查看: 5657|回复: 10
收起左侧

[病毒样本] SS.exe

[复制链接]
电影结束了
发表于 2008-5-18 13:26:20 | 显示全部楼层 |阅读模式
...http://bbs.kafan.cn/viewthread.php?tid=253781&extra=page%3D1里的一个东西的下载物和生成物...
无语...估计还有东西...

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Exia 该用户已被删除
发表于 2008-5-18 13:30:44 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\AV\新建文件夹'
E:\AV\新建文件夹\38 (1).exe
      [DETECTION] Contains detection pattern of the dropper DR/BHO.abf.5
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\Setup35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [NOTE]      DR/Eachnet:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\cpush.dll
      [DETECTION] Is the Trojan horse TR/PSW.Agent.258560
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\Uninst.exe
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Boran.BD
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\Setup13.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet.A
      [NOTE]      DR/Eachnet.A:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\apcdli.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\ccnj.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Boran.EP.2
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\xxie.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Baidu.kkt.1
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\9fnr17poby.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Cinmus.ejd.1
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\36.exe
      [DETECTION] Is the Trojan horse TR/Drop.Bree
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\37.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\38.exe
      [DETECTION] Is the Trojan horse TR/Downloader.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\39.exe
      [DETECTION] Contains detection pattern of the dropper DR/Drop.Agent.qoa.35
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\40.exe
      [DETECTION] Contains detection pattern of the dropper DR/Boran.EL.24
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\41.exe
      [DETECTION] Is the Trojan horse TR/Downloader.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\42.exe
      [DETECTION] Contains detection pattern of the dropper DR/BHO.abf.5
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\44.exe
  [0] Archive type: ZIP SFX (self extracting)
  --> Setup35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [NOTE]      DR/Eachnet:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\ncy656g4uu.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\dev06.inf
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\6gas3tk5.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\acpidisk.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\p024.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\an.exe
      [DETECTION] Is the Trojan horse TR/Agent.49152
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\mscomfixs.exe
  [0] Archive type: RSRC
  --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\vistaAA.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The file was deleted!
E:\AV\新建文件夹\~de10.tmp
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Baidu.kkt
      [NOTE]      The file was deleted!


End of the scan: 2008年5月18日  13:32
Used time: 00:21 min

The scan has been done completely.

      1 Scanning directories
     47 Files were scanned
     27 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
     27 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     20 Files not concerned
      2 Archives were scanned
      0 Warnings
     27 Notes

25021942aalh.lex20 ByteUNDER ANALYSIS
25021943Contxt.dat629 ByteUNDER ANALYSIS
25010785eachnet.exe44 KBCLEAN
25021944ffqm.ini113 ByteUNDER ANALYSIS
25021945jjuq.ini99 ByteUNDER ANALYSIS
25021946lj4t3ie.sys47.56 KBUNDER ANALYSIS
25021947mscpx32r.det2.5 KBUNDER ANALYSIS
25021948oozv.ini92 ByteUNDER ANALYSIS
25021949pl.exe2.25 MBUNDER ANALYSIS
25020761qqbx.dll40 KBUNDER ANALYSIS
25018744uninstall.exe32.8 KBCLEAN
25021950uufb.dll464 KBUNDER ANALYSIS
25021951zzkg.dll72 KBUNDER ANALYSIS


The file 'vistaAA.exe' has been determined to be 'UNDER ANALYSIS'

[ 本帖最后由 Exia 于 2008-5-18 13:42 编辑 ]
醉一生爱妍
发表于 2008-5-18 13:33:10 | 显示全部楼层
BD
醉一生爱妍
发表于 2008-5-18 13:33:55 | 显示全部楼层
bitdefender日志文件!!!!!
产品 : BitDefender Antivirus 2008
版本 : BitDefenderUI扫描机v.11
日志日期 : 13:33:37 18/05/2008
日志路径: : C:\Documents and Settings\Administrator\Application Data\BitDefender\Desktop\Profiles\Logs\contextual\1211088817_1_02.xml

扫描路径 : 路径0000: C:\Documents and Settings\Administrator\桌面\virus


扫描选项扫描寻找病毒 : 是
扫描广告软件 : 是
扫描间谍软件 : 是
选择应用程序: : 是
扫描寻找病毒 : 是
扫描 rootkits : 否


目标选择选项扫描注册表密钥 : 否
扫描cookies : 否
扫描启动扇区 : 否
扫描内存进程 : 否
扫描存档 : 是
扫描时间运行器 : 是
扫描电子邮件 : 是
扫描所有文件 : 是
启发式扫描 : 是
扫描拥有用户所指定的扩展名的文件 :  
不包括扩展名 :  


针对加工受感染对象的默认操作 : 未受感染的  
可疑的对象默认操作 : 无
隐藏对象的默认操作 : 无


扫描引擎摘要病毒有效更新的时间 : 1194985
存档插件 : 42
邮件插件 : 6
扫描插件 : 12
存档插件 : 42
系统插件 : 4
解压插件 : 7


整体扫描摘要扫描过的项目 : 104
被感染的文件 : 10
可疑的对象 : 0
已被解决的项目 : 1
发现个别病毒 : 8
扫描过的目录 : 1
扫描启动扇区 : 0
扫描存档 : 34
输入输出错误 : 0
扫描时间: : 00:00:00:31
每秒扫描过的文件: : 3


已扫描的进程扫描过的文件 : 0
被感染的: : 0


扫描过的注册表项密钥扫描过的文件 : 0
被感染的: : 0


扫描过的cookies扫描过的文件 : 0
被感染的: : 0


剩下的问题:对象名称 威胁的名称: 最终的状态
C:\Documents and Settings\Administrator\桌面\virus\35.exe=](NSIS o)=]lzma_solid_nsis0002=](NSIS o)=]lzma_nsis0002 Adware.Cinmus.Gen 清除失败
C:\Documents and Settings\Administrator\桌面\virus\35.exe=](NSIS o)=]lzma_solid_nsis0000 Adware.Cinmus.XY 清除失败
C:\Documents and Settings\Administrator\桌面\virus\35.exe=](NSIS o)=]lzma_solid_nsis0002=](NSIS o)=]lzma_nsis0000 Adware.Cinmus.XY 清除失败
C:\Documents and Settings\Administrator\桌面\virus\cpush.dll Adware.Sogou.Gen 清除失败
C:\Documents and Settings\Administrator\桌面\virus\38 (1).exe Dropped:Adware.Cpush.U 清除失败
C:\Documents and Settings\Administrator\桌面\virus\42.exe Dropped:Adware.Cpush.U 清除失败
C:\Documents and Settings\Administrator\桌面\virus\39.exe Dropped:Trojan.Delf.PED 清除失败
C:\Documents and Settings\Administrator\桌面\virus\vistaAA.exe Generic.Malware.P!dldPk!g.9208117E 清除失败
C:\Documents and Settings\Administrator\桌面\virus\mscomfixs.exe Trojan.Delf.PED 清除失败


解决的问题:对象名称 威胁的名称: 最终的状态
C:\Documents and Settings\Administrator\桌面\virus\Uninst.exe Adware.CPush.H 被删除的


无法扫描的对象对象名称 原因 最终的状态
电影结束了
 楼主| 发表于 2008-5-18 13:34:46 | 显示全部楼层
有几个是0KB...
去掉它们....
挪威的冬天
发表于 2008-5-18 14:02:10 | 显示全部楼层
信息        2008-05-18  14:02:04        您此次查毒隔离了7个文件                       
信息        2008-05-18  14:02:04        您此次查毒清除了5个病毒                       
信息        2008-05-18  14:02:04        您此次查毒共查出12个病毒以及危险代码                       
信息        2008-05-18  14:02:04        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件49个                       
信息        2008-05-18  14:02:04        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
风险程序        2008-05-18  14:02:04        D:\Desktop\New Folder (2)\virus\zzkg.dll        Win32.Adware.Boran.fa.73728        隔离成功       
风险程序        2008-05-18  14:02:04        D:\Desktop\New Folder (2)\virus\xxie.dll        Win32.Adware.Boran.fb.73728        隔离成功       
风险程序        2008-05-18  14:02:04        D:\Desktop\New Folder (2)\virus\qqbx.dll        Win32.Adware.Boran.40960        隔离成功       
风险程序        2008-05-18  14:02:04        D:\Desktop\New Folder (2)\virus\cpush.dll        Win32.Adware.BHO.116226        隔离成功       
风险程序        2008-05-18  14:02:03        D:\Desktop\New Folder (2)\virus\ccnj.dll        Win32.Adware.Boran.57344        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\dev06.inf        Win32.Troj.BizMD.a.81920        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\apcdli.sys        Win32.Troj.CinmusT.dm.198212        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\an.exe        Win32.TrojDownloader.Adload.172032        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\acpidisk.sys        Win32.Troj.RootKitT.qb.176772        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\42.exe        Win32.Troj.Agent.lu.106270        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\38 (1).exe        Win32.Troj.Agent.lu.106270        隔离成功       
病毒        2008-05-18  14:02:02        D:\Desktop\New Folder (2)\virus\37.exe        Win32.Troj.Downloader.gy.69632        隔离成功
sam.to
发表于 2008-5-18 19:34:40 | 显示全部楼层
Start of the scan: Sunday,18 May 2008  19:34

Starting the file scan:

Begin scan in 'C:\Documents and Settings\kato9096\桌面\v\virus'
C:\Documents and Settings\kato9096\桌面\v\virus\35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Cinmus.ejd.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\36.exe
      [DETECTION] Is the Trojan horse TR/Drop.Bree
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\37.exe
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\38 (1).exe
      [DETECTION] Contains detection pattern of the dropper DR/BHO.abf.5
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\38.exe
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\39.exe
      [DETECTION] Contains detection pattern of the dropper DR/Drop.Agent.qoa.35
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\40.exe
      [DETECTION] Contains detection pattern of the dropper DR/Boran.EL.24
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\41.exe
      [DETECTION] Is the Trojan horse TR/Downloader.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\42.exe
      [DETECTION] Contains detection pattern of the dropper DR/BHO.abf.5
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\44.exe
  [0] Archive type: ZIP SFX (self extracting)
  --> Setup35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [NOTE]      DR/Eachnet:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\6gas3tk5.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\9fnr17poby.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\acpidisk.sys
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\an.exe
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\apcdli.sys
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\ccnj.dll
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\cpush.dll
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\mscomfixs.exe
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\ncy656g4uu.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\p024.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\Setup13.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet.A
      [NOTE]      DR/Eachnet.A:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\Setup35.exe
      [DETECTION] Contains detection pattern of the dropper DR/Eachnet
      [NOTE]      DR/Eachnet:[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions//{FFB2385E-E812-4091-8C12-2370DC67F769}]
      [NOTE]      The file was deleted!
C:\Documents and Settings\kato9096\桌面\v\virus\uufb.dll
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\vistaAA.exe
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\xxie.dll
      [WARNING]   The file could not be opened!
C:\Documents and Settings\kato9096\桌面\v\virus\zzkg.dll
      [WARNING]   The file could not be opened!


End of the scan: Sunday,18 May 2008  19:34
Used time: 00:09 min

The scan has been done completely.

      1 Scanning directories
     47 Files were scanned
     15 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     14 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
     12 Files cannot be scanned
     32 Files not concerned
      2 Archives were scanned
     12 Warnings
     14 Notes
sam.to
发表于 2008-5-18 19:36:41 | 显示全部楼层
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Cinmus.esa        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\35.exe//stream//data0002//data0003
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Cinmus.ejd        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\35.exe//stream//data0002//data0004
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ahwl        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\37.exe//UPX
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.BHO.aai        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\38 (1).exe//stream//data0001
已刪除: 特洛伊木馬程式 Trojan-Downloader.Win32.Agent.pjq        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\38.exe
已刪除: 特洛伊木馬程式 Trojan-Dropper.Win32.Agent.qoa        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\39.exe//data0002
已刪除: 特洛伊木馬程式 Trojan.Win32.Obfuscated.ant        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\39.exe//data0003
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.el        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\40.exe//stream//data0001
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.BHO.aai        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\42.exe
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Cinmus.ejd        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\acpidisk.sys
已刪除: 特洛伊木馬程式 Trojan.Win32.Obfuscated.ant        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\an.exe
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Cinmus.hen        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\apcdli.sys
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.ep        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\ccnj.dll
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.BHO.aai        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\cpush.dll
已刪除: 特洛伊木馬程式 Trojan-Downloader.Win32.QQHelper.bhq        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\dev06.inf
已刪除: 特洛伊木馬程式 Trojan-Dropper.Win32.Agent.qoa        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\mscomfixs.exe
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.fc        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\uufb.dll
已刪除: 特洛伊木馬程式 Trojan-Downloader.Win32.Agent.pjr        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\vistaAA.exe//PE_Patch.PECompact//PecBundle//PECompact
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.fb        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\xxie.dll
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.fa        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\zzkg.dll
已刪除: 廣告軟體 not-a-virus:AdWare.Win32.Boran.el        檔案: C:\Documents and Settings\kato9096\桌面\v\virus\~de10.tmp


21,有26个不报,2个是"CLEAN"已上报24个到卡巴

[ 本帖最后由 kato9096 于 2008-5-18 19:39 编辑 ]
IllusionWing
发表于 2008-5-18 20:17:00 | 显示全部楼层
杀完剩13个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2008-5-18 20:56:47 | 显示全部楼层

84/9

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.Win32.Undef.gjx   
病毒: Suspicious.RootKit.Win32.Obscure.a
病毒: AdWare.Win32.Cpush.ae   
病毒: Trojan.DL.Win32.Mnless.acf

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.44.62
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-15 23:42 , Processed in 0.121387 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表