12
返回列表 发新帖
楼主: sam.to
收起左侧

[病毒样本] 44个,大包

[复制链接]
feihongtian 该用户已被删除
发表于 2008-10-23 00:36:58 | 显示全部楼层
已扫描: 
文件: 44 
未扫描: 0 

结果: 
病毒: 13 
间谍软件: 1 
可疑项目: 0 
危险软件: 1 

操作: 
已杀毒: 0 
已重命名: 0 
删除: 0 
已隔离: 15 
失败: 0 


选项
定义版本:
病毒: 2008-10-22_10 
间谍软件: 2008-10-22_07 
扫描引擎: 
F-Secure AVP: 7.00.171, 2008-10-22 
F-Secure Hydra: 2.08.8110, 2008-10-22
mofunzone
发表于 2008-10-23 02:33:01 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Desktop\2222222222222'
C:\Users\morgan\Desktop\2222222222222\2281424512\
  051123Webshots17.jpg ... .exe3
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
    [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      The file was moved to '493071fd.qua'!
  1.exe3
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was moved to '496471f7.qua'!
  2gY7kl.dll3
  45454.vbs3
    [DETECTION] Contains recognition pattern of the VBS/Autorun.AL VBS script virus
    [NOTE]      The file was moved to '493371fe.qua'!
  5a09.EDT
  5a09.inf
  a1.css1
    [0] Archive type: Runtime Packed
    --> Object
    [NOTE]      The file was moved to '492d71fa.qua'!
  A9installer_770522150044.exe3
    [DETECTION] Contains recognition pattern of the SPR/Dldr.FraudLoad.FY program
    [NOTE]      The file was moved to '49687202.qua'!
  agovuwji.nls.ba3k
  com.run
  d1a8.inf
  delnice.dll3
    [DETECTION] Is the TR/Hijacker.Gen Trojan
    [NOTE]      The file was moved to '496b722e.qua'!
  delnicek.ex3e
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
    [DETECTION] Is the TR/Hijacker.Gen Trojan
    [NOTE]      The file was moved to '4a59eb1f.qua'!
  dp1.fne
  eAPI.fne
  hnmaf.sys3
    [DETECTION] Is the TR/Rootkit.Gen Trojan
    [NOTE]      The file was moved to '496c7237.qua'!
  HtmlView.fne
  iext.fnr
  inetinfo.exe3
  internet.fne
  krnln.fnr
  LF.PIF3
    [DETECTION] Is the TR/Crypt.PEPM.Gen Trojan
    [NOTE]      The file was moved to '492d720f.qua'!
  LPK.dll3
  mm.bat3
  mm1.dat3
  mm2.dat3
  MSTQ.PIF3
    [DETECTION] Is the TR/Crypt.PEPM.Gen Trojan
    [NOTE]      The file was moved to '4953721c.qua'!
  net.exe3
  net1.ex3
  ntkrnlpa.exe3
  RegEx.fnr
  setup.exe3
    [DETECTION] Is the TR/Drop.Agent.apd Trojan
    [NOTE]      The file was moved to '4973722e.qua'!
  shell.fne
  spec.fne
  srgui.exe3
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was moved to '4966723b.qua'!
  ver.swf3
    [0] Archive type: SWC
    --> Object
    [NOTE]      The file was moved to '4971722e.qua'!
  wdfmgr.exe.bak2
    [0] Archive type: Runtime Packed
    --> Object
    [NOTE]      The file was moved to '4965722d.qua'!
  winicreg.ex3e
  winlcreg.ex3e
  winmcreg.ex3e
  WowInitcode.dat3
    [DETECTION] Is the TR/Dldr.Delphi.Gen Trojan
    [NOTE]      The file was moved to '49767238.qua'!
  XTHOF.SYS3
    [DETECTION] Is the TR/Rootkit.Gen Trojan
    [NOTE]      The file was moved to '4947721d.qua'!
  刷钻挖掘鸡.exe3
    [DETECTION] Is the TR/Agent.avu Trojan
    [NOTE]      The file was moved to 'ac160684.qua'!
  磁碟机木马.exe3
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
        --> Object
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was moved to 'b039ea68.qua'!


End of the scan: 2008年10月22日  11:32
Used time: 00:06 Minute(s)

The scan has been done completely.

      2 Scanning directories
     44 Files were scanned
     17 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
     18 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     26 Files not concerned
      0 Archives were scanned
      0 Warnings
     18 Notes
capsshift
发表于 2008-10-23 09:40:49 | 显示全部楼层
类别:
特洛伊木马下载程序

描述:
这个程序显示欺骗性的产品消息。

建议:
立即删除这个软件。

资源:
file:
D:\virus\2222222222222\2281424512\A9installer_770522150044.exe3->(UPX)

containerfile:
D:\virus\2222222222222\2281424512\A9installer_770522150044.exe3
shouji5310
发表于 2008-10-23 10:21:06 | 显示全部楼层
麦卡非都不让下载CAO
liuzhe2
发表于 2008-10-23 14:14:42 | 显示全部楼层
Internet Security 2009
拒絕存取
無法擷取要求的網址

當試著擷取網址:

http://bbs.kafan.cn/attachment.php?aid=
382510&k=a58d303c111d684915f947163524226
9&t=1224742431

發生以下錯誤:

要求的物件感染下列病毒: Trojan-Clicker.Win32.Agent.eeg


若您認為這不正確,請連絡服務供應商。
產生於:
Thu Oct 23 14:14:10 2008
Kaspersky Internet Security 2009
sam.to
 楼主| 发表于 2008-10-24 15:57:03 | 显示全部楼层

回复 1楼 kato9096 的帖子

Hello.

¦¦¦¦гєдьЙ¦.exe3 - Trojan-Clicker.Win32.Agent.eeg
2gY7kl.dll3 - Trojan-Downloader.Win32.Agent.akzk
LPK.dll3 - Trojan-GameThief.Win32.WOW.cha
WowInitcode.dat3 - Trojan-GameThief.Win32.WOW.cgx

These files are already detected. Please update your antivirus bases.

5a09.EDT,
5a09.inf,
agovuwji.nls.ba3k,
com.run,
d1a8.inf,
delnice.dll3,
dp1.fne,
eAPI.fne,
HtmlView.fne,
iext.fnr,
inetinfo.exe3,
internet.fne,
krnln.fnr,
mm.bat3,
mm1.dat3,
mm2.dat3,
net.exe3,
net1.ex3,
ntkrnlpa.exe3,
RegEx.fnr,
shell.fne,
spec.fne,
winicreg.ex3e,
winlcreg.ex3e

No malicious code were found in these files.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-1-1 23:05 , Processed in 1.451389 second(s), 4 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表