查看: 2633|回复: 4
收起左侧

[讨论] 这是误报还是P与C的差别

[复制链接]
龙井茶
发表于 2007-3-9 14:57:26 | 显示全部楼层 |阅读模式
C版前不久才扫过一次,今天用P版一扫,出来一大堆东西,这是P与C的差距?

下面是报告,请周版帮忙看下

Version information:
BUILD.DAT    : 259           13889 Bytes   2006-12-5 17:20:00
AVSCAN.EXE   : 7.0.3.5      208936 Bytes    2007-3-8 04:34:09
AVSCAN.DLL   : 7.0.3.1       35880 Bytes   2006-12-5 09:20:23
LUKE.DLL     : 7.0.3.2      143400 Bytes  2006-10-31 09:07:46
LUKERES.DLL  : 7.0.2.0        9256 Bytes   2006-12-5 09:20:23
ANTIVIR0.VDF : 6.35.0.1    7371264 Bytes   2006-5-31 06:14:26
ANTIVIR1.VDF : 6.37.1.151  4303360 Bytes   2007-2-23 09:23:30
ANTIVIR2.VDF : 6.38.0.5     143360 Bytes    2007-3-6 09:23:30
ANTIVIR3.VDF : 6.38.0.22    101376 Bytes    2007-3-8 01:42:57
AVEWIN32.DLL : 7.3.1.41    2355712 Bytes    2007-3-7 09:03:14
AVPREF.DLL   : 7.0.2.0       23592 Bytes   2006-11-3 03:53:44
AVREP.DLL    : 6.38.0.6    1179688 Bytes    2007-3-7 09:22:32
AVRPBASE.DLL : 7.0.0.0     2162728 Bytes   2006-3-30 01:43:31
AVPACK32.DLL : 7.2.1.6      368680 Bytes   2007-1-19 04:06:12
AVREG.DLL    : 7.0.1.2       30760 Bytes    2007-3-8 04:34:09
NETNT.DLL    : No Information!
RCIMAGE.DLL  : 7.0.1.3     2334760 Bytes   2006-11-8 01:39:53
RCTEXT.DLL   : 7.0.12.0      77864 Bytes   2006-12-5 09:20:22
Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Premium\PROFILES\folder.avp
Logging..........................: low
Primary action...................: delete
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Skipped archive types............: BSD Mailbox, Netscape/Mozilla Mailbox, Eudora Mailbox, Squid cache, Pegasus Mailbox, MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: high
Different risk categories........: +GAME,+JOKE,+PCK,+SPR,
Start of the scan: 2007年3月9日  14:26
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'wmiprvse.exe' - '1' Modules have been scanned
Scan process 'wuauclt.exe' - '1' Modules have been scanned
Scan process 'alg.exe' - '1' Modules have been scanned
Scan process 'avmailc.exe' - '1' Modules have been scanned
Scan process 'wdfmgr.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'snmp.exe' - '1' Modules have been scanned
Scan process 'ShadowService.exe' - '1' Modules have been scanned
Scan process 'guard.exe' - '1' Modules have been scanned
Scan process 'avesvc.exe' - '1' Modules have been scanned
Scan process 'avguard.exe' - '1' Modules have been scanned
Scan process 'sched.exe' - '1' Modules have been scanned
Scan process 'ctfmon.exe' - '1' Modules have been scanned
Scan process 'avgnt.exe' - '1' Modules have been scanned
Scan process 'FYFireWall.exe' - '1' Modules have been scanned
Scan process 'VM303_STI.EXE' - '1' Modules have been scanned
Scan process 'realsched.exe' - '1' Modules have been scanned
Scan process 'spoolsv.exe' - '1' Modules have been scanned
Scan process 'explorer.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'lsass.exe' - '1' Modules have been scanned
Scan process 'services.exe' - '1' Modules have been scanned
Scan process 'winlogon.exe' - '1' Modules have been scanned
Scan process 'csrss.exe' - '1' Modules have been scanned
Scan process 'smss.exe' - '1' Modules have been scanned
31 processes with 31 modules were scanned
Start scanning boot sectors:
Boot sector 'D:\'
      [NOTE]      No virus was found!
Boot sector 'C:\'
      [NOTE]      No virus was found!
Boot sector 'E:\'
      [NOTE]      No virus was found!
Starting to scan the registry.
The registry was scanned ( 11 files ).

Starting the file scan:
Begin scan in 'D:\My Documents\'
Begin scan in 'C:\' <WINXPSYS>
C:\hiberfil.sys
      [WARNING]   The file could not be opened!
C:\pagefile.sys
      [WARNING]   The file could not be opened!
C:\Program Files\FlashGet\fgiebar.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/FlashGet
      [INFO]      A backup was created as '4659ff0e.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
Begin scan in 'D:\'
D:\Downloads\51pycs.rar
  [0] Archive type: RAR
  --> 51pycs\51cq.dat
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      A backup was created as '466101db.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
D:\Downloads\jsy7.67pj.rar
  [0] Archive type: RAR
  --> TTee-&frac14;°&Ecirc;±&Oacute;ê7.67&AElig;&AElig;&frac12;&acirc;°&aelig;\&frac14;°&Ecirc;±&Oacute;ê7.67&AElig;&AElig;&frac12;&acirc;°&aelig;\JSY.DLL
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      A backup was created as '466a0259.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
D:\Downloads\51pycs\51pycs\51cq.dat
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '4654027f.qua'!
D:\Downloads\jsy7.67pj\TTee-及时雨7.67破解版\及时雨7.67破解版\JSY.DLL
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '464a02a6.qua'!
D:\Downloads\卡巴杀毒\落雪专杀工具.rar
  [0] Archive type: RAR
  --> &Acirc;&auml;&Ntilde;&copy;ר&Eacute;±&sup1;¤&frac34;&szlig;.com
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      A backup was created as '94049982.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
D:\Program Files\Shanda\Legend of Mir\mir2hook.dll
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Repacked). Please verify the origin of the file
      [INFO]      The file was moved to '4663033e.qua'!
D:\应用小软件\龙卷风收音机绿色版2.7.exe
      [DETECTION] Contains signature of the joke program JOKE/Msgbox.A.2
      [INFO]      A backup was created as 'debf56c0.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
Begin scan in 'E:\'
E:\301p.exe
  [0] Archive type: RAR SFX (self extracting)
    --> 301p\Setup.exe
      [1] Archive type: CAB SFX (self extracting)
      --> \Disk1\setup.exe
          [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      A backup was created as '4622037b.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
E:\301p\Setup.exe
  [0] Archive type: CAB SFX (self extracting)
  --> \Disk1\setup.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      A backup was created as '466503b3.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
E:\Program Files\Shanda\Legend of Mir\mir2hook.dll
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Repacked). Please verify the origin of the file
      [INFO]      The file was moved to '4663040f.qua'!
Begin scan in 'F:\'
The path F:\ could not be found!
设备未就绪。
Begin scan in 'C:\Documents and Settings\All Users\Documents\'

End of the scan: 2007年3月9日  14:50
Used time: 24:41 min
The scan has been done completely.
   4057 Scanning directories
170351 Files were scanned
     11 viruses and/or unwanted programs were found
      7 files were deleted
      0 files were repaired
     11 files were moved to quarantine
      0 files were renamed
      2 Files cannot be scanned
170340 Files not concerned
   1775 Archives were scanned
      2 Warnings
      1 Notes

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
周杰伦
发表于 2007-3-9 15:02:13 | 显示全部楼层
有几个是间谍程序和广告程序,应该是没有误报的,如果不放心的话,把样本发到样本区,让高手分析看看

[ 本帖最后由 周杰伦 于 2007-3-9 15:03 编辑 ]
龙井茶
 楼主| 发表于 2007-3-9 15:05:59 | 显示全部楼层
没误报就好,谢了.
龙井茶
 楼主| 发表于 2007-3-9 15:21:31 | 显示全部楼层
看来C版与P版差距还有点明显啊,我机子用AVG、卡巴、大蜘蛛、C版全扫过的,居然还会有这么多广告和间谍程序。真是不敢想象。
fido_lee
发表于 2007-3-9 17:56:05 | 显示全部楼层
好像启发更强势了一些。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-9-20 05:52 , Processed in 0.123428 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表