查看: 3400|回复: 8
收起左侧

[病毒样本] CAD的最新病毒,杀软报4个

[复制链接]
a87750530
发表于 2008-11-27 08:43:17 | 显示全部楼层 |阅读模式
VirSCAN.org Scanned Report :
Scanned time   : 2008/11/27 08:39:55 (CST)
Scanner results: 10%的杀软(4/39)报告发现病毒
File Name      : bd.rar
File Size      : 29905 byte
File Type      : RAR archive data, v1d, os
MD5            : 0cdf476e89ca0a1442152b788e233b78
SHA1           : 9365a464ac0207d92d3fb59a83673474f4123f26
Online report  : http://virscan.org/report/ac0256a2426c453b824aae4d05ce1397.html
Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      4.0.0.26        20081127050733    2008-11-27  3.00   -
安博士V3       2008.11.27.01   2008.11.27        2008-11-27  1.04   -
AntiVir        7.9.0.35        7.1.0.143         2008-11-26  1.61   -
安天           2.0.18          20081126.1749264  2008-11-26  0.22   -
Arcavir        1.0.5           200811231052      2008-11-23  1.32   -
Authentium     5.1.1           200811261808      2008-11-26  1.06   -
AVAST!         3.0.1           081126-0          2008-11-26  0.75   BV:Bursted-A
AVG            7.5.52.442      270.9.10/1813     2008-11-26  1.76   -
BitDefender    7.81008.2266444 7.22110           2008-11-27  2.17   -
CA (VET)       9.0.0.143       31.6.6230         2008-11-26  5.97   -
ClamAV         0.94.1          8684              2008-11-26  0.03   -
Comodo         2.11            2.0.0.712         2008-11-20  0.42   -
CP Secure      1.1.0.715       2008.11.27        2008-11-27  6.39   ALS.Bursted
Dr.Web         4.44.0.9170     2008.11.26        2008-11-26  3.62   -
ewido          4.0.0.2         2008.11.26        2008-11-26  5.43   -
F-Prot         4.4.4.56        20081126          2008-11-26  1.05   -
F-Secure       5.51.6100       2008.11.26.13     2008-11-26  3.88   -
飞塔           2.81-3.117      9.748             2008-11-26  0.15   -
GData          19.1683/19.124  20081127          2008-11-27  2.77   BV:Bursted-A [Engine:B]
ViRobot        20081126        2008.11.26        2008-11-26  0.41   -
Ikarus         T3.1.01.45      2008.11.26.71917  2008-11-26  3.50   -
江民杀毒       11.0.706        2008.11.26        2008-11-26  1.40   -
卡巴斯基       5.5.10          2008.11.26        2008-11-26  0.04   -
金山毒霸       2008.9.8.18     2008.11.26.20     2008-11-26  1.35   -
迈克菲         5.3.00          5446              2008-11-26  2.53   -
Microsoft      1.4104          2008.11.26        2008-11-26  4.59   -
mks_vir        2.01            2008.11.17        2008-11-17  2.65   -
Norman         5.93.01         5.93.00           2008-11-26  5.45   -
熊猫卫士       9.05.01         2008.11.26        2008-11-26  3.17   -
趋势科技       8.700-1004      5.678.11          2008-11-26  0.03   ALS_BURSTED.AA
Quick Heal     10.00           2008.11.26        2008-11-26  0.95   -
瑞星           20.0            21.05.22.00       2008-11-26  0.70   -
Sophos         2.80.0          4.35              2008-11-27  2.19   -
Sunbelt        4474            4474              2008-11-04  0.52   -
赛门铁克       1.3.0.24        20081126.003      2008-11-26  0.17   -
nProtect       2008-11-26.00   2629064           2008-11-26  3.49   -
The Hacker     6.3.1.1         v00163            2008-11-25  0.46   -
VBA32          3.12.8.9        20081126.1036     2008-11-26  1.51   -
VirusBuster    4.5.11.10       10.94.7/729311    2008-11-26  0.94   -

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
a87750530
 楼主| 发表于 2008-11-27 08:49:17 | 显示全部楼层
这个病毒会感染记事本文件,在记事本的右下角会有一个标志,很特殊!请高手看看帮忙解决一下
啊弥陀佛
发表于 2008-11-27 09:06:05 | 显示全部楼层
lsp文件类型的  跑不起来
laolaoliu
发表于 2008-11-27 09:14:12 | 显示全部楼层
EAV4无视
a87750530
 楼主| 发表于 2008-11-27 09:42:48 | 显示全部楼层
依班娜
发表于 2008-11-27 14:52:31 | 显示全部楼层
卡巴无视
astorm
发表于 2008-11-27 14:58:54 | 显示全部楼层
F-Secure 认为没有毒:

========================================
Hello,

Thank you for the sample that you sent to us.

The file you submitted is clean. It is not malicious.

acad.lsp - no code, blank
acadappp.lsp - no code blank
mvsetup.lsp - lisp script fro some setup program.

Should you have further concerns, please do not hesitate to e-mail us again.

Have a nice day!
得巴
发表于 2008-11-27 15:01:22 | 显示全部楼层
此病毒甚是可恶,好多cad命令出现无效。。。。
lingbo110120
发表于 2008-11-27 15:58:45 | 显示全部楼层
这是什么东西

;;;
;;;    mvsetup.lsp
;;;
;;;    Copyright 1990-2003 by Autodesk, Inc.
;;;   
;;;    Permission to use, copy, modify, and distribute this software
;;;    for any purpose and without fee is hereby granted, provided
;;;    that the above copyright notice appears in all copies and
;;;    that both that copyright notice and the limited warranty and
;;;    restricted rights notice below appear in all supporting
;;;    documentation.
;;;   
;;;    AUTODESK PROVIDES THIS PROGRAM "AS IS" AND WITH ALL FAULTS.  
;;;    AUTODESK SPECIFICALLY DISCLAIMS ANY IMPLIED WARRANTY OF
;;;    MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE.  AUTODESK, INC.
;;;    DOES NOT WARRANT THAT THE OPERATION OF THE PROGRAM WILL BE
;;;    UNINTERRUPTED OR ERROR FREE.
;;;   
;;;    Use, duplication, or disclosure by the U.S. Government is subject to
;;;    restrictions set forth in FAR 52.227-19 (Commercial Computer
;;;    Software - Restricted Rights) and DFAR 252.227-7013(c)(1)(ii)
;;;    (Rights in Technical Data and Computer Software), as applicable.
;;;
;;;
;;; DESCRIPTION
;;;
;;;   This is a setup routine for Mview.
;;;   
;;;   It is based around a set of functionality that was determined to be a
;;;   necessary part of preparing a drawing for plotting.  This routine allows
;;;   the user to insert several pre-defined title blocks (ANSI A - E) and in
;;;   addition it allows the user to create a set of viewports within the
;;;   title block just inserted.  A global scale may be specified as a ratio
;;;   between the scale of the title block in paperspace and the model geometry
;;;   in modelspace.  For example, if you were doing an engineering drawing at
;;;   a scale of 1:4 or quarter scale, then you would specify that you wanted
;;;   a ratio of 1 paperspace unit to 4 modelspace units.  The routine will
;;;   convert this to 0.25xp for the Zoom command.  You may also elect to
;;;   align the viewports.
;;;   
;;;   (The first time you invoke MVSETUP, you may notice a slight delay.
;;;   This occurs because the routine is creating a default file of various
;;;   title blocks and viewport layouts.  If you should accidentally erase
;;;   your default file, another will be created the next time you invoke
;;;   MVSETUP.  The file will be created in the directory specified by the
;;;   AutoCAD system variable "ACADPREFIX".  If you run AutoCAD from a
;;;   directory other than that one, and the system variables ACAD or ACADCFG
;;;   do not point to that directory, then MVSETUP will not be able to find
;;;   it, and will create a new one in the directory pointed to by the first
;;;   path found in the current setting of the AutoCAD system variable
;;;   "ACADPREFIX".)
;;;   
;;;   When you invoke MVSETUP from the command line or one of the menus, you
;;;   are given four options;  three dealing with the creation and manipulation
;;;   of viewports, and one which allows you to insert various "title blocks".
;;;   The initial prompt is shown below.
;;;   
;;;         Align/Create/Scale viewports/Options/Title block/Undo:  
;;;         
;;;   The Align viewports option presents you with several more options; you
;;;   are asked to determine the type of alignment you wish to perform.
;;;   
;;;         Angled/Horizontal/Vertical alignment/Rotate view/Undo?
;;;           
;;;   The Horizontal and Vertical options ask you to pick a basepoint in one
;;;   viewport, and the point to move in another viewport.  The view in the
;;;   second viewport is panned by the offset distance in X or Y between
;;;   the two points relative to the zoom scale factor of the second viewport.
;;;   
;;;   The Angled option asks you for these two points and for a distance and
;;;   angle from the basepoint.  The point in the first viewport at the
;;;   specified distance and angle from the basepoint is where the "other"
;;;   point will be panned.
;;;   
;;;   The Rotate view option asks you for a basepoint and a rotation angle
;;;   and uses the DVIEW command to change the view twist.  This generally
;;;   will be useful only when the UCS of the view you are rotating is
;;;   parallel to the screen and would be used to align a view with an
;;;   angled edge with the Align Angled option.
;;;   
;;;   Selecting Create viewports prompts you with the following:
;;;   
;;;         Delete objects/<Create viewports>:
;;;   
;;;   Selecting Delete objects provides you with a general selection prompt
;;;   at which time you may delete any paperspace objects that you wish.
;;;   This is intended to allow you to clear an area for your new viewports.
;;;   Modelspace entities will NOT be removed.
;;;   
;;;   
;;;   Selecting Create viewports prompts you to select one of the viewport
;;;   options listed.
;;;   
;;;         Available Mview viewport layout options:
;;;
;;;         0:       None
;;;         1:       Single
;;;         2:       Std. Engineering
;;;         3:       Array of Viewports
;;;
;;;         Redisplay/<Number of entry to load>:
;;;         
;;;   Pressing RETURN or selecting "None" returns you to the main prompt
;;;   without creating any viewports.  
;;;   
;;;   "Single" is a single viewport which can fill the default area open in
;;;   the sheet or it can be located by picking two points on the screen.  
;;;   
;;;   Std. Engineering is a set of four viewports with the upper left viewport
;;;   in plan view, the lower left in a front view, the lower right in a right
;;;   side view, and the upper right in an oblique view at -45 degrees from 0
;;;   and up 30 degrees.
;;;   
;;;   The "Array of Viewports" allows you to specify any array of viewports
;;;   that you want to place on your sheet, from a 1 by 2 or 2 by 1 to any
;;;   level allowed by AutoCAD.
;;;   
;;;   
;;;   After selecting option 1, 2 or 3, you are prompted to specify the bounding
;;;   area for the viewports that are to be created.  Each of the title blocks
;;;   provided has a bounding region defined for it in the default file.  You
;;;   can elect to create all of the viewports within this region by selecting
;;;   "Default" at the following prompt:
;;;   
;;;         Bounding area for viewports.  Default/<First point >:
;;;   
;;;   You can also select two points on the screen and the number of viewports
;;;   you subsequently define will be mapped into this area.
;;;   
;;;   Picking options 2 or 3 prompts you to specify the distance between the
;;;   viewports; the interstitial distance.  This value must be a positive
;;;   number but may be zero.  The value you enter for X is automatically
;;;   assigned to Y, though you may specify Y to have a different value.
;;;   If you selected option 2 above, then the four viewports are created and
;;;   the four views are mapped into them as defined in the default file.
;;;   The other options create the viewports but do not change the views in
;;;   any of them; the view will be a plan view in the current UCS.
;;;   
;;;   
;;;   Selecting Scale viewports at the main menu prompts you to select the
;;;   viewports you wish to scale.  If you select one or more viewports
;;;   you asked whether you wnat to set the zoom scales all at once or for
;;;   each viewport separately:
;;;   
;;;         Set zoom scale factors for viewports.  Interactively/<Uniform>:
;;;   
;;;   After selecting one of these you are asked the following;
;;;   
;;;         Enter the ratio of paper space units to model space units...
;;;         Number of paper space units.  <1.0>:
;;;         Number of model space units.  <1.0>:
;;;   
;;;   The number of viewports specified will have their zoom scales changed
;;;   by the ratio of the paper space units divided by the model space units.
;;;   This is cumulative over time, so performing this operation twice with
;;;   paper space units set to 1.0 and model space units set to 2.0 will give
;;;   the same results as doing it once with 1.0 an 4.0 as the values.
;;;   
;;;   
;;;   Selecting Options at the main menu allows you to specify several
;;;   preferences for operation of Mvsetup.  They are:
;;;
;;;         Set Layer/LImits/Units/Xref:
;;;   
;;;   The Layer option allows you to specify a layer, existing or new, on
;;;   which to insert the title block, the LImits option allows you to
;;;   specify whether or not to reset the limits to the drawing extents after
;;;   a title block has been inserted, Units specifies whether the sizes and
;;;   point locations are to be translated to inch or millimeter paper units,
;;;   and the Xref option let's you determine whether the title block is to
;;;   be inserted or Xref'ed.
;;;
;;;
;;;   Selecting Title block from the main menu gives you another sub-menu.
;;;   
;;;         Delete objects/Origin/<Insert title block>:
;;;   
;;;   Delete objects works as described above under Create viewports.
;;;   Origin allows you to specify a new UCS origin for the subsequent
;;;   insertion of a title block.  Pressing RETURN will cause you to be
;;;   presented with a list of available title blocks or sheets.
;;;   
;;;         Available title block options:  
;;;
;;;         0:       NONE
;;;         1:       ISO A4 Size(mm)
;;;         2:       ISO A3 Size(mm)
;;;         3:       ISO A2 Size(mm)
;;;         4:       ISO A1 Size(mm)
;;;         5:       ISO A0 Size(mm)
;;;         6:       ANSI-V Size(in)
;;;         7:       ANSI-A Size(in)
;;;         8:       ANSI-B Size(in)
;;;         9:       ANSI-C Size(in)
;;;         10:      ANSI-D Size(in)
;;;         
;;;         11:      ANSI-E Size(in)
;;;         12:      Arch/Engineering (24 x 36 in)
;;;
;;;         Add/Redisplay/<Number of entry to load>:      
;;;         
;;;   This list includes ISO standard sheets used outside the US, specified
;;;   in millimeters, the ANSI standard sheet layouts from A to E and size
;;;   A Vertical specified in inches.  Selecting the number preceding one of the
;;;   selections causes one of two things to occur.  One, if the AutoCAD
;;;   drawing associated with the selections cannot be found, then the
;;;   default file is read, a definition is extracted, and the drawing is
省略...
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-20 03:59 , Processed in 0.128826 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表