查看: 1991|回复: 7
收起左侧

[病毒样本] 还是老毒

[复制链接]
The EQs
发表于 2007-3-7 22:30:02 | 显示全部楼层 |阅读模式
555555555555555555555

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
 楼主| 发表于 2007-3-7 22:31:48 | 显示全部楼层
Scan performed at: 2007-3-7 22:30:55
Scanning Log
NOD32 version 2100 (20070307) NT
Command line: C:\Documents and Settings\EQ2\桌面\ZS917.rar C:\Documents and Settings\EQ2\桌面\myd.rar C:\Documents and Settings\EQ2\桌面\QQLogin.rar C:\Documents and Settings\EQ2\桌面\Z927.rar C:\Documents and Settings\EQ2\桌面\ZR917.rar
Operating memory - is OK

Date: 7.3.2007  Time: 22:31:00
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\ZS917.rar; C:\Documents and Settings\EQ2\桌面\myd.rar; C:\Documents and Settings\EQ2\桌面\QQLogin.rar; C:\Documents and Settings\EQ2\桌面\Z927.rar; C:\Documents and Settings\EQ2\桌面\ZR917.rar
C:\Documents and Settings\EQ2\桌面\myd.rar ?RAR ?myd.exe - Win32/TrojanDownloader.Adload.FR trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\QQLogin.rar ?RAR ?QQLogin.exe - Win32/GreyBird.MD trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\Z927.rar ?RAR ?Z927.exe - Win32/PSW.QQRob.NAH trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\ZR917.rar ?RAR ?ZR917.com - probably a variant of Win32/TrojanDownloader.VB.APY trojan
Number of scanned files: 11
Number of threats found: 4
Number of files cleaned: 4
Time of completion: 22:31:00 Total scanning time: 0 sec (00:00:00)


nod隔离了4个,干掉了4个
mofunzone
发表于 2007-3-8 00:02:13 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\ZS917.rar'
C:\Documents and Settings\Administrator\My Documents\
  ZS917.rar
    [0] Archive type: RAR
    --> ZS917.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\myd.rar'
C:\Documents and Settings\Administrator\My Documents\
  myd.rar
    [0] Archive type: RAR
    --> myd.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Adload.FR
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\QQLogin.rar'
C:\Documents and Settings\Administrator\My Documents\
  QQLogin.rar
    [0] Archive type: RAR
    --> QQLogin.exe
        [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/GrayBird.MD Backdoor server programs
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\Z927.rar'
C:\Documents and Settings\Administrator\My Documents\
  Z927.rar
    [0] Archive type: RAR
    --> Z927 (1).asp
    --> Z927.exe
        [DETECTION] Contains signature of the exploits EXP/JS.ADODB.St.Y.2
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\ZR917.rar'
C:\Documents and Settings\Administrator\My Documents\
  ZR917.rar
    [0] Archive type: RAR
    --> ZR917.com
        [DETECTION] Is the Trojan horse TR/Dldr.VB.aip.1
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年3月7日  08:01
Used time: 00:08 min

The scan has been done completely.

      0 Scanning directories
     11 Files were scanned
      4 viruses and/or unwanted programs were found
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      7 Files not concerned
      5 Archives were scanned
      8 Warnings
      0 Notes
jlennon
头像被屏蔽
发表于 2007-3-8 08:04:40 | 显示全部楼层
Virus check with AntiVirusKit
Version 17.0.6282
Virus signatures of 3/6/2007
Start time: 3/8/2007 08:03
Engine(s): Engine A (AVK 17.3103), Engine B (BD 17.2113)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: myd.exe
        In archive: C:\Documents and Settings\Administrator\桌面\myd.rar
        Status: Virus detected
        Virus: Trojan-Downloader.Win32.Adload.fr (Engine A), Trojan.Downloader.Agent.AMS (Engine B)
Object: myd.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan-Downloader.Win32.Adload.fr (Engine A), Trojan.Downloader.Agent.AMS (Engine B)
Object: QQLogin.exe
        In archive: C:\Documents and Settings\Administrator\桌面\QQLogin.rar
        Status: Virus detected
        Virus: Backdoor.Win32.GrayBird.md (Engine A), Backdoor.GrayBird.GA (Engine B)
Object: QQLogin.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Backdoor.Win32.GrayBird.md (Engine A), Backdoor.GrayBird.GA (Engine B)
Object: Z927.exe
        In archive: C:\Documents and Settings\Administrator\桌面\Z927.rar
        Status: Virus detected
        Virus: Trojan-PSW.Win32.QQPass.ms (Engine A), Trojan.Pws.Qqpass.MS (Engine B)
Object: Z927.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.QQPass.ms (Engine A), Trojan.Pws.Qqpass.MS (Engine B)
Object: ZR917.com
        In archive: C:\Documents and Settings\Administrator\桌面\ZR917.rar
        Status: Virus detected
        Virus: Trojan-Downloader.Win32.VB.aip (Engine A), GenPack:Generic.Malware.Sdld!.29B7F7CF (Engine B)
Object: ZR917.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan-Downloader.Win32.VB.aip (Engine A), GenPack:Generic.Malware.Sdld!.29B7F7CF (Engine B)
Analysis complete: 3/8/2007 08:03
    5 files checked
    4 infected files detected
    0 suspected files detected
hsjj2005
发表于 2007-3-8 10:01:10 | 显示全部楼层
微点
木马名称:Trojan-Downloader.Win32.Adload.nv

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEXA\MYD.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Backdoor.Win32.Huigezi.efm

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEXB\QQLOGIN.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

木马名称:Trojan-Downloader.Win32.VB.gi

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEXD\ZR917.COM
是木马程序!
已成功阻止其运行,是否要删除此文件?
hsjj2005
发表于 2007-3-8 10:02:05 | 显示全部楼层
费尔右键扫描最后一个未报

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
soul20010
发表于 2007-3-8 13:16:26 | 显示全部楼层
FS7.0
Result: 4 malware found
Trojan-Downloader.Win32.VB.aip (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\ZR917.rar\ZR917.com
Trojan-Downloader.Win32.Adload.fr (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\myd.rar\myd.exe
Backdoor.Win32.GrayBird.md (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\QQLogin.rar\QQLogin.exe
Trojan-PSW.Win32.QQPass.ms (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\Z927.rar\Z927.exe
马力
发表于 2007-3-8 13:19:37 | 显示全部楼层
瑞星报四个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-10 15:19 , Processed in 0.145412 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表