Pages

Kamis, 10 November 2011

第四章、病毒与木马的防范 Chapter IV, to prevent viruses and Trojan

Text / Jianghai off (seak@163.net)

一、病毒 First, the virus
由于网络是一个开放的环境,因此网上用户受到恶意的程序的威胁要比普通用户大一些,其中主要的是病毒和特络绎木马程序。 As the network is an open environment, Internet users by the threat of malicious programs larger than the average user, which is the main stream of viruses and Trojans special. 当然对中国的用户来说,主要的威胁似乎仍然来自光盘或者磁盘这样的传统介质,可以作为以上观点重要佐证的就是:以光盘为主要传播手段的CIH病毒给国内造成了巨大损失,而以邮件附件传播的melissa病毒则在国内没有掀起什么波澜。 Of course, users in China, the main threat still seems to come from such traditional CD-ROM or disk media can be used as important evidence for the above observations is: CD-ROM as the main means of transmission of CIH virus caused huge losses to the country, and to the spread of the virus melissa e-mail attachments are not stir up any waves in the country.
我一向认为,对普通用户来说,除了了解病毒的一些知识,破除病毒的神秘感,增强保护意识之外,更重要的是要选择一套可靠的杀毒软件,但关于杀毒软件的优劣是一个非常敏感的问题。 I always thought that, for ordinary users, in addition to some knowledge about the virus, get rid of the virus of mystery, and enhance awareness of conservation, it is more important to choose a reliable anti-virus software, but on the merits of anti-virus software is a very sensitive issue. 我认为,一个合格95/98平台的杀毒软件至少实现以下特点: In my opinion, a qualified anti-virus software at least 95/98 platform to achieve the following characteristics:
1、 软件结构合理,采用反病毒引擎/反病毒库分离的结构,具有成熟的虚拟机和启发式扫描引擎的机制。 1, the software structure is reasonable, the use of anti-virus engine / anti-virus database separate structure, with a mature virtual machine and the heuristic scanning engine mechanism.
2、 合理嵌入95/98内核,兼容性好,占用系统资源低,有在线防御能力,能监控用户的多项操作。 2, a reasonable embedding 95/98 core, good compatibility, low system resources, there are online defense capability, users can monitor the number of operations.
3、 对病毒处理安全可靠,没有造成文件损坏、数据和分区丢失的安全隐患。 3, safe and reliable treatment for the virus, did not cause file corruption, data loss and partition security risks.
4、 出品公司有覆盖面广泛的反病毒网络,或者与其他反病毒公司形成有效的标本共享机制,对新病毒反应时间短,可处理病毒总数至少在15000以上。 4, the production company has extensive coverage of anti-virus, network, or with other companies to form an effective anti-virus sample-sharing mechanism, short reaction time to new viruses, the virus can handle the total number of at least 15,000 more.
5、 能查解各种常见压缩包,能一定程度上抵御恶意active X和JAVA小程序。 5, the solution to check all common archive, to some extent against malicious active X and JAVA applets.
6、 完善的数据保护机制,可以备份重要信息到应急盘。 6, improve data protection mechanism, you can back up important information to the emergency disk.
7、 有完整的帮助机制和详细的病毒库资料,提示信息准确。 7, a complete help system and detailed information on virus, suggesting that information is accurate.
8、 有完善的升级机制,支持自动网上升级、下载升级等方式。 8, a perfect upgrade mechanisms to support automatic online update, download the upgrade, etc..
… …等等,难以一一列举。 ... ... And so, difficult to enumerate.
这些都是先进反病毒产品的有效特征,国外这样产品的代表是AVP、NAV、MCAFEE SCAN等等,国内的AV98和金辰与美国CA公司联合推出的KILL98、趋势与乐亿阳发布的PC-CILLIN也是非常不错的。 These are the advanced features of an effective anti-virus products, the foreign representative of this product is AVP, NAV, MCAFEE SCAN, etc., domestic AV98 and Kim Jin-CA jointly with the United States launched KILL98, trends and music release of PC-Oceans CILLIN also very good. 另外,金山公司的金山毒霸目前还没有正式上市,如果这个程序能进一步提高运行效率和稳定性,也将是一个不错的产品。 In addition, Kingsoft Duba has not officially listed, if this program will further improve operational efficiency and stability, will also be a good product.
WIN9X 用户对于病毒防御必须有一些观念的变革,第一是为了杀毒而杀毒:我再次重申一个观点,杀毒的目的是保证用户数据安全和正常使用,如果某个杀毒软件解毒后的情况比杀毒前更坏,造成文件损坏、分区丢失、系统无法正常启动等情况,这决不是病毒造成的,而是杀毒软件的质量造成的。 WIN9X virus defense for the user must have some concept of change, the first anti-virus and anti-virus in order: I reiterate a point of view, the purpose is to ensure anti-virus security and proper use of user data, if an anti-virus software after detoxification than in previous anti-virus worse, resulting in file corruption, partition loss, the system does not start, etc., This is not caused by the virus, but antivirus software quality result. 不能保证用户数据安 Can not guarantee security of user data
全的的杀毒软件是没有意义的。 Complete anti-virus software does not make sense. 如果你的杀毒软件是可以信赖的,一般的来说,你也无须想到从新格式化硬盘。 If your antivirus software is reliable, generally speaking, you do not think the new format the hard drive. 顺便说一下,我特别反对低格硬盘,杀除任何病毒都无须低格,低格是损害硬盘寿命的,这两点都已经是技术定论,。 By the way, I am particularly opposed to low grid drive, do not kill viruses in addition to any low grid, low-grid is the damage the hard disk life, and these two are already technical findings.

Tidak ada komentar:

Posting Komentar