楼主: Sherry.ai
收起左侧

[病毒样本] -CHEAT-AV-4月30日-5.1篇(827楼过主流)

[复制链接]
mofunzone
发表于 2009-7-8 05:12:42 | 显示全部楼层
IKARUS - T3SCAN V1.32.10.0 (WIN32)
         T3 V1.01.64
         Copyright (c) 2006 - 2009 by Ikarus Software.
         All rights reserved.

Signature-database from 7.7.2009 20:01:16 (Build: 72995)

C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\11d33a920cb849192e2cc345a6a130dc - Signature 'not-a-virus:FraudTool.Win32.AntivirusBest' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\2b5cdd82620507da0b2be1525653d01a - Signature 'Trojan.Win32.FakeVimes' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\365d862557423b7b975fd52abc162cc5
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\4a00c9ca4f0033bd217e73272d8ec39d - Signature 'not-a-virus:.FraudTool' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\5c59c75690653a5bbac809a9e7451b74 - Signature 'AdWare.Fakes' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\7ae99f503ca992d4283a96f8cb57ef93 - Signature 'not-a-virus:FraudTool.Win32.MalwareRomovalBot' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\83713b43647b96939d13da50c7df6acd - Signature 'Trojan.Win32.FakeVimes' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\9f257083ca594d5e8240e31b9d75a98e
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\b24ab661a2615d70ad0c2cde4643d358
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\b9b0d8a2460bae29c0ee9b755f72b870 - Signature 'Downloader.FraudTool.AntiSpywareBot.CC' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\bcf5c07e7f05a6a743bd9f479c2def25 - Signature 'not-a-virus:FraudTool.Win32.SpywareBot' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\C3328B44E86821AA6C0BD22D269D7AC9 - Signature 'Packed.Win32.Tdss' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\d4d7bd997afd3eb8b61855050f311d96 - Signature 'Trojan.Win32.FakeVimes' found
C:\Users\Administrator\Desktop\090707  Fake 14X\090707  Fake 14X\ddfc99daa5850b23004ca62e30a0231c

        14 Files scanned
          (0 Archives with 0 files)
        10 Signatures found
        0 Suspect code-parts found
        Used time: 0:00.780
sam.to
发表于 2009-7-10 12:11:41 | 显示全部楼层

回复 722楼 Sherry.ai 的帖子

to kl

916ad87f - not-a-virus:FraudTool.Win32.FastAntivirus2009.bz
c24b9372 - Trojan.Win32.FraudPack.plm,
ed7cd297 - Trojan.Win32.FraudPack.pln

722部分

[ 本帖最后由 sam.to 于 2009-7-14 11:34 编辑 ]
taoyuan237
发表于 2009-7-10 12:20:52 | 显示全部楼层
原帖由 Sherry.ai 于 2009-7-10 12:03 发表
☆飓风中篇☆
http://d.namipan.com/d/904ad382a ... c3742b9a01200008000
http://d.namipan.com/d/c255be683 ... b6a89bbfd6c00008000
http://d.namipan.com/d/66608e9e0 ... 34f340798dc00008000
http://d.nam ...

to rs
mofunzone
发表于 2009-7-10 12:30:53 | 显示全部楼层

回复 722楼 Sherry.ai 的帖子

to avira
mofunzone
发表于 2009-7-10 12:34:59 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\Administrator\Desktop\090709 Fake 30X'
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\21ABF4F7A114CAB35E62CBAECE49D9EF
    [DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\378C1B964CEB42B147B361C9C4463E80
    [DETECTION] Is the TR/InternetAntivirus.A.79 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\3d7d01fb561b5041b84d54f9d0366878
    [DETECTION] Is the TR/FakeVimes.A.32 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\5CF145CBF54CB9E2DEE215672994C845
    [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\64E24EA66B37FC7F967D712FE2274C1B
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\6FB41AD575C8538DD6C3079DDC7E0B84
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\7DBBE9726D3FCCDC9B6E9C53544557C0
  [0] Archive type: NSIS
    [NOTE]      The file was deleted!
    --> ProgramFilesDir/CCIntro.exe
      [DETECTION] Is the TR/Dldr.F.LKM.77824 Trojan
    --> ProgramFilesDir/CodeClean.exe
      [DETECTION] Is the TR/CodeClean.A Trojan
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\85a4c8946e4abad0c0249b6811a9d346
    [DETECTION] Is the TR/FakeVimes.A.35 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\87EF56BFBAC59122FBB083F7AA588061
    [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\916ad87f4f584162a961cb481cca08b8
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\abb489cc74b9b7599962e32cd50e81fa
    [DETECTION] Is the TR/FakeVimes.A.36 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\b134a8bf0314a6146d9597abbeb27842
    [DETECTION] Is the TR/Dldr.FakeVimes.21 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\BB364C9F83B6EB114B9E7734F0B37392
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\DF34626C79FA7F401B00BC9C6DAE0CEC
    [DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\edd981af67192f1d1deb52c9f80a7183
    [DETECTION] Is the TR/FakeVimes.A.19 Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\090709 Fake 30X\090709 Fake 30X\fc1f36c71a7d1a0d24a37eb98cf83d54
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!


End of the scan: 2009年7月9日  21:32
Used time: 00:04 Minute(s)

The scan has been done completely.

      2 Scanned directories
     44 Files were scanned
     17 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
     16 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
     27 Files not concerned
      1 Archives were scanned
      0 Warnings
     16 Notes
sam.to
发表于 2009-7-10 14:03:20 | 显示全部楼层
4fea791d2c3323f065ca9c218f3196c4
cc5822040c238d1b7e2a6d48a8c68bf0
not-a-virus:FraudTool.Win32.FastAntivirus2009.bz


21ABF4F7A114CAB35E62CBAECE49D9EF
No malicious code was found in this file.
sam.to
发表于 2009-7-13 23:22:41 | 显示全部楼层

回复 728楼 Sherry.ai 的帖子

好!今天第一天用光纖,大派用場~~~


TO KL

[ 本帖最后由 sam.to 于 2009-7-13 23:36 编辑 ]
sam.to
发表于 2009-7-14 16:13:28 | 显示全部楼层

回复 729楼 sam.to 的帖子

549ED55C8AEE33CA3879B676B8858E73 - Trojan.Win32.FraudPack.pls
abb489cc74b9b7599962e32cd50e81fa - Trojan.Win32.FraudPack.plt
ac39dde0d2bb79cd47aa7c98c5af6557 - Trojan-Downloader.Win32.FraudLoad.ezb
e8275bf77bdc927737bc1a26263803a6 - not-a-virus:RiskWare.FraudTool.Win32.FastAntivirus2009.cb
a14f31d8b70abd1609d656b722060239 - not-a-virus:RiskWare.FraudTool.Win32.FastAntivirus2009.ca
ed7cd2976b4c5ca87c5392dd01efbb04 - Trojan.Win32.FraudPack.pln
0BD58E1102606F8930D5D0E430BA0478 - Trojan.Win32.FraudPack.plv
26b4de29ca28e514cdcf77ce43b714e0 - Trojan-Downloader.Win32.Agent.cihy
6e7e8e0f78449089807464c2b05e766e - Trojan.Win32.FraudPack.pmb
6fb41ad575c8538dd6c3079ddc7e0b84 - Trojan.Win32.FraudPack.pln
01efbb04 - Trojan.Win32.FraudPack.pln
22060239 - not-a-virus:FraudTool.Win32.FastAntivirus2009.ca
263803a6 - not-a-virus:FraudTool.Win32.FastAntivirus2009.cb
B8858E73 - Trojan.Win32.FraudPack.pls,
c5af6557 - Trojan-Downloader.Win32.Fraudload.ezb,
d50e81fa - Trojan.Win32.FraudPack.plt
30BA0478 - Trojan.Win32.FraudPack.plv,
43b714e0 - Trojan-Downloader.Win32.Agent.cihy,
b05e766e - Trojan.Win32.FraudPack.pmb,
dc7e0b84 - Trojan.Win32.FraudPack.pln



455CB9E0040D70D55C9C6BF1C293D404
84E9EF60729C0243DC4E852DD69F2973
D69F2973
C293D404
Clean

[ 本帖最后由 sam.to 于 2009-7-16 16:30 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-15 07:37 , Processed in 0.096151 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表