今天,一同事電腦出了問題:打開Excel表格文件總提示是否運行宏。顯然是中了宏病毒。同事的電腦原來裝有RIS2011,他嫌RIS2011拖慢了系統,把RIS2011卸載了。讓電腦祼奔,如今杯具了……php
同事據說金山毒霸體積小,速度快,不卡機,讓我裝毒霸。jquery
挺久沒用金山毒霸了,正好測試一下。app
從http://www.duba.net下載了金山毒霸,安裝過程確實很快,而後全盤查殺:ide
看到金山毒霸窗口上的宣傳標語:「金山毒霸全面支持宏病毒殺和免疫,Office文檔中毒再也不擔憂!」着實讓人眼前一亮。測試
惋惜查殺結果又是杯具:Excel表格文件中的病毒沒查出來,倒把幾個正常的程序文件當病毒殺了。
ui
在同事電腦中找了一個Excel表格文件上傳到https://www.virustotal.com/在線掃描,結果以下:
.net
SHA256: | 8fc3abc66b663732836d9af342a879704ad1c8f4636488592b0dad4356af6231 |
File name: | 1.xls |
Detection ratio: | 35 / 43 |
Analysis date: | 2012-09-29 10:28:53 UTC ( 0 分鐘 ago ) |
Antivirus | Result | Update |
---|---|---|
Agnitum | - | 20120929 |
AhnLab-V3 | XF/Sic | 20120928 |
AntiVir | X2000M/Mailcab.A | 20120929 |
Antiy-AVL | - | 20120928 |
Avast | MX97:Mailcab-C [Trj] | 20120929 |
AVG | X97M/Dropper.Agent.B | 20120928 |
BitDefender | X97M.Mailcab.A@mm | 20120929 |
ByteHero | - | 20120918 |
CAT-QuickHeal | XF.Sic.f | 20120927 |
ClamAV | X97M.Agent | 20120928 |
Commtouch | Heuristic-21!VBAMacro | 20120928 |
Comodo | Worm.MSExcel.Mailcab.A | 20120929 |
DrWeb | W97M.Keylog.1 | 20120927 |
Emsisoft | X97.DelAll!IK | 20120919 |
eSafe | - | 20120927 |
ESET-NOD32 | XF/Sic.H1 | 20120928 |
F-Prot | Heuristic-20!VBAMacro | 20120926 |
F-Secure | X97M.Mailcab.A@mm | 20120927 |
Fortinet | X97M/Agent.F@mm | 20120929 |
GData | X97M.Mailcab.A@mm | 20120929 |
Ikarus | X97.DelAll | 20120929 |
Jiangmin | XM.DelAll.ra | 20120928 |
K7AntiVirus | Virus | 20120928 |
Kaspersky | Virus.MSExcel.Agent.f | 20120929 |
Kingsoft | - | 20120925 |
McAfee | XF/Sic.gen | 20120927 |
McAfee-GW-Edition | XF/Sic.gen | 20120928 |
Microsoft | Virus:XF/Sic.H | 20120926 |
Norman | - | 20120928 |
nProtect | X97M.Mailcab.A@mm | 20120929 |
Panda | W97/Mailcab.A | 20120929 |
PCTools | XF.Helpopy | 20120929 |
Rising | Trojan.Script.VBS.Dole.a | 20120928 |
Sophos | XM97/MailCab-A | 20120929 |
SUPERAntiSpyware | - | 20120911 |
Symantec | XF.Helpopy | 20120929 |
TheHacker | X97M/Generico | 20120929 |
TotalDefense | Mailcab.A | 20120928 |
TrendMicro | XF_HELPOPY.AW | 20120929 |
TrendMicro-HouseCall | XF_HELPOPY.AW | 20120926 |
VBA32 | - | 20120929 |
VIPRE | Virus.MSExcel.Mailcab.a (v) | 20120928 |
ViRobot | X97M.X97M.Ecsys | 20120929 |
果真Kingsoft(金山毒霸)查不出來,瑞星能查殺。orm
把金山毒霸卸掉,裝回瑞星……用着安心!ip