查看: 4706|回复: 26
收起左侧

[病毒样本] 39个不杀的 MD5[70A8FC...........

[复制链接]
qqq000@qq.com
头像被屏蔽
发表于 2007-6-27 20:35:21 | 显示全部楼层 |阅读模式
[凝逸.扫描记录]
MD5[70A8FC 70a8fc e28f94 6afb16 e7d558 c294a0 47fda2 c294a0 bf3ca4 70a8fc 7f79a7 7f79a7 813415 1ff1d7 d70c3d c294a0 70a8fc 0dfc08 940286 47fda2 46a7c9 ff83ae 70a8fc d61529 ac09c2 e28f94 f8aac2 b44c21 288e9c 63bed5 5f411f e01be4 d6101c df09d7 b9a28d 338823 b819e8 59edc9 e28f94 ]
f:\070627\不杀的\70A8FC_96f86b43.exe,木马
f:\070627\不杀的\70a8fc_96f86b43.exe,木马
f:\070627\不杀的\e28f94_256728f2(1).exe,木马
f:\070627\不杀的\6afb16_bind_50201.exe,木马
f:\070627\不杀的\e7d558_bind_50099.exe,木马
f:\070627\不杀的\c294a0_auto.exe,木马
f:\070627\不杀的\47fda2_05a747af.dll,木马
f:\070627\不杀的\c294a0_235c3f97.exe,木马
f:\070627\不杀的\bf3ca4_8eb70e70.dll,木马
f:\070627\不杀的\70a8fc_1b43d60d.exe,木马
f:\070627\不杀的\7f79a7_up.exe,木马
f:\070627\不杀的\7f79a7_risingup.exe,木马
f:\070627\不杀的\813415_nwizqjsj.dll,木马
f:\070627\不杀的\1ff1d7_ravasktao.dll,木马
f:\070627\不杀的\d70c3d_msfeed.exe,木马
f:\070627\不杀的\c294a0_oooo[1].exe,木马
f:\070627\不杀的\70a8fc_756e5c4ccaa4b342[1].exe,木马
f:\070627\不杀的\0dfc08_explroer.exe,木马
f:\070627\不杀的\940286_88342c60.exe,木马
f:\070627\不杀的\47fda2_0268bbf5.dll,木马
f:\070627\不杀的\46a7c9_46bf8e6b.dll,木马
f:\070627\不杀的\ff83ae_54dcd80d.dll,木马
f:\070627\不杀的\70a8fc_84a64f25.exe,木马
f:\070627\不杀的\d61529_fd012.exe,木马
f:\070627\不杀的\ac09c2_6to4svc.dll,木马
f:\070627\不杀的\e28f94_256728f2.exe,木马
f:\070627\不杀的\f8aac2_1fj1ugwg.dll,木马
f:\070627\不杀的\b44c21_auditusr.exe,木马
f:\070627\不杀的\288e9c_autochk.exe,木马
f:\070627\不杀的\63bed5_autoconv.exe,木马
f:\070627\不杀的\5f411f_autofmt.exe,木马
f:\070627\不杀的\e01be4_autolfn.exe,木马
f:\070627\不杀的\d6101c_fdeploy.dll,木马
f:\070627\不杀的\df09d7_fltmc.exe,木马
f:\070627\不杀的\b9a28d_net1.exe,木马
f:\070627\不杀的\338823_net.exe,木马
f:\070627\不杀的\b819e8_twain_32.dll,木马
f:\070627\不杀的\59edc9_ieaux.dll,木马
f:\070627\不杀的\e28f94_复件auto.exe,木马
感染:39/文件:39
扫描完成|文件:39|耗时:1252

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2007-6-27 20:39:28 | 显示全部楼层
deleted: Trojan program Trojan-Spy.Win32.Agent.nb        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\0DFC08_explroer.exe
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.sl        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\1FF1D7_ravasktao.dll
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\BF3CA4_8eb70e70.dll
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\C294A0_235c3f97.exe//PE_Patch
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\C294A0_auto.exe//PE_Patch
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\C294A0_oooo[1].exe//PE_Patch
deleted: Trojan program Trojan-Downloader.Win32.QQHelper.vn        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\D61529_fd012.exe//data0002
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\E28F94_256728f2(1).exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\E28F94_256728f2.exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\E28F94_¸´¼þauto.exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\46A7C9_46bf8e6b.dll
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\70A8FC_96f86b43.exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\96F86B43.EXE
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\70A8FC_1b43d60d.exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\70A8FC_756e5c4ccaa4b342[1].exe
deleted: Trojan program Backdoor.Win32.Agent.ahj        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\70A8FC_84a64f25.exe
deleted: Trojan program Trojan.Win32.StartPage.aok        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\7F79A7_risingup.exe
deleted: Trojan program Trojan.Win32.StartPage.aok        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\7F79A7_up.exe
deleted: Trojan program Trojan-PSW.Win32.Nilage.bjp        File: E:\Ñù±¾\н¨Îļþ¼Ð (2)\813415_nwizqjsj.dll
蓝色牛仔裤
发表于 2007-6-27 20:41:31 | 显示全部楼层
蜘蛛8个。。。


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1688388728
发表于 2007-6-27 20:45:22 | 显示全部楼层
以 AntiVirusKit 掃瞄病毒
版本 17.0.6353
病毒特徵碼 6/27/2007
開始時間: 6/27/2007 20:49
引擎: 引擎 A (AVK 17.5688), 引擎 B (AVKB 17.275)
啟發式: 開啟
壓縮檔: 開啟
系統區域: 開啟

掃瞄系統區域...
掃瞄所選的目錄及檔案...
物件: 0DFC08_explroer.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-Spy.Win32.Agent.nb (引擎 A)
物件: 1FF1D7_ravasktao.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-PSW.Win32.OnLineGames.sl (引擎 A)
物件: 46A7C9_46bf8e6b.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: [NsPack]
        壓縮檔中: E:\病毒库\不杀的\47FDA2_0268bbf5.dll
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
物件: 47FDA2_0268bbf5.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
物件: [NsPack]
        壓縮檔中: E:\病毒库\不杀的\47FDA2_05a747af.dll
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
物件: 47FDA2_05a747af.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
物件: 6AFB16_bind_50201.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.QQHelper.wk (引擎 A)
物件: 70A8FC_1b43d60d.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 70A8FC_756e5c4ccaa4b342[1].exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 70A8FC_84a64f25.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 70A8FC_96f86b43.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 7F79A7_risingup.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan.Win32.StartPage.aok (引擎 A)
物件: 7F79A7_up.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan.Win32.StartPage.aok (引擎 A)
物件: 813415_nwizqjsj.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-PSW.Win32.Nilage.bjp (引擎 A)
物件: 940286_88342c60.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 96F86B43.EXE
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: BF3CA4_8eb70e70.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: C294A0_235c3f97.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: C294A0_auto.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: C294A0_oooo[1].exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: data0002
        壓縮檔中: E:\病毒库\不杀的\D61529_fd012.exe
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.QQHelper.vn (引擎 A)
物件: D61529_fd012.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.QQHelper.vn (引擎 A)
物件: E28F94_256728f2(1).exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: E28F94_256728f2.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: E28F94_复件auto.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: E7D558_bind_50099.exe
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.QQHelper.rb (引擎 A)
物件: [NsPack]
        壓縮檔中: E:\病毒库\不杀的\FF83AE_54dcd80d.dll
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
物件: FF83AE_54dcd80d.dll
        路徑: E:\病毒库\不杀的
        狀態: 偵測到病毒
        病毒: Win32:Agent-GPD [Trj] (引擎 B)
分析完成: 6/27/2007 20:49
    已掃瞄 39 檔案
    偵測到 25 已感染的檔案
    偵測到 0 可疑的檔案
saga3721
发表于 2007-6-27 20:49:07 | 显示全部楼层
小红伞18个
yashoo
头像被屏蔽
发表于 2007-6-27 20:50:12 | 显示全部楼层
咖啡12个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2007-6-27 20:51:37 | 显示全部楼层
ess表象不错
2007/6/27 20:44:50        eAmon        file        D:\病毒上报\70A8FC_84a64f25.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:49        eAmon        file        D:\病毒上报\70A8FC_756e5c4ccaa4b342[1].exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:47        eAmon        file        D:\病毒上报\70A8FC_1b43d60d.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:45        eAmon        file        D:\病毒上报\96F86B43.EXE        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:43        eAmon        file        D:\病毒上报\70A8FC_96f86b43.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:41        eAmon        file        D:\病毒上报\47FDA2_05a747af.dll        probably a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:39        eAmon        file        D:\病毒上报\47FDA2_0268bbf5.dll        probably a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:38        eAmon        file        D:\病毒上报\46A7C9_46bf8e6b.dll        probably a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:37        eAmon        file        D:\病毒上报\FF83AE_54dcd80d.dll        probably a variant of Win32/Genetik trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:35        eAmon        file        D:\病毒上报\E28F94_复件auto.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:34        eAmon        file        D:\病毒上报\E28F94_256728f2.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:33        eAmon        file        D:\病毒上报\E28F94_256728f2(1).exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:32        eAmon        file        D:\病毒上报\D61529_fd012.exe        probably unknown NewHeur_PE virus        deleted - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:30        eAmon        file        D:\病毒上报\C294A0_oooo[1].exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:29        eAmon        file        D:\病毒上报\C294A0_auto.exe        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined                Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:27        eAmon        file        D:\病毒上报\C294A0_235C3F97.EXE        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined        NT AUTHORITY\SYSTEM        Event occurred during an attempt to access the file by the application: C:\Program Files\WinRAR\WinRAR.exe.
2007/6/27 20:44:25        eAmon        file        D:\病毒上报\BF3CA4_8EB70E70.DLL        probably a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined        NT AUTHORITY\SYSTEM        Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
2007/6/27 20:44:22        eAmon        file        D:\病毒上报\940286_88342C60.EXE        a variant of Win32/Agent.NEO trojan        cleaned by deleting - quarantined        NT AUTHORITY\SYSTEM        Event occurred during an attempt to access the file by the application: C:\Program Files\WinRAR\WinRAR.exe.
javeil
头像被屏蔽
发表于 2007-6-27 20:52:28 | 显示全部楼层
诺顿0个?????
晕死
yashoo
头像被屏蔽
发表于 2007-6-27 20:53:39 | 显示全部楼层
AVK太变态了,有25个 红伞和NOD都是18个,卡巴19个


现在就差壳王VBA32和IKARUS了

[ 本帖最后由 yashoo 于 2007-6-27 21:26 编辑 ]
hj5abc
发表于 2007-6-27 21:14:11 | 显示全部楼层
Scan performed at: 2007-6-27 21:16:46
Scanning Log
NOD32 version 2358 (20070627) NT
Command line: F:\不杀的
Operating memory - is OK


















Date: 27.6.2007  Time: 21:16:49
Anti-Stealth technology is enabled.
Scanned disks, folders and files: F:\不杀的\
F:\不杀的\46A7C9_46bf8e6b.dll - probably a variant of Win32/Agent.NEO trojan
F:\不杀的\47FDA2_0268bbf5.dll - probably a variant of Win32/Agent.NEO trojan
F:\不杀的\47FDA2_05a747af.dll - probably a variant of Win32/Agent.NEO trojan
F:\不杀的\70A8FC_1b43d60d.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\70A8FC_756e5c4ccaa4b342[1].exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\70A8FC_84a64f25.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\70A8FC_96f86b43.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\940286_88342c60.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\96F86B43.EXE - a variant of Win32/Agent.NEO trojan
F:\不杀的\BF3CA4_8eb70e70.dll - probably a variant of Win32/Agent.NEO trojan
F:\不杀的\C294A0_235c3f97.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\C294A0_auto.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\C294A0_oooo[1].exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\D61529_fd012.exe ?NSIS ?netdde32.exe - probably unknown NewHeur_PE virus [7] - was a part of the deleted object
F:\不杀的\D61529_fd012.exe ?NSIS ?d03.exe - error occurred while reading archive
F:\不杀的\E28F94_256728f2(1).exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\E28F94_256728f2.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\E28F94_复件auto.exe - a variant of Win32/Agent.NEO trojan
F:\不杀的\FF83AE_54dcd80d.dll - probably a variant of Win32/Genetik trojan
Number of scanned files: 40
Number of threats found: 18
Number of files cleaned: 18
Time of completion: 21:17:03 Total scanning time: 14 sec (00:00:14)
Notes:
[7] File is probably infected with an unknown virus.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-24 14:14 , Processed in 0.141343 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表