楼主: mofunzone
收起左侧

[病毒样本] 今日的包

[复制链接]
HC303
发表于 2008-5-21 11:22:04 | 显示全部楼层

回复 7楼 solcroft 的帖子

没有呀,用WEBGUARD不算作弊吧。
mofunzone
 楼主| 发表于 2008-5-21 12:13:17 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\WINDOWS'
C:\Documents and Settings\morgan\My Documents\WINDOWS\
  emxg.exe
  gktxaspm.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/AdSpy.Gen
      [NOTE]      The file was deleted!
  gnowmebk.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/AdSpy.Gen
      [NOTE]      The file was deleted!
  mdtgkswr.exe
  msprint.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
      [DETECTION] Is the Trojan horse TR/Downloader.Gen
      [NOTE]      The file was deleted!
  nldfmtapanw.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/AdSpy.Gen
      [NOTE]      The file was deleted!
  pxgdslro.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Agent.PB
      [NOTE]      The file was deleted!
  setup_526_1_.exe
      [DETECTION] Is the Trojan horse TR/Dldr.FraudLoad.abk
      [NOTE]      The file was deleted!
  urqNGYRH.dll


End of the scan: 2008年5月20日  21:12
Used time: 00:04 min

The scan has been done completely.

      1 Scanning directories
      9 Files were scanned
      6 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      6 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      0 Archives were scanned
      0 Warnings
      6 Notes
Palkia
发表于 2008-5-21 12:24:36 | 显示全部楼层
kv 0
挪威的冬天
发表于 2008-5-21 12:28:51 | 显示全部楼层
信息        2008-05-21  12:28:18        您此次查毒清除了2个病毒                       
信息        2008-05-21  12:28:18        您此次查毒共查出2个病毒以及危险代码                       
信息        2008-05-21  12:28:18        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件11个                       
信息        2008-05-21  12:28:18        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-05-21  12:28:18        D:\Desktop\WINDOWS.rar\WINDOWS\setup_526_1_.exe        Win32.TrojDownloader.FraudLoad.33280        清除成功       
病毒        2008-05-21  12:28:18        D:\Desktop\WINDOWS.rar\WINDOWS\emxg.exe        Win32.Troj.Vapsup.94208        清除成功
欠妳緈諨
发表于 2008-5-21 13:05:17 | 显示全部楼层
4

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
沙加
发表于 2008-5-21 14:08:47 | 显示全部楼层
赛门铁克不报
电影结束了
发表于 2008-5-21 15:04:10 | 显示全部楼层
msprint.exe

The following Internet Connections were established:
Server Name Server Port Connect as User Connection Password
s2.cookingluck.com 80 (null) (null)
setup.jobusiness.org 80 (null) (null)

The following files were created in the system:
# Filename(s) File Size File MD5 Alias
1 c:\453453453.bat  130 bytes 0x06EE95977B9EB5BDAFA04004845C3BF2 (not available)
2 %ProgramFiles%\antiviirus.exe
%ProgramFiles%\tmp0.exe
%ProgramFiles%\tmp1.exe
%ProgramFiles%\tmp2.exe  9,728 bytes 0x1EA24452FC9533D355A0D62FBC58E9E3 (not available)
3 %Windir%\Resources\ComponentRunOnce.dll  14,886 bytes 0xEFD160A75ED12280DB1A9374FEA5A9E4 (not available)
4 %System%\673351\673351.dll  13,312 bytes 0xCF1C4152E811C43EF65FC641509FCD34 Trojan.Popuper [PCTools]
not-a-virus:AdWare.Win32.E404.az [Kaspersky Lab]
5 [file and pathname of the sample #1]  40,960 bytes 0x30399BD95BB3294D336D72D2FD8614FD (not available)
http://www.threatexpert.com/repo ... 94d336d72d2fd8614fd
star_xing
发表于 2008-5-21 15:09:55 | 显示全部楼层
vista sp1 下

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
syt9419
发表于 2008-5-21 15:18:10 | 显示全部楼层
学习了,但是硬是弄不明白
solcroft
发表于 2008-5-21 15:29:28 | 显示全部楼层

回复 11楼 HC303 的帖子

关键是要看杀几个,不要只杀得出一个就胡乱混过去了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-15 23:03 , Processed in 0.097968 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表