查看: 8589|回复: 67
收起左侧

[病毒样本] 海量样本测试

 关闭 [复制链接]
mofunzone
发表于 2007-3-20 13:56:51 | 显示全部楼层 |阅读模式
根绝这个帖子下载下来的http://bbs.kafan.cn/viewthread.php?tid=63806&extra=page%3D1
一共51个,大家都测试能杀多少个
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\virus.rar'
C:\Documents and Settings\morgan\My Documents\
  virus.rar
    [0] Archive type: RAR
    --> zu.exe
        [DETECTION] Is the Trojan horse TR/Small.DBY.AP
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1(1).exe
        [DETECTION] Is the Trojan horse TR/Dldr.Small.agq.4
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1(2).exe
        [DETECTION] Is the Trojan horse TR/PSW.WOW.EC.7
        [WARNING]   Infected files in archives cannot be repaired!
    --> 01.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 02.exe
        [DETECTION] Is the Trojan horse TR/Drop.OnLineGa.GS
        [WARNING]   Infected files in archives cannot be repaired!
    --> 2.exe
        [DETECTION] Is the Trojan horse TR/Agent.22675
        [WARNING]   Infected files in archives cannot be repaired!
    --> 03.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 3.exe
        [DETECTION] Contains code of the Windows virus W32/Delf.AQ.1.C
        [WARNING]   Infected files in archives cannot be repaired!
    --> 04.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 4.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.465
        [WARNING]   Infected files in archives cannot be repaired!
    --> 05.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 5.exe
        [DETECTION] Is the Trojan horse TR/PSW.Wow.AD.15
        [WARNING]   Infected files in archives cannot be repaired!
    --> 06.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 07.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 7.exe
        [DETECTION] Is the Trojan horse TR/PSW.Agent.NEW
        [WARNING]   Infected files in archives cannot be repaired!
    --> 16.exe
    --> 101.exe
        [DETECTION] Contains signature of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 60787.exe
        [DETECTION] Is the Trojan horse TR/Spambot.BXA
        [WARNING]   Infected files in archives cannot be repaired!
    --> 510392322.exe
        [DETECTION] Contains signature of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> a.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> ad2072.exe
        [DETECTION] Contains signature of the dropper DR/BHO.AV.73
        [WARNING]   Infected files in archives cannot be repaired!
    --> bd2.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Cdnup.A.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> bd3.exe
    --> bd5.exe
        [DETECTION] Contains signature of the dropper DR/Softomate.AG.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> bd6.rar
        [1] Archive type: RAR SFX (self extracting)
        --> 57sex108.exe
            [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
            [WARNING]   Infected files in archives cannot be repaired!
    --> bd7.rar
        [1] Archive type: RAR SFX (self extracting)
        --> 57sex108.exe
            [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
            [WARNING]   Infected files in archives cannot be repaired!
    --> bd8.exe
        [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> bd9.exe
        [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> bind.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> bind_50077.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> cha.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> count.dll
        [DETECTION] Is the Trojan horse TR/Drop.BHO.F.3
        [WARNING]   Infected files in archives cannot be repaired!
    --> cpush.dll
    --> d.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> dd.exe
        [DETECTION] Is the Trojan horse TR/Small.DBY.AP
        [WARNING]   Infected files in archives cannot be repaired!
    --> hostbot.exe
        [DETECTION] Is the Trojan horse TR/Agent.6688.8
        [WARNING]   Infected files in archives cannot be repaired!
    --> j.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Zhongsou.D.6
        [WARNING]   Infected files in archives cannot be repaired!
    --> javas.exe
        [DETECTION] Contains suspicious code HEUR/Crypted
        [WARNING]   Infected files in archives cannot be repaired!
    --> ma.exe
        [DETECTION] Is the Trojan horse TR/Small.DBY.AP
        [WARNING]   Infected files in archives cannot be repaired!
    --> mouse.exe
        [DETECTION] Is the Trojan horse TR/Click.BHO.N.6
        [WARNING]   Infected files in archives cannot be repaired!
    --> pp.exe
        [DETECTION] Is the Trojan horse TR/Small.DBY.AP
        [WARNING]   Infected files in archives cannot be repaired!
    --> rproxy.exe
        [DETECTION] Is the Trojan horse TR/Proxy.H
        [WARNING]   Infected files in archives cannot be repaired!
    --> server.exe
        [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
        [WARNING]   Infected files in archives cannot be repaired!
    --> sm.exe
        [DETECTION] Is the Trojan horse TR/Small.DBY.AP
        [WARNING]   Infected files in archives cannot be repaired!
    --> test1.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Small.agq.4
        [WARNING]   Infected files in archives cannot be repaired!
    --> test.exe
        [DETECTION] Is the Trojan horse TR/RKit.Agent.EA.5
        [WARNING]   Infected files in archives cannot be repaired!
    --> update0.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Boran.XSS
        [WARNING]   Infected files in archives cannot be repaired!
    --> update7.exe
        [DETECTION] Contains signature of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> update71.exe
        [DETECTION] Contains signature of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> update.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Boran.XSS
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年3月19日  22:51
Used time: 00:20 min

The scan has been done completely.

      0 Scanning directories
     54 Files were scanned
     48 viruses and/or unwanted programs were found
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      6 Files not concerned
      3 Archives were scanned
     49 Warnings
      0 Notes

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
 楼主| 发表于 2007-3-20 13:59:49 | 显示全部楼层
雨伞没报的3个样本除了一个dll因为无法运行之外剩下两个运行后都报了
Thank you for your submission. Below you can see the current status of the uploaded files.



We received the following archive files:File ID         Filename         Size (Byte)        Result
229801         My Documents.rar        291.640        OK


A listing of files contained inside archives alongside their results can be found below:File ID         Filename         Size (Byte)        Result
229802         cpush.dll         163.840         UNDER ANALYSIS
229803         16.exe         82.848         UNDER ANALYSIS
229804         bd3.exe         165.174         UNDER ANALYSIS



Please find a detailed report concerning each individual sample below: Filename        Result
cpush.dll         UNDER ANALYSIS


The file 'cpush.dll' has been determined to be 'UNDER ANALYSIS'.
Filename        Result
16.exe         UNDER ANALYSIS


The file '16.exe' has been determined to be 'UNDER ANALYSIS'.
Filename        Result
bd3.exe         UNDER ANALYSIS


The file 'bd3.exe' has been determined to be 'UNDER ANALYSIS'.

Please note that you will receive an email which will contain the results shown above. In case the final outcome of the analysis is not yet finished for all files the notification will be sent once ready.
欠妳緈諨
发表于 2007-3-20 14:38:52 | 显示全部楼层
金山才杀了19个
欠妳緈諨
发表于 2007-3-20 14:43:49 | 显示全部楼层
卡巴杀36
欠妳緈諨
发表于 2007-3-20 14:48:26 | 显示全部楼层
AVG ANTI SPYWARE 30
mofunzone
 楼主| 发表于 2007-3-20 14:59:17 | 显示全部楼层
看来ls的那三个软件真碰上了新病毒就都完蛋了。。
这些都是直接从网上拉下来的,俗称网马,可不是vb和avc这种机构搜集了不知道几个月的外加大面积爆发几乎全能侦测到的病毒
这种扫描能达到很高的检测率才是真正优秀的杀毒软件,因为avc和vb的病毒如果比较有名的反病毒软件基本都可以查杀,不过在日常生活中,这些木马病毒才是最需要查杀率的东西
如果可以查杀40个以上,那么这个反病毒软件就很优秀了,目前只有antivir达到标准,等着看nod和dr.web还有avast

[ 本帖最后由 mofunzone 于 2007-3-19 23:00 编辑 ]
欠妳緈諨
发表于 2007-3-20 15:03:29 | 显示全部楼层
我现在用红伞 ,期待NOD32和AVK,蜘蛛的结果
sdbsky
发表于 2007-3-20 15:16:36 | 显示全部楼层
安铁诺全杀
Anycall-D908
发表于 2007-3-20 15:22:16 | 显示全部楼层
扫描进行于:2007-3-20 15:18
扫描日志
NOD32版本 2128 (20070319) NT
命令行: C:\Documents and Settings\xxx\桌面\51个病毒样本

日期: 20.3.2007  时间:15:18:24
已开启反隐藏功能.
已扫描的磁盘,文件夹及文件:C:\Documents and Settings\xxx\桌面\51个病毒样本\
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>cpush.dll - a variant of Win32/Adware.BHO.AV 应用程序
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>dd.exe - Win32/Nuwar.gen worm
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>hostbot.exe - 未查明的 NewHeur_PE virus [7]
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>j.exe - Win32/Adware.Zhongsou 应用程序
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>ma.exe - Win32/Nuwar.gen worm
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>mouse.exe - Win32/TrojanDropper.Delf.NDM trojan
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>pp.exe - Win32/Nuwar.gen worm
C:\Documents and Settings\xxx\桌面\51个病毒样本\virus[1].part1.rar >>RAR >>server.exe - 未能找到下一个压缩文件卷
已扫描的文件数目:11
已发现的病毒数目:7
完成时间: 15:18:28 总扫描时间:4 秒 (00:00:04)

注意:
[7] 该文件可能感染上未知病毒。
NOD32这个表现....我心情好不安....

[ 本帖最后由 Anycall-D908 于 2007-3-20 15:24 编辑 ]
mofunzone
 楼主| 发表于 2007-3-20 15:23:25 | 显示全部楼层
原帖由 sdbsky 于 2007-3-19 23:16 发表
安铁诺全杀

你在搞笑吗?
至少我不相信的,报告或者抓图来。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-25 19:20 , Processed in 0.130510 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表