若干
凝逸: 3
UGuard: 43
Dr.Web: 17
Vita: 35
MicroVita AntiSpyware
_____________________________________________
风暴微塔反间谍 T2
[强力查杀各种Win32位的病毒,木马,蠕虫,恶意软件]
http://221.10.254.214/
----------------------------------------------
开始扫描……
正在检查启动……
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp1834.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:10527 MD5:b6b952d331b71b049e3d2e47af01f1a3
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp280C.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11820 MD5:66bc0316e1bc4afc818bf9a2a542f214
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp3739.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:12433 MD5:feab8588b71bc094c65ae30c0e4f8130
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp3A64.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:12858 MD5:b2b3c7251c42495557a7ea06e53aa22e
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp5FBF.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11292 MD5:0a37da831bef8e10c5e16f88b37daa1f
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp965.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11412 MD5:918cf66f210eef276a9dc7cea2cff40c
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmpD5B8.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:13382 MD5:3a95d5585ab1491c13310c39e4822a2a
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmpE38E.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11987 MD5:a1ef6bc5939c0edf66e2d7551fa141bc
[F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmpFCD8.tmp]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:10680 MD5:531038c59d9851ff93d254530f60f73d
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\adnyolcy.exe]
…………发现Spy!报告:[1] Win32.NkHack.FSG.A
文件信息: 大小:20705 MD5:fa08f35957123228ef2e158438e253e1
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\cinfonmc.exe]
…………发现Spy!报告:[1] Win32.NkHack.FSG.A
文件信息: 大小:18729 MD5:85c19926ddca8a6b51738a81ddcb3b48
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\dbhlp32.exe]
…………发现Spy!报告:[1] Win32.NkHack.FSG.A
文件信息: 大小:19373 MD5:cfaac2e6fe9b7f122e2e2182f670a6e8
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\fmsiocps.exe]
…………发现Spy!报告:[1] Win32.NkHack.FSG.A
文件信息: 大小:19621 MD5:de66e9e2382e8f4042de797bdb4dac11
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\ticisms.exe]
…………发现Spy!报告:[1] Win32.NkHack.FSG.A
文件信息: 大小:20609 MD5:a1365ea4c26656f6114bbc9eb18c60f8
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\cinfonmc.dll]
…………发现Spy!报告:[1] Win32.Badsoft.RX[8] HOOK者
文件信息: 大小:27932 MD5:dcf8078b9f75e6c4547b479aff074cd2
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\dbhlp32.dlL]
…………发现Spy!报告:[1] Win32.Badsoft.RX[8] HOOK者
文件信息: 大小:29464 MD5:13b309423922043cbd782222dab486c0
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\fmsiocps.dll]
…………发现Spy!报告:[7] 映像劫持者[8] HOOK者
文件信息: 大小:32540 MD5:79c6b0379550f56881391f33af5dbe75
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\frznbtul.dll]
…………发现Spy!报告:[1] Win32.Badsoft.RX[8] HOOK者
文件信息: 大小:31512 MD5:20d18b4eee39199a2896049918ec540a
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msoscqit00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11292 MD5:0a37da831bef8e10c5e16f88b37daa1f
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosdohs00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:12858 MD5:b2b3c7251c42495557a7ea06e53aa22e
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosdrop00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:10680 MD5:531038c59d9851ff93d254530f60f73d
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosfmsq00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:10527 MD5:b6b952d331b71b049e3d2e47af01f1a3
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosjtio00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11820 MD5:66bc0316e1bc4afc818bf9a2a542f214
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosmhfp00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:13382 MD5:3a95d5585ab1491c13310c39e4822a2a
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosmnsf00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11987 MD5:a1ef6bc5939c0edf66e2d7551fa141bc
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosping00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:11412 MD5:918cf66f210eef276a9dc7cea2cff40c
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\nicozftp00.dll]
…………发现Spy!报告: [4] [1] Win32.F/S.ByDwing
文件信息: 大小:12433 MD5:feab8588b71bc094c65ae30c0e4f8130
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\SysDaJHv.dll]
…………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息: 大小:19483 MD5:64010040b26c36cb2c511cf6715c88d8
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\ticisms.dll]
…………发现Spy!报告:[1] Win32.Badsoft.RX[8] HOOK者
文件信息: 大小:31512 MD5:4693de767618d05dc15a5f10fa0856e7
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\WanPacket.dll]
…………发现Spy!报告:[2]
文件信息: 大小:61440 MD5:12aa2da30d1d2889511b4c1d14fb99b9
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\beep.sys]
…………发现Spy!报告: [4]
文件信息: 大小:3072 MD5:a2909c3ecf7fa4ba7d18dab4b581d8a5
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\msosmsfpfis64.sys]
…………发现Spy!报告: [4]
文件信息: 大小:2560 MD5:8b1d7cccaa9888f50ec6abb0c5822c7b
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\msosmsp2p32.sys]
…………发现Spy!报告: [4]
文件信息: 大小:3072 MD5:a2909c3ecf7fa4ba7d18dab4b581d8a5
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\nicomsp2p32.sys]
…………发现Spy!报告: [4]
文件信息: 大小:3072 MD5:a2909c3ecf7fa4ba7d18dab4b581d8a5
[F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\Microsoft\svchost.exe]
…………发现Spy!报告:[2]
文件信息: 大小:61507 MD5:125fbafaf99c0e26f863c2416502dd82
文件数:62 病毒数:35 比重:0.5645161290323
OK 扫描完毕!
***日志解释
[4] 集中有害分析引擎
[3] 全局系统判断引擎
[2] 文件特征码引擎
[1] 文件启发式引擎
Kaspersky7: 24
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aerr 文件: F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp280C.tmp//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aicy 文件: F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp3739.tmp//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aign 文件: F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp3A64.tmp//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aers 文件: F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmp5FBF.tmp//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aigm 文件: F:\Sandbox\Administrator\DefaultBox\drive\D\Temp\tmpD5B8.tmp//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.ahvj 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\adnyolcy.exe//FSG
检测到:病毒 Heur.Trojan.Generic (修改) 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\cinfonmc.exe//FSG
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aegm 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\dbhlp32.exe//FSG
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aidk 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\fmsiocps.exe//FSG
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aieb 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\ticisms.exe//FSG
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.ahze 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\dbhlp32.dlL
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aiej 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\frznbtul.dll
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aers 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msoscqit00.dll//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aign 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosdohs00.dll//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aerr 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosjtio00.dll//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aigm 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\msosmhfp00.dll//UPack
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aicy 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\nicozftp00.dll//UPack
检测到:木马程序 Trojan-PSW.Win32.WOW.azc 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\SysDaJHv.dll//UPack//PE_Patch.MaskPE
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aiea 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\ticisms.dll
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aigh 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\beep.sys
检测到:木马程序 Trojan-Proxy.Win32.Xorpix.fb 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\msosmsfpfis64.sys
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aigh 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\msosmsp2p32.sys
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.aigh 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\drivers\nicomsp2p32.sys
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.acjm 文件: F:\Sandbox\Administrator\DefaultBox\drive\F\Windows\System32\Microsoft\svchost.exe
File drive.rar received on 05.18.2008 10:22:13 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 26/32 (81.25%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___
.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Antivirus | Version | Last Update | Result | AhnLab-V3 | 2008.5.16.0 | 2008.05.18 | - | AntiVir | 7.8.0.19 | 2008.05.17 | TR/Onlinegames.NVI | Authentium | 5.1.0.4 | 2008.05.17 | - | Avast | 4.8.1195.0 | 2008.05.17 | Win32:OnLineGames-DJX | AVG | 7.5.0.516 | 2008.05.17 | Win32/PEMask | BitDefender | 7.2 | 2008.05.18 | Trojan.PWS.OnLineGames.NVI | CAT-QuickHeal | 9.50 | 2008.05.17 | TrojanPSW.OnLineGames.aegm | ClamAV | 0.92.1 | 2008.05.18 | Trojan.Spy-34505 | DrWeb | 4.44.0.09170 | 2008.05.17 | Trojan.PWS.Wsgame.5201 | eSafe | 7.0.15.0 | 2008.05.16 | suspicious Trojan/Worm | eTrust-Vet | 31.4.5796 | 2008.05.16 | - | Ewido | 4.0 | 2008.05.14 | - | F-Prot | 4.4.2.54 | 2008.05.16 | - | F-Secure | 6.70.13260.0 | 2008.05.18 | Trojan-PSW.Win32.OnLineGames.ahvj | Fortinet | 3.14.0.0 | 2008.05.18 | W32/OnLineGames.AHVJ!tr.pws | GData | 2.0.7306.1023 | 2008.05.18 | Trojan-PSW.Win32.OnLineGames.ahvj | Ikarus | T3.1.1.26.0 | 2008.05.18 | Virus.Win32.OnLineGames.DJX | Kaspersky | 7.0.0.125 | 2008.05.18 | Trojan-PSW.Win32.OnLineGames.ahvj | McAfee | 5297 | 2008.05.17 | New Malware.ey | Microsoft | 1.3408 | 2008.05.13 | PWS:Win32/OnLineGames.ZDI | NOD32v2 | 3106 | 2008.05.16 | probably unknown NewHeur_PE virus | Norman | 5.80.02 | 2008.05.16 | - | Panda | 9.0.0.4 | 2008.05.17 | Generic Malware | Prevx1 | V2 | 2008.05.18 | Malicious Software | Rising | 20.44.60.00 | 2008.05.18 | Trojan.PSW.Win32.GameOL.nka | Sophos | 4.29.0 | 2008.05.18 | Mal/Packer | Sunbelt | 3.0.1123.1 | 2008.05.17 | VIPRE.Suspicious | Symantec | 10 | 2008.05.18 | Infostealer | TheHacker | 6.2.92.311 | 2008.05.15 | Trojan/PSW.OnLineGames.aegm | VBA32 | 3.12.6.6 | 2008.05.17 | MalwareScope.Trojan-PSW.Game.1 | VirusBuster | 4.3.26:9 | 2008.05.17 | Packed/FSG | Webwasher-Gateway | 6.6.2 | 2008.05.18 | Trojan.Onlinegames.NVI |
Additional information | File size: 407415 bytes | MD5...: 4a341e733af9c2d76d39899da9c5c0bc | SHA1..: 5613494288a43e6145289fe2a7f4dcde9f370b0a | SHA256: 9f28a3fff00639a928fedf500d1f00cef7b54ba98dc43269becbc533ef243f6c | SHA512: d258c0eaa187a58b4f7b5717cbea4ea24dac4d67b4ed0eb4f567b20304ecaa8d
aa750736f9cdebdbad6dabe6db0fff36bff21313348bc21abd96701a423b062e | PEiD..: - | PEInfo: - | Prevx info: http://info.prevx.com/aboutprogr ... 08FCF9885008A80FB0D | packers (Kaspersky): FSG, FSG, FSG, FSG, FSG, UPack, UPack, UPack, UPack, UPack, UPack, UPack, UPack, UPack, UPack, PE_Patch.MaskPE, UPack, UPack, UPack, UPack, UPack, UPack, UPack, UPack, UPack | packers (Avast): FSG, FSG, FSG, FSG, FSG, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack, Upack |
|