查看: 2098|回复: 5
收起左侧

[病毒样本] 感染:46 [凝逸.扫描记录]MD5[A430AC 7351F1 F83F4A DF0D82 ..]

[复制链接]
qqq000@qq.com
头像被屏蔽
发表于 2007-6-18 07:36:11 | 显示全部楼层 |阅读模式
[凝逸.扫描记录]
MD5[A430AC 7351F1 F83F4A DF0D82 446C5F 60503B 727C22 4A41D8 385B66 386BC4 88C849 9144CF 6D1211 597610 46654D 0BC785 E80274 90F994 33B19A 69CB16 a430ac 7351f1 f83f4a df0d82 446c5f 60503b 727c22 385b66 386bc4 88c849 9144cf 6d1211 597610 46654d 0bc785 e80274 90f994 69cb16 05F2B5 05f2b5 05F2B5 05f2b5 05F2B5 05f2b5 05F2B5 05f2b5 ]
f:\未知\1+1\11\0\A430AC_4(3).exe,木马
f:\未知\1+1\11\0\7351F1_ad1697.exe,木马
f:\未知\1+1\11\0\F83F4A_mm(3).exe,木马
f:\未知\1+1\11\0\DF0D82_xuik.exe,木马
f:\未知\1+1\11\0\446C5F_ad1939.exe,木马
f:\未知\1+1\11\0\60503B_mac.exe,木马
f:\未知\1+1\11\0\727C22_12(1).exe,木马
f:\未知\1+1\11\0\4A41D8_bind_50077.exe,木马
f:\未知\1+1\11\0\385B66_shang.exe,木马
f:\未知\1+1\11\0\386BC4_woool.exe,木马
f:\未知\1+1\11\0\88C849_ztjh.exe,木马
f:\未知\1+1\11\0\9144CF_ad967.exe,木马
f:\未知\1+1\11\0\6D1211_winlogin.exe,木马
f:\未知\1+1\11\0\597610_zbox2.exe,木马
f:\未知\1+1\11\0\46654D_tx2cs.exe,木马
f:\未知\1+1\11\0\0BC785_intranet.exe,木马
f:\未知\1+1\11\0\E80274_taskmor.exe,木马
f:\未知\1+1\11\0\90F994_ad2072.exe,木马
f:\未知\1+1\11\0\33B19A_1(2)_unpacked.exe,木马
f:\未知\1+1\11\0\69CB16_winlogin_unpacked.exe,木马
f:\未知\1+1\11\0\a430ac_4(3).exe,木马
f:\未知\1+1\11\0\7351f1_ad1697.exe,木马
f:\未知\1+1\11\0\f83f4a_mm(3).exe,木马
f:\未知\1+1\11\0\df0d82_xuik.exe,木马
f:\未知\1+1\11\0\446c5f_ad1939.exe,木马
f:\未知\1+1\11\0\60503b_mac.exe,木马
f:\未知\1+1\11\0\727c22_12(1).exe,木马
f:\未知\1+1\11\0\385b66_shang.exe,木马
f:\未知\1+1\11\0\386bc4_woool.exe,木马
f:\未知\1+1\11\0\88c849_ztjh.exe,木马
f:\未知\1+1\11\0\9144cf_ad967.exe,木马
f:\未知\1+1\11\0\6d1211_winlogin.exe,木马
f:\未知\1+1\11\0\597610_zbox2.exe,木马
f:\未知\1+1\11\0\46654d_tx2cs.exe,木马
f:\未知\1+1\11\0\0bc785_intranet.exe,木马
f:\未知\1+1\11\0\e80274_taskmor.exe,木马
f:\未知\1+1\11\0\90f994_ad2072.exe,木马
f:\未知\1+1\11\0\69cb16_winlogin_unpacked.exe,木马
f:\未知\1+1\11\0\ad967\$commonfiles\cpush\05F2B5_cpush.tmp,木马
f:\未知\1+1\11\0\ad967\$commonfiles\cpush\05f2b5_cpush.tmp,木马
f:\未知\1+1\11\0\ad2072\$commonfiles\cpush\05F2B5_cpush.tmp,木马
f:\未知\1+1\11\0\ad2072\$commonfiles\cpush\05f2b5_cpush.tmp,木马
f:\未知\1+1\11\0\ad1939\$commonfiles\cpush\05F2B5_cpush.tmp,木马
f:\未知\1+1\11\0\ad1939\$commonfiles\cpush\05f2b5_cpush.tmp,木马
f:\未知\1+1\11\0\ad1697\$commonfiles\cpush\05F2B5_cpush.tmp,木马
f:\未知\1+1\11\0\ad1697\$commonfiles\cpush\05f2b5_cpush.tmp,木马
感染:46/文件:46
扫描完成|文件:46|耗时:4977

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2007-6-18 07:42:22 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\zbox2.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  zbox2.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\ztjh.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  ztjh.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\1(2)_unpacked.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  1(2)_unpacked.exe
      [DETECTION] Contains suspicious code HEUR/Damaged
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\4(3).exe'
C:\Documents and Settings\Administrator\My Documents\0\
  4(3).exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\12(1).exe'
C:\Documents and Settings\Administrator\My Documents\0\
  12(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\ad967.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  ad967.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  ad1697.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  ad1939.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  ad2072.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\bind_50077.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  bind_50077.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.atk.47
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\cpush.tmp'
C:\Documents and Settings\Administrator\My Documents\0\
  cpush.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BHO.AV.32
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\intranet.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  intranet.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\mac.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  mac.exe
      [DETECTION] Is the Trojan horse TR/Delf.NEG.5
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\mm(3).exe'
C:\Documents and Settings\Administrator\My Documents\0\
  mm(3).exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.26481.1
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\shang.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  shang.exe
      [DETECTION] Contains signature of the dropper DR/PcClient.Gen
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\taskmor.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  taskmor.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\tx2cs.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  tx2cs.exe
      [DETECTION] Is the Trojan horse TR/Agent.34708.B
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\winlogin.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  winlogin.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\winlogin_unpacked.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  winlogin_unpacked.exe
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\woool.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  woool.exe
      [DETECTION] Is the Trojan horse TR/PCK.NSAnti.N.50
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0\xuik.exe'
C:\Documents and Settings\Administrator\My Documents\0\
  xuik.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [WARNING]   The file was ignored!


End of the scan: 2007年6月17日  16:44
Used time: 00:12 min

The scan has been done completely.

      0 Scanning directories
     21 Files were scanned
     12 viruses and/or unwanted programs were found
      1 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      8 Files not concerned
      0 Archives were scanned
     12 Warnings
      0 Notes
      0 Hidden objects were found


正在检查NOD32.EXE文件的CRC:状态正常
D:\Eset\nod32.exe - 是正常的
扫描系统内存中:没有进行 (选项已关闭)
扫描MBR及引导区中:没有进行 (选项已关闭)
日期: 17.6.2007  时间:16:44:23
已关闭反隐藏功能.
已扫描的磁盘,文件夹及文件:C:\Documents and Settings\ ?
?Administrator\My Documents\0\zbox2.exe; C:\Documents  ?
?and Settings\Administrator\My Documents\0\ztjh.exe; C:\ ?
?Documents and Settings\Administrator\My Documents\0\ ?
?1(2)_unpacked.exe; C:\Documents and Settings\ ?
?Administrator\My Documents\0\4(3).exe; C:\Documents and  ?
?Settings\Administrator\My Documents\0\12(1).exe; C:\ ?
?Documents and Settings\Administrator\My Documents\0\ ?
?ad967.exe; C:\Documents and Settings\Administrator\My  ?
?Documents\0\ad1697.exe; C:\Documents and Settings\ ?
?Administrator\My Documents\0\ad1939.exe; C:\Documents  ?
?and Settings\Administrator\My Documents\0\ad2072.exe;  ?
?C:\Documents and Settings\Administrator\My Documents\0\ ?
?bind_50077.exe; C:\Documents and Settings\Administrator\ ?
?My Documents\0\cpush.tmp; C:\Documents and Settings\ ?
?Administrator\My Documents\0\intranet.exe; C:\Documents  ?
?and Settings\Administrator\My Documents\0\mac.exe; C:\ ?
?Documents and Settings\Administrator\My Documents\0\ ?
?mm(3).exe; C:\Documents and Settings\Administrator\My  ?
?Documents\0\shang.exe; C:\Documents and Settings\ ?
?Administrator\My Documents\0\taskmor.exe; C:\Documents  ?
?and Settings\Administrator\My Documents\0\tx2cs.exe; C:\ ?
?Documents and Settings\Administrator\My Documents\0\ ?
?winlogin.exe; C:\Documents and Settings\Administrator\ ?
?My Documents\0\winlogin_unpacked.exe; C:\Documents and  ?
?Settings\Administrator\My Documents\0\woool.exe; C:\ ?
?Documents and Settings\Administrator\My Documents\0\ ?
?xuik.exe
C:\Documents and Settings\Administrator\My Documents\0\ ?
?zbox2.exe >>ASPack v2.12 - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?ztjh.exe >>ASPack v2.12 - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?1(2)_unpacked.exe - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?4(3).exe - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?12(1).exe - Win32/Pacex.Gen 病毒
C:\Documents and Settings\Administrator\My Documents\0\ ?
?ad967.exe >>NSIS >>cpush.dll - Win32/Adware.BHO.AV  ?
?应用程序
C:\Documents and Settings\Administrator\My Documents\0\ ?
?ad1697.exe >>NSIS >>cpush.dll - Win32/Adware.BHO.AV  ?
?应用程序
C:\Documents and Settings\Administrator\My Documents\0\ ?
?ad1939.exe >>NSIS >>cpush.dll - Win32/Adware.BHO.AV  ?
?应用程序
C:\Documents and Settings\Administrator\My Documents\0\ ?
?ad2072.exe >>NSIS >>cpush.dll - Win32/Adware.BHO.AV  ?
?应用程序
C:\Documents and Settings\Administrator\My Documents\0\ ?
?bind_50077.exe - 未查明的 NewHeur_PE 病毒 [7]
C:\Documents and Settings\Administrator\My Documents\0\ ?
?cpush.tmp - Win32/Adware.BHO.AV 应用程序
C:\Documents and Settings\Administrator\My Documents\0\ ?
?intranet.exe >>ASPack v2.12 - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?mac.exe - 可能是 Win32/Genetik 木马 的一个变种
C:\Documents and Settings\Administrator\My Documents\0\ ?
?mm(3).exe - Win32/PSW.Delf.NHI 木马的变种
C:\Documents and Settings\Administrator\My Documents\0\ ?
?shang.exe - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?taskmor.exe >>ASPack v2.12 - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?tx2cs.exe - Win32/PSW.Agent.NDP 木马的变种
C:\Documents and Settings\Administrator\My Documents\0\ ?
?winlogin.exe >>ASPack v2.12 - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?winlogin_unpacked.exe - 是正常的
C:\Documents and Settings\Administrator\My Documents\0\ ?
?woool.exe - Win32/Pacex.Gen 病毒
C:\Documents and Settings\Administrator\My Documents\0\ ?
?xuik.exe - 可能是 Win32/Genetik 木马 的一个变种
已扫描的文件数目:21
已发现的病毒数目:12
完成时间: 16:45:07 总扫描时间:44 秒 (00:00:44)
注意:
[7] 该文件可能感染上未知病毒。



[Scan path] C:\Documents and Settings\Administrator\My Documents\0\intranet.exe
>C:\Documents and Settings\Administrator\My Documents\0\intranet.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\mac.exe
>C:\Documents and Settings\Administrator\My Documents\0\mac.exe infected with BackDoor.Beizhu

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\mm(3).exe
>>C:\Documents and Settings\Administrator\My Documents\0\mm(3).exe infected with Trojan.PWS.Gamania

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\shang.exe
C:\Documents and Settings\Administrator\My Documents\0\shang.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\taskmor.exe
>C:\Documents and Settings\Administrator\My Documents\0\taskmor.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\tx2cs.exe
>C:\Documents and Settings\Administrator\My Documents\0\tx2cs.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\winlogin.exe
>C:\Documents and Settings\Administrator\My Documents\0\winlogin.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\winlogin_unpacked.exe
C:\Documents and Settings\Administrator\My Documents\0\winlogin_unpacked.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\woool.exe
>C:\Documents and Settings\Administrator\My Documents\0\woool.exe infected with Trojan.PWS.Poptang

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\xuik.exe
>C:\Documents and Settings\Administrator\My Documents\0\xuik.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\zbox2.exe
>C:\Documents and Settings\Administrator\My Documents\0\zbox2.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\ztjh.exe
>C:\Documents and Settings\Administrator\My Documents\0\ztjh.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\1(2)_unpacked.exe
C:\Documents and Settings\Administrator\My Documents\0\1(2)_unpacked.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\4(3).exe
>C:\Documents and Settings\Administrator\My Documents\0\4(3).exe infected with Trojan.MulDrop.6426

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\12(1).exe
C:\Documents and Settings\Administrator\My Documents\0\12(1).exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\ad967.exe
>>C:\Documents and Settings\Administrator\My Documents\0\ad967.exe\data001 is an adware program Adware.Sogou.origin
>C:\Documents and Settings\Administrator\My Documents\0\ad967.exe\data002 - Ok
>C:\Documents and Settings\Administrator\My Documents\0\ad967.exe\data003 - Ok
C:\Documents and Settings\Administrator\My Documents\0\ad967.exe - archive contains infected objects

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe
>>C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe\data001 is an adware program Adware.Sogou.origin
>C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe\data002 - Ok
>C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe\data003 - Ok
C:\Documents and Settings\Administrator\My Documents\0\ad1697.exe - archive contains infected objects

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe
>>C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe\data001 is an adware program Adware.Sogou.origin
>C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe\data002 - Ok
>C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe\data003 - Ok
C:\Documents and Settings\Administrator\My Documents\0\ad1939.exe - archive contains infected objects

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe
>>C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe\data001 is an adware program Adware.Sogou.origin
>C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe\data002 - Ok
>C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe\data003 - Ok
C:\Documents and Settings\Administrator\My Documents\0\ad2072.exe - archive contains infected objects

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\bind_50077.exe
C:\Documents and Settings\Administrator\My Documents\0\bind_50077.exe - Ok

[Scan path] C:\Documents and Settings\Administrator\My Documents\0\cpush.tmp
C:\Documents and Settings\Administrator\My Documents\0\cpush.tmp is an adware program Adware.Sogou.origin

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 27
Infected objects found: 4
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 5
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 427 Kb/s
Scan time: 00:00:10

[ 本帖最后由 mofunzone 于 2007-6-17 15:43 编辑 ]
红心王子
发表于 2007-6-18 08:00:02 | 显示全部楼层
3,4,5,6,8 Part
KV都不报
剩下的监控基本全部截获
砍杀病毒工作开始进行中

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2007-6-18 08:46:22 | 显示全部楼层
deleted: Trojan program Trojan-Dropper.Win32.Agent.bdw        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\4(3).exe
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad1697.exe//stream//data0001
deleted: Trojan program Trojan-PSW.Win32.Delf.qc        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\mm(3).exe//UPX
deleted: Trojan program Trojan-Downloader.Win32.Delf.bcm        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\xuik.exe
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad1939.exe//stream//data0001
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.qv        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\12(1).exe
deleted: Trojan program Trojan-Downloader.Win32.VB.atk        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\bind_50077.exe
deleted: Trojan program Backdoor.Win32.PcClient.yz        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\shang.exe
deleted: virus Packed.Win32.NSAnti.n        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\woool.exe
deleted: Trojan program Trojan-PSW.Win32.Nilage.aeg        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ztjh.exe//ASPack
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad967.exe//stream
deleted: Trojan program Trojan-Clicker.Win32.Chimoz.ak        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\winlogin.exe//ASPack
deleted: Trojan program Trojan-Clicker.Win32.Chimoz.ak        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\taskmor.exe//ASPack
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad2072.exe//stream//data0001
deleted: Trojan program Trojan-Clicker.Win32.Chimoz.ak        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\winlogin_unpacked.exe
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad967\$COMMONFILES\CPUSH\cpush.tmp
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad2072\$COMMONFILES\CPUSH\cpush.tmp
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad1939\$COMMONFILES\CPUSH\cpush.tmp
deleted: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\ad1697\$COMMONFILES\CPUSH\cpush.tmp
detected: Trojan program Backdoor.Win32.Hupigon.ene        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\mac.exe//SYST.DLL
detected: virus Trojan.Generic        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\mac.exe
detected: virus Invader (modification)        File: C:\Documents and Settings\Owner\×ÀÃæ\1+1\11\0\tx2cs.exe
傻猪猪米走鸡
发表于 2007-6-18 12:21:12 | 显示全部楼层
nod12个!
rasis
发表于 2007-6-18 13:13:52 | 显示全部楼层
Begin scan in '\0\ad1697'
\0\ad1697\$COMMONFILES\CPUSH\cpush.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BHO.AV.32
      [WARNING]   The file was ignored!
Begin scan in '\0\ad1939'
\0\ad1939\$COMMONFILES\CPUSH\cpush.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BHO.AV.32
      [WARNING]   The file was ignored!
Begin scan in '\0\ad2072'
\0\ad2072\$COMMONFILES\CPUSH\cpush.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BHO.AV.32
      [WARNING]   The file was ignored!
Begin scan in '\0\ad967'
\0\ad967\$COMMONFILES\CPUSH\cpush.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BHO.AV.32
      [WARNING]   The file was ignored!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-5 06:33 , Processed in 0.121733 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表