ÔÚÃüÁîÐз½Ê½ÏÂÔËÐÐ6.0°æµÄInocmd32.exeÎļþ£¬ÏÔʾÈçÏ£º
Usage:Inocmd32.exe [ -options ] file|directory|drive ...
-options:
: MOD <mod> Scan mode
<mod> can be one of: Secure or Reviewer (default Secure)
: ACT <action> Infected file action
<action> can be one of: Cure, Rename, Delete or Move
: EXE Specified files
(based on the InoculateIT 'Specified' extension list)
: EXC Exclude files
(based on the InoculateIT 'Exclude' extension list)
: ARC Scan archive files
: NEX Detect compressed files by content, not file extension
: NOS No subdirectory traverse
: FIL:<pattern> Only scan files that match <pattern> (shell wildcard)
: SCA <action> Special Cure Action (ACT must be set to Cure)
<action> can be one of: CB (Copy Before),
RF (Rename if cure fails) or MF (Move if cure fails)
: MCA <action> Macro Cure Action
<action> can be either: RA (remove all) or RI (remove infected)
: SPM <mode> Special Mode
<mode> can only be: H (heuristics)
: SFI Stop at first infection in archive
: SMF Scan migrated files
: INC Incremental scan
: SRF Skip regular file scanning of archives
: BOO Boot sector scan
: MEM Scan memory (currently running programs)
: LIS:<file> Create scan report file <file>
: APP:<file> Append scan report to file <file>
: VER Verbose mode
: QUI Count of scanned files rather than list
: SIG Display signature version numbers
: SIG:<dir> Display signature version numbers of
engine located in <dir>
: HEL or ? Display this help
file|directory|drive ...: Specify at least one file, directory or drive to scan
InoculateIT Signature version: vet.dat 30.07.3641 2007/05/18
Vet Signature version: vet.dat 30.07.3641 2007/05/18
ÔÚÃüÁîÐз½Ê½ÏÂÔËÐÐ7.1°æµÄInocmd32.exeÎļþ£¬ÏÔʾÈçÏ£º
InoculateIT ÒýÇæ°æ±¾: 30.07.00 2007-03-29
InoculateIT ÌØÕ÷Âë°æ±¾: vet.dat 30.07.3641 2007-05-18
Vet ÒýÇæ°æ±¾: 30.07.00 2007-03-29
Vet ÌØÕ÷Âë°æ±¾: vet.dat 30.07.3641 2007-05-18
Ó÷¨:Inocmd32.exe [ -options ] file|directory||Çý¶¯Æ÷ ...
-options:
ENG <engine>
<engine> ¿ÉÒÔÊÇÒÔÏÂÖ®Ò»: Ino »ò Vet
MOD <mod> ɨÃèģʽ
<mod> ¿ÉÒÔÊÇÒÔÏÂÖ®Ò»: °²È«»òÆÀÂÛ (ĬÈÏΪ°²È«Ä£Ê½)
ACT <action> ¶ÔÊܸÐȾÎļþµÄ²Ù×÷
<action> ¿ÉÒÔÊÇÒÔÏÂÖ®Ò»: ±¨¸æ¡¢ÐÞ¸´¡¢ÖØÃüÃû¡¢É¾³ý»òÒÆ¶¯
EXE Ö¸¶¨µÄÎļþ
(»ùÓÚ Local Scanner µÄ 'Ö¸¶¨' À©Õ¹ÃûÁбí)
EXC ÅųýµÄÎļþ
(»ùÓÚ Local Scanner µÄ 'Åųý' À©Õ¹ÃûÁбí)
ARC ɨÃè´æµµÎļþ
NEX °´ÄÚÈݶø²»Êǰ´ÎļþÀ©Õ¹Ãûɾ³ýѹËõÎļþ
NOS ²»±éÀú×ÓĿ¼
FIL:<pattern> ½öɨÃèͬ <pattern> (shell ͨÅä·û) Æ¥ÅäµÄÎļþ
SCA <action> ÌØÊâÐÞ¸´²Ù×÷ (ACT ±ØÐë±»ÉèΪÐÞ¸´²Ù×÷)
<action> ¿ÉÒÔÊÇÒÔÏÂÖ®Ò»: CB (Ê×Ïȸ´ÖÆ)¡¢
RF (ÐÞ¸´Ê§°ÜÔòÖØÃüÃû) »ò MF (ÐÞ¸´Ê§°ÜÔòÒÆ¶¯)
MCA <action> ºêÐÞ¸´²Ù×÷
<action> ¿ÉÒÔÊÇÒÔÏÂÖ®Ò»: RA (È«²¿É¾³ý) »ò RI (ɾ³ý±»¸ÐȾµÄºê)
SPM <mode> ÌØÊâģʽ
<mode> ¿ÉÒÔÊÇ: H (Æô·¢Ê½)
SFI ÔÚ´æµµ°üÖмì²âµ½Ê׸ö¸ÐȾÎļþʱֹͣ
SMF ɨÃèÇ¨ÒÆµÄÎļþ
SRF Ìø¹ý¶Ô´æµµ°üµÄ³£¹æÎļþɨÃè
ARF ½«À©Õ¹Ãû¹ýÂËÆ÷Ó¦ÓÃÓÚ´æµµÄÚÈÝ
BOO Æô¶¯ÉÈÇøÉ¨Ãè
MEM ɨÃèÄÚ´æ (µ±Ç°ÔËÐеijÌÐò)
LIS:<file> ´´½¨É¨Ã豨¸æÎļþ <file>
APP:<file> ½«É¨Ã豨¸æÎļþ¸½¼Óµ½ <file> ÎļþÖ®ºó
SYS ÆôÓÃϵͳÐÞ¸´¹¦ÄÜ
¶ÔÕÒµ½µÄÈκÎÒѸÐȾµÄ²¢ÇÒͬϵͳÐÞ¸´¹ØÁªµÄÎļþ£¬
µ÷ÓÃϵͳÐÞ¸´¹¦ÄÜ¡£ÓйØÌض¨²¡¶¾µÄÏêϸÐÅÏ¢£¬
Çë·ÃÎÊ
www.ca.com ÉϵIJ¡¶¾°Ù¿ÆÈ«Êé
ͬϵͳÐÞ¸´µÄ¿ÉÐÐÐÔÓйء£ÔÚijЩʱºòÇë¶à¼Ó×¢Òâ
ϵͳÐÞ¸´ÐèÒªÖØÆô²ÅÄÜÉúЧ¡£
VER Ïêϸģʽ
COU:<n> ·¢ËÍÏûÏ¢£¬Ã¿ <n> ¸öɨÃèµÄÎļþ
COU ÿɨÃè 1000 ¸öÎļþ¸ø³öÒ»ÌõÏûÏ¢
SIG ÏÔÊ¾ÌØÕ÷Âë°æ±¾ºÅ
SIG:<dir> ÏÔʾλÓÚ <dir> ϵÄÒýÇæµÄ
ÌØÕ÷Âë°æ±¾ºÅ
HEL »ò ? ÏÔʾ±¾°ïÖú
Îļþ|Ŀ¼|Çý¶¯Æ÷ ...:
ÇëÖÁÉÙÖ¸¶¨Ò»¸öҪɨÃèµÄÎļþ¡¢Ä¿Â¼»òÇý¶¯Æ÷
ÕâÁ½¸ö°æ±¾ÖÐÏàÓ¦ÃüÁîÐпª¹ØÏîµÄ½âÊÍÍêȫһÖ£¬¿´À´Ò²²»ÊÇÅäÖÃÎļþµÄÎÊÌâ¡£ÕâÑù¿´À´Ó¦¸ÃÊÇKillµÄÎÊÌâ¡£ÉÏbbs.5dmail.netÎÊÁËһϣ¬WinWebMailÊÇͨ¹ý·ÖÎöKillÃüÁîÐÐÒýÇæµÄɱ¶¾ÈÕÖ¾À´Ê¶±ðÓʼþÖеIJ¡¶¾¡£¿´À´¿ÉÄÜÊÇKill¸Ä±äÁËɱ¶¾ÈÕÖ¾µÄ±£´æ¸ñʽ£¬µ¼ÖÂWinWebMailÎÞ·¨ÕýÈ·¹¤×÷ÁË¡£
ËùÒÔĿǰ¶ÔÓÚWinWebMail¶øÑÔ£¬Ö»ÄܺÍKill6.0°æÅäºÏʵÏÖÓʼþ·À¶¾¹¦ÄÜ£¬²»ÄܺÍKill7.1°æÅäºÏʵÏÖ¡£
ÉϴηÖÎö·¢ÏÖÓÉÓÚKill6.0Óë7.1°æÃüÁîÐÐÒýÇæÉ±¶¾ÈÕÖ¾µÄ±£´æ¸ñʽ²»Ò»ÑùÔì³ÉWinWebMailÎÞ·¨Õýȷʶ±ð£¬´Ó¶øÎÞ·¨ÊµÏÖÓʼþ·À¶¾¹¦ÄÜ¡£µ«ÊÇ×Ðϸ·ÖÎöÁËÕâÁ½¸ö°æ±¾µÄËùÓÐÈÕÖ¾Îļþ£¬·¢ÏÖ²¢Ã»ÓÐÃüÁîÐÐÒýÇæµÄɱ¶¾ÈÕÖ¾¡£ÄÇôÓпÉÄÜWinWebMail²¢²»ÊÇ·ÖÎöÈÕÖ¾Îļþ£¬¶øÊÇÖ±½Ó·ÖÎöÃüÁîÐÐÒýÇæÉ±¶¾Êä³ö½á¹ûÀ´ÊµÏÖÓʼþ·À¶¾¹¦ÄÜ¡£
ÏÂÃæÊÇKill6.0°æÃüÁîÐÐÒýÇæÉ±¶¾½á¹û£º
C:\Program Files\KILL\ScanEngine>Inocmd32.exe -ARC -NEX -SFI -NOS c:\temp\eicar.com.txt
File c:\temp\eicar.com.txt is infected by virus: the EICAR test string
Total Files Scanned: 1
Total Viruses Found: 1
Total Infected Files Found: 1
Scan Mode: Secure
*** End Of Summary ***
ÏÂÃæÊÇKill7.1°æÃüÁîÐÐÒýÇæÉ±¶¾½á¹û£º
C:\Program Files\CA\SharedComponents\ScanEngine>Inocmd32.exe -ARC -NEX -SFI -NOS c:\temp\eicar.com.txt
Îļþ c:\temp\eicar.com.txt ±»ÒÔϲ¡¶¾¸ÐȾ: the EICAR test string
ɨÃèµÄÎļþ×ÜÊý: 1
ÕÒµ½µÄ²¡¶¾×ÜÊý: 1
ÕÒµ½µÄÊܸÐȾÎļþ×ÜÊý: 1
ɨÃèģʽ: °²È«
*** ¸ÅÒª½áÊø ***
´ÓÕâÁ½¸ö½á¹û¿ÉÒÔ·¢ÏÖKillµÄÈ·ÐÞ¸ÄÁËÃüÁîÐÐɱ¶¾ÒýÇæµÄÊä³ö½á¹ûÐÅÏ¢£¬°ÑKill6.0°æµÄÓ¢ÎĽá¹û¸ÄΪÁËKill7.1°æµÄÖÐÎĽá¹û¡£
»¹¼ÇµÃWinWebMailµÄ·À¶¾ÉèÖÃÅäÖÃÎļþ¡°WinWebMail\adminmsg\KILL °²È«ëм×.eav¡±ÖÐÓÐÒ»¾ä¡°is infected by virus:¡±£¬ÕâÓ¦¸Ã¾ÍÊÇWinWebMailʶ±ð²¡¶¾µÄ¹Ø¼ü×Ö¡£¶øKill6.0ɱ¶¾Êä³ö½á¹ûÐÅÏ¢ÖÐÓÐÒ»¾ä¡°File c:\temp\eicar.com.txt is infected by virus: the EICAR test string¡±£¬ÀïÃæ¾Íº¬ÓÐÕâ¸ö¹Ø¼ü×Ö¡£ÔÚKill7.1ÖÐÕâÒ»¾ä¸ÄΪ¡°
Îļþ c:\temp\eicar.com.txt ±»ÒÔϲ¡¶¾¸ÐȾ: the EICAR test string¡±¡£
Í£Ö¹WinWebMailµÄ·þÎñ³ÌÐò£¬°Ñ¡°KILL °²È«ëм×.eav¡±ÖеĹؼü×Ö¡°is infected by virus:¡±¶¼¸ÄΪ¡°±»ÒÔϲ¡¶¾¸ÐȾ:¡±¡£È»ºóÖØÆôWinWebMailµÄ·þÎñ³ÌÐò£¬·¢ËÍÒ»·â´øÓв¡¶¾¸½¼þµÄ²âÊÔÓʼþ£¬½ÓÊն˵ÄȷûÓÐÊÕµ½¸Õ²Å·¢Ë͵IJâÊÔÓʼþ¡£ÔÚ·¢ËÍÒ»·ÝÕý³£Óʼþ£¬Õâ´ÎÕý³£ÊÕµ½¡£
ͨ¹ýÒÔÉϲâÊÔ˵Ã÷WinWebMailÊÇͨ¹ý·ÖÎöKillÃüÁîÐÐɱ¶¾ÒýÇæµÄÊä³ö½á¹ûÐÅÏ¢À´ÊµÏÖÓʼþ·À¶¾¹¦ÄÜ¡£Ö±½ÓÐÞ¸ÄWinWebMailµÄ·À¶¾ÉèÖÃÅäÖÃÎļþ¾Í¿ÉÒÔÈÃWinWebMailÖ§³ÖKill7.1°æ¡£²»¹ýÕâÑùÐÞ¸ÄÖ®ºóWinWebMail²»ÄÜÔÚ·¢ÏÖ²¡¶¾Óʼþʱ֪ͨ·¢¼þÈË£¬ÕâµÄÈ·ÊÇÒ»¸öССµÄÒź¶¡£
Ç°Ãæ½øÐеÄËùÓвâÊÔ¶¼ÒÅ©ÁËÒ»µã£¬¼´Ê¹ÓõÄWinWebMailÊÇ3.6.2.1°æ¡£ÕâÊÇÒ»¸ö±È½ÏÔçµÄ°æ±¾£¬µ±Ê±µÄÕýʽÃû³ÆÊÇEasyWebMail£¬´Ó3.7°æÒÔºó¿ªÊ¼¸ÄÃûΪWinWebMail¡£
Ç°Ãæ²âÊÔÖÐÐÞ¸ÄÁËWinWebMailµÄ·À¶¾ÅäÖÃÎļþºó£¬ÒѾ¿ÉÒÔÕý³£¹ýÂËÓʼþÖеIJ¡¶¾£¬µ«ÊÇÎÞ·¨½«Ê¶±ð³öµÄ²¡¶¾ÐÅÏ¢·´À¡¸ø·¢¼þÈË¡£½«WinWebMailÉý¼¶µ½×îеÄ3.7.3.1°æ£¨2006Äê11ÔÂ28ÈÕ·¢²¼£©ºó¡£Ôٴη¢ËÍ´øÓв¡¶¾¸½¼þµÄ²âÊÔÓʼþ£¬Õâ´Î·¢¼þÈËÊÕµ½µÄWinWebMail·µ»ØµÄ¡°²¡¶¾Óʼþ¾¯¸æ¡±¡£
ÖÁ´ËWinWebMail3.7.3.1°æÓëKill7.1°æÅäºÏʵÏÖÓʼþ·À¶¾¹¦ÄÜÍêÈ«¿ÉÒÔÕý³£Ê¹Óá£