful verification is for it to actually be a good enough copy that it is not recognized as a copy. Put another way, only a successful forgery of the original is a good enough copy to avoid easy forgery.<br /><br /><strong>要求很容易伪造的身份证明</strong>：凡是涉及到传真签名，或发送影印或扫描身份证的，情形基本上类似于一个安全戏院——作了大型演出，实际上却没有真品（安全，在这种情况下）。到目前为止，伪造诸如第二代（或更糟的）低质量的副本太容易了。其实，对于类似签字和身份证的东西，让一份拷贝起到有效核查作用的唯一方法是它要是一个足以以假乱真的副本。换句话说，只有一个成功的赝品才是避免易于伪造的足够好的副本。<br /><br />《endurer注：1、genuine article：真品<br />2、serve as：担任(充当,起...的作用)》<br /></li><li><strong>Unnecessarily reinventing the wheel:</strong> Often, developers of new security software are recreating something that already exists without any good reason for doing so. Many software vendors suffer from <a href="http://blogs.techrepublic.com.com/security/?p=460"><u><font color="#0000ff">Not Invented Here</font></u></a> disease, and end up creating new software that doesn’t really do anything new or needed. That might not be a big deal, if not for the fact that the new software is often not peer reviewed, makes security mistakes that have already been ironed out of the previous implementation of the idea, and generally just screws things up pretty badly. Whenever creating a new piece of software, consider whether you’re replacing something else that already does that job, and whether your replacement actually does anything different that is important. Then, if it is doing something important and different, think about whether you might be able to just add that to the already existing software so you will not create a whole new bundle of problems by trying to replace it.<br /><br /><strong>不必要的重复制造</strong>：通常，新安全软件的开发者没来由地重新创建一些已经存在的东东。一些软件供应商患上了非我发明症，最终创建了没有新意或需要的新软件。这可能没什么大不了的，如果不在意新软件通常未经同行审查，犯了先前贯彻思想已摆平的安全失误，通常弄得一团糟。每当创建一款新软件时，思考一下你是否正在替换已经在做那项工作的别的东西，你的替换是否确实有重大差别。然后，如果它做的是重要并且不同的工作，考虑你是否能把它增加到现存软件中，这样你就不会因试图替换而产生一包新问题。<br /><br />《endurer注：1、suffer from：遭受(因...而蒙受损害)<br />2、Not Invented Here Syndrome：非我发明症, 指不愿意或拒绝使用外人发明的技术<br />3、big deal：要人(可好哇)<br />4、iron out：熨平，摆平，理顺，解决<br />5、screw up：拧紧(强迫,加强,鼓足)<br />Don't ask them to organize the trip, they'll only screw everything up.别让他们组织此行，他们准得把一切都搞糟了。<br />6、The bad news has shaken her up pretty badly.那坏消息一直使她感到极度不安。》<br /></li><li><strong>Giving up the means of your security in exchange for a feeling of security:</strong> This is a mistake so absurd to make that I have difficulty formulating an explanation. It is also so common that there’s no way I can leave it out of the list. People give up the keys to their private security kingdoms to anyone who comes along and tells them, “Trust me, I’m an expert,” and they do it willingly, eagerly, often without thought. “Certificate Authorities” tell you who to trust, thus stripping you of your ability to make your own decisions about trust; Webmail service providers offer on-server encryption and decryption, thus stripping you of end-to-end encryption and control over your own encryption keys; operating systems decide what to execute without your consent, thus stripping you of your ability to protect yourself from mobile malicious code. Don’t give up control of your security to some third party. Sure, you may not be able to develop a good security program or policy yourself, but that doesn’t mean the program or policy shouldn’t give you control over its operation on your behalf. <br /><br /><strong>放弃安全手段，换取安全感</strong>：这是一个错误，荒谬得令我难于解释，但它是如此普遍，以致我无法将其从清单中剔除。只要有人宣称，“相信我，我是一个专家，”人们就会将个人隐私安全王国的钥匙双手奉上，并且他们是如此心甘情愿，热切，通常不加思索。 “证书颁发机构”告诉你信任谁，从而剥夺了你就信任问题作出自己的决定的能力；Webmail服务供应商提供了服务器端的加密和解密，从而剥夺你的端对端加密和对自有密钥的控制；操作系统决定执行什么，无需您的同意，从而剥夺了你保护自己免于移动恶意代码侵害的能力。不要将安全控制对弃给第三方。当然，你自己未必能够开发一个良好的安全程序或策略，但这并不意味着该程序或策略不应该让您为自身利益而其控制运作。<br /><br />《endurer注：1、in exchange for：交换(调换)<br />2、give control over：对...给予控制》</li></ol></div>]]></description> 
<guid isPermaLink="false">6787540@http://endurer.bokee.com/</guid> 
<dc:subject>安全技术分析</dc:subject> 
<dc:date>2008-08-25T12:22:05Z</dc:date> 
</item> 
<item> 
<title><![CDATA[梅西助攻迪玛利亚绝杀 阿根廷蝉联奥运男足冠军]]></title> 
<link>http://endurer.bokee.com/6786921.html</link> 
<description><![CDATA[　　北京时间8月23日12时，第29届北京奥运会男足决赛在国家体育场“鸟巢”打响。<br /><br />　　第58分钟，梅西后场左脚长距离直传策动反击，迪马里亚左肋突进面对出击的门将范泽金，在禁区线上冷静地左脚挑射得分！<br /><br />　　阿根廷1比0力克尼日利亚，蝉联奥运男足冠军！<br /><br />　　在奥运赛场上，迪马里亚防守到位、跑位合理、进攻犀利、为人低调，皇马需要的正是这类球员。把罗比尼奥这种三脚猫处理掉罢。]]></description> 
<guid isPermaLink="false">6786921@http://endurer.bokee.com/</guid> 
<dc:subject>心情随笔</dc:subject> 
<dc:date>2008-08-24T09:15:39Z</dc:date> 
</item> 
<item> 
<title><![CDATA[阿根廷3:0完胜 巴西2个红牌，爽！]]></title> 
<link>http://endurer.bokee.com/6784946.html</link> 
<description><![CDATA[<p>阿根廷3:0完胜 巴西2个红牌，爽！</p><p>　　19日奥运会足球赛，阿根廷队 vs 巴西队</p><p>　　此前未开和的阿圭罗不负众望，果然拿巴西队开刀了~</p><p>　　下半时开始7分钟，加戈中路分球被梅西让过，迪马里亚在禁区左侧距门14米处左脚大力斜射远角，阿圭罗在门前7米处用“上帝之胸”将球撞进大门左侧1:0！</p><p>　　阿圭罗拼抢中鞋掉了。准备换金靴?<img src="http://www.blogdriver.com/jsp/face/14.gif" /></p><p>　　第58分钟，迪马里亚左路传球，梅西横向盘带到禁区右侧分给插上的加雷，加雷右脚大力抽射中路，阿圭罗在门前3米处轻推入远角，2:0！</p><p>　　第75分钟，梅西右路内切左脚直塞，阿圭罗禁区右侧转身摆脱被布雷诺绊倒，点球！里克尔梅主罚右脚推半高球入大门中路，3:0！</p><p>　　第81分钟，卢卡斯背后铲倒利物浦队友马斯切拉诺，被红牌罚下！</p><p>　　第84分钟，内维斯背后扫倒马斯切拉诺，也被红牌逐出场外。</p><p>　　阿根廷最终3比0完胜。</p><p>　　丑陋的“稀巴足球”终被打回原形！爽！！！</p>]]></description> 
<guid isPermaLink="false">6784946@http://endurer.bokee.com/</guid> 
<dc:subject>心情随笔</dc:subject> 
<dc:date>2008-08-20T21:32:14Z</dc:date> 
</item> 
<item> 
<title><![CDATA[瑞星杀毒软件导致Windows进入桌面后任务栏、图标无显示？]]></title> 
<link>http://endurer.bokee.com/6783931.html</link> 
<description><![CDATA[<p>瑞星杀毒软件导致Windows进入桌后任务栏、图标无显示？</p><p><font color="#990099">endurer</font> 原创<br />2008-08-19 第<font color="#ff0000">1</font>版</p><p>　　一位同事的电脑开机后，Windows进入桌面后任务栏、图标无显示，请偶帮忙检修。</p><p>　　由于前段时间恶意软件流行替换explorer.exe，所以初步感觉是电脑中标了。</p><p>　　打开任务管理器查看进程，果然没有explorer.exe，但也没有发现异常进程。</p><p>　　新建一个命令提示符任务，用dir命令检查，发现c:\windows下的explorer.exe还在，用fc命令与system32\dllcache中explorer.exe相同，文件最后修改时间是2004年，不像是恶意软件的换的赝品。</p><p>　　启动瑞星卡卡安全助手检查启动项，也没有发现异常。</p><p>　　运行explorer.exe，任务栏、图标都显示出来了。</p><p>　　瑞星防火墙也正常启动了，但瑞星杀毒软件实时监控没有出现，手动启动，正常，手动升级，提示已经是最新版本。</p><p>　　重启电脑，问题依旧。</p><p>　　询问同事得知，他昨天下载、运行了一个清理垃圾的东东。</p><p>　　会不会是这个清理垃圾的东东影响了瑞星杀毒软件，进而导致explorer.exe无法正常自启动呢？</p><p>　　于是修复安装瑞星杀毒软件，然后重启电脑，这下正常了。</p>]]></description> 
<guid isPermaLink="false">6783931@http://endurer.bokee.com/</guid> 
<dc:subject>系统维护</dc:subject> 
<dc:date>2008-08-19T11:34:16Z</dc:date> 
</item> 
<item> 
<title><![CDATA[译＞戏弄用户的恶作剧及其效果]]></title> 
<link>http://endurer.bokee.com/6782628.html</link> 
<description><![CDATA[Pranks and their effects<br />恶作剧及其效果<br /><br />Author: Jeff Dray<br />作者：Jeff Dray<br /><br />翻译：<font style="LINE-HEIGHT: 1.3em" color="#990099">endurer</font><wbr />, 2008-08-16 第1版<br /><br />Category: General, Customer Relations, Training, windows, Help desk<br />分类：常规，客户关系，培训窗口，帮助桌面<br /><br />Tags: Computer, Desktops, Productivity, Hardware, Jeff Dray<br />标签：计算机，桌面电脑，生产率，硬件，Jeff Dray<br /><br />英文来源：<a href="http://blogs.techrepublic.com.com/helpdesk/?p=267&amp;tag=nl.e101" target="_blank">http://blogs.techrepublic.com.com/helpdesk/?p=267&amp;amp;tag=nl.e101</a><wbr /><br /><br />Over the years there have been many pranks played on users – some highly amusing and some downright malicious. When Windows 95 arrived and the new style desktop appeared, we had a great deal of fun with a user who insisted on fiddling with absolutely everything.<br /><br />这些年来有许多戏弄用户的恶作剧—有些非常有趣，而有些则是完全恶毒的。当Windows 95问世，并且新风格桌面出现时，我们有许多与一个用户相关的很大的趣事，该用户坚持独立地摆弄一切。<br /><br /><br />《endurer注：1、Over the years：经过多个年月<br />2、play on：演奏(利用,喷射,在...上闪耀,产生作用)<br />3、insist on：坚持(强调,坚决要求,坚决主张)<br />4、fiddle with：摆弄,玩弄,弄虚作假》<br /><br />——————————————————————————————————————-<br /><br />Back in the midst of time — well, 1995 actually — I installed my first copy of Windows 95 from a stack of 3.5 inch floppies. It was soon apparent that it was a bit different from the system we had been using up to that point.<br /><br />早在——其实就是1995年——我用一堆3.5英寸软盘安装了第1个Windows 95的拷贝。它与我们已在使用的系统的一点不同随即显现。<br /><br />《endurer注：1、in the midst of：在...当中》<br /><br /><br />As soon as it was rolled out to the first users, the problems started to pour in. These were mostly related to unfamiliarity and compatibility, but many questions related to altering settings. There being no security on this version, it was easy for users to destroy the system while trying to customize the appearance.<br /><br />它一交付给第一批用户，问题就开始大量涌现。这些问题大多与不熟悉和兼容性有关，但也有许多问题涉及到改变设置。这个版本并不安全，用户在试图自定义外观时很容易破坏系统。<br /><br />《endurer注：1、As soon as：一...就<br />2、roll out：辊平(转出)<br />3、pour in：大量涌入,蜂拥而至<br />4、be related to：与...有关》<br /><br />One guy became a regular headache, managing to delete important system files on more than one occasion, so we devised our vengeance.<br /><br />有一家伙逐渐变得经常令人头痛，他在不止一个场合设法删除了重要的系统文件.因此，我们制定了报复方案。<br /><br />《endurer注：1、manage to：达成；设法》<br /><br /><br />We took a screenshot of his desktop and set it as his wallpaper.<br /><br />我们取得了他的桌面屏幕截图并且将其设置为他的墙纸。<br /><br />Next we moved all his desktop icons into one stack, with My Computer on the top, then moved the stack onto the image of the My Computer image on the screen shot.<br /><br />然后，我们将他的桌面图标移成一堆，将“我的电脑”放在顶端，接着把这个堆移到屏幕截图上的“我的电脑”图像上。<br /><br />Then, we went back to our office and waited for the call.<br /><br />接下来，我们回到办公室等待电话。<br /><br />“Hi guys, I’ve got another problem — could one of you pop up and take a look please?”<br /><br />“喂，各位，我遇到了其它的问题——你们能派一位来看看吗？”<br /><br />《endurer注：1、Hi, guys! 喂！各位。》<br /><br /><br />“What seems to be the trouble?”<br /><br />“看来起像是什么麻烦呢？”<br /><br />“None of my desktop icons are working.”<br /><br />“我的桌面图标一个都没法用。”<br /><br />“What, none of them?”<br />“什么，一个都不行？”<br /><br />“No.”<br /><br />“是的。”<br /><br />“Have you tried them all?”<br /><br />“你已经把它们都试过了吗？”<br /><br />This user had set up almost a screen full of shortcuts and spent the next few minutes clicking through all of them. Eventually he returned to the phone:<br /><br />这名用户已经创建了几乎满屏幕的快捷方式，并花了接下来的几分钟来点击他们全部。最后，他回话：<br /><br />“The only one that is working is My Computer.”<br /><br />“惟一能工作的图标是我的电脑。”<br /><br />There was a combined drawing in of breath from our side of the phone connection.<br /><br />我方的电话连线已统一了口径。<br /><br />《endurer注：1、drawing in：引入的》<br /><br />“Just the My Computer icon, you say?”<br /><br />“你是说，就只有我的电脑图标？”<br /><br /><br />“Yes, is that bad?”<br /><br />“是的，坏了吗？”<br /><br /><br />More sucking of teeth.<br /><br /><br />“We’ll have to take it in for repair; it’s a well known problem, a new virus called Desktop Paralysis. It might take a day or two to fix.”<br /><br />“我们将只能取回维修；这是一个众所周知的问题，一个名为‘桌面瘫痪’的病毒。这可能需要一或两天来修复。”<br /><br />《endurer注：1、take in：接受(理解,包括,定阅,欺骗,收进,吸收,对...加以考虑)》<br /><br /><br />We took a trolley up to the second floor, collected the PC, and brought it back to our lair, where we put it up on a shelf until after the weekend.<br /><br />我们用手推车上二楼回收了那台电脑，并带回到我们的老窝，我们在那里把它放到架上，直至周末。<br /><br />When we returned the unit, minus the screenshot, the user was contrite; he wondered what he could do to avoid any further problems.<br /><br />当我们回到单位，减去屏幕截图，那个用户痛悔了；他想知道他可以做些什么来避免任何进一步的问题。<br /><br />We delivered our demands, in the form of sound advice. We showed him which system folders were out of bounds; we made sure that he connected to the Internet only through our proxy server, rather than through his own dial-up modem; and we brought the company’s policy on the standard corporate desktop image to his attention.<br /><br />我们以忠告的形式表达了我们的要求。我们表明，哪个系统文件夹越轨了；我们确信他只通过我们的代理服务器连接到互联网，而不是通过他自己的拨号调制解调器；我们提出了该公司规范企业桌面图像的政策引起他的注意。<br /><br />《endurer注：1、sound advice：忠告<br />2、out of bounds：越轨(越限,禁止入内)<br />3、bring on：引起(使成长,发展,前进,提出)》<br /><br />Surprisingly, he wrote a letter to the head of IT, praising us to the heights about our caring service, our in-depth product knowledge, and our readiness to help out in a crisis.<br /><br />令人感到意外地是，他写信给IT领导，高度地称赞了我们的体贴服务，深厚的产品知识，以及扶危救急的敏捷。<br /><br />《endurer注：1、out in：远在(到)》<br /><br />All we had thought of was getting through a couple of days without getting a call from him.<br /><br />我们全认定数天内没有接到他的电话。<br /><br />《endurer注：1、thoughts of：思考, 想法<br />2、get through：结束(做完,通过,到达)》]]></description> 
<gid isPermaLink="false">6782628@http://endurer.bokee.com/</guid> 
<dc:subject>系统维护</dc:subject> 
<dc:date>2008-08-16T23:51:59Z</dc:date> 
</item> 
<item> 
<title><![CDATA[译 > 基于行为的反病毒解决方案未能独挡一面]]></title> 
<link>http://endurer.bokee.com/6778386.html</link> 
<description><![CDATA[Behavior-based AV solutions cannot stand alone<br />基于行为的反病毒解决方案未能独挡一面<br /><br />Author: Tom Olzak<br />作者：Tom Olzak<br /><br />翻译：<font style="LINE-HEIGHT: 1.3em" color="#990099">endurer</font><wbr />，2008-08-09 第1版<br /><br />Category: Security, Virus, Threats, Intrusion Detection, Antivirus, Spyware, Malware, Internet<br />分类：安全，病毒，威胁，入侵检测，反病毒，间谍软件，恶意软件，互联网<br /><br />Tags: Malware, Behavior Analysis, Signature Comparison, Spyware, Adware &amp;amp; Malware, Cyberthreats, Viruses And Worms, Security, Tom Olzak <br />标签：恶意软件，行为分析，特征码比较，间谍软件，广告软件 &amp;amp; 恶意软件，电脑网络威胁，病毒和蠕虫，安全，Tom Olzak<br /><br />英文来源：<a onclick="function anonymous()
{
function anonymous()
{
showLinkBubble(this);return false
}
}" href="http://blogs.techrepublic.com.com/security/?p=531&amp;tag=nl.e101" target="_blank" link="http://blogs.techrepublic.com.com/security/?p=531&amp;tag=nl.e101">http://blogs.techrepublic.com.com/security/?p=531&amp;amp;tag=nl.e101</a><wbr /><br /><br /><i><wbr />Someday, behavior analysis might replace signature comparison in AV solutions.&amp;nbsp;&amp;nbsp;But I don’t think so.&amp;nbsp;&amp;nbsp;Like all security controls, these two approaches to detecting malware are layered defenses, supporting each other, identifying threats the other misses.</i><wbr /><br /><br /><i><wbr />某一天，行为分析可能在反病毒解决方案中取代特征码比较。但我不这么认为。像所有安全控制一样，这两种检测恶意软件的方法是层叠防御，互相支持，鉴别对方漏掉的威胁。<br /></i><wbr /><br /><br />Not every break-through security product is a good idea, an effective solution for protecting devices from the effects of malware attacks.&amp;nbsp;&amp;nbsp;This seems to be the case with a new product called NovaShield AntiMalware 2.0.<br /><br />并非每个突破性的安全产品都是一个好的主意，一个保护设备免受恶意软件攻击影响的有效解决方案。一款名为诺瓦盾反恶意软件（NovaShield AntiMalware） 2.0的新产品看来就是这种情况。<br /><br />Earlier this year, NovaShield, Inc. announced that it had received a $500,000 grant from the U.S. National Science Foundation (NSF) to enable completion and introduction of a new behavior-based anti-malware product (<a onclick="function anonymous()
{
function anonymous()
{
showLinkBubble(this);return false
}
}" href="http://www.redorbit.com/news/technology/1278540/novashield_receives_national_science_foundation_grant_for_breakthrough_malware_detection/index.html?source=r_technology" target="_blank" link="http://www.redorbit.com/news/technology/1278540/novashield_receives_national_science_foundation_grant_for_breakthrough_malware_detection/index.html?source=r_technology"><font style="LINE-HEIGHT: 1.3em" color="#003399">RedOrbit, 3 March 2008</font><wbr /></a><wbr />).&amp;nbsp;&amp;nbsp; Detecting malware based on behavior instead of the traditional signature comparison approach is touted as being a better defense against zero-day attacks.&amp;nbsp;&amp;nbsp;Attacks that occur before AV vendors can update customer signature files.&amp;nbsp;&amp;nbsp;I agree with this view, but I’ve yet to see a product that effectively defense using behavior heuristics alone, without support from signature reviews.&amp;nbsp;&amp;nbsp;NovaShield AntiMalware 2.0, released this week and priced at $19.95, seems to reinforce this point.<br /><br />今年早些时候，NovaShield, Inc声称已收到来自于美国国家科学基金会（NSF）的500，000美元拨款，以使新的基于行为的反恶意软件产品能够完成并推介（redorbit，2006年3月3日）。用基于行为替代传统的特征码比较的方法来检测恶意软件被用于一个为对付零日攻击的更好的防御。该攻击出现在防病毒产品供应商能升级客户特征码文件之前。我同意这个观点，但我还没有看到过一个单独使用行为启发式，无需特征码复审就能有效防御的产品。本周发布的、售价19.95美元的瓦盾反恶意软件2.0，似乎增援了这一点。<br /><br /><br />Neil J. Rubenking posted the results of his NovaShield test at <a onclick="function anonymous()
{
function anonymous()
{
showLinkBubble(this);return false
}
}" href="http://www.pcmag.com/article2/0,2817,2326826,00.asp" target="_blank" link="http://www.pcmag.com/article2/0,2817,2326826,00.asp"><font style="LINE-HEIGHT: 1.3em" color="#003399">pcmag.com</font><wbr /></a><wbr />.&amp;nbsp;&amp;nbsp;He gave it a rating of “Poor,” with the following bottom line comments:<br /><br />Neil J. Rubenking公布了他的诺瓦盾在pcmag.com测试的结果。他给了它“Poor（稍逊）”等级，及下列结果注释评论：<br /><br />《endurer注：1。bottom line：末行数字,结果》<br /><i><wbr />NovaShield AntiMalware aims to block malware by detecting malicious behaviors. In testing it was a near-total flop, though it detected several valid utilities as “high risk” threats. And it rendered two test systems unusable. There’s no reason to buy this when you can get ThreatFire free.</i><wbr /><br /><br /><i><wbr />诺瓦盾反恶意软件旨在通过检测恶意行为来封锁恶意软件。在测试中，它近乎彻底失败，尽管检测到了几个“高风险”威胁的有效利用。并且它提供的两个测试系统无法使用。当您可以免费得到ThreatFire时，就没有理由购买该产品了。</i><wbr /><br /><br />《endurer注：1。aim to：目的在于(旨在,志在)<br />2。ThreatFire前身为Cyberhawk，被PCTools收购后的改名为ThreatFire，是一个传统安全软件的辅助工具,可以弥补许多传统安全软件防护不足的地方,依照ThreatFire自己的说法,它可以与原有的反病毒、反间谍、防火墙等软件共存》<br />The only positive Rubenking had to say was it installed quickly.<br /><br />惟一可以说是稍挽颜面的是它安装快速。<br /><br />NovaShield isn’t the only AV vendor trying to get to market with a behavior analysis engine.&amp;nbsp;&amp;nbsp;As mentioned in the PC Magazine review, <a onclick="function anonymous()
{
function anonymous()
{
showLinkBubble(this);return false
}
}" href="http://www.threatfire.com/" target="_blank" link="http://www.threatfire.com/"><font style="LINE-HEIGHT: 1.3em" color="#003399">ThreatFire</font><wbr /></a><wbr /> is a free behavior detection product, but the company positions its product as a supplement to signature-based solutions.&amp;nbsp;&amp;nbsp;Not a replacement.&amp;nbsp;&amp;nbsp;Figure 1 depicts alleged detection improvements when using ThreatFire with popular AV products.<br /><br />诺瓦盾不是惟一一个尝试用行为分析引擎来获取市场的反病毒产品供应商。PC Magazine的评论曾提到，ThreatFire是一个免费的行为检测产品，但公司将该产品定位为基于特征码的解决方案的补充，而不是代替品。图1描绘了当ThreatFire与threatfire与流行的反病毒产品配合使用时的检测改善情况。<br /><br /><center><wbr /><a href="http://sz6.photo.store.qq.com/http_imgload.cgi?/rurl2=d07e0b4a923f9224cc4be6a3f38c1578709ee8f9d06537282f6c8495027f2c137d0727248a8110630ca43e6f8a49c171202c7ce8bc0b02462de0fed4a72ad21ccdd7d43b1a8ac6e13b84ab929c198f0c16bfc9d7" target="_blank"></a><img src="http://endurer.bokee.com/inc/ThreatFire.jpg" /><wbr /><br /><br /></center><center><b><wbr />Figure 1: Increased Protection when Using ThreatFire<br />图1：使用ThreatFire时增加的保护</b><wbr /></center><br />All the main AV vendors (e.g. McAfee, Trend, and Symantec) have integrated some level of behavior analysis into their malware defense products.&amp;nbsp;&amp;nbsp;However, none are making claims that behavior heuristics alone provide sufficient protection.<br /><br />所有的主要反病毒产品提供商（例如麦克菲, 趋势科技, 和 赛门铁克）已将一些级别的行为分析集成到其恶意软件防御产品中。然而，没有一个声称行为启发式单独提供了足哆的保护。<br /><br />Someday, behavior analysis might replace signature comparison in AV solutions.&amp;nbsp;&amp;nbsp;But I don’t think so.&amp;nbsp;&amp;nbsp;Like all security controls, these two approaches to detecting malware are layered defenses, supporting each other, identifying threats the other&amp;nbsp;&amp;nbsp;misses.&amp;nbsp;&amp;nbsp;Whether located on desktops or in intrusion defense appliances, only a combination of the two provides sufficient protection to networks and end-user devices.<b /><br />某一天，行为分析可能在反病毒解决办案中取代特征码比较。但我不这么认为。像所有安全控制一样，这两种检测恶意软件的方法是层叠防御，互相支持，鉴别对方漏掉的威胁。无论是在桌面系统或在入侵防御应用程序中，只有两者的结合才能向网络和终端用户设备提供足够的保护。 ]]></description> 
<guid isPermaLink="false">6778386@http://endurer.bokee.com/</guid> 
<dc:subject>名家访谈</dc:subject> 
<dc:date>2008-08-09T21:11:40Z</dc:date> 
</item> 

</channel> 
</rss> 