楼主: wslam
收起左侧

[已解决] Choices

[复制链接]
woai_jolin
发表于 2008-2-13 14:56:12 | 显示全部楼层

回复 40楼 stonejr 的帖子

等我用FS试验完了就知道了 把报告贴出来就知道了
我只要TT   口说无凭没有意思

[ 本帖最后由 woai_jolin 于 2008-2-13 14:57 编辑 ]
stonejr
头像被屏蔽
发表于 2008-2-13 14:58:11 | 显示全部楼层
顺便试下NORMAN的SANDBOX,看看多牛B
stonejr
头像被屏蔽
发表于 2008-2-13 14:59:47 | 显示全部楼层
报告来了.重装用的红伞P

Starting the file scan:

Begin scan in 'C:\'
C:\lsass.exe.1791468.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
C:\lsass.exe.270015.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
C:\037589.log
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
C:\AUTORUN.INF
      [DETECTION] Is the Trojan horse TR/Harnig.WA
      [INFO]      The file was deleted!
C:\WINDOWS\system32\drivers\sptd.sys
      [WARNING]   The file could not be opened!
C:\Documents and Settings\Administrator\Local Settings\Temp\glbackup\codecxt.dat
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Boran.H.3
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\Local Settings\Temp\glbackup\codeeb.dat
  [0] Archive type: RAR SFX (self extracting)
  --> EbayShop\EbayShopSetup.exe
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/WebSearch.AJ.2
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\Local Settings\Temp\glbackup\codecnn.dat
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Cdnup.A.1
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8R9166FM\新建文件夹[1].rar
  [0] Archive type: RAR
  --> 2008×îÐÂÃâ·ÑË¢Q±ÒÈí¼þ.rar                                                                         .exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPI.Gen
  --> °ÖºÍÅ®¶ùÍæ½ÓÎÇ.DVD                                                                         .exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPI.Gen
  --> ÃÃ,¹ýÀ´¸øÎÒÃþÒ»Ãþ.DVD                                                                         .exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPI.Gen
  --> ×îÃÀµÄAVÅ®ÓÅ.DVD                                                                         .exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPI.Gen
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M5F5DC6Z\Setup[2].zip
  [0] Archive type: ZIP
  --> Setup.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgio.sys
      [WARNING]   The file could not be read!
C:\Program Files\F-Secure\Anti-Virus\avpfpi1.dll
      [WARNING]   The file could not be read!
C:\Recycled\Dc6.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
C:\Recycled\Dc7.zip
  [0] Archive type: ZIP
  --> Setup.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [INFO]      The file was deleted!
Begin scan in 'D:\' <PROGRAM>
D:\pagefile.sys
      [WARNING]   The file could not be opened!
D:\Program Files\webhy\webhy\msetup.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Dudu.a.1.B
      [INFO]      The file was deleted!
D:\Program Files\webhy\webhy\ly2_02.exe
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Dudu.a.1.A
      [INFO]      The file was deleted!
Begin scan in 'E:\' <GAME>
E:\AUTORUN.INF
      [DETECTION] Is the Trojan horse TR/Harnig.WA
      [INFO]      The file was deleted!
E:\OPKTools\samples\Oobe\oemhw.htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\OPKTools\samples\Oobe\nousbms.htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\OPKTools\samples\Oobe\nousbkm.htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\OPKTools\samples\Oobe\nousbkbd.htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\OPKTools\samples\Oobe\ispsgnup.htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\BattleNet\(PC)BNetMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\BattleNet\(PC)BNetTroubleshooting.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\BattleNet\ChatHelp.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\BattleNet\ClanHelp.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Layout\Index.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Layout\Index2.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Layout\IndexMac.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(Mac)InGame.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(Mac)PatchUninstall.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(Mac)ReadMeMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(Mac)Start.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(Mac)UIMainMenus.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)Addendum.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)InGame.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)PatchUninstall.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)ReadMeMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)Start.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\(PC)UIMainMenus.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\BNTOU.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\Contact.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\EULA.en.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\EULA.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Readme\Games.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(Mac)InstallUninstall.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(Mac)LAN.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(Mac)LockCrashDrivers.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(Mac)Patches.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(Mac)SupportMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(PC)InstallUninstall.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(PC)LAN.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(PC)LockCrashDrivers.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(PC)Patches.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\Support\(PC)SupportMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\(Mac)WorldEditMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\(PC)WorldEditMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\(WEH)WorldEditMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\AIEditor.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\CampaignEditor.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\CreationSet.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\FeaturesNav.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\Menus.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\ObjectEditor.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\SoundEditor.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\TerrainEdit.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\TriggerEdit.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\UnitEdit.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!
E:\Game\Warcraft 3\support\WorldEdit\WorldEditMenu.html
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Xorer
      [INFO]      The file was deleted!


End of the scan: 2008年2月13日  14:59
Used time: 34:26 min

The scan has been done completely.

   5046 Scanning directories
221612 Files were scanned
     69 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     66 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      4 Files cannot be scanned
221543 Files not concerned
   2001 Archives were scanned
      4 Warnings
     11 Notes
woai_jolin
发表于 2008-2-13 15:00:02 | 显示全部楼层

回复 42楼 stonejr 的帖子

难道你不知道FS的SY提示窗口里有norman对程序的评分 这就是sandbox的威力
我说了这么久你还是不知道
我彻底的被折服了
顺便说说磁盘机会感染非系统盘的exe rar程序
真不知道FS没有拦截成功 你的小红伞是怎末安装上去的

[ 本帖最后由 woai_jolin 于 2008-2-13 15:05 编辑 ]
stonejr
头像被屏蔽
发表于 2008-2-13 15:04:41 | 显示全部楼层

回复 44楼 woai_jolin 的帖子

我说了FS的系统控制弹出了几个窗口,看清楚!别再让我重复了.弹窗之后窗口消失,不断报毒,但杀不了.安全模式也挂了.拦截成功了?
stonejr
头像被屏蔽
发表于 2008-2-13 15:10:47 | 显示全部楼层

回复 44楼 woai_jolin 的帖子

没看到E盘被感染的HTML?
woai_jolin
发表于 2008-2-13 15:11:40 | 显示全部楼层

回复 46楼 stonejr 的帖子

看完你的log
发现这个磁盘机的威力太强悍了
woai_jolin
发表于 2008-2-13 15:12:24 | 显示全部楼层

回复 45楼 stonejr 的帖子

高级里面有sandbox的评分
stonejr
头像被屏蔽
发表于 2008-2-13 15:16:04 | 显示全部楼层

回复 48楼 woai_jolin 的帖子

不管你什么评分.我只关心NORMAN能不能拦截到这个样本.就这样,其他的就别浪费口水了
woai_jolin
发表于 2008-2-13 15:17:09 | 显示全部楼层

回复 49楼 stonejr 的帖子

norman又没有SY

说白了你到现在还没有明白norman的怎样的
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-7-5 12:09 , Processed in 0.103734 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表