查看: 3803|回复: 18
收起左侧

[病毒样本] 下载者产物82个

[复制链接]
promised
发表于 2007-8-1 16:59:13 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
taihuxian
发表于 2007-8-1 17:00:19 | 显示全部楼层
Virus: Win32:Agent-HFX [Trj] (16x), Win32:Agent-ISZ [Trj] (2x), Win32:Trojan-gen. {Other} (2x), Win32:Delf-FDB [Trj] (2x), Win32:Delf-FKJ [Trj], Win32:VB-EIZ [Trj], Win32:Agent-JOF [Trj], Win32:Cryptic-OV [Trj], Win32:Small-GWM [Trj], Win32:Delf-DTM [Wrm] (3x), Win32:Adware-gen. [Adw] (2x), Win32:Agent-JQL [Trj]

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Trojan-Dropper.Win32.Small.ayg, Trojan-Downloader.Win32.Agent.bys, Trojan-Downloader.Win32.Cryptic.gen, not-a-virus:AdWare.Win32.Cinmus.t (3x), Trojan-Downloader.Win32.Small.dxm (2x), not-a-virus:AdWare.Win32.Zhongsou.g (4x), not-a-virus:AdWare.Win32.Zhongsou.i (3x), Trojan-Downloader.Win32.VB.atk, not-a-virus:AdWare.Win32.Rond.c, Trojan-Downloader.Win32.Agent.bls (3x), Backdoor.Win32.Small.bq, not-a-virus:AdWare.Win32.Zhongsou.h

Virus found while downloading Web content.

Address: bbs.kafan.cn


Virus: Trojan.Win32.Small.oa, Trojan-Downloader.Win32.Cryptic.gen, not-a-virus:AdWare.Win32.Rond.c, Trojan-Downloader.Win32.Small.eqn

Virus found while downloading Web content.

Address: bbs.kafan.cn

[ 本帖最后由 taihuxian 于 2007-8-1 19:52 编辑 ]
欠妳緈諨
发表于 2007-8-1 17:15:16 | 显示全部楼层
金山

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-8-1 17:15:33 | 显示全部楼层
Scan performed at: 2007-8-1 17:14:09
Scanning Log
NOD32 version 2430 (20070731) NT
Command line: C:\Documents and Settings\EQ2\桌面\virus
Operating memory - is OK

Date: 1.8.2007  Time: 17:14:15
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\virus\
C:\Documents and Settings\EQ2\桌面\virus\virus\0.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\023[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\10.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\10012[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\1012[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\103.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\1063.exe ?NSIS ?wr-1-22.exe - a variant of Win32/TrojanDownloader.Small.EQN trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\1063.exe ?NSIS ?guyi1234.exe - Win32/TrojanDownloader.Small.DXM trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\1063[1].exe ?NSIS ?wr-1-22.exe - a variant of Win32/TrojanDownloader.Small.EQN trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\1063[1].exe ?NSIS ?guyi1234.exe - Win32/TrojanDownloader.Small.DXM trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\1093[1].exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\virus\virus\1093[2].exe - a variant of Win32/TrojanDownloader.Ieser trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\11.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\virus\virus\112.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\virus\virus\1228[1].exe ?NSIS ?565.exe - Win32/TrojanDownloader.Small.EQN trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\1228[1].exe ?NSIS ?cmd.exe - Win32/TrojanDropper.Small.NGC trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\123.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\13715C84.EXE - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\1jh3jq.sys - a variant of Win32/Rootkit.Agent.NCK trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\2.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\2209[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\3.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\3EE4F2CC.EXE - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\4.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\5.exe - Win32/TrojanDownloader.VB.APY trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\565.exe - Win32/TrojanDownloader.Small.EQN trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\6.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\62205[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\66005[1].exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\7.exe - a variant of Win32/Agent.NAU worm
C:\Documents and Settings\EQ2\桌面\virus\virus\8.exe ?NSIS ?565.exe - Win32/TrojanDownloader.Small.EQN trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\8.exe ?NSIS ?cmd.exe - Win32/TrojanDropper.Small.NGC trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\847[1].exe - a variant of Win32/Agent.NAU worm
C:\Documents and Settings\EQ2\桌面\virus\virus\9.exe - a variant of Win32/Agent.NAU worm
C:\Documents and Settings\EQ2\桌面\virus\virus\944.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\999[1].rar - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\acpidisk.sys - a variant of Win32/Adware.Cinmus application
C:\Documents and Settings\EQ2\桌面\virus\virus\bd2[1].rar - probably a variant of Win32/TrojanDownloader.QQHelper.NDD trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\bd4[1].rar ?NSIS ?944.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\cc_231[1].exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\cmd.exe - Win32/TrojanDropper.Small.NGC trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\dodolook264[1].exe - Win32/TrojanDownloader.VB.APY trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\guyi1234.exe - Win32/TrojanDownloader.Small.DXM trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\gwTiN.exe - a variant of Win32/Agent.NAU worm
C:\Documents and Settings\EQ2\桌面\virus\virus\husjdd8s.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\imlgotgwckmja.dll - a variant of Win32/TrojanDownloader.Ieser trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\mclient.exe - a variant of Win32/TrojanDownloader.Ieser trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\mminstall[1] - probably a variant of Win32/TrojanDownloader.QQHelper.NDF trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\my_70136[1].rar - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\virus\virus\retadpu22.exe - a variant of Win32/TrojanDownloader.Agent.BLS trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\retadpu565.exe - a variant of Win32/TrojanDownloader.Agent.BLS trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\retadpu[1].exe - a variant of Win32/TrojanDownloader.Agent.BLS trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\sb.exe - probably a variant of Win32/TrojanDownloader.QQHelper.NDD trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\sd.exe ?NSIS ?944.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\virus\virus\tempaq - probably a variant of Win32/TrojanDownloader.QQHelper.NDF trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\tnisiddnwaexy.dll - a variant of Win32/TrojanDownloader.Ieser trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\uj5geqq3.dll - a variant of Win32/TrojanDownloader.Agent.NPO trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\wdfmgrnt.exe - Win32/TrojanDownloader.VB.APY trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\virus\virus\wr-1-22.exe - a variant of Win32/TrojanDownloader.Small.EQN trojan
C:\Documents and Settings\EQ2\桌面\virus\virus\y9r5hl.sys - a variant of Win32/Rootkit.Agent.NBQ trojan
Number of scanned files: 108
Number of threats found: 60
Number of files cleaned: 56
Time of completion: 17:14:49 Total scanning time: 34 sec (00:00:34)

Notes:
[7] File is probably infected with an unknown virus.
欠妳緈諨
发表于 2007-8-1 17:17:03 | 显示全部楼层
AVAST删除58个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jxxfcwb
发表于 2007-8-1 17:20:10 | 显示全部楼层
Begin scan in 'D:\virus.part1.rar'
D:\virus.part1.rar
  [0] Archive type: RAR
  --> virus\0.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\023[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\10.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\10012[1].exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
  --> virus\1012[1].exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
  --> virus\103.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
  --> virus\1063.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.58
  --> virus\1063[1].exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.58
  --> virus\1093[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\1093[2].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\11.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\112.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.atk.58
  --> virus\1228[1].exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.23
  --> virus\123.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\13715C84.EXE
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\1jh3jq.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> virus\2.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
  --> virus\2209[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\3.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\3EE4F2CC.EXE
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
  --> virus\4.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\5.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
  --> virus\565.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
  --> virus\6.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\62205[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\66005[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
  --> virus\7.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\8.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.23
  --> virus\847[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\9.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\944.exe
      [DETECTION] Contains signature of the dropper DR/Cinmus.T.5
  --> virus\999[1].rar
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> virus\aabb.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.bys
  --> virus\acpidisk.sys
      [DETECTION] Contains signature of the rootkit RKIT/Cinmus.M
  --> virus\bao118[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> virus\bd2[1].rar
      [DETECTION] Is the Trojan horse TR/Dldr.Agen.YZ.3.A
      [WARNING]   The file was ignored!
yurius
发表于 2007-8-1 17:23:03 | 显示全部楼层
卡巴68个

deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/0.exe//ASPack//#
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/023[1].exe//ASPack//#
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/10.exe//#
deleted: Trojan program Trojan-Downloader.Win32.Flux.a        File: C:\virus\virus1.zip/virus/10012[1].exe//UPack//ASPack
deleted: Trojan program Trojan-Downloader.Win32.Flux.a        File: C:\virus\virus1.zip/virus/1012[1].exe//UPack//ASPack
deleted: Trojan program Trojan-Downloader.Win32.Flux.a        File: C:\virus\virus1.zip/virus/103.exe//UPack//ASPack
deleted: Trojan program Trojan-Downloader.Win32.Small.eqn        File: C:\virus\virus1.zip/virus/1063.exe//stream//data0001//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.h        File: C:\virus\virus1.zip/virus/1063.exe//stream//data0002//PE_Patch
deleted: Trojan program Trojan-Downloader.Win32.Small.dxm        File: C:\virus\virus1.zip/virus/1063.exe//stream//data0003
deleted: Trojan program Trojan-Downloader.Win32.Small.dxm        File: C:\virus\virus1.zip/virus/1063[1].exe
deleted: virus Heur.Downloader (modification)        File: C:\virus\virus1.zip/virus/1093[1].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: virus Heur.Downloader (modification)        File: C:\virus\virus1.zip/virus/11.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.VB.atk        File: C:\virus\virus1.zip/virus/112.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.eqn        File: C:\virus\virus1.zip/virus/1228[1].exe//stream//data0001//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.bys        File: C:\virus\virus1.zip/virus/1228[1].exe//stream//data0002//stream//data0002
deleted: Trojan program Trojan-Dropper.Win32.Small.ayg        File: C:\virus\virus1.zip/virus/1228[1].exe//stream//data0003
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/123.exe//#
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/13715C84.EXE//#
deleted: Trojan program Trojan-Downloader.Win32.Flux.a        File: C:\virus\virus1.zip/virus/2.exe//UPack//ASPack
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/2209[1].exe//ASPack//#
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/3.exe
deleted: Trojan program Trojan-Downloader.Win32.Flux.a        File: C:\virus\virus1.zip/virus/3EE4F2CC.EXE//UPack//ASPack
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/4.exe//ASPack//#
deleted: Trojan program Trojan-Downloader.Win32.Cryptic.gen        File: C:\virus\virus1.zip/virus/5.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.eqn        File: C:\virus\virus1.zip/virus/565.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/6.exe//ASPack//#
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/62205[1].exe//#
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/66005[1].exe//ASPack//#
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/7.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Dropper.Win32.Small.ayg        File: C:\virus\virus1.zip/virus/8.exe
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/847[1].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/9.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/944.exe//data0003
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/944.exe//data0004
deleted: Trojan program Trojan.BAT.KillAV.ff        File: C:\virus\virus1.zip/virus/999[1].rar//#
deleted: Trojan program Trojan-Downloader.Win32.Agent.bys        File: C:\virus\virus1.zip/virus/aabb.exe
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/acpidisk.sys
deleted: adware not-a-virus:AdWare.Win32.Rond.c        File: C:\virus\virus1.zip/virus/b122.exe
deleted: adware not-a-virus:AdWare.Win32.Rond.c        File: C:\virus\virus1.zip/virus/b122.exe.bin/b122.exe
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/bd4[1].rar//data0003
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/cc_231[1].exe
deleted: Trojan program Trojan-Dropper.Win32.Small.ayg        File: C:\virus\virus1.zip/virus/cmd.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bys        File: C:\virus\virus1.zip/virus/cuod.exe
deleted: Trojan program Trojan-Downloader.Win32.Cryptic.gen        File: C:\virus\virus1.zip/virus/dodolook264[1].exe
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/DoSSSetup.dll
deleted: Trojan program Trojan-Downloader.Win32.Small.dxm        File: C:\virus\virus1.zip/virus/guyi1234.exe
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/gwTiN.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: virus Heur.Trojan.Generic (modification)        File: C:\virus\virus1.zip/virus/husjdd8s.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.dxm        File: C:\virus\virus1.zip/virus/ldcore.dll
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.g        File: C:\virus\virus1.zip/virus/MSURLPAR.dll
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.g        File: C:\virus\virus1.zip/virus/MSURLPAR.dll.zgx.tmp/MSURLPAR.dll.zgx
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.g        File: C:\virus\virus1.zip/virus/mszstb.dll
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.g        File: C:\virus\virus1.zip/virus/mszstb.dll.zgx.tmp/mszstb.dll.zgx
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.i        File: C:\virus\virus1.zip/virus/mszstb.sys
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.i        File: C:\virus\virus1.zip/virus/mszstb.sys.tmp/mszstb.sys
deleted: Trojan program Trojan-Downloader.Win32.VB.atk        File: C:\virus\virus1.zip/virus/my_70136[1].rar
deleted: adware not-a-virus:AdWare.Win32.Rond.c        File: C:\virus\virus1.zip/virus/popinstall.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bls        File: C:\virus\virus1.zip/virus/retadpu22.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.bls        File: C:\virus\virus1.zip/virus/retadpu565.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.bls        File: C:\virus\virus1.zip/virus/retadpu[1].exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Backdoor.Win32.Small.bq        File: C:\virus\virus1.zip/virus/SCardSevr.exe//UPX
deleted: adware not-a-virus:AdWare.Win32.Cinmus.t        File: C:\virus\virus1.zip/virus/sd.exe
deleted: adware not-a-virus:AdWare.Win32.Zhongsou.h        File: C:\virus\virus1.zip/virus/Setup.exe//PE_Patch
detected: adware not-a-virus:AdWare.Win32.Zhongsou.i        File: C:\virus\virus1.zip/virus/setup.tmp
deleted: Trojan program Trojan.Win32.Small.oa        File: C:\virus\virus1.zip/virus/UnInstall.exe
deleted: Trojan program Trojan-Downloader.Win32.Cryptic.gen        File: C:\virus\virus1.zip/virus/wdfmgrnt.exe
deleted: adware not-a-virus:AdWare.Win32.Rond.c        File: C:\virus\virus1.zip/virus/winpop.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.eqn        File: C:\virus\virus1.zip/virus/wr-1-22.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
dsl5
发表于 2007-8-1 17:41:06 | 显示全部楼层
我没有装winrar,没法解压测微点,用微点的帮忙测下
rasis
发表于 2007-8-1 19:14:36 | 显示全部楼层
Begin scan in 'virus'
virus\0.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\010001[1].exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [WARNING]   The file was ignored!
virus\023[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\1.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [WARNING]   The file was ignored!
virus\10.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\10012[1].exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
      [WARNING]   The file was ignored!
virus\1012[1].exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
      [WARNING]   The file was ignored!
virus\103.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
      [WARNING]   The file was ignored!
virus\1063.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.58
      [WARNING]   The file was ignored!
virus\1063[1].exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.58
      [WARNING]   The file was ignored!
virus\1093[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\1093[2].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\11.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\112.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.atk.58
      [WARNING]   The file was ignored!
virus\1228[1].exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.23
      [WARNING]   The file was ignored!
virus\123.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\13715C84.EXE
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\1jh3jq.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [WARNING]   The file was ignored!
virus\2.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
      [WARNING]   The file was ignored!
virus\2209[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\3.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\3EE4F2CC.EXE
      [DETECTION] Is the Trojan horse TR/Dldr.Flux.A
      [WARNING]   The file was ignored!
virus\4.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\5.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\565.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\6.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\62205[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\66005[1].exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [WARNING]   The file was ignored!
virus\7.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\8.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Small.eqn.23
      [WARNING]   The file was ignored!
virus\847[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\9.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\944.exe
      [DETECTION] Contains signature of the dropper DR/Cinmus.T.5
      [WARNING]   The file was ignored!
virus\999[1].rar
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\aabb.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.bys
      [WARNING]   The file was ignored!
virus\acpidisk.sys
      [DETECTION] Contains signature of the rootkit RKIT/Cinmus.M
      [WARNING]   The file was ignored!
virus\bao118[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\bd2[1].rar
      [DETECTION] Is the Trojan horse TR/Dldr.Agen.YZ.3.A
      [WARNING]   The file was ignored!
virus\bd4[1].rar
      [DETECTION] Contains signature of the dropper DR/Cinmus.T.7
      [WARNING]   The file was ignored!
virus\bd8[1].rar
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\cc_231[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\cmd.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [WARNING]   The file was ignored!
virus\comvspn.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\cuod.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Agent.bys.1
      [WARNING]   The file was ignored!
virus\dodolook264[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\DoSSSetup.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Cinmus.JH
      [WARNING]   The file was ignored!
virus\guyi1234.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
      [WARNING]   The file was ignored!
virus\gwTiN.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\husjdd8s.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
virus\imlgotgwckmja.dll
      [DETECTION] Is the Trojan horse TR/Ieser.A
      [WARNING]   The file was ignored!
virus\internat.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [WARNING]   The file was ignored!
virus\ldcore.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Small.dxm.3
      [WARNING]   The file was ignored!
virus\mclient.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\mszstb.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\mszstb.dll.zgx.tmp
  [0] Archive type: CAB (Microsoft)
  --> mszstb.dll.zgx
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\mszstb.sys
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Zhongsou.I
      [WARNING]   The file was ignored!
virus\mszstb.sys.tmp
  [0] Archive type: CAB (Microsoft)
  --> mszstb.sys
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Zhongsou.I
      [WARNING]   The file was ignored!
virus\my_70136[1].rar
      [DETECTION] Is the Trojan horse TR/Dldr.VB.atk.58
      [WARNING]   The file was ignored!
virus\popinstall.exe
      [DETECTION] Is the Trojan horse TR/Popwin.DE.1
      [WARNING]   The file was ignored!
virus\retadpu22.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\retadpu565.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\retadpu[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\sb.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agen.YZ.3.A
      [WARNING]   The file was ignored!
virus\SCardSevr.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\sd.exe
      [DETECTION] Contains signature of the dropper DR/Cinmus.T.7
      [WARNING]   The file was ignored!
virus\Setup.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [WARNING]   The file was ignored!
virus\sh.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
virus\spnvup.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\tnisiddnwaexy.dll
      [DETECTION] Is the Trojan horse TR/Ieser.A
      [WARNING]   The file was ignored!
virus\uj5geqq3.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
virus\UnInstall.exe
      [DETECTION] Is the Trojan horse TR/Small.OA
      [WARNING]   The file was ignored!
virus\wdfmgrnt.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\winpop.exe
      [DETECTION] Is the Trojan horse TR/Popwin.DE
      [WARNING]   The file was ignored!
virus\wr-1-22.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
virus\y9r5hl.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [WARNING]   The file was ignored!


End of the scan: 2007年8月1日  19:14
Used time: 00:15 min

The scan has been done completely.

      1 Scanning directories
     86 Files were scanned
     75 viruses and/or unwanted programs were found
     11 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      4 Archives were scanned
     75 Warnings
      0 Notes
      0 Hidden objects were found
scottxzt
发表于 2007-8-1 19:16:41 | 显示全部楼层
微全部测了,除了DLL SYS 文件.

[ 本帖最后由 scottxzt 于 2007-8-1 19:19 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-9 19:34 , Processed in 0.138657 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表