查看: 1869|回复: 8
收起左侧

[病毒样本] BD报的

[复制链接]
liunanyuan
发表于 2007-10-28 13:30:20 | 显示全部楼层 |阅读模式
Scanned files C:\Documents and Settings\Administrator\Desktop\2.rar OK C:\Documents and Settings\Administrator\Desktop\2.rar=>KAVPassport.DLL Infected: Backdoor.Assasin.X C:\Documents and Settings\Administrator\Desktop\2.rar=>KAVPassport.DLL Disinfection failed C:\Documents and Settings\Administrator\Desktop\2.rar=>KAVPassport.DLL Move failed C:\Documents and Settings\Administrator\Desktop\2.rar=>cnnic.exe Infected: Trojan.Muldrop.EA C:\Documents and Settings\Administrator\Desktop\2.rar=>cnnic.exe Disinfection failed C:\Documents and Settings\Administrator\Desktop\2.rar=>cnnic.exe Move failed

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
dyw1021
头像被屏蔽
发表于 2007-10-28 13:36:17 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\cnnic.rar'
C:\Documents and Settings\Administrator\桌面\cnnic.rar
  [0] Archive type: RAR
  --> cnnic.exe
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Cdnup.A.1
      [INFO]      The file was moved to '47922039.qua'!


End of the scan: 2007年10月28日  13:36
Used time: 00:03 min

The scan has been done completely.

      0 Scanning directories
      2 Files were scanned
      1 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
mofunzone
发表于 2007-10-28 13:41:13 | 显示全部楼层
We received the following archive files:
File ID          Filename          Size (Byte)         Result
2229167          KAVPassport.rar         168.79 KB         OK

A listing of files contained inside archives alongside their results can be found below:
File ID          Filename          Size (Byte)         Result
199858          KAVPassport.DLL          172.5 KB          FALSE POSITIVE


Please find a detailed report concerning each individual sample below:
Filename         Result
KAVPassport.DLL          FALSE POSITIVE

The file 'KAVPassport.DLL' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection is removed from our virus definition file (VDF) with the version: 6.37.1.24 .
平淡
发表于 2007-10-28 13:49:50 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
BING126
头像被屏蔽
发表于 2007-10-28 15:48:23 | 显示全部楼层
McAfee MISS
Nerazzurri
发表于 2007-10-28 16:09:16 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
HC303
发表于 2007-10-28 18:01:40 | 显示全部楼层
楼主是不是装了金山词霸破解版
KAVPASSPORT.DLL好像是用来破解金山通行证的.
Nerazzurri
发表于 2007-10-28 18:03:33 | 显示全部楼层

第二个

Hello.
No malicious software was found in the attached file.

Please quote all when answering. Do not forget to include you registration data.
-----------------
Regards, Vyacheslav Zakorzhevsky
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com


> Attachment: KAVPassport.rar
29159011
发表于 2007-10-29 19:02:39 | 显示全部楼层
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\SETUP\SETUP.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\CNNIC\CDN\IDNCONV.DLL
2) C:\PROGRAM FILES\CNNIC\CDN\CDNUNINS.EXE
3) C:\PROGRAM FILES\CNNIC\CDN\CDNAUX.DLL
4) C:\PROGRAM FILES\CNNIC\CDN\CLIENT.DLL
5) C:\PROGRAM FILES\CNNIC\CDN\CDNCTR.EXE
6) C:\PROGRAM FILES\CNNIC\CDN\CDNIEHLP.DLL
7) C:\PROGRAM FILES\CNNIC\CDN\CDNGLO.DLL
8) C:\PROGRAM FILES\CNNIC\CDN\CDNDET.DLL
是否删除木马程序及其衍生物?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 10:12 , Processed in 0.126083 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表