查看: 2657|回复: 11
收起左侧

[病毒样本] 一包

[复制链接]
ck893210
发表于 2008-7-31 15:01:38 | 显示全部楼层 |阅读模式
..........
woai_jolin
发表于 2008-7-31 15:07:27 | 显示全部楼层
Scan Log
Version of virus signature database: 3311 (20080730)
Date: 2008-7-31  Time: 15:07:23
Scanned disks, folders and files: G:\v\xx
G:\v\xx\1.exe - is OK
G:\v\xx\2.exe - Win32/TrojanDownloader.QQHelper.NGO trojan - cleaned by deleting - quarantined [1]
G:\v\xx\4.exe » NSIS » Entries.bin - is OK
G:\v\xx\4.exe » NSIS » Strings.txt - is OK
G:\v\xx\4.exe » NSIS » System.dll - is OK
G:\v\xx\4.exe » NSIS » 19.exe » NSIS » Entries.bin - is OK
G:\v\xx\4.exe » NSIS » 19.exe » NSIS » Strings.txt - is OK
G:\v\xx\4.exe » NSIS » 19.exe » NSIS » System.dll - is OK
G:\v\xx\4.exe » NSIS » 19.exe » NSIS » 龏
kkgh
发表于 2008-7-31 15:18:52 | 显示全部楼层
费尔5个
dollsgame
发表于 2008-7-31 15:28:35 | 显示全部楼层


Starting the file scan:


Begin scan in 'E:\xx'
E:\xx\1.exe
    [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      A backup was created as '38d2efb2.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\2.exe
    [DETECTION] Is the TR/Downloader.Gen Trojan
    [NOTE]      A backup was created as '395d9963.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\4.exe
    [DETECTION] Contains recognition pattern of the DR/Cinmus.kgp dropper
    [NOTE]      A backup was created as '38d2efb4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\9.exe
    [DETECTION] Contains recognition pattern of the DR/BHO.cbt.54 dropper
    [NOTE]      A backup was created as '395d9965.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\ex32de.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '38a0effc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\file.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '38d9efee.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\mm.exe
    [DETECTION] Is the TR/Crypt.FKM.Gen Trojan
    [NOTE]      A backup was created as '389beff2.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
E:\xx\x.gif
    [0] Archive type: RAR
    --> ᅰᅰᅥᆲ                                                                                                         .exe
      [DETECTION] Contains HEUR/Crypted suspicious code
    [NOTE]      A backup was created as '38d4efb4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2000-01-01  20:13
Used time: 00:33 Minute(s)

The scan has been done completely.

      1 Scanning directories
     10 Files were scanned
      6 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
      8 files were deleted
      0 files were repaired
      8 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      2 Files not concerned
      1 Archives were scanned
      0 Warnings
      8 Notes
sbbdms
发表于 2008-7-31 15:55:37 | 显示全部楼层
卡巴杀4启发1漏4

已隔离:病毒 Heur.Trojan.Generic (修改)        文件 : D:\软件\其它\v\k\new\1\xx\1.exe
已删除:广告程序 not-a-virus:AdWare.Win32.Cinmus.kgp        文件 : D:\软件\其它\v\k\new\1\xx\4.exe//stream//data0002//data0003
已删除:广告程序 not-a-virus:AdWare.Win32.BHO.cbt        文件 : D:\软件\其它\v\k\new\1\xx\9.exe//data0002
已删除:木马程序 Trojan-Downloader.Win32.Mutant.aqt        文件 : D:\软件\其它\v\k\new\1\xx\ex32de.exe
已删除:木马程序 Rootkit.Win32.Clbd.gs        文件 : D:\软件\其它\v\k\new\1\xx\file.exe

TO KL
网逸渔樵
发表于 2008-7-31 17:45:17 | 显示全部楼层
NOD杀5个
电影结束了
发表于 2008-7-31 17:50:18 | 显示全部楼层
WebSoftCodecDrivern



这东西不知道有没有更新。。。
欠妳緈諨
发表于 2008-7-31 17:53:12 | 显示全部楼层
IK   8
D:\病毒测试\临时解压\1.exe - 特征码 'Backdoor.Win32.Agent.ahj' 被发现
D:\病毒测试\临时解压\2.exe - 特征码 'Trojan-Downloader' 被发现
D:\病毒测试\临时解压\4.exe - 特征码 'Virus.Win32.AdWare' 被发现
D:\病毒测试\临时解压\9.exe - 特征码 'Virus.Win32.Trojan' 被发现
D:\病毒测试\临时解压\ex32de.exe - 特征码 'Trojan-Downloader.Win32.Mutant.aqt' 被发现
D:\病毒测试\临时解压\file.exe - 特征码 'Trojan.Fakealert.TK' 被发现
D:\病毒测试\临时解压\mm.exe - 特征码 'Backdoor.Win32.Agent.ahj' 被发现
D:\病毒测试\临时解压\WebSoftCodecDrivern(1).exe
D:\病毒测试\临时解压\x.gif:\照片                                                                                                         .exe - 特征码 'Trojan-Downloader.Win32.Banload.ams' 被发现
D:\病毒测试\临时解压\x.gif

        10 文件被扫描
          (2 压缩档 1 文件)
        8 特征码被侦测
        0 可疑代码段被发现
        耗时: 0:00.380
欠妳緈諨
发表于 2008-7-31 17:55:13 | 显示全部楼层
avast!  7
醉一生爱妍
发表于 2008-7-31 17:59:53 | 显示全部楼层
已删除:病毒 Heur.Trojan.Generic (修改)        文件: C:\Documents and Settings\Administrator\桌面\xx[1]\1.exe
已删除:广告程序 not-a-virus:AdWare.Win32.Cinmus.kgp        文件: C:\Documents and Settings\Administrator\桌面\xx[1]\4.exe//stream//data0002//data0003
已删除:广告程序 not-a-virus:AdWare.Win32.BHO.cbt        文件: C:\Documents and Settings\Administrator\桌面\xx[1]\9.exe//data0002
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-14 07:42 , Processed in 0.153090 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表