<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Security Line</title>
	<atom:link href="http://www.anansafe.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anansafe.com</link>
	<description>给你的电脑37℃安全感。</description>
	<pubDate>Sat, 15 Nov 2008 07:56:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>破坏王盗号器致使系统断网不能复制</title>
		<link>http://www.anansafe.com/2008/11/15/discredit-king-os-windows/</link>
		<comments>http://www.anansafe.com/2008/11/15/discredit-king-os-windows/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 07:56:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[安全技术]]></category>

		<category><![CDATA[QQ密码]]></category>

		<category><![CDATA[Rpcss.dll]]></category>

		<guid isPermaLink="false">http://www.anansafe.com/?p=104</guid>
		<description><![CDATA[该毒采用消息拦截的方式来盗取QQ游戏的帐号和密码，它在释放出子文件后，就会建立钩子，拦截用户输入的帐号信息。
病毒子文件gdipro.dll、rpcss.dll、sys17002.dll会被释放到%WINDOWS%＼SYSTEM32＼目录下，并写入注册表启动项，实现开机自 启动。其中gdipro.dll和rpcss.dll会被用于替换掉系统自身一个名为rpcss.dll的文件及其备份，使得病毒能够躲避系统安全模块和 安全软件的查杀。但也正因如此，当查杀该毒时，系统就可能因失去rpcss.dll文件而运行异常，比如网络中断、无法粘贴文档等。
而sys17002.dll则负责盗取帐号信息，盗取成功后就将赃物加密发送到病毒作者指定的地址。
用户如果进行手动查杀，需要将上述几个文件全部删除，然后将系统文件“C:＼WINDOWS＼system32＼srpcss.dll”改名为“C:＼WINDOWS＼system32＼rpcss.dll”，以恢复系统自身功能。同时，需对注册表做以下两项修改：
将“HKEY_LOCAL_MACHINE＼SYSTEM＼CurrentControlSet＼Services＼rpcss＼ObjectName”改为“NTAUTHORITY＼NetworkService”。
将“HKEY_LOCAL_MACHINE＼SYSTEM＼CurrentControlSet＼Services＼rpcss＼Parameters＼ServiceDll”改为“%SystemRoot%＼system32＼rpcss.dll”
完成以上步骤后，重启电脑，然后利用杀毒软件全盘查杀一次，系统就可以完全恢复正常了。
如果以上操作无效，可以参考爱毒霸社区版主vistalong的文章：HBkernel系列病毒（蝗虫军团）病毒的总结尝试恢复系统文件。
]]></description>
			<content:encoded><![CDATA[<p>该毒采用消息拦截的方式来盗取QQ游戏的帐号和密码，它在释放出子文件后，就会建立钩子，拦截用户输入的帐号信息。</p>
<p>病毒子文件gdipro.dll、rpcss.dll、sys17002.dll会被释放到%WINDOWS%＼SYSTEM32＼目录下，并写入注册表启动项，实现开机自 启动。其中gdipro.dll和rpcss.dll会被用于替换掉系统自身一个名为rpcss.dll的文件及其备份，使得病毒能够躲避系统安全模块和 安全软件的查杀。但也正因如此，当查杀该毒时，系统就可能因失去rpcss.dll文件而运行异常，比如网络中断、无法粘贴文档等。</p>
<p>而sys17002.dll则负责盗取帐号信息，盗取成功后就将赃物加密发送到病毒作者指定的地址。</p>
<p>用户如果进行手动查杀，需要将上述几个文件全部删除，然后将系统文件“C:＼WINDOWS＼system32＼srpcss.dll”改名为“C:＼WINDOWS＼system32＼rpcss.dll”，以恢复系统自身功能。同时，需对注册表做以下两项修改：</p>
<p>将“HKEY_LOCAL_MACHINE＼SYSTEM＼CurrentControlSet＼Services＼rpcss＼ObjectName”改为“NTAUTHORITY＼NetworkService”。</p>
<p>将“HKEY_LOCAL_MACHINE＼SYSTEM＼CurrentControlSet＼Services＼rpcss＼Parameters＼ServiceDll”改为“%SystemRoot%＼system32＼rpcss.dll”</p>
<p>完成以上步骤后，重启电脑，然后利用杀毒软件全盘查杀一次，系统就可以完全恢复正常了。</p>
<p>如果以上操作无效，可以参考爱毒霸社区版主vistalong的文章：HBkernel系列病毒（蝗虫军团）病毒的总结尝试恢复系统文件。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.anansafe.com/2008/11/15/discredit-king-os-windows/feed/</wfw:commentRss>
		</item>
		<item>
		<title>墨者安全专家二代使用评测</title>
		<link>http://www.anansafe.com/2008/10/24/mozhe2008nianshidazuiliuxingbingdubaogao/</link>
		<comments>http://www.anansafe.com/2008/10/24/mozhe2008nianshidazuiliuxingbingdubaogao/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 03:49:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[安全软件]]></category>

		<guid isPermaLink="false">http://www.anansafe.com/?p=70</guid>
		<description><![CDATA[墨者安全专家免疫革离术二代终于面世了。之前在媒体上出现很多关于墨者安全专家的报道，类似独创的免疫革离术、终身免费升级、终身免费杀毒、等耀眼的词汇，吸引了很多爱好者的关注。]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: left;"><span style="font-size: small;"><span style="color: #333333; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><a href="http://www.anansafe.com/wp-content/uploads/2008/11/mianyiweizhi.jpg"></a>墨者安全专家免疫革离术二代终于面世了。之前在媒体上出现很多关于墨者安全专家的报道，类似</span><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">独创的免疫革离术、终身免费升级、终身免费杀毒、等耀眼的词汇，吸引了很多爱好者的关注。笔者</span><span style="color: #333333; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">试用之余，也信手敲下一些感受，不敢妄称</span><span style="color: #333333; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">“</span></span><span style="color: #333333; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">深入分析</span><span style="color: #333333; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">”</span></span><span style="color: #333333; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">，恐有误导读者之嫌！</span><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> 以下几点是针对墨者的相关功能的亮点做的一些测试和比较。</span></span></p>
<p class="MsoNormal" style="text-align: left;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">（一）<span lang="EN-US">.</span>免疫革离术功能介绍</span></span></strong></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">据官方介绍：墨者安全专家的免疫革离术是融合了反</span><span lang="EN-US"><span style="font-family: Times New Roman;">rootkit</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">技术、用户权限管理技术和白名单技术并有机集成的免疫防御技术。普通应用程序在墨者免疫</span><span lang="EN-US"><span style="font-family: Times New Roman;">&#8220;</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">革离</span><span lang="EN-US"><span style="font-family: Times New Roman;">&#8220;</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">术下被剥夺了对系统关键资源如启动时自运行、安装驱动、服务、钩子等的访问权限，仅在确认无害而且是必须访问关键资源的应用程序才赋予相应的权限。这样未知新病毒和木马就无法在用户电脑系统中自动被安装、潜伏和实施攻击、窃取帐号密码等敏感资料。就像是未知的恶意软件被关进了牢房，无法对用户电脑造成伤害。而这一</span><span lang="EN-US"><span style="font-family: Times New Roman;">&#8220;</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">牢房</span><span lang="EN-US"><span style="font-family: Times New Roman;">&#8220;</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">又由墨者强大的反</span><span lang="EN-US"><span style="font-family: Times New Roman;">rootkit</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">技术又保证不会被突破。此外，墨者安全专家系统资源占用极小</span><span lang="EN-US"><span style="font-family: Times New Roman;">(</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">硬盘、内存、</span><span lang="EN-US"><span style="font-family: Times New Roman;">CPU…)</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">且基本无需更新，让用户的电脑系统资源尽最大可能地被用于用户的工作和娱乐。</span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">比起墨者第一代的革离术，开启第二代革离术显得更方便。用户在开启第一代革离术时，需要转换不同的磁盘格式，并且同时创建一个新帐户，甚至还要修改一些目录属性，而第二代革离术只需要点“立即开启”，一秒钟内便轻松开启了革离术。</span></span><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（如图</span><span lang="EN-US"><span style="font-family: Times New Roman;">1</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">）</span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">   <a href="http://www.anansafe.com/images/image001.jpg"><img class="alignnone" title="test" src="http://www.anansafe.com/images/image001.jpg" alt="" width="758" height="396" /></a></span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（二）</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">免疫革离术防毒测试</span></strong></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">免疫革离术在功能上更加易用了，但是会不会在安全上打折扣呢？笔者在未安装杀毒软件的情况下，基于墨者免疫革离术开启的环境里运行了数十款九月份比较流行的木马，截上几张比较有代表性的图片。</span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><a href="http://www.anansafe.com/wp-content/uploads/2008/10/image001.jpg"><img class="aligncenter" title="imags003.jpg" src="http://www.anansafe.com/images/image003.jpg" alt="" width="479" height="123" /></a></span></span></p>
<p class="MsoNormal" style="text-align: center;"> </p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span lang="EN-US"><span style="mso-spacerun: yes"><span style="font-family: Times New Roman;">   </span></span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（图</span><span lang="EN-US"><span style="font-family: Times New Roman;">2. </span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">号称饿死杀毒软件厂商的病毒——中华吸血鬼立刻胎死腹中）</span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><img class="alignnone" title="image005.jpg" src="http://www.anansafe.com/images/image005.jpg" alt="" width="420" height="231" /></span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（图</span><span lang="EN-US"><span style="font-family: Times New Roman;">3. </span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">横行一时的机器狗木马变种立刻出错并且无法运行）</span></span></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><img class="alignnone" title="image007.jpg" src="http://www.anansafe.com/images/image007.jpg" alt="" width="425" height="276" /></span></span></span></p>
<p style="text-align: center;">
<p style="text-align: center;">
<div></div>
<div><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></span></div>
<p><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></p>
<p class="MsoNormal" style="text-align: left;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">大家可以看到墨者二代革离术依旧把电脑进行了病毒免疫，让那些未知的病毒木马都毫无用处。</span></span></p>
<div class="MsoNormal" style="text-align: left;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（三）</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">免疫革离术资源占用情况</span></strong></span></span></div>
<div></div>
<p><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">资源占用情况是用户在选择一款放心安全软件所必看的参数，我们来看看墨者安全专家在这方面的具体数据</span></span> </p>
<p> </p>
<p></span></p>
<p class="MsoNormal" style="TEXT-ALIGN: center; LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"><img class="aligncenter" title="image009.jpg" src="http://www.anansafe.com/images/image009.jpg" alt="" width="468" height="403" /></p>
<div></div>
<div><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></span></div>
<p><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<div></div>
<p></span></span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<p></font></font></span><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<p></font></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（图</span><span lang="EN-US"><span style="font-family: Times New Roman;">5.</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者安全专家所运行的进程以及内存使用情况）</span></span></span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0">
<p style="text-align: center;">
<table class="MsoNormalTable" style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: auto 6.75pt; BORDER-COLLAPSE: collapse; BACKGROUND: #99cc00; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid windowtext .5pt; mso-table-lspace: 9.0pt; mso-table-rspace: 9.0pt; mso-table-anchor-vertical: paragraph; mso-table-anchor-horizontal: margin; mso-table-left: 86.2pt; mso-table-top: 23.15pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext" border="1" cellspacing="0" cellpadding="0" align="left">
<tbody>
<tr style="height: 8.25pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0cm; width: 140.4pt; padding-top: 0cm; height: 8.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; border: windowtext 1pt solid;" width="187" valign="top">
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">软件名称</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 8.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者安全专家</span></span></p>
</td>
</tr>
<tr style="height: 17.05pt; mso-yfti-irow: 1;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 17.05pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">安装文件磁盘占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 17.05pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">4.08MB</span></span></span></p>
</td>
</tr>
<tr style="height: 14.8pt; mso-yfti-irow: 2;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 14.8pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">安装后磁盘占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 14.8pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">22.4MB</span></span></span></p>
</td>
</tr>
<tr style="height: 23.25pt; mso-yfti-irow: 3;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 23.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">未开启革离术内存占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 23.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-family: Times New Roman;"><span style="font-size: small;">11.6MB</span></span></span></p>
</td>
</tr>
<tr style="height: 15.85pt; mso-yfti-irow: 4;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15.85pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">未开启革离术</span><span lang="EN-US"><span style="font-family: Times New Roman;">CPU</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15.85pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span lang="EN-US"><span style="font-family: Times New Roman;">0</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（不占用）</span></span></p>
</td>
</tr>
<tr style="height: 15pt; mso-yfti-irow: 5;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">开启革离术内存占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">22.4MB</span></span></span></p>
</td>
</tr>
<tr style="height: 23.25pt; mso-yfti-irow: 6; mso-yfti-lastrow: yes;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 140.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 23.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="187" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: 86.25pt; mso-element-top: 23.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">开启革离术</span><span lang="EN-US"><span style="font-family: Times New Roman;">CPU</span></span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 99pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 23.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="132" valign="top">
<p class="MsoNormal"><span style="font-size: small;"><span lang="EN-US"><span style="font-family: Times New Roman;">0 </span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（不占用）</span></span></p>
</td>
</tr>
</tbody>
</table>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> <span style="font-size: small;"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">上面的图和数据看来，墨者这款安全软件的确做到了它所说的“让用</span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">户的电脑系统资源尽最大可能地被用于用户的工作和娱乐。”</span><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="text-align: center;"><strong style="mso-bidi-font-weight: normal"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="text-align: left;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal"><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终身免费杀毒软件</span></strong></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者的免疫革离术主要作用发挥在用户还未中毒前，以及安装后将针对新的未知病毒和木马进行防御。而对于一些已经中招的用户，或者需要把病毒彻底删除干净的网民，可以通过墨者这个安全平台来下载杀毒软件。特别要说明的是墨者提供的软件是终身免费的，包括杀毒软件的病毒库升级也同样免费。下图是墨者的</span><span lang="EN-US"><span style="font-family: Times New Roman;">OEM</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">合作伙伴，全球前三位的顶级杀毒企业趋势科技的个人杀毒软件。</span></span></p>
<p class="MsoNormal" style="text-align: center;"><img class="alignnone" title="image011.jpg" src="http://www.anansafe.com/images/image011.jpg" alt="" width="349" height="258" /></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（</span><span lang="EN-US"><span style="mso-spacerun: yes"><span style="font-family: Times New Roman;">  </span></span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">图</span><span lang="EN-US"><span style="font-family: Times New Roman;">6</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者版终身免费趋势杀毒专家）</span></span></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;">
<p style="text-align: center;">
<div></div>
<p><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">一个是墨者革离术免疫未知病毒木马，一个是顶级杀毒企业提供的终身免费升级的查杀软件，这样的组合基本上用户可以放心使用了。不过相对免疫革离术，趋势杀毒占用的资源是比较大，但是杀毒效果着实没有让我们失望，笔者测试用的</span><span lang="EN-US"><span style="font-family: Times New Roman;">36</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">个已知的病毒样本均被都被查出来了</span></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（见图</span><span lang="EN-US"><span style="font-family: Times New Roman;">7</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">）。</span></span></p>
<p> </p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><img class="alignnone" title="image013.jpg" src="http://www.anansafe.com/images/image013.jpg" alt="" width="420" height="260" /></span></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">图</span><span lang="EN-US"><span style="font-family: Times New Roman;">7.</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">趋势病毒扫描）</span></span></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0">
<div class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 21pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 2.0"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></div>
<div></div>
<div><span lang="EN-US"></span></div>
<p><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"></p>
<table class="MsoNormalTable" style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: auto 6.75pt; BORDER-COLLAPSE: collapse; BACKGROUND: #99cc00; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid windowtext .5pt; mso-table-lspace: 9.0pt; mso-table-rspace: 9.0pt; mso-table-anchor-vertical: paragraph; mso-table-anchor-horizontal: margin; mso-table-left: center; mso-table-top: 88.15pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext" border="1" cellspacing="0" cellpadding="0" align="left">
<tbody>
<tr style="height: 29.25pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes;">
<td style="padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0cm; width: 122.4pt; padding-top: 0cm; height: 29.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; border: windowtext 1pt solid;" width="163" valign="top">
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">软件名称</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 29.25pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者趋势杀毒专家</span></span></p>
</td>
</tr>
<tr style="height: 15pt; mso-yfti-irow: 1;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">安装文件磁盘占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt 3.6pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">41.6MB</span></span></span></p>
</td>
</tr>
<tr style="height: 22.5pt; mso-yfti-irow: 2;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">安装、升级后磁盘占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">222MB</span></span></span></p>
</td>
</tr>
<tr style="height: 22.5pt; mso-yfti-irow: 3;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">未扫描内存占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">46.12MB</span></span></p>
</td>
</tr>
<tr style="height: 22.5pt; mso-yfti-irow: 4;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">未扫描<span lang="EN-US">CPU</span>占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">0</span><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">（未占用）</span></span></p>
</td>
</tr>
<tr style="height: 24.75pt; mso-yfti-irow: 5;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 24.75pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">扫描中内存占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 24.75pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span style="font-size: small;">101MB</span></span></p>
</td>
</tr>
<tr style="height: 22.5pt; mso-yfti-irow: 6; mso-yfti-lastrow: yes;">
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: windowtext 1pt solid; width: 122.4pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="163" valign="top">
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-element: frame; mso-element-frame-hspace: 9.0pt; mso-element-wrap: around; mso-element-anchor-vertical: paragraph; mso-element-anchor-horizontal: margin; mso-element-left: center; mso-element-top: 88.15pt; mso-height-rule: exactly"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">扫描中</span><span lang="EN-US"><span style="font-family: Times New Roman;">CPU</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">占用</span></span></p>
</td>
<td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #d4d0c8; padding-left: 5.4pt; padding-bottom: 0cm; border-left: #d4d0c8; width: 129.75pt; padding-top: 0cm; border-bottom: windowtext 1pt solid; height: 22.5pt; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" width="173" valign="top">
<p class="MsoNormal"><span style="font-size: small;"><span lang="EN-US"><span style="font-family: Times New Roman;">0 </span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（未占用）</span></span></p>
</td>
</tr>
</tbody>
</table>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p><span lang="EN-US"><font style="font-size: small;" face="Times New Roman" size="3"> </p>
<p></font></span></span> </p>
<p class="MsoNormal" style="TEXT-ALIGN: left; TEXT-INDENT: 21pt; MARGIN: 0cm 0cm 0pt; mso-char-indent-count: 2.0" align="left"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">现在各个安全软件里都加了一个系统漏洞修复的工具，墨者也不例外。但是表现不佳，笔者使用</span><span lang="EN-US"><span style="font-family: Times New Roman;">360</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">安全卫士扫出两个漏洞，而使用墨者革离术只扫描出一个安全漏洞。据官方解释，墨者仅对一些对会造成较高安全隐患的漏洞进行补丁更新，一些只有在特定情况下才会发生异常的补丁更新墨者不会对其处理，以节省用户时间。</span></span></p>
<p class="MsoNormal" style="text-align: center;" align="left"><img class="alignnone" title="015" src="http://www.anansafe.com/images/image015.jpg" alt="" width="444" height="315" /></p>
<p class="MsoNormal" style="TEXT-ALIGN: center; LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto"> </p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><span style="font-size: small;"><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">（</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">8.</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">墨者安全专家</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">&#8211;</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">漏洞修复）</span></span></p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"> </p>
<p class="MsoNormal" style="text-align: center;"> <img class="aligncenter" title="image017.jpg" src="http://www.anansafe.com/images/image017.jpg" alt="" width="407" height="294" /></p>
<p class="MsoNormal" style="TEXT-ALIGN: center; LINE-HEIGHT: 15pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">墨者安全专家以及</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">360</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">安全卫士的漏洞补丁均是从微软官方网站下载。所以下载速度落差不大。</span></span></p>
<p class="MsoNormal" style="text-align: center;"><img class="alignnone" title="019" src="http://www.anansafe.com/images/image019.jpg" alt="" width="359" height="225" /></p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><span style="font-size: small;"><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">（图</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">10 360</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">安全卫士补丁下载）</span></span></p>
<p> </p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><img class="alignnone" title="020.jpg" src="http://www.anansafe.com/images/image020.jpg" alt="" width="497" height="265" /></span></p>
<div></div>
<p><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: small;"><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">(</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">图</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">11.</span></span><span style="color: #000000; font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: ˎ̥; mso-hansi-font-family: ˎ̥;">墨者安全专家补丁下载</span><span style="color: #000000; font-family: ˎ̥; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">)</span></span></span></p>
<p> </p>
<p> </p>
<p> </p>
<p></span></p>
<p class="MsoNormal" style="text-align: center;"><img class="alignnone" title="021" src="http://www.anansafe.com/images/image021.jpg" alt="" width="717" height="602" /></p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><span style="font-size: 10pt; color: #000000; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt; mso-ansi-language: ZH-CN;">（图12.墨者安全专家，隐私清除功能主界面）</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 10pt; color: #000000; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt; mso-ansi-language: ZH-CN;">在隐私清除功能上360安全卫士显得更加专业，可列出更多的清除现象供用户选择，但是在清除结果上与墨者并无落差。</span><span style="font-size: 10pt; color: #000000; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt; mso-ansi-language: ZH-CN;"><img class="alignnone" title="023" src="http://www.anansafe.com/images/image023.jpg" alt="" width="810" height="587" /></span><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">综合以上几个方面的评测，<span style="mso-bidi-font-weight: bold;">墨者安全专家还是一款很不错的免费防御软件。最大的特点在于可以防御未知的新病毒和木马，</span>同时虽然墨者可以和一些主流杀毒软件兼容</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">弥补了<span style="mso-bidi-font-weight: bold;">现在杀毒软件所存在的一个弊端。</span>当然，墨者也有不尽如人意的地方！其自带的趋势科技终身免费杀毒软件在系统资源占用以及稳定性上都表现不佳，墨者还需要加强跟更多的杀毒软件、防火墙进行有效的兼容。</span><span lang="EN-US"><span style="mso-spacerun: yes;"><span style="font-family: Times New Roman;">  </span></span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">如果墨者能有自己的杀毒模块并且兼容其它的杀毒软件，那么对于安全方面的贡献应该更显著些。</span></span></p>
<p class="MsoNormal" style="text-align: left; margin: 0cm 0cm 0pt;" align="left"> </p>
<p> </p>
<p> </p>
<p> </p>
<p></span><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">漏洞修复</span></span></strong></p>
<p></span></p>
<p></font></font></font></font></span><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<p></font></font></font></span><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<p></font></font></span><font style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';" face="宋体"></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
<p></font></span></p>
<p class="MsoNormal" style="LINE-HEIGHT: 15pt; TEXT-INDENT: 31.5pt; MARGIN: 7.5pt 0cm 0pt; mso-margin-bottom-alt: auto; mso-char-indent-count: 3.0"> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.anansafe.com/2008/10/24/mozhe2008nianshidazuiliuxingbingdubaogao/feed/</wfw:commentRss>
		</item>
		<item>
		<title>墨者2008年十大最流行病毒报告</title>
		<link>http://www.anansafe.com/2008/10/21/the-most-popular-virus-in-2008/</link>
		<comments>http://www.anansafe.com/2008/10/21/the-most-popular-virus-in-2008/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 03:23:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[新闻业界]]></category>

		<guid isPermaLink="false">http://www.anansafe.com/?p=67</guid>
		<description><![CDATA[2008年上半年，电脑病毒、木马的数量依然保持着高速增长，新病毒不断涌现，一些“老”病毒在大量下载器病毒的带动下也异常活跃。 与此同时，病毒、木马与安全软件之间的对抗日益加剧，以机器狗、磁碟机、AUTO木马群为代表的对抗型病毒已经成为广大用户电脑安全的主要威胁。]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 15pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者</span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 15pt;" lang="EN-US"><span style="font-family: Times New Roman;">2008</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 15pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">年十大最流行病毒报告</span></strong><strong style="mso-bidi-font-weight: normal;"></strong></p>
<p class="MsoNormal" style="text-align: center; margin: 0cm 0cm 0pt;" align="center"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="text-indent: 15.75pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.5;"><span style="font-size: small;"><span lang="EN-US"><span style="font-family: Times New Roman;">2008</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">年上半年，电脑病毒、木马的数量依然保持着高速增长，新病毒不断涌现，一些“老”病毒在大量下载器病毒的带动下也异常活跃。</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">与此同时，病毒、木马与安全软件之间的对抗日益加剧，以机器狗、磁碟机、</span><span lang="EN-US"><span style="font-family: Times New Roman;">AUTO</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">木马群为代表的对抗型病毒已经成为广大用户电脑安全的主要威胁。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">一</span><span style="font-family: Times New Roman;"> <span lang="EN-US">.</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">机器狗</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan.Psw.Onlinegame.Dog </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒中文名：</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">机器狗</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：木马</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win9X/2000/XP/NT/Me</span></span></span></p>
<p class="MsoNormal" style="text-indent: 10.5pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述</span><span lang="EN-US"><span style="font-family: Times New Roman;">:</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">机器狗病毒因最初的版本采用电子狗的照片做图标而被网民命名为“机器狗”，该病毒变种繁多，多表现为杀毒软件无法正常运行。该病毒的主要危害是充当病毒木马下载器，与</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者病毒相似，病毒通过修改注册表，让大多数流行的安全软件失效，然后疯狂下载各种盗号工具或黑客工具，给用户电脑带来严重的威胁。机器狗病毒直接操作磁盘以绕过系统文件完整性的检验，通过感染系统文件（比如</span><span lang="EN-US"><span style="font-family: Times New Roman;">explorer.exe</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">，</span><span lang="EN-US"><span style="font-family: Times New Roman;">userinit.exe,winhlp32.exe</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">等）达到隐蔽启动；通过底层技术穿透冰点，影子等还原系统软件导致大量网吧用户感染病毒，无法通过还原来保证系统的安全；通过修复</span><span lang="EN-US"><span style="font-family: Times New Roman;">SSDT</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（就是恢复安全软件对系统关键</span><span lang="EN-US"><span style="font-family: Times New Roman;">API</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">的</span><span lang="EN-US"><span style="font-family: Times New Roman;">HOOK</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">），映像挟持，进程操作等方法使得大量的安全软件失去作用；联网下载大量的盗号木马给广大网民的网络虚拟财产造成巨大威胁，部分机器狗变种还会下载</span><span lang="EN-US"><span style="font-family: Times New Roman;">ARP</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">恶意攻击程序对所在局域网（或者服务器）进行</span><span lang="EN-US"><span style="font-family: Times New Roman;">ARP</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">欺骗影响网络安全。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes;">       </span></span></span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">二</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">磁碟机</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan.Psw.Onlinegame.CD</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒中文名：磁碟机</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：木马</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win9X/2000/XP/NT/Me</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">简介</span><span lang="EN-US"><span style="font-family: Times New Roman;">:</span></span></span></p>
<p class="MsoNormal" style="text-indent: 11pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0;"><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">电脑感染</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">“</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">磁碟机</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">”</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">变种病毒后，症状表现为运行任意程序时系统经常性死机或长时间卡住不动，病毒会以加密感染的方式感染除系统盘外的其它所有分区内的</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">EXE</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">文件、网页文件、</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">RAR</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">和</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">ZIP</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">压缩包中的文件等。被感染的文件图标变为</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">16</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">位图标，图标变得模糊，类似马赛克状。病毒一旦发现带有符合安全工具软件相关的窗口名存在，就会强行将其关闭（发送洪水似垃圾消息）。在所有盘符下生成</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">“autorun.inf”</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">和病毒程序文件体，并且会实时检测保护这些文件。病毒会下载</span><span style="font-size: 11pt;" lang="EN-US"><span style="font-family: Times New Roman;">20</span></span><span style="font-size: 11pt; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">余种木马病毒，用以窃取中毒电脑中有价值的隐私信息。病毒通过十余种方式实现自我保护和避免被杀毒软件查杀，其隐藏和自我保护技术超过机器狗。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">三</span><span lang="EN-US"><span style="font-family: Times New Roman;">.AV</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan/Anti-AV</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒中文名：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Av</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：木马</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win9X/2000/XP/NT/Me</span></span></span></p>
<p class="MsoNormal" style="text-indent: 10.5pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述</span><span lang="EN-US"><span style="font-family: Times New Roman;">:</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者”即＂帕虫＂是一系列反击杀毒软件，破坏系统安全模式、植入木马下载器的病毒，它指的是一批具备如下破坏性的病毒、木马和蠕虫。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者”名称中的“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">”即为英文“反病毒”</span><span lang="EN-US"><span style="font-family: Times New Roman;">(Anti-Virus)</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">的缩写。它能破坏大量的杀毒软件和个人防火墙的正常监控和保护功能</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">导致用户电脑的安全性能下降</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">容易受到病毒的侵袭。同时它会下载并运行其他盗号病毒和恶意程序</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">严重威胁到用户的网络个人财产。此外</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">它还会造成电脑无法进入安全模式</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">并可通过可移动磁盘传播。目前该病毒已经衍生多个新变种</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">有可能在互联网上大范围传播。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者”设计中最恶毒的一点是，用户即使重装操作系统也无法解决问题：格式化系统盘重装后很容易被再次感染。用户格式化后，只要双击其他盘符，病毒将再次运行。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者”会使用户电脑的安全防御体系被彻底摧毁，安全性几乎为零。它还自动连接到某网站，下载数百种木马病毒及各类盗号木马、广告木马、风险程序，在用户电脑毫无抵抗力的情况下，鱼贯而来，用户的网银、网游、</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">账号密码以及机密文件都处于极度危险之中。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">四</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">网游窃贼</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan/PSW.GamePass.Gen<strong style="mso-bidi-font-weight: normal;"></strong></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒中文名：网游大盗</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：木马</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win 9X/ME/NT/2000/XP/2003</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan/PSW.GamePass</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“网游大盗”是一个盗取网络游戏帐号的木马程序，会在被感染计算机系统的后台秘密监视用户运行的所有应用程序窗口标题，然后利用键盘钩子、内存截取或封包截取等技术盗取网络游戏玩家的游戏帐号、游戏密码、所在区服、角色等级、金钱数量、仓库密码等信息资料，并在后台将盗取的所有玩家信息资料发送到骇客指定的远程服务器站点上。致使网络游戏玩家的游戏帐号、装备物品、金钱等丢失，会给游戏玩家带去不同程度的损失。</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“网游大盗”会通过在被感染计算机系统注册表中添加启动项的方式，来实现木马开机自启动。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">五</span><span style="color: #000000;"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">下载者</span><span style="font-family: Times New Roman;"><span style="color: #000000;"> </span><span style="color: #ff0000;"><span style="mso-spacerun: yes;">  </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="color: #ff0000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">（</span><span style="color: #ff0000;"><a href="http://hi.baidu.com/mp_man/blog/item/057144db564526ddb7fd482f.html"><span style="color: #800080; font-family: Times New Roman;">http://hi.baidu.com/mp_man/blog/item/057144db564526ddb7fd482f.html</span></a><span style="mso-spacerun: yes;"><span style="font-family: Times New Roman;">  </span></span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="color: #ff0000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">）</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;"><span style="font-size: small;">病毒名称：</span></span><span style="font-size: small;"><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;">w32.Troja.downloader<br />
</span><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">中</span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"> </span><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">文</span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"> </span><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">名：下载者</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;"><span style="font-size: small;">病毒类型：木马下载器</span></span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"><br />
</span><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">危害等级：</span><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体;">★★★★</span></span></p>
<p class="MsoNormal" style="text-indent: -26.25pt; margin: 0cm 0cm 0pt 26.25pt; mso-char-indent-count: -2.5;"><span style="font-size: small;"><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体;">描述<span lang="EN-US">:</span></span><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana; mso-bidi-font-size: 10.5pt;">该病毒为</span><span style="color: #000000; font-family: Verdana; mso-bidi-font-size: 10.5pt;">Windows</span><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana; mso-bidi-font-size: 10.5pt;">平台下通过网络下载</span><span style="color: #000000; font-family: Verdana; mso-bidi-font-size: 10.5pt;">QQ</span><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana; mso-bidi-font-size: 10.5pt;">木马、网游木或其它病毒的下载器病毒运行后将自己伪装成伪系统正常文件，并利用特殊技术将病毒代码注入到系统正常进程中，以绕过网络防火墙的监视。然后下载其它病毒。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: small;"><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">六</span><span style="color: #000000;"><span style="font-family: Times New Roman;">.Rootkit</span></span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 21.75pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">病毒名称：</span><span style="color: #000000; mso-bidi-font-size: 10.5pt;"><span style="font-family: Times New Roman;">Rootkit.Agent.xd</span></span></span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"><br />
</span><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">中</span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"> </span><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">文</span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;"> </span><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">名：</span><span style="font-family: Tahoma; mso-bidi-font-size: 10.5pt;">Rootkit</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 21.75pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">病毒类型：病毒</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 21.75pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: Tahoma; mso-hansi-font-family: Tahoma; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: Tahoma;">危害等级：</span><span style="font-family: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体;">★★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span lang="EN-US"><span style="font-family: Times New Roman;"> Rootkit</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">基本是由几个独立程序组成，一个典型</span><span lang="EN-US"><span style="font-family: Times New Roman;">rootkit</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">包括：</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">以太网嗅探器程序，用于获得网络上传输的用户名和密码等信息。</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">特洛伊木马程序，为攻击者提供后门。</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">隐藏攻击者目录和进程的程序。还包括一些日志清理工具，攻击者用其删除</span><span lang="EN-US"><span style="font-family: Times New Roman;">wtmp</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">、</span><span lang="EN-US"><span style="font-family: Times New Roman;">utmp</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">和</span><span lang="EN-US"><span style="font-family: Times New Roman;">lastlog</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">等日志文件中有关自己行踪的条目。</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">复杂的</span><span lang="EN-US"><span style="font-family: Times New Roman;">rootkit</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">还可以向攻击者提供</span><span lang="EN-US"><span style="font-family: Times New Roman;">telnet</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">、</span><span lang="EN-US"><span style="font-family: Times New Roman;">shell</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">和</span><span lang="EN-US"><span style="font-family: Times New Roman;">finger</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">等服务。还包括一些用来清理</span><span lang="EN-US"><span style="font-family: Times New Roman;">/var/log</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">和</span><span lang="EN-US"><span style="font-family: Times New Roman;">/var/adm</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">目录中其</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">它文件的脚本。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">七</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">灰鸽子</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 21.75pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Backdoor/Huigezi</span></span></span></p>
<p class="MsoNormal" style="text-indent: 21pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 2.0;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒中文名：灰鸽子</span></span></p>
<p class="MsoNormal" style="text-indent: 21pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 2.0;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：后门</span></span></p>
<p class="MsoNormal" style="text-indent: 21pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 2.0;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★</span></span></p>
<p class="MsoNormal" style="text-indent: 21pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 2.0;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win 9X/ME/NT/2000/XP/2003</span></span></span></p>
<p class="MsoNormal" style="text-indent: 21pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 2.0;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Backdoor/Huigezi </span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“灰鸽子”是后门家族的最新成员之一，采用</span><span lang="EN-US"><span style="font-family: Times New Roman;">Delphi</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">语言编写，并经过加壳保护处理。“灰鸽子”运行后，会自我复制到被感染计算机系统的指定目录下，并重新命名保存</span><span lang="EN-US"><span style="font-family: Times New Roman;">(</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">文件属性设置为：只读、隐藏、存档</span><span lang="EN-US"><span style="font-family: Times New Roman;">)</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">。“灰鸽子”是一个反向连接远程控制后门程序，运行后会与骇客指定远程服务器地址进行</span><span lang="EN-US"><span style="font-family: Times New Roman;">TCP/IP</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">网络通讯。中毒后的计算机会变成网络僵尸，骇客可以远程任意控制被感染的计算机，还可以窃取用户计算机里所有的机密信息资料等，会给用户带去不同程度的损失。“灰鸽子”会把自身注册为系统服务，以服务的方式来实现开机自启动运行。“灰鸽子”主安装程序执行完毕后，会自我删除。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 21.75pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">八</span><span style="color: #000000;"><span style="font-family: Times New Roman;">.U</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="color: #000000; font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘病毒</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Checker/Autorun</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒中文名：</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：蠕虫</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">一周感染量：</span></span><span style="font-size: 10pt; color: #000000; font-family: Arial;">18184</span><span style="font-size: 10pt; color: #000000; font-family: 宋体; mso-ascii-font-family: Arial; mso-hansi-font-family: Arial; mso-bidi-font-family: Arial;">台</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win 9X/ME/NT/2000/XP/2003</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Checker/Autorun</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”是一个利用</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘等移动存储设备进行自我传播的蠕虫病毒。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">运行后，会自我复制到被感染计算机系统的指定目录下，并重新命名保存。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”会在被感染计算机系统中的所有磁盘根目录下创建“</span><span lang="EN-US"><span style="font-family: Times New Roman;">Autorun.inf</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">”文件和蠕虫病毒主程序体，来实现用户双击盘符而启动运行“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”蠕虫病毒主程序体的目的。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”还具有利用</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘、移动硬盘等移动存储设备进行自我传播的功能。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”运行时，可能会在被感染计算机系统中定时弹出恶意广告网页，或是下载其它恶意程序到被感染计算机系统中并调用安装运行，会给用户带去不同程度的损失。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">U</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">盘寄生虫”</span><span style="font-family: Times New Roman;"> </span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">会通过在被感染计算机系统注册表中添加启动项的方式，来实现蠕虫开机自启动。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">九</span><span lang="EN-US"><span style="font-family: Times New Roman;">.QQ</span></span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗</span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan/Psw.Ala.QQpass</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒中文名：</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗</span><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">病毒类型：蠕虫</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';"><span style="font-size: small;">危险级别：★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win 9X/ME/NT/2000/XP/2003</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">描述：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Trojan/PSW.QQPass</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗”是木马家族的最新成员之一，采用高级语言编写，并经过加壳保护处理。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗”运行时，会在被感染计算机的后台搜索用户系统中有关</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">注册表项和程序文件的信息，然后强行删除用户计算机中的</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">医生程序“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQDoctorMain.exe</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">”、“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQDoctor.exe</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">”和“</span><span lang="EN-US"><span style="font-family: Times New Roman;">TSVulChk.dat</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">”文件，从而来保护自身不被查杀。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗”运行时，会在后台盗取计算机用户的</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">帐号、</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">密码、会员信息、</span><span lang="EN-US"><span style="font-family: Times New Roman;">ip</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">地址、</span><span lang="EN-US"><span style="font-family: Times New Roman;">ip</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">所属区域等信息资料，并且会在被感染计算机后台将窃取到的这些信息资料发送到骇客指定的远程服务器站点上或邮箱里，会给被感染计算机用户带去不同程度的损失。“</span><span lang="EN-US"><span style="font-family: Times New Roman;">QQ</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">大盗”通过在注册表启动项中添加键的方式，来实现开机木马自启动。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">十</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></strong><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;" lang="EN-US"><span style="font-family: Times New Roman;"> Flash</span></span></strong><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">漏洞攻击器</span></strong><strong></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒名称：</span></strong><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;" lang="EN-US"><span style="font-family: Times New Roman;">Hack.Exploit.Swf.A</span></span></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒中文名：</span></strong><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;" lang="EN-US"><span style="font-family: Times New Roman;">Flash</span></span></strong><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">漏洞攻击器</span></strong><strong></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">病毒类型：蠕虫</span></strong><strong></strong></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><strong><span style="font-weight: normal; font-family: 宋体; mso-bidi-font-weight: bold; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">危害级别：</span></strong><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">★★★★</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">一周感染量：</span><span style="font-family: Verdana; mso-bidi-font-size: 10.5pt;">1890453</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">影响平台：</span><span lang="EN-US"><span style="font-family: Times New Roman;">Win 9X/ME/NT/2000/XP/2003</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">这是一个黑客程序，可以破坏</span><span lang="EN-US"><span style="font-family: Times New Roman;">Flash</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">插件的安全机制，使其它病毒获取系统权限，侵入用户电脑。目前每天有数十万台电脑被此病毒感染，危害十分严重。此病毒会被植入</span><span lang="EN-US"><span style="font-family: Times New Roman;">“</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">挂马网站</span><span lang="EN-US"><span style="font-family: Times New Roman;">”</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">中，用户浏览时就可能中毒。目前已截获的主要是木马下载器病毒，它们会从网上下载其它多种盗号木马，窃取流行网络游戏的账号和装备。</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="mso-spacerun: yes;"><span style="font-size: small; font-family: Times New Roman;">  </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: small;"><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">墨者安全专家认为：尽管杀毒厂商有对以上病毒作出反应，但是传统的特征码扫描技术被病毒木马打击的溃不成军，如果下一个类似“磁碟机”“</span><span lang="EN-US"><span style="font-family: Times New Roman;">AV</span></span><span style="font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">终结者”出现的时候谁来保护杀毒软件，网络安全现在的问题不仅仅是传统厂家与黑客之间的博弈，面对日益完善的黑色产业链，靠杀毒软件支持的时代已经过去，安全厂商应该把防御放到首要未知，主动免疫的时代已经来临。</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.anansafe.com/2008/10/21/the-most-popular-virus-in-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>奇虎郑文彬：还原系统保护技术原理和攻防</title>
		<link>http://www.anansafe.com/2008/10/10/return-to-original-state-system-preservation-technology-principle-and-attack-and-defense/</link>
		<comments>http://www.anansafe.com/2008/10/10/return-to-original-state-system-preservation-technology-principle-and-attack-and-defense/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 07:03:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[安全软件]]></category>

		<category><![CDATA[突破还原]]></category>

		<category><![CDATA[还原保护]]></category>

		<guid isPermaLink="false">http://www.anansafe.com/?p=60</guid>
		<description><![CDATA[由中国最大的互联网综合服务提供商腾讯发起和组织的互联网安全峰会进入第二天。包括微软、盛大、新浪等互联网界各大巨头的技术专家，学者和专业人士参与了此次的交流。此次峰会是今年以来首场由中国互联网各顶尖企业共同参与的大型网络安全专业盛会。 ]]></description>
			<content:encoded><![CDATA[<p style="text-indent: 2em;"><strong>腾讯科技讯</strong> 3月19日，由中国最大的互联网综合服务提供商腾讯发起和组织的互联网安全峰会进入第二天。包括微软、盛大、新浪等互联网界各大巨头的技术专家，学者和专业人士参与了此次的交流。此次峰会是今年以来首场由中国互联网各顶尖企业共同参与的大型网络安全专业盛会。</p>
<p style="text-indent: 2em;"> </p>
<p style="text-indent: 2em;">来自奇虎的反木马专家郑文彬，在现场发表演讲。以下为文字实录：</p>
<p style="text-indent: 2em;"> </p>
<p style="text-indent: 2em;"> </p>
<p style="text-indent: 2em;">郑文彬：大家好！我今天给大家介绍这几个方面：背景、还原系统技术原理概览、流行还原系统穿透技术介绍、通用还原系统保护技术、演示&amp;GuardField、还原系统保护之未来趋势。最近一段时间，有机器狗这类病毒工具对还原系统攻击，使用还原系统环境的用户一般都不会安装其他的防护软件，一旦还原软件被穿透的话，会带来比较大的安全威胁。</p>
<p style="text-indent: 2em;">还原系统技术原理：基本原理是磁盘设备过滤驱动。比较常用方法是自己会建一个磁盘卷设备，在harddiskX进行文件过滤。过滤驱动如何做到还原？首先还原系统会在磁盘上分配一块预留的区域，应用程序以为他已经写到真实磁盘，实际上被分配到一块内容区域里，真实磁盘根本就没有被写入。</p>
<p style="text-indent: 2em;">下面介绍一下还原软件怎么更新过滤。首先是一个普通的Windows程序，会调用Win32API，从用户模式到内存模式，这些函数调用Windows内核，把文件请求发到文件系统上，根据磁盘卷分区格式不同来创建。文件系统设备会将上层发来的文件读写请求转化磁盘读写请求，在harddisk volume之前会有还原系统过滤驱动。再往下会根据硬盘接口不同而有不同。如果IDE结构硬盘，会发布到电源系统。api最终会调用函数读写端口。如果是USB设备，会发送到usb stor。</p>
<p style="text-indent: 2em;">刚才说了还原系统的一些基本原理，知道原理之后对如何穿透还原也就很简单了。既然还原系统都在磁盘上过滤驱动，只要我们解除过滤驱动与真实磁盘之间的关系，绕过过滤关系的话，就等于直接穿透了还原。第一种方法：DR0设备过滤设备链摘链。这种方法其实就是摘除一个harddiskDR0上的过滤设备。指明设备上会有哪些过滤设备，第一代机器狗病毒将这个域给清零，导致还原系统设备被清除，所有请求就不通过还原系统直接到达过滤磁盘设备。对于没有防备的还原系统就被成功攻破了。国内大部分还原系统都没有办法对抗这种技术。但是这种技术也是有一些缺陷的，只能摘除在DR0上的物理设备。文件请求先到达磁盘卷，磁盘卷上的过滤设备摘除的话对系统有影响。所以第一代机器狗病毒使用了自己解析文件系统方式进行感染，这是它的缺陷。</p>
<p style="text-indent: 2em;">第二种方法：会自己创建虚拟磁盘设备，作为磁盘卷挂载到文件系统上，对虚拟磁盘读写影射到真实磁盘，将请求下发到下层设备。相对第一代机器狗来说，这种方法不需要对磁盘系统摘除，可以通过文件对虚拟磁盘操作，操作结果是和对真实磁盘操作是一样的，可以成功穿透还原。在这里还用一种方式就是他没有直接发送磁盘读写请求，发送SCSI-REQUEST-BLOCK下发到下层磁盘设备。</p>
<p style="text-indent: 2em;">还有一种方法，这是方法不使用驱动程序，直接在用户模式穿透还原系统。磁盘系统提供一套passthrough指令，不向磁盘发送直接请求，就可以获取磁盘信息甚至直接读写磁盘扇区。IDE/SCSI/ATA Pass Through指令穿透还原，RING3下使用Devicelocontrel函数发送请求。大多数还原系统对此过滤不严或根本未过滤，导致在RING3下即可达成攻击。</p>
<p style="text-indent: 2em;">其他一些方法，比如说直接操作端口驱动，比如USB，更底层的磁盘操作：端口驱动、直接IO等等，缺点是难度大，通用较麻烦。另外的方法是可以摘除其他一些过滤设备，Attach到还原系统上，先于磁盘系统获得磁盘的请求，可以做一个绕过动作。可以在磁盘卷设备保存指针上所手脚。方法很多，不再一一解释了。主要是两类，第一类是新的磁盘技术或者磁盘卷绕过或者穿透的一些技巧。</p>
<p style="text-indent: 2em;">通用还原系统的保护技术，GuardField。还原系统脆弱的原因是什么呢？刚才也说过了他是通过磁盘设备上的过滤驱动，也就是说他跟磁盘设备没有紧密联系，只要被攻击者使用、摘除或者绕过方法就可以把磁盘请求发送到真实磁盘上。穿透基本原理：必须使读写请求不经过还原系统物理驱动，而是到了下层的物理磁盘设备。这里就有一个穿透思路，一个磁盘请求是从上层逐层发布到下层，我们只要监控发送路径，进行对比操作，就可以作为一个还原穿透的