12
返回列表 发新帖
楼主: promised
收起左侧

[病毒样本] 21个一包

[复制链接]
The EQs
发表于 2007-7-7 18:46:34 | 显示全部楼层
Scan performed at: 2007-7-7 18:45:50
Scanning Log
NOD32 version 2383 (20070706) NT
Command line: C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1
Operating memory - is OK
Date: 7.7.2007  Time: 18:45:57
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\028.exe ?NSIS ?update.exe - Win32/Adware.Zhongsou application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\102032.exe - Win32/Adware.DM application - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\bg_tianyi.exe ?NSIS ?aaa - Win32/Adware.Toolbar.Baigoo application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\caishow2.exe ?RAR ?tool.exe - Win32/Adware.DM application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\hymm.dll - Win32/VB.ZE trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\ly2_02.exe - a variant of Win32/Adware.DM application
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\setup.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\streg.dll - Win32/TrojanDownloader.Small.BTN trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\svchost.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\version.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\wd2_051117_wis274_mini.exe - Win32/Adware.BHO.IEHelper application - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\_ir_sf7_temp_1\_ir_sf7_temp_1\《风云再起》无限魅力.exe - Win32/Delf.AJN trojan - quarantined - unable to clean - deleted
Number of scanned files: 51
Number of threats found: 17
Number of files cleaned: 12
Time of completion: 18:46:05 Total scanning time: 8 sec (00:00:08)
Notes:
[7] File is probably infected with an unknown virus.
woai_jolin
发表于 2007-7-7 18:48:38 | 显示全部楼层
原帖由 电影结束了 于 2007-7-7 17:22 发表
Scan performed at: 2007-7-7 17:21:48
Scanning Log
NOD32 version 2383 (20070706) NT
Command line: D:\_ir_sf7_temp_1.part1.rar D:\_ir_sf7_temp_1.part2.rar D:\_ir_sf7_temp_1.part3.rar D:\_ir_sf7_ ...

你没开高启吗
uhthn2002
发表于 2007-7-7 20:27:15 | 显示全部楼层

C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\028.exe : infected Trojan.DownLoader.10376
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\102032.exe : infected Trojan-Downloader.Win32.Adload.ca
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\caishow2.exe:<RAR>\tool.exe : infected AdWare.Win32.Dm.g
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\hymm.dll : infected Backdoor.Win32.PcClient.jl
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\in124.dll : infected Trojan.MulDrop.2139
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\in124.dll:<CAB>\BaiduBar.dll : infected Application.Win32.Adware.Toolbar.Baidu
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\inkt4.dll:<RAR>\ExePro11.exe : infected Trojan-Downloader.Win32.Banload.alq
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\ly2_02.exe : infected Trojan.MulDrop.3501
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\qq.exe : infected Trojan-Dropper.Win32.Agent.ru
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\qqmm.exe : is suspected of Trojan-PSW.Game.1 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\setup.exe : infected Trojan.Win32.KillFiles.mo
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\streg.dll : infected Trojan-Downloader.Win32.Small.btn
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\version.exe : infected Trojan-Downloader.Win32.VB.akk
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\wd2_051117_wis274_mini.exe : infected AdWare.Win32.IEHlpr.e
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\《云再~1.EXE : infected Trojan.Win32.Delf.AJN
C:\Documents and Settings\uhthn\Desktop\_ir_sf7_temp_1\心奇QQ爆力破解2007(PP版).exe : infected Trojan.MulDrop.3797


Directories       : 0       Files in archives:      Files on disks:
Archives:                   - total       : 8       - total       : 21   
- scanned         : 3       -  scanned    : 8       - scanned     : 21   
- contain viruses : 3       -  infected   : 3       - infected    : 14   
- deleted         : 0       -  suspicious : 0       - suspicious  : 1
wangjay1980
发表于 2007-7-7 21:26:57 | 显示全部楼层
Hello,

2007.exe - Trojan-Dropper.Win32.Agent.amw

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

bg_tianyi.exe, in124.dll, in126.dll, inkt2.dll

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Yaroslav Kirillov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: _ir_sf7_temp_1.zip
电影结束了
发表于 2007-7-7 21:28:54 | 显示全部楼层

回复 #12 woai_jolin 的帖子

MS是的
tracydk
发表于 2007-7-7 21:31:48 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\_ir_sf7_temp_1.part1.rar'
F:\病毒样本\_ir_sf7_temp_1.part1.rar
  [0] Archive type: RAR
  --> _ir_sf7_temp_1\028.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.YZ.2
  --> _ir_sf7_temp_1\102032.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Dm.H.4
  --> _ir_sf7_temp_1\2007.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> _ir_sf7_temp_1\caishow2.exe
      [DETECTION] Contains signature of the dropper DR/Agent.asa.2
  --> _ir_sf7_temp_1\hymm.dll
      [DETECTION] Is the Trojan horse TR/VB.ZE.1
  --> _ir_sf7_temp_1\in124.dll
      [DETECTION] Is the Trojan horse TR/MulDrop.Baid.A.1
  --> _ir_sf7_temp_1\inkt2.dll
      [DETECTION] Is the Trojan horse TR/Agent.53196.B
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\_ir_sf7_temp_1.part2.rar'
F:\病毒样本\_ir_sf7_temp_1.part2.rar
  [0] Archive type: RAR
  --> _ir_sf7_temp_1\ly2_02.exe
      [DETECTION] Contains signature of the dropper DR/Agent.XZ
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\_ir_sf7_temp_1.part3.rar'
F:\病毒样本\_ir_sf7_temp_1.part3.rar
  [0] Archive type: RAR
  --> _ir_sf7_temp_1\qqmm.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.VT
  --> _ir_sf7_temp_1\setup.exe
      [DETECTION] Is the Trojan horse TR/KillFiles.MO
  --> _ir_sf7_temp_1\Setup_s39.exe
      [DETECTION] Contains signature of the dropper DR/Boran.K
  --> _ir_sf7_temp_1\streg.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Small.btn
  --> _ir_sf7_temp_1\svchost.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.2 Backdoor server programs
  --> _ir_sf7_temp_1\version.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.akk.5
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\_ir_sf7_temp_1.part4.rar'
F:\病毒样本\_ir_sf7_temp_1.part4.rar
  [0] Archive type: RAR
  --> _ir_sf7_temp_1\&ETH;&Auml;&AElig;&aelig;QQ±&not;&Aacute;&brvbar;&AElig;&AElig;&frac12;&acirc;2007(PP°&aelig;).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.dim Backdoor server programs
      [INFO]      The file was deleted!


End of the scan: 2007年7月7日  21:31
Used time: 00:12 min

The scan has been done completely.

      0 Scanning directories
     27 Files were scanned
     15 viruses and/or unwanted programs were found
      1 classified as suspicious:
      4 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     11 Files not concerned
      5 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 18:33 , Processed in 0.093817 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表