查看: 3748|回复: 25
收起左侧

[技术原创] 安装1月14号发布的QQ2007II版本红伞狂报警

[复制链接]
ghjkl119
发表于 2008-1-15 08:28:40 | 显示全部楼层 |阅读模式
2008-1-13,20:03:15 [WARNING] Is the Trojan horse TR/IFrame.AW.1!
  C:\Documents and Settings\zxc\Local Settings\Temporary Internet Files\Content.IE5\97Q1VZLP\6655996[1].htm
      [INFO] The file will be deleted.
2008-1-13,20:08:10 [CONFIG] On-Access configuration used:
      - Files to scan:  scan files from local drives
      - Device mode:  scan files on open, scan files on close
      - Scan files with all extensions (smart)
      - Unpack runtime compressed files
      - Actions: Delete file
      - Heuristic: MACRO , WIN32 MEDIUM
      - Logfile report level 1
2008-1-13,20:21:26 Avira AntiVir PersonalEdition Premium service has been stopped!
2008-1-14,7:13:48 ---------------------------------------------------------
2008-1-14,7:13:53 Keyfile contains a valid license. The Avira AntiVir PersonalEdition Premium will run as a fully functional version!
2008-1-14,7:13:53 AntiVir Guard version: 7.00.00.82,engine version 7.6.0.46,VDF version: 7.0.1.227
2008-1-14,7:13:54 Start Filter Device.
2008-1-14,7:13:54 Avira AntiVir PersonalEdition Premium has been started successfully!
2008-1-14,7:13:54 [CONFIG] On-Access configuration used:
      - Files to scan:  scan files from local drives
      - Device mode:  scan files on open, scan files on close
      - Scan files with all extensions (smart)
      - Unpack runtime compressed files
      - Actions: Delete file
      - Heuristic: MACRO , WIN32 MEDIUM
      - Logfile report level 1
2008-1-14,7:16:14 Update process started!
2008-1-14,7:16:15 Current Engine Version: 7.6.0.46
2008-1-14,7:16:15 Current Pattern File: 7.0.1.228 from 2008-1-13, 22:35
2008-1-14,7:16:16 [CONFIG] On-Access configuration used:
      - Files to scan:  scan files from local drives
      - Device mode:  scan files on open, scan files on close
      - Scan files with all extensions (smart)
      - Unpack runtime compressed files
      - Actions: Delete file
      - Heuristic: MACRO , WIN32 MEDIUM
      - Logfile report level 1
2008-1-14,21:05:12 Avira AntiVir PersonalEdition Premium service has been stopped!
2008-1-15,7:21:15 ---------------------------------------------------------
2008-1-15,7:21:19 Keyfile contains a valid license. The Avira AntiVir PersonalEdition Premium will run as a fully functional version!
2008-1-15,7:21:19 AntiVir Guard version: 7.00.00.82,engine version 7.6.0.46,VDF version: 7.0.1.228
2008-1-15,7:21:20 Start Filter Device.
2008-1-15,7:21:21 Avira AntiVir PersonalEdition Premium has been started successfully!
2008-1-15,7:21:21 [CONFIG] On-Access configuration used:
      - Files to scan:  scan files from local drives
      - Device mode:  scan files on open, scan files on close
      - Scan files with all extensions (smart)
      - Unpack runtime compressed files
      - Actions: Delete file
      - Heuristic: MACRO , WIN32 MEDIUM
      - Logfile report level 1
2008-1-15,7:23:42 Update process started!
2008-1-15,7:23:43 Current Engine Version: 7.6.0.46
2008-1-15,7:23:43 Current Pattern File: 7.0.1.236 from 2008-1-14, 16:33
2008-1-15,7:23:44 [CONFIG] On-Access configuration used:
      - Files to scan:  scan files from local drives
      - Device mode:  scan files on open, scan files on close
      - Scan files with all extensions (smart)
      - Unpack runtime compressed files
      - Actions: Delete file
      - Heuristic: MACRO , WIN32 MEDIUM
      - Logfile report level 1
2008-1-15,8:20:06 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsq10.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:20:12 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsj13.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:24:51 [WARNING] Is the Trojan horse TR/IFrame.AW.1!
  C:\Documents and Settings\zxc\Local Settings\Temporary Internet Files\Content.IE5\RWZWEU6K\6655996[1].htm
      [INFO] The file will be deleted.
2008-1-15,8:25:26 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:33 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:46 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:47 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:47 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:54 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:25:54 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsd16.tmp\Setup_QQ.exe
      [INFO] The file will be deleted.
2008-1-15,8:37:53 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:38:00 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:38:02 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:38:02 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:38:09 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\ProcDll2.dll
      [INFO] The file will be deleted.
2008-1-15,8:38:09 [WARNING] Contains detection pattern of the Ad- or Spyware ADSPY/AdPlus.B.6!
  C:\Documents and Settings\zxc\Local Settings\Temp\nsi23.tmp\Setup_QQ.exe
      [INFO] The file will be deleted.

[ 本帖最后由 ghjkl119 于 2008-1-15 08:39 编辑 ]
周杰伦
发表于 2008-1-15 08:39:56 | 显示全部楼层
建议楼主把红伞报警的文件发上来,让我们分析看看
Graybird
发表于 2008-1-15 08:45:50 | 显示全部楼层
广告插件~
ghjkl119
 楼主| 发表于 2008-1-15 08:46:27 | 显示全部楼层
原帖由 周杰伦 于 2008-1-15 08:39 发表
建议楼主把红伞报警的文件发上来,让我们分析看看

要发啥?你去腾讯主页下个最新的QQ2007II正式版 点开安装下就行了  我抓的日志而已
周杰伦
发表于 2008-1-15 08:48:13 | 显示全部楼层

回复 4楼 ghjkl119 的帖子

ok,不过,可以确定应该是流氓软件了
ucfeg
头像被屏蔽
发表于 2008-1-15 09:20:53 | 显示全部楼层
qq怎么这样流氓
Ueetee
发表于 2008-1-15 09:38:08 | 显示全部楼层
哎 QQ越来越流氓了 呵呵
desertone
发表于 2008-1-15 09:50:10 | 显示全部楼层
是啊,我也是昨晚安装的,红伞一直狂报。
wwtd
发表于 2008-1-15 10:00:00 | 显示全部楼层
报的基本都是广告,应该不算什么大问题
吃佛念斋
头像被屏蔽
发表于 2008-1-15 10:48:12 | 显示全部楼层
QQ不是什么好东西。用TM吧
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-4 17:29 , Processed in 0.146633 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表