原帖由 欠妳緈諨 于 2008-5-31 13:55 发表
这个样本,直接扫压缩包报2个,解压却不报,怎么回事
unzip後掃到一個,設定是 t3scan.exe -l report.txt -r 30 -w 0 C:\malware\exploits
C:\malware\exploits\flash1.swf
C:\malware\exploits\flash2.swf - Signature 'Trojan-Downloader.SWF.Small.l' found
C:\malware\exploits\i1231.swf
C:\malware\exploits\i1232.swf
C:\malware\exploits\win 9,0,115,0f.swf
C:\malware\exploits\WIN 9,0,115,0f_1.swf
C:\malware\exploits\win 9,0,115,0i.swf
C:\malware\exploits\win 9,0,115,0ie.swf
C:\malware\exploits\WIN 9,0,115,0i_1.swf
C:\malware\exploits\win 9,0,47,0f.swf
10 Files scanned
(0 Archives with 0 files)
1 Signature found
0 Suspect code-parts found
Used time: 0:00.593
未unzip掃到3個,設定是 t3scan.exe -l report.txt -r 30 -w 0 C:\malware\exploits.zip
C:\malware\exploits.zip:\exploits\flash1.swf
C:\malware\exploits.zip:\exploits\flash2.swf - Signature 'Trojan-Downloader.SWF.Small.l' found
C:\malware\exploits.zip:\exploits\i1231.swf - Signature 'Exploit.SWF' found
C:\malware\exploits.zip:\exploits\i1232.swf
C:\malware\exploits.zip:\exploits\win 9,0,115,0f.swf
C:\malware\exploits.zip:\exploits\WIN 9,0,115,0f_1.swf
C:\malware\exploits.zip:\exploits\win 9,0,115,0i.swf
C:\malware\exploits.zip:\exploits\win 9,0,115,0ie.swf
C:\malware\exploits.zip:\exploits\WIN 9,0,115,0i_1.swf - Signature 'Virus.Exploit.SWF.Downloader.a' found
C:\malware\exploits.zip:\exploits\win 9,0,47,0f.swf
C:\malware\exploits.zip
11 Files scanned
(1 Archiv with 10 files)
3 Signatures found
0 Suspect code-parts found
Used time: 0:00.188
你應該是path 沒設好
[ 本帖最后由 andylau 于 2008-5-31 14:10 编辑 ] |