楼主: kp2006
收起左侧

转贴剑盟 杀软最新脱壳测试(25个壳)

[复制链接]
mofunzone
发表于 2007-6-1 23:13:07 | 显示全部楼层
漏掉一个。。

Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\wyQQ2007[1]'
C:\Documents and Settings\morgan\My Documents\wyQQ2007[1]\wyQQ2007\加壳后的文件\
  wyQQ2007aspack 212r.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  wyQQ2007ASProtect SKE 2.3 Beta6.26.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b137fb.qua'!
  wyQQ2007depack.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4719d238.qua'!
  wyQQ2007ExeShield1.4cryptor.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '46b137fd.qua'!
  wyQQ2007ExeStealth v2.76.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  wyQQ2007FSG2.0.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [INFO]      The file was deleted!
  wyQQ2007mew 11se12.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b137fc.qua'!
  wyQQ2007MoleBox Pro v2.6.3.2462.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4719d239.qua'!
  wyQQ2007npack.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [INFO]      The file was deleted!
  wyQQ2007Obsidium1334.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '4719d23a.qua'!
  wyQQ2007PECompact2.7.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  wyQQ2007pespin 1.304.exe
      [DETECTION] Contains signature of the worm WORM/Mytob.LU
      [INFO]      The file was deleted!
  wyQQ2007petite 2.3.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  wyQQ2007polyene0.01.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b137fe.qua'!
  wyQQ2007rlpack1.18.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO]      The file was deleted!
  wyQQ2007tElock 0.99.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4719d23b.qua'!
  wyQQ2007UPX3.00.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  wyQQ2007VBOWatch v2.0.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '46b137ff.qua'!
  wyQQ2007vmprotect v1.4.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4719ddc4.qua'!
  wyQQ2007yoda's Protector1.03.3.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '46b13801.qua'!
  wyQQ2007上兴V1.1.exe
  wyQQ2007免疫007-2.0.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b13800.qua'!
  wyQQ2007免疫007-2.6.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSAnti.Gen
      [INFO]      The file was deleted!
  wyQQ2007北斗3.7.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '4719ddc5.qua'!
  wyQQ2007北斗4.1.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '4719ddc6.qua'!
C:\Documents and Settings\morgan\My Documents\wyQQ2007[1]\wyQQ2007\原文件\
  wyQQ2007.exe
      [DETECTION] Is the Trojan horse TR/PSW.Stealer.66122
      [INFO]      The file was deleted!


End of the scan: 2007年6月1日  08:13
Used time: 00:13 min

The scan has been done completely.

      4 Scanning directories
     26 Files were scanned
     25 viruses and/or unwanted programs were found
     14 classified as suspicious:
     11 files were deleted
      0 files were repaired
     14 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
    -13 Files not concerned
      0 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
hj5abc
发表于 2007-6-1 23:31:43 | 显示全部楼层
怪..

NOD32 21个..漏了4个..原文件不报
其中2个报了:
F:\wyQQ2007\加壳后的文件\wyQQ2007上兴V1.1.exe - a variant of Win32/TrojanDropper.Delf.AAH trojan
F:\wyQQ2007\加壳后的文件\wyQQ2007免疫007-2.6.exe - Win32/Rootkit.Vanti.E trojan

另外19个清一色: probably a variant of Win32/Genetik trojan..
scottxzt
发表于 2007-6-1 23:54:35 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件'
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007aspack 212r.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was moved to '46b14114.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007depack.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b14115.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007ExeShield1.4cryptor.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4732d312.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007ExeStealth v2.76.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was moved to '46b14116.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007FSG2.0.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [INFO]      The file was moved to '4732d313.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007mew 11se12.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b14110.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007MoleBox Pro v2.6.3.2462.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b14117.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007npack.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [INFO]      The file was moved to '4732d31c.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007Obsidium1334.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Obsidium). Please verify the origin of the file
      [INFO]      The file was moved to '46b14119.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007PECompact2.7.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was moved to '4732d31e.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007pespin 1.304.exe
      [DETECTION] Contains signature of the worm WORM/Mytob.LU
      [INFO]      The file was moved to '46b14118.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007petite 2.3.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was moved to '4732d31d.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007polyene0.01.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Polyene). Please verify the origin of the file
      [INFO]      The file was moved to '46b1411a.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007rlpack1.18.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO]      The file was moved to '46b1411b.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007UPX3.00.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was moved to '4732d318.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007VBOWatch v2.0.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46b1411d.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007vmprotect v1.4.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4732d31a.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007yoda's Protector1.03.3.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/YodaProt). Please verify the origin of the file
      [INFO]      The file was moved to '4732d31f.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007北斗3.7.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/NSPack). Please verify the origin of the file
      [INFO]      The file was moved to '46b14124.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007北斗4.1.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/NSPack). Please verify the origin of the file
      [INFO]      The file was moved to '4732d321.qua'!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007免疫007-2.6.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSAnti.Gen
      [INFO]      The file was moved to '46b1411f.qua'!


End of the scan: 2007年6月1日  23:52
Used time: 00:29 min

The scan has been done completely.

      1 Scanning directories
     25 Files were scanned
     21 viruses and/or unwanted programs were found
scottxzt
发表于 2007-6-1 23:59:22 | 显示全部楼层

三个高启发,剩一只

Begin scan in 'D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件'
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007ASProtect SKE 2.3 Beta6.26.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007tElock 0.99.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\wyQQ2007\加壳后的文件\wyQQ2007免疫007-2.0.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
aoyang
头像被屏蔽
发表于 2007-6-2 00:03:49 | 显示全部楼层
NOD报壳了
hj5abc
发表于 2007-6-2 00:07:14 | 显示全部楼层
原帖由 aoyang 于 2007-6-2 00:03 发表
NOD报壳了

确实是很奇怪..
不过你的笑话不好笑撒..
aoyang
头像被屏蔽
发表于 2007-6-2 00:08:39 | 显示全部楼层

回复 #16 hj5abc 的帖子

因为EQ2最讨厌报壳的杀软了,而且经常BS之,现在NOD报了壳,而原文件没报,不知道有什么感想 好奇
goodfish2002
发表于 2007-6-2 00:38:36 | 显示全部楼层
瑞星杀了22个,成绩还不错
KAV-Longhorn
发表于 2007-6-2 04:38:53 | 显示全部楼层
算了一下,红伞真正能杀的(不包括报壳),只有17个左右
wkwx
发表于 2007-6-2 05:59:09 | 显示全部楼层

微点全杀

微点全杀:

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-26 16:40 , Processed in 0.093575 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表