查看: 6911|回复: 44
收起左侧

[讨论] 新年eset大礼物!8mb病毒库大清仓!

[复制链接]
傻猪猪米走鸡
发表于 2008-1-2 22:56:06 | 显示全部楼层 |阅读模式
今晚突然更新了8mb的特征库,果然不同啊!!!
先看一堆例子里面至少有半年前的货……

D:\firefox download\old samples\003.rar » RAR » 003.htm - probably a variant of JS/TrojanDownloader.Agent trojan - was a part of the deleted object
D:\firefox download\old samples\003.rar - probably a variant of JS/TrojanDownloader.Agent trojan - deleted - quarantined
D:\firefox download\old samples\al.rar » RAR » al.exe - probably a variant of Win32/TrojanDownloader.Delf trojan - was a part of the deleted object
D:\firefox download\old samples\al.rar - probably a variant of Win32/TrojanDownloader.Delf trojan - deleted - quarantined
D:\firefox download\old samples\bf.rar » RAR » bf\conime0.exe - probably a variant of Win32/PSW.OnLineGames trojan - was a part of the deleted object
D:\firefox download\old samples\bf.rar - probably a variant of Win32/PSW.OnLineGames trojan - deleted - quarantined
D:\firefox download\old samples\gz.rar » RAR » gz.exe - probably a variant of Win32/TrojanDropper.Agent trojan - was a part of the deleted object
D:\firefox download\old samples\gz.rar - probably a variant of Win32/TrojanDropper.Agent trojan - deleted - quarantined
D:\firefox download\old samples\MYOFFICES.rar » RAR » MYOFFICES.EXE - probably a variant of Win32/Spy.Agent trojan - was a part of the deleted object
D:\firefox download\old samples\MYOFFICES.rar - probably a variant of Win32/Spy.Agent trojan - deleted - quarantined
D:\firefox download\old samples\NetRunTime.rar » RAR » NetRunTime.exe - probably a variant of Win32/Spy.Delf trojan - was a part of the deleted object
D:\firefox download\old samples\NetRunTime.rar - probably a variant of Win32/Spy.Delf trojan - deleted - quarantined
D:\firefox download\old samples\sample.rar » RAR » sample.EXE » CAB » 2VMP~1.EXE - probably a variant of Win32/Obfuscated trojan - was a part of the deleted object
D:\firefox download\old samples\sample.rar » RAR » sample.EXE - probably a variant of Win32/Obfuscated trojan - was a part of the deleted object
D:\firefox download\old samples\sample.rar - probably a variant of Win32/Obfuscated trojan - deleted - quarantined
D:\firefox download\old samples\SWZ.rar » RAR » a55_.dll - probably a variant of Win32/Spy.Delf trojan - was a part of the deleted object
D:\firefox download\old samples\SWZ.rar - probably a variant of Win32/Spy.Delf trojan - deleted - quarantined
D:\firefox download\old samples\uusee.rar » RAR » uusee.exe - probably a variant of Win32/TrojanDownloader.Delf trojan - was a part of the deleted object
D:\firefox download\old samples\uusee.rar - probably a variant of Win32/TrojanDownloader.Delf trojan - deleted - quarantined
D:\firefox download\old samples\样本(2).rar » RAR » 样本(2)\33890.exe - probably a variant of Win32/VB trojan - was a part of the deleted object
D:\firefox download\old samples\样本(2).rar » RAR » 样本(2)\dianji2.exe - probably a variant of Win32/VB trojan - was a part of the deleted object
D:\firefox download\old samples\样本(2).rar » RAR » 样本(2)\gx.exe - probably a variant of Win32/VB trojan - was a part of the deleted object
D:\firefox download\old samples\样本(2).rar - probably a variant of Win32/VB trojan - deleted - quarantined
D:\firefox download\old samples\桌面.rar » RAR » 04[1].htm - probably a variant of HTML/Exploit.Agent trojan - was a part of the deleted object
D:\firefox download\old samples\桌面.rar - probably a variant of HTML/Exploit.Agent trojan - deleted - quarantined
D:\firefox download\old samples\gz\gz.exe - probably a variant of Win32/TrojanDropper.Agent trojan - cleaned by deleting - quarantined
傻猪猪米走鸡
 楼主| 发表于 2008-1-2 22:57:39 | 显示全部楼层
明显增加了html的特征码!
所以里面的html病毒侦测出来了!
NOD32 - v.2761 (20080102)
Virus signature database updates:
Mac/Rootkit.Weapox.A, Win32/Adware.CDN, Win32/Adware.SearchSpy (2), Win32/Agent.NOQ (2), Win32/Agent.QT (2), Win32/AutoRun.FH, Win32/IRCBot.ABT, Win32/PSW.Agent.NEC, Win32/PSW.Agent.NGY, Win32/PSW.OnLineGames.DTR, Win32/PSW.OnLineGames.DVV, Win32/PSW.OnLineGames.HCV (5), Win32/PSW.OnLineGames.KDP, Win32/PSW.OnLineGames.MST (2), Win32/PSW.OnLineGames.NFL (10), Win32/PSW.OnLineGames.YA (2), Win32/Rootkit.Vanti.NAI, Win32/Rustock.NDA, Win32/Scramble.A, Win32/SpamTool.Agent.NAO, Win32/Spy.Banker.OOL, Win32/Theals (4), Win32/TrojanDownloader.Agent.NUE (2), Win32/TrojanDownloader.Banload.BDA, Win32/TrojanDownloader.Banload.GAF (2), Win32/TrojanProxy.Small.NAS

NOD32 - v.2760 (20080102)
Virus signature database updates:
HTML/TrojanDownloader.Agent.IQ, JS/Exploit.BO.NAE, VBS/Agent.W, VBS/AutoRun.B (2), VBS/AutoRun.Y (5), Win32/Adware.IeDefender.NAY, Win32/Adware.IeDefender.NAZ (4), Win32/Adware.IeDefender.NBA (2), Win32/Adware.SearchSpy (5), Win32/AutoRun.FG, Win32/AutoRun.FH, Win32/AutoRun.FI (2), Win32/HackTool.WpaKill.A, Win32/Hakaglan.B, Win32/HideProc.C, Win32/Inject.NAJ (3), Win32/Nuwar.BF (3), Win32/Pacex.Gen (22), Win32/PSW.Hangame.NAU (3), Win32/PSW.Legendmir.NFF, Win32/PSW.OnLineGames.HCV (6), Win32/PSW.OnLineGames.HTM, Win32/PSW.OnLineGames.JRG, Win32/PSW.OnLineGames.MQS, Win32/PSW.OnLineGames.NBR (2), Win32/PSW.OnLineGames.NFL (8), Win32/PSW.OnLineGames.NFN (3), Win32/PSW.OnLineGames.NFO (2), Win32/PSW.OnLineGames.YA, Win32/PSW.WOW.WU, Win32/Rootkit.Agent.NBQ, Win32/Rootkit.Agent.NCK, Win32/Spy.Agent.AHD, Win32/Spy.Agent.ALD, Win32/Spy.Agent.ALJ, Win32/Spy.Agent.AVZ (3), Win32/Spy.Agent.NEM, Win32/Spy.Sters, Win32/TrojanClicker.VB.NDI, Win32/TrojanDownloader.Agent.GXP (4), Win32/TrojanDownloader.Agent.NPO, Win32/TrojanDownloader.Agent.NUD, Win32/TrojanDownloader.Delf.DQP, Win32/TrojanDownloader.Flux, Win32/TrojanDownloader.Flux.K, Win32/TrojanDownloader.QQHelper.NDW, Win32/TrojanDownloader.Small.EQL, Win32/TrojanDownloader.Tiny.Y (2), Win32/VB.NKM (2), Win32/Virut.AD
风野胤
发表于 2008-1-2 23:10:24 | 显示全部楼层
Win32/Adware.CDN
eset,good job!
sunrqing
发表于 2008-1-2 23:25:43 | 显示全部楼层
病毒库2761,我怎么还是2759?我的可是官方的。
clc78223
发表于 2008-1-2 23:35:29 | 显示全部楼层
nod32版本还是2760,这回是优先升级新版本了,哈
运指如飞
发表于 2008-1-2 23:43:19 | 显示全部楼层
我怎么还是2759,而且升级提示是最新版本

用的PPLIVE半年ID
clc78223
发表于 2008-1-2 23:55:50 | 显示全部楼层
用自动服务器更新,国内的服务器更新比较慢
欠妳緈諨
发表于 2008-1-3 00:09:46 | 显示全部楼层
我也升到2761.只更新了231K?
remember24
发表于 2008-1-3 00:32:12 | 显示全部楼层
我装的ESET NOD32 Antivirus 怎么更新后在关于里查看多出了个人防火墙模块和邮件模块,之前都没的???????
zfznbic
发表于 2008-1-3 00:34:04 | 显示全部楼层
好消息。。。估计不少人又得来这了哦。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 09:38 , Processed in 0.133189 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表