楼主: format
收起左侧

[病毒样本] 卡巴报毒但还是中招了

[复制链接]
scottxzt
发表于 2007-12-5 20:14:26 | 显示全部楼层
程序:
C:\DOCUMENTS AND SETTINGS\DELL\桌面\AUTO.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\EB3FC60C.EXE
2) C:\WINDOWS\SYSTEM32\E5046A58.DLL
是否删除木马程序及其衍生物?
sam.to
发表于 2007-12-5 20:25:32 | 显示全部楼层
xfsd
发表于 2007-12-5 21:02:41 | 显示全部楼层
会吐气泡的丽丽鱼
来源:观赏鱼热线 时间:2005-12-5 16:35:00 点击次数:1663 【字体:大 中 小】
  丽丽鱼又名小丽丽鱼、核桃鱼、加拉米鱼、密妒鱼。它是原籍在印度的小型热带鱼。它体长只有 6 厘米左右,呈椭圆形,稍侧扁。雄鱼非常漂亮,有红、橙、蓝三色组成。头部为橙色、黑眼晴、红眼眶,鳃盖上有大块蓝色斑,整个躯干上有橙、蓝相间的条纹,背、臀、尾三鳍均有红、蓝、灰斑点,并镶以红边。其雌鱼体色稍浅,呈银灰色,有黄蓝相间的彩色条纹,各鳍均比雄鱼短。
  丽丽鱼的雌、雄鱼的胸鳍无色透明,腹鳍移到胸部演化成长长的须,很是别致。丽丽鱼以其美丽的颜色,深受人们喜爱,也是目前饲养较普遍、较广泛的观赏鱼。养丽丽鱼时,不必配对,可多养一些色彩鲜艳的雄鱼,少养一些雌鱼。
xfsd
发表于 2007-12-5 21:03:15 | 显示全部楼层
可呢被挂了的。没情况
hyacinth
发表于 2007-12-5 21:07:09 | 显示全部楼层
我又也遇到这样的情况啊!!!
mofunzone
发表于 2007-12-6 00:00:09 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\auto.exe'
C:\Users\morgan\Documents\
  auto.exe
    [0] Archive type: Runtime Packed
    --> Object
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
      [WARNING]   The file was ignored!
mofunzone
发表于 2007-12-6 00:01:33 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\TDDOWNLOAD\zt0616.exe'
C:\TDDOWNLOAD\
  zt0616.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Spy.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cq0619.exe'
C:\TDDOWNLOAD\
  cq0619.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cs0619.exe'
C:\TDDOWNLOAD\
  cs0619.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Spy.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\dh3.exe'
C:\TDDOWNLOAD\
  dh3.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Contains suspicious code HEUR/Malware
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\dh0616.exe'
C:\TDDOWNLOAD\
  dh0616.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Contains suspicious code HEUR/Malware
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\jh0619.exe'
C:\TDDOWNLOAD\
  jh0619.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Contains suspicious code HEUR/Malware
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\qqhx.exe'
C:\TDDOWNLOAD\
  qqhx.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jlf
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\qqsg.exe'
C:\TDDOWNLOAD\
  qqsg.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Contains suspicious code HEUR/Malware
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\tl0619.exe'
C:\TDDOWNLOAD\
  tl0619.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Spy.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\wd0618.exe'
C:\TDDOWNLOAD\
  wd0618.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Spy.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\wl0618.exe'
C:\TDDOWNLOAD\
  wl0618.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Spy.Gen
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\wow0617.exe'
C:\TDDOWNLOAD\
  wow0617.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGa.iqw
      [INFO]      The file was deleted!


End of the scan: 2007年12月5日  08:01
Used time: 00:06 min

The scan has been done completely.

      0 Scanning directories
     12 Files were scanned
      8 viruses and/or unwanted programs were found
      4 Files were classified as suspicious:
     12 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
     11 Archives were scanned
     11 Warnings
      0 Notes
Love=卡巴+费尔
发表于 2007-12-6 00:59:03 | 显示全部楼层
费尔都报了。
patrick9802
发表于 2007-12-6 03:57:34 | 显示全部楼层
进去,BD报了,木马,并且隔离了,还不错哦,实时监控很好。
leonfg
发表于 2007-12-6 14:29:28 | 显示全部楼层
估计漏了一些进来
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-13 22:08 , Processed in 0.091249 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表