查看: 2493|回复: 17
收起左侧

[病毒样本] 一小包

[复制链接]
virus007
发表于 2007-6-29 21:28:57 | 显示全部楼层 |阅读模式
全是一个毒网上的

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
tracydk
发表于 2007-6-29 21:33:49 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\1.part1.rar'
F:\病毒样本\1.part1.rar
  [0] Archive type: RAR
  --> 1.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zhidao
  --> 819.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> pv0009.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/UPACK). Please verify the origin of the file
  --> 1012.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\1.part2.rar'
F:\病毒样本\1.part2.rar
  [0] Archive type: RAR
  --> down.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.3537
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.bko
  --> 002.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.ahj.564 Backdoor server programs
      [INFO]      The file was deleted!
小邪邪
发表于 2007-6-29 21:42:29 | 显示全部楼层
剩一个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-6-29 21:45:53 | 显示全部楼层
Scan performed at: 2007-6-29 21:45:34
Scanning Log
NOD32 version 2364 (20070629) NT
Command line: C:\Documents and Settings\EQ2\桌面\1
Operating memory - is OK

Date: 29.6.2007  Time: 21:45:39
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\1\
C:\Documents and Settings\EQ2\桌面\1\002.exe - a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\1\1012.exe - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\1\1224.exe ?NSIS ?loadadv579.exe - a variant of Win32/TrojanDownloader.Small.NUS trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\1224.exe ?NSIS ?stats.exe ?NSIS ?XYZ.EXE - Win32/TrojanDownloader.Small.NSQ trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\237.exe - a variant of Win32/Agent.ABE trojan
C:\Documents and Settings\EQ2\桌面\1\3.exe - Win32/TrojanDownloader.Delf.BHO trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\805.exe ?NSIS ?805.exe - probably a variant of Win32/Agent.NAU worm - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\805.exe ?NSIS ?805~.exe - a variant of Win32/Agent.NEO trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\819.exe - probably a variant of Win32/Agent.NAU worm
C:\Documents and Settings\EQ2\桌面\1\dodolook264.exe ?NSIS ?1069.exe ?NSIS ?acpidisk.sys - a variant of Win32/Adware.Cinmus application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\down.exe - Win32/TrojanDownloader.Delf.BHO trojan - quarantined - unable to clean - deleted
Number of scanned files: 22
Number of threats found: 11
Number of files cleaned: 9
Time of completion: 21:45:43 Total scanning time: 4 sec (00:00:04)
1688388728
发表于 2007-6-29 21:49:34 | 显示全部楼层
以 AntiVirusKit 掃瞄病毒
版本 17.0.6353
病毒特徵碼 6/29/2007
開始時間: 6/29/2007 21:47
引擎: 引擎 A (AVK 17.5732), 引擎 B (AVKB 17.278)
啟發式: 開啟
壓縮檔: 開啟
系統區域: 開啟

掃瞄系統區域...
掃瞄所選的目錄及檔案...
掃瞄目錄 E:\病毒库\1
物件: 002.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 1.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Virus.Win32.Drowor.d (引擎 A)
物件: [NsPack]
        壓縮檔中: E:\病毒库\1\1012.exe
        狀態: 偵測到病毒
        病毒: Win32:Agent-HFX [Trj] (引擎 B)
物件: 1012.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Win32:Agent-HFX [Trj] (引擎 B)
物件: stream/data0002/stream data0002
        壓縮檔中: E:\病毒库\1\1224.exe
        狀態: 偵測到病毒
        病毒: Trojan.Win32.Patched.v (引擎 A)
物件: stream data0003
        壓縮檔中: E:\病毒库\1\1224.exe
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.Small.eqn (引擎 A)
物件: 1224.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Trojan.Win32.Patched.v, Trojan-Downloader.Win32.Small.eqn (引擎 A)
物件: 3.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Trojan-Downloader.Win32.Delf.bko (引擎 A)
物件: data0002
        壓縮檔中: E:\病毒库\1\805.exe
        狀態: 偵測到病毒
        病毒: Worm.Win32.Agent.t (引擎 A)
物件: data0003
        壓縮檔中: E:\病毒库\1\805.exe
        狀態: 偵測到病毒
        病毒: Backdoor.Win32.Agent.ahj (引擎 A)
物件: 805.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Worm.Win32.Agent.t, Backdoor.Win32.Agent.ahj (引擎 A)
物件: 819.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Worm.Win32.Agent.t (引擎 A)
物件: data0003 data0003
        壓縮檔中: E:\病毒库\1\dodolook264.exe
        狀態: 偵測到病毒
        病毒: not-a-virus:AdWare.Win32.Cinmus.g (引擎 A)
物件: data0003 data0004
        壓縮檔中: E:\病毒库\1\dodolook264.exe
        狀態: 偵測到病毒
        病毒: not-a-virus:AdWare.Win32.Cinmus.f (引擎 A)
物件: dodolook264.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: not-a-virus:AdWare.Win32.Cinmus.g, not-a-virus:AdWare.Win32.Cinmus.f (引擎 A)
物件: down.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Virus.Win32.AutoRun.z (引擎 A)
物件: [Upack]
        壓縮檔中: E:\病毒库\1\pv0009.exe
        狀態: 偵測到病毒
        病毒: Win32:Agent-GRW [Trj] (引擎 B)
物件: pv0009.exe
        路徑: E:\病毒库\1
        狀態: 偵測到病毒
        病毒: Win32:Agent-GRW [Trj] (引擎 B)
分析完成: 6/29/2007 21:47
    已掃瞄 11 檔案
    偵測到 10 已感染的檔案
    偵測到 0 可疑的檔案
红心王子
发表于 2007-6-29 21:50:37 | 显示全部楼层
狮子吃掉9个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
remind_me
发表于 2007-6-29 21:51:37 | 显示全部楼层
卡巴拦截了,证明有它认识到,哈哈
taihuxian
发表于 2007-6-29 22:14:51 | 显示全部楼层
Virus: Virus.Win32.Drowor.d, Worm.Win32.Agent.t (2x), Trojan.Win32.Patched.v, Trojan-Downloader.Win32.Small.eqn, Backdoor.Win32.Agent.ahj

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Virus.Win32.AutoRun.z, Trojan-Downloader.Win32.Delf.bko, Backdoor.Win32.Agent.ahj

Virus found while downloading Web content.

Address: bbs.kafan.cn
liunanyuan
发表于 2007-6-29 22:23:33 | 显示全部楼层
Start of the scan: 2007年6月29日  22:23

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\11.rar'
C:\Documents and Settings\Administrator\桌面\11.rar
  [0] Archive type: RAR
  --> 11\1.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zhidao
  --> 11\819.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> 11\1012.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> 11\dodolook264.exe
      [DETECTION] Contains signature of the dropper DR/Cinmus.G.54
  --> 11\down.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.3537
  --> 11\3.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.bko
  --> 11\002.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.ahj.564 Backdoor server programs
      [INFO]      The file was deleted!


End of the scan: 2007年6月29日  22:23
Used time: 00:04 min

The scan has been done completely.

      0 Scanning directories
     12 Files were scanned
      7 viruses and/or unwanted programs were found
      1 classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
promised
发表于 2007-6-29 22:46:51 | 显示全部楼层
C:/ABC/\1\002.exe - Signature 'Backdoor.Win32.Agent.ahj' found
C:/ABC/\1\1.exe - Signature 'Trojan-PWS.Win32.Small.br' found
C:/ABC/\1\1012.exe - Signature 'Backdoor.Win32.Agent.ahj' found
C:/ABC/\1\1224.exe
C:/ABC/\1\237.exe
C:/ABC/\1\3.exe - Signature 'Trojan-PWS.Win32.QQPass.pb' found
C:/ABC/\1\805.exe - Signature 'not-a-virus:AdWare.Win32.NewWeb.i' found
C:/ABC/\1\819.exe - Suspect code-parts found (Level: 150)
C:/ABC/\1\dodolook264.exe - Signature 'not-a-virus:AdWare.Win32.Cinmus.f' found
C:/ABC/\1\down.exe - Signature 'Trojan-PWS.Win32.QQPass.pb' found
C:/ABC/\1\pv0009.exe - Signature 'Trojan-Downloader.Win32.Zlob.and' found

        11 Files scanned
          (0 Archives with 0 files)
        8 Signatures found
        1 Suspect code-part found
        Used time: 0:00.157
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 07:13 , Processed in 0.135948 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表