查看: 3596|回复: 15
收起左侧

[病毒样本] 21个一包

[复制链接]
promised
发表于 2007-7-7 16:49:39 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
promised
 楼主| 发表于 2007-7-7 16:50:45 | 显示全部楼层
19个
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\028.exe - Signature 'Trojan-Downloader' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\102032.exe - Signature 'Trojan-Downloader.Win32.Adload.cz' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\2007.exe - Suspect code-parts found (Level: 75)
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe - Signature 'Trojan-Downloader.Win32.Zlob.aem' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\caishow2.exe:\tool.exe - Signature 'AdWare.Win32.Dm.g' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\caishow2.exe
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\hymm.dll - Signature 'Backdoor.Win32.PcClient.JL' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\in124.dll - Signature 'Trojan.MulDrop.2139' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\in126.dll - Signature 'Trojan-Downloader.4535' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\inkt2.dll
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\inkt4.dll:\BCNET2005011.exe
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\inkt4.dll:\ExePro11.exe
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\inkt4.dll
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\ly2_02.exe - Signature 'Trojan.MulDrop.3501' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\qq.exe - Signature 'Backdoor.Win32.Pigeon.42' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\qqmm.exe - Signature 'Backdoor.Win32.Agent.ahj' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\setup.exe - Signature 'Trojan.Win32.KillFiles.mo' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\Setup_s39.exe - Signature 'AdWare.MetaDirect.B' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\streg.dll - Signature 'Trojan-Downloader.Win32.Small.btn' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\svchost.exe - Signature 'Trojan-Clicker.Win32.VB.fn' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\version.exe - Signature 'Trojan-Downloader.Win32.VB.akk' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\wd2_051117_wis274_mini.exe - Signature 'AdWare.Win32.IEHlpr.m' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\《风云再起》无限魅力.exe - Signature 'Backdoor.Win32.Delf.AJN' found
c:\ABC\_ir_sf7_temp_1\_ir_sf7_temp_1\心奇QQ爆力破解2007(PP版).exe - Signature 'Backdoor.Win32.PcClient.GV' found

        24 Files scanned
          (0 Archives with 3 files)
        18 Signatures found
        1 Suspect code-part found
        Used time: 0:04.922
红心王子
发表于 2007-7-7 17:01:50 | 显示全部楼层
狮子啃掉13个
剩下漏杀的上报

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2007-7-7 17:03:56 | 显示全部楼层
detected: Trojan program Trojan-Downloader.Win32.Podcast.a        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\028.exe//data0005
detected: Trojan program Trojan-Downloader.Win32.Adload.cz        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\102032.exe
detected: adware not-a-virus:AdWare.Win32.Dm.g        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\caishow2.exe/tool.exe
detected: Trojan program Trojan.Win32.VB.ze        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\hymm.dll//UPX
detected: Trojan program Trojan-Downloader.Win32.Banload.alq        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\inkt4.dll/ExePro11.exe//UPX
detected: adware not-a-virus:AdWare.Win32.Dudu.e        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\ly2_02.exe
detected: Trojan program Backdoor.Win32.Hupigon.dl        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\qq.exe
detected: Trojan program Trojan-Spy.Win32.Delf.vt        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\qqmm.exe//NSPack
detected: Trojan program Trojan.Win32.KillFiles.mo        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\setup.exe//ASPack
detected: adware not-a-virus:AdWare.Win32.Boran.k        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\Setup_s39.exe//data0003//UPX
detected: Trojan program Trojan-Downloader.Win32.Small.btn        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\streg.dll
detected: Trojan program Trojan-Clicker.Win32.VB.fn        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\svchost.exe
detected: Trojan program Trojan-Downloader.Win32.VB.akk        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\version.exe
detected: adware not-a-virus:AdWare.Win32.IEHlpr.e        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\wd2_051117_wis274_mini.exe
detected: Trojan program Backdoor.Win32.Delf.ajn        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\¡¶·çÔÆÔÙÆð¡·ÎÞÏÞ÷ÈÁ¦.exe
detected: Trojan program Trojan-Spy.Win32.Delf.uc        File: C:\Documents and Settings\Owner\×ÀÃæ\_ir_sf7_temp_1\ÐÄÆæQQ±¬Á¦Æƽâ2007(PP°æ).exe
16


Hello,

2007.exe - Trojan-Dropper.Win32.Agent.amw

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

bg_tianyi.exe, in124.dll, in126.dll, inkt2.dll

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Yaroslav Kirillov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: _ir_sf7_temp_1.zip

[ 本帖最后由 wangjay1980 于 2007-7-7 21:26 编辑 ]
moonsilver
发表于 2007-7-7 17:09:38 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.DL.VB.dfd         
病毒: Trojan.DL.VB.bwi         
病毒: Dropper.Agent.wd         
病毒: Binder.Dasha.a           
病毒: Backdoor.Delf.uxt        
病毒: Dropper.Sbwy.bj         
病毒: Hack.EXEBinder.b         
病毒: Trojan.DL.Adload.je      
病毒: Trojan.DL.Diyer.a        
病毒: Trojan.QQMSG.ForceVideo.b
病毒: Trojan.DL.Mnless.wb      
病毒: Trojan.DL.Banload.dkh   
病毒: Trojan.Clicker.Win32.Delf.hs
病毒: Trojan.DL.Agent.hgv      

用户来源:互联网

软件版本:19.30.52
1688388728
发表于 2007-7-7 17:09:55 | 显示全部楼层
反病毒专家 AntiVirusKit 2007 扫描病毒日志记录
版本
双引擎反病毒签名 7/7/2007
开始时间: 7/7/2007 17:08
引擎: KAV 引擎 (AVK 17.5924), AVST 引擎 (AVKB 17.290)
高启发式: 打开
压缩文件: 打开
系统区域: 打开

扫描系统区域...
扫描所选择的目录和文件...
对象: data0005
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\028.exe
狀態: 已发现病毒
        病毒: Trojan-Downloader.Win32.Podcast.a (KAV 引擎)
对象: 028.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 已发现病毒
        病毒: Trojan-Downloader.Win32.Podcast.a (KAV 引擎), Win32:Adware-gen. [Adw] (AVST 引擎)
对象: 102032.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Downloader.Win32.Adload.cz (KAV 引擎), Win32:Adloader-JC [Trj] (AVST 引擎)
对象: 2007.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Win32:Agent-ZM [Trj] (AVST 引擎)
对象: bg_tianyi.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Win32:Adware-gen. [Adw] (AVST 引擎)
对象: data.rar tool.exe
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\caishow2.exe
狀態: 已发现病毒
        病毒: not-a-virus:AdWare.Win32.Dm.g (KAV 引擎)
对象: [UPX]
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\caishow2.exe
狀態: 已发现病毒
        病毒: Win32:Adware-gen. [Adw] (AVST 引擎)
对象: tool.exe
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\caishow2.exe
狀態: 已发现病毒
        病毒: Win32:Adware-gen. [Adw] (AVST 引擎)
对象: caishow2.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 已发现病毒
        病毒: not-a-virus:AdWare.Win32.Dm.g (KAV 引擎), Win32:Trojan-gen. {UPX!} (AVST 引擎)
对象: hymm.dll
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan.Win32.VB.ze (KAV 引擎), Win32:Pcclient-AH [Trj] (AVST 引擎)
对象: in124.dll
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Win32:Trojan-gen. {Other} (AVST 引擎)
对象: in126.dll
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Win32:Trojan-gen. {Other} (AVST 引擎)
对象: data.rar ExePro11.exe
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\inkt4.dll
狀態: 已发现病毒
        病毒: Trojan-Downloader.Win32.Banload.alq (KAV 引擎)
对象: ExePro11.exe
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\inkt4.dll
狀態: 已发现病毒
        病毒: Win32:Trojan-gen. {UPX!} (AVST 引擎)
对象: inkt4.dll
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 已发现病毒
        病毒: Trojan-Downloader.Win32.Banload.alq (KAV 引擎), Win32:Trojan-gen. {UPX!} (2x) (AVST 引擎)
对象: ly2_02.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: not-a-virus:AdWare.Win32.Dudu.e (KAV 引擎), Win32:Banload-KV [Trj] (AVST 引擎)
对象: qq.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Backdoor.Win32.Hupigon.dl (KAV 引擎), Win32:Agent-ZM [Trj] (AVST 引擎)
对象: qqmm.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Spy.Win32.Delf.vt (KAV 引擎), Win32:Nilage-AI [Trj] (AVST 引擎)
对象: setup.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan.Win32.KillFiles.mo (KAV 引擎), Win32:VB-BAU [Trj] (AVST 引擎)
对象: data0003
        在压缩档案里: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1\Setup_s39.exe
狀態: 已发现病毒
        病毒: not-a-virus:AdWare.Win32.Boran.k (KAV 引擎)
对象: Setup_s39.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 已发现病毒
        病毒: not-a-virus:AdWare.Win32.Boran.k (KAV 引擎), Win32:Adware-gen. [Adw] (AVST 引擎)
对象: streg.dll
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Downloader.Win32.Small.btn (KAV 引擎), Win32:Trojan-gen. {Other} (AVST 引擎)
对象: svchost.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Clicker.Win32.VB.fn (KAV 引擎), Win32:Trojan-gen. {VB} (AVST 引擎)
对象: version.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Downloader.Win32.VB.akk (KAV 引擎), Win32:VB-APA [Trj] (AVST 引擎)
对象: wd2_051117_wis274_mini.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: not-a-virus:AdWare.Win32.IEHlpr.e (KAV 引擎), Win32:Adan-C [Adw] (AVST 引擎)
对象: 《风云再起》无限魅力.exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Backdoor.Win32.Delf.ajn (KAV 引擎), Win32:Trojan-gen. {Other} (AVST 引擎)
对象: 心奇QQ爆力破解2007(PP版).exe
        路径: E:\病毒库\_ir_sf7_temp_1[1]\_ir_sf7_temp_1
狀態: 无法清除病毒
        病毒: Trojan-Spy.Win32.Delf.uc (KAV 引擎), Win32:Hupigon-AIE [Trj] (AVST 引擎)
扫描完成: 7/7/2007 17:08
    已检查 21 个文件
    已发现 20 个染毒文件
风雪
发表于 2007-7-7 17:20:30 | 显示全部楼层
费尔17个。
电影结束了
发表于 2007-7-7 17:22:22 | 显示全部楼层
Scan performed at: 2007-7-7 17:21:48
Scanning Log
NOD32 version 2383 (20070706) NT
Command line: D:\_ir_sf7_temp_1.part1.rar D:\_ir_sf7_temp_1.part2.rar D:\_ir_sf7_temp_1.part3.rar D:\_ir_sf7_temp_1.part4.rar
C:\Program Files\Eset\nod32.exe - is OK

Date: 7.7.2007  Time: 17:21:49
Anti-Stealth technology is enabled.
Scanned disks, folders and files: D:\_ir_sf7_temp_1.part1.rar; D:\_ir_sf7_temp_1.part2.rar; D:\_ir_sf7_temp_1.part3.rar; D:\_ir_sf7_temp_1.part4.rar
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\028.exe ?NSIS ?InstallOptions.dll - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\028.exe ?NSIS ?ioSpecial.ini - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\028.exe ?NSIS ?modern-wizard.bmp - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\028.exe ?NSIS ?update.exe - Win32/Adware.Zhongsou application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\028.exe ?NSIS ?download.ini - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\102032.exe - Win32/Adware.DM application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\2007.exe - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?plugin.ini - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?uninst.exe ?UPX v12_m2 - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\bg_tianyi.exe ?UPX v12_m2 - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\caishow2.exe ?RAR ?tool.exe - Win32/Adware.DM application
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\caishow2.exe ?UPX v12_m2 - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\hymm.dll - Win32/VB.ZE trojan
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\in124.dll - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\in126.dll ?NSIS ?NSISdl.dll - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\inkt2.dll ?NSIS ?ebaylink.ico - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\inkt2.dll ?NSIS ?ebaylink.ini - is OK
D:\_ir_sf7_temp_1.part1.rar ?RAR ?_ir_sf7_temp_1\inkt4.dll - next archive volume not found
Number of scanned files: 24
Number of threats found: 10
Number of active threats: 1
Time of completion: 17:21:54 Total scanning time: 5 sec (00:00:05)
陌上尘
发表于 2007-7-7 17:24:35 | 显示全部楼层
都在临时文件夹里面呢, 这种病毒如何感染呀
snakebone
头像被屏蔽
发表于 2007-7-7 17:26:14 | 显示全部楼层
2007-7-7,14:54:50 [WARNING] Is the Trojan horse TR/Crypt.FKM.Gen!
  C:\Documents and Settings\Administrator\桌面\SACH0ST.EXE
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:34 [WARNING] Is the Trojan horse TR/Dldr.Dm.H.4!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\102032.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:34 [WARNING] Is the Trojan horse TR/Drop.Agent.YZ.2!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\028.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:34 [WARNING] Contains suspicious code HEUR/Crypted!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\2007.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:35 [WARNING] Contains signature of the dropper DR/Agent.asa.2!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\caishow2.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:35 [WARNING] Is the Trojan horse TR/VB.ZE.1!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\hymm.dll
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:35 [WARNING] Is the Trojan horse TR/MulDrop.Baid.A.1!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\in124.dll
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:35 [WARNING] Is the Trojan horse TR/Agent.53196.B!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\inkt2.dll
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:35 [WARNING] Contains signature of the dropper DR/Agent.XZ!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\ly2_02.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:37 [WARNING] Contains signature of the Ad- or Spyware ADSPY/Baigoo.N!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\bg_tianyi.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.dim Backdoor server

programs!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\心奇QQ爆力破解2007(PP版).exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains signature of the Ad- or Spyware ADSPY/Drop.AllSum.A!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\wd2_051117_wis274_mini.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Is the Trojan horse TR/Dldr.VB.akk.5!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\version.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Is the Trojan horse TR/KillFiles.MO!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\setup.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains signature of the dropper DR/Boran.K!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\Setup_s39.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Is the Trojan horse TR/Dldr.Small.btn!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\streg.dll
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Is the Trojan horse TR/Spy.Delf.VT!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\qqmm.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains signature of the dropper DR/Delf.AJN.5!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\《风云再起》无限魅力.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains a signature of the (dangerous) backdoor program BDS/Agent.2 Backdoor server programs!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\svchost.exe
      [INFO] The file will be moved to quarantine.
      [INFO] The file will be deleted.
2007-7-7,17:14:39 [WARNING] Contains a signature of the (dangerous) backdoor program BDS/Agent.2 Backdoor server programs!
  C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\svchost.exe
      [ERROR] Unable to move the file to the quarantine directory:


C:\Documents and Settings\Administrator\桌面\_ir_sf7_temp_1\
  inkt4.dll
    [0] Archive type: RAR SFX (self extracting)
    --> BCNET2005011.exe
    --> ExePro11.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      A backup was created as '46fa59fa.qua'  ( QUARANTINE )
        [INFO]      The file was deleted!

[ 本帖最后由 snakebone 于 2007-7-7 17:29 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 15:52 , Processed in 0.131629 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表