查看: 3629|回复: 12
收起左侧

[病毒样本] 8 可能有误报

[复制链接]
qianwenxiang
发表于 2008-4-10 20:49:21 | 显示全部楼层 |阅读模式
arca micro scan的启发开到最大的结果..排除几个明显误报的..剩下来的传上来(里面那两个exe也可能是误报)..




ArcaMicroScan - Scanning report [2008.04.10 20:25:26]
Base date : 2008.04.09 17:38:18


[Scanning : C:\WINDOWS]

C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard.resources\2.0.2589.34698_nl_90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.resources.DLL <- Adware.Ttc.C : No action
C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard.resources\2.0.2589.34789_ja_90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.resources.DLL <- Adware.Ttc.C : No action
C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard.resources\2.0.2589.34748_de_90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.resources.DLL <- Adware.Ttc.C : No action
C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2589.34815__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL <- Adware.Ttc.C : No action
C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard.resources\2.0.2589.34821_el_90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.resources.DLL <- Adware.Ttc.C : No action
C:\WINDOWS\system32\drivers\v3engine.sys <- Heur.RoundKick : No action
C:\WINDOWS\system32\zsfiles\00008.rps<GZIP>:EmbGZIP <- Trojan.Psw.Onlinegames.Jct : No action
C:\WINDOWS\system32\zsfiles\00008.rps<GZIP>:EmbGZIP<UPack>:EmbGZIP <- Trojan.Psw.Onlinegames.Jct : No action
C:\WINDOWS\Temp\thupdate.exe <- Trojan.Downloader.Nsis.Agent.Y : No action
C:\WINDOWS\Temp\Vscan.exe<NSIS>:file1 <- Trojan.Downloader.Nsis.Agent.Y : No action

Scanned objects : 39543
Infected objects : 10

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
allinwonderi
发表于 2008-4-10 20:50:40 | 显示全部楼层

回复 1楼 qianwenxiang 的帖子

版主也用了啊,呵呵。
[Found Trojan]     <W32/Trojan.CCJM (exact, not disinfectable)>    C:\Documents and Settings\All Users\Documents\Test\WINDOWS.rar->00008.rps->(packed)->(embedded)->(embedded)

---------------------------------------------------------------------
Scan ended:    2008-4-10, 20:51:22
Duration:    0:00:03

Scan result:

Scanned files:         6
Infected objects:     1
Disinfected objects:     0
Quarantined files:     0
---------------------------------------------------------------------
nosferatu
头像被屏蔽
发表于 2008-4-10 20:51:18 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\WINDOWS.rar'
C:\Documents and Settings\Administrator\桌面\WINDOWS.rar
  [0] Archive type: RAR
    --> 00008.rps
      [1] Archive type: GZ
      --> unkwn
          [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
    --> 00009.rps
      [1] Archive type: GZ
      --> unkwn
          [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/ZSearch.G
      [INFO]      The file was deleted!


End of the scan: 星期四 2008年4月10日  20:51
Used time: 00:07 min

The scan has been done completely.

      0 Scanning directories
     13 Files were scanned
      2 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     11 Files not concerned
      4 Archives were scanned
      0 Warnings
      0 Notes
Exia 该用户已被删除
发表于 2008-4-10 20:51:21 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\新建文件夹 (2)\WINDOWS.rar'
E:\新建文件夹 (2)\WINDOWS.rar
  [0] Archive type: RAR
    --> 00008.rps
      [1] Archive type: GZ
      --> unkwn
          [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
    --> 00009.rps
      [1] Archive type: GZ
      --> unkwn
          [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/ZSearch.G
      [INFO]      The file was deleted!
qigang
发表于 2008-4-10 20:53:04 | 显示全部楼层

28/1

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.Win32.Mnless.zvz  

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.39.31
qianwenxiang
 楼主| 发表于 2008-4-10 20:54:22 | 显示全部楼层
hoho 免费的东东 偶喜欢~
wangjay1980
发表于 2008-4-10 20:56:23 | 显示全部楼层
不是可能,是肯定。TO KL

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
allinwonderi
发表于 2008-4-10 21:31:58 | 显示全部楼层

回复 6楼 qianwenxiang 的帖子

07感觉比06的启发有了些变化。貌似没有了Heur.Win32。上报反应很快的说。但没有回复。
sweeb
发表于 2008-4-10 21:38:09 | 显示全部楼层
下了试试!!!!!!!!!!!!!!!
wangjay1980
发表于 2008-4-10 22:10:49 | 显示全部楼层
Hello,

00001.rps, 00005.rps, 00007.rps, 00009.rps, 00010.rps, thupdate.exe_, Vscan.exe_

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Vyacheslav Zakorzhevsky
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: WINDOWS.rar
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-3-10 10:02 , Processed in 0.102142 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表