楼主: promised
收起左侧

[病毒样本] 10[MD5: B6DCD7 011D1C 81A00C 90D80D 5D7006 FD92CB F6F78F FAF462 C8E7CD 47C914]

[复制链接]
seamonkey
发表于 2007-8-19 11:46:36 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.IMMSG.Win32.TBMSG.ke
病毒: Trojan.Win32.Agent.vpz   
病毒: Trojan.Clicker.Win32.PopHot.a
病毒: Trojan.Win32.Agent.vqe   
病毒: Trojan.DL.Win32.Agent.xfj
病毒: Trojan.Win32.MultiDrop.b
hj5abc
发表于 2007-8-19 11:50:51 | 显示全部楼层
7..

Scanned disks, folders and files: F:\ABC.zip
F:\ABC.zip ?ZIP ?2.exe - probably a variant of Win32/Genetik trojan
F:\ABC.zip ?ZIP ?3.exe - probably a variant of Win32/Agent.NEO trojan
F:\ABC.zip ?ZIP ?4.exe - probably a variant of Win32/Genetik trojan
F:\ABC.zip ?ZIP ?5.exe - probably a variant of Win32/Genetik trojan
F:\ABC.zip ?ZIP ?6.exe - probably unknown NewHeur_PE virus [7]
F:\ABC.zip ?ZIP ?8.exe - a variant of Win32/Agent.NAU worm
F:\ABC.zip ?ZIP ?7.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application
kp2006
头像被屏蔽
发表于 2007-8-19 12:14:41 | 显示全部楼层
瑞星2007报8个
电影结束了
发表于 2007-8-19 12:25:15 | 显示全部楼层
扫描系统区域...
扫描所选择的目录和文件...
对象: 1.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Trojan.Dropper.Sramler.B (BD 引擎)
对象: 2.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: DeepScan:Generic.Malware.SBdldspg.C33A5DDA (BD 引擎)
对象: 3.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: GenPack:Generic.Popwin.AC61DAB6 (BD 引擎)
对象: 4.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: GenPack:Generic.Malware.SBdldg.D8FBEB03 (BD 引擎)
对象: 5.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Generic.Onlinegames.5.0D4AF3E9 (BD 引擎)
对象: 6.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 可疑病毒
        病毒: Dropped:Generic.Malware.dldsp.8BBDD9DA (BD 引擎)
对象: 8.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Win32.Worm.Agent.AQ (BD 引擎)
对象: 7.exe=>(NSIS o) lzma_nsis0000
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Trojan.Cinmeng.A (BD 引擎)
对象: 7.exe=>(NSIS o) lzma_nsis0002
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Generic.Adw.Cinmus.2.C6C99AAF (BD 引擎)
对象: 0.exe
        在压缩档案里: C:\Documents and Settings\wangcheng\桌面\ABC.zip
        Status: 已发现病毒
        病毒: Trojan.Dropper.Sramler.B (BD 引擎)
对象: ABC.zip
        路径: C:\Documents and Settings\wangcheng\桌面
        Status: 已发现病毒
        病毒: Trojan.Dropper.Sramler.B (2x), DeepScan:Generic.Malware.SBdldspg.C33A5DDA, GenPack:Generic.Popwin.AC61DAB6, GenPack:Generic.Malware.SBdldg.D8FBEB03, Generic.Onlinegames.5.0D4AF3E9, Dropped:Generic.Malware.dldsp.8BBDD9DA, Win32.Worm.Agent.AQ, Trojan.Cinmeng.A, Generic.Adw.Cinmus.2.C6C99AAF (BD 引擎)
扫描完成: 2007-8-19 12:24
    已检查 1 个文件
    已发现 1 个染毒文件
gho
发表于 2007-8-19 12:28:06 | 显示全部楼层
2007-8-19        12:26:27        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\2.exe        New Malware.dm (Trojan)
2007-8-19        12:26:29        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\3.exe        New Malware.dm (Trojan)
2007-8-19        12:26:29        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\4.exe        New Malware.dm (Trojan)
2007-8-19        12:26:29        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\5.exe        New Malware.aj (Trojan)
gho
发表于 2007-8-19 12:28:26 | 显示全部楼层
剩下的
已删除: 病毒 Worm.Win32.Agent.t        文件: C:\Documents and Settings\gho\桌面\8.exe//PE_Patch.PECompact//PecBundle//PECompact
已删除: 木马程序 Trojan-Dropper.Win32.Sramler.e        文件: C:\Documents and Settings\gho\桌面\0.exe
已删除: 木马程序 Trojan-Dropper.Win32.Sramler.e        文件: C:\Documents and Settings\gho\桌面\1.exe
已删除: 木马程序 Trojan.Win32.Agent.awf        文件: C:\Documents and Settings\gho\桌面\6.exe//PE_Patch.UPX//UPX
已删除: 广告程序 not-a-virus:AdWare.Win32.Cinmus.al        文件: C:\Documents and Settings\gho\桌面\7.exe//data0003
已删除: 广告程序 not-a-virus:AdWare.Win32.Cinmus.al        文件: C:\Documents and Settings\gho\桌面\7.exe//data0004
uhthn2002
发表于 2007-8-19 13:38:29 | 显示全部楼层
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\1.exe : infected Trojan-Dropper.Win32.Sramler.b
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\2.exe : infected Backdoor.Win32.Agent.arn
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\3.exe : infected Backdoor.Win32.Agent.ahj
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\5.exe : is suspected of Trojan-PSW.Game.39 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\8.exe : infected Worm.Win32.Agent.t
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\9.exe : infected Trojan.MulDrop.7434
C:\Documents and Settings\uhthn\Desktop\ABC.zip:<ZIP>\0.exe : infected Trojan-Dropper.Win32.Sramler.b


Directories       : 0       Files in archives:      Files on disks:
Archives:                   - total       : 10      - total       : 1     
- scanned         : 1       -  scanned    : 10      - scanned     : 1     
- contain viruses : 1       -  infected   : 6       - infected    : 1     
- deleted         : 0       -  suspicious : 1       - suspicious  : 0
taihuxian
发表于 2007-8-19 15:32:26 | 显示全部楼层
Scan performed at: 2007-8-19 15:31:28
Scanning Log
NOD32 version 2469 (20070818) NT
Command line: C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip
Operating memory - is OK

Date: 19.8.2007  Time: 15:31:36
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?2.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?3.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?4.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?5.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?6.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?8.exe - a variant of Win32/Agent.NAU worm
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾\ABC.zip ?ZIP ?7.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application - was a part of the deleted object
Number of scanned files: 13
Number of threats found: 7
Number of files cleaned: 1
Time of completion: 15:31:42 Total scanning time: 6 sec (00:00:06)

Notes:
[7] File is probably infected with an unknown virus.
woai_jolin
发表于 2007-8-19 15:34:46 | 显示全部楼层
===================================================================================================
NVCOD On Demand Scanner 5.80.02

NSE revision 5.91.04
nvcbin.def revision 5.90.00 of 2007/08/17 08:03:55 (830940 variants)
nvcmacro.def revision 5.90.00 of 2007/08/06 19:46:49 (20358 variants)
Total number of variants: 851298
Command line: "@C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~OD12.tmp"
===================================================================================================

       Time  Filename                                                     Virus name
---------------------------------------------------------------------------------------------------
- Scanning files matching: F:\v\ABC.zip
     16922 ms F:\v\ABC.zip : 1.exe                                       
       16 ms F:\v\ABC.zip : 2.exe                                         Trojan Hupigon.gen66 ()
        0 ms F:\v\ABC.zip : 3.exe                                         Trojan Hupigon.gen66 ()
        0 ms F:\v\ABC.zip : 4.exe                                         Trojan Hupigon.gen66 ()
       15 ms F:\v\ABC.zip : 5.exe                                         Security Risk W32/Suspicious_U.gen ()
      641 ms F:\v\ABC.zip : 6.exe                                       
       62 ms F:\v\ABC.zip : 8.exe                                         Worm W32/Smallworm.ABR ()
      125 ms F:\v\ABC.zip : 9.exe                                       
      953 ms F:\v\ABC.zip : 7.exe                                       
     5375 ms F:\v\ABC.zip : 0.exe                                       
        0 ms F:\v\ABC.zip                                                
        0 ms F:\v\ABC.zip:Zone.Identifier                                
- File F:\v\ABC.zip quarantined.
- File F:\v\ABC.zip quarantined.
- File F:\v\ABC.zip quarantined.
- File F:\v\ABC.zip quarantined.
- File F:\v\ABC.zip quarantined.

===================================================================================================

The scanning started: 2007/08/19 15:34:16
               ended: 2007/08/19 15:34:41
Logged on as        : Administrator
on hostname         : 2FF87FC2B9AB46F

Scanning results:
   Total number of files found..............................:      12
   Number of files scanned..................................:      12
   Number of files/directories skipped due to exclude list..:       0
   Number of files that could not be opened.................:       0
   Number of archive files unpacked.........................:       1
   Number of archive files not unpacked.....................:       0
   Number of infections.....................................:       5

Copyright (c) 1993-2005 Norman ASA.
taihuxian
发表于 2007-8-19 19:04:40 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\样本\ABC.zip'
C:\Documents and Settings\Administrator\桌面\样本\ABC.zip
  [0] Archive type: ZIP
  --> 1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 4.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Agent.PN.345
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/Agent.avl.7
  --> 8.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> 9.exe
      [DETECTION] Contains signature of the dropper DR/Agent.BZ.23
  --> 0.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      A backup was created as '470b23f8.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!


End of the scan: 2007年8月19日  19:04
Used time: 00:20 min

The scan has been done completely.

      0 Scanning directories
     11 Files were scanned
      9 viruses and/or unwanted programs were found
      2 classified as suspicious:
      1 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
     11 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 04:09 , Processed in 0.101808 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表