12
返回列表 发新帖
楼主: promised
收起左侧

[病毒样本] 睡觉前来10个一包

[复制链接]
Giggs
发表于 2007-7-3 23:06:20 | 显示全部楼层
全灭 [:1:]
wangjay1980
发表于 2007-7-3 23:06:29 | 显示全部楼层
唉,CDN无处不在


可惜卡巴不杀
hj5abc
发表于 2007-7-3 23:06:43 | 显示全部楼层

回复 #8 promised 的帖子

绑流氓比较有前途.
mingwang69
发表于 2007-7-3 23:49:01 | 显示全部楼层
Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2005-10-5
Start time: 2007-7-3 23:51
Engine(s): KAV engine (AVK 16.818), BD-Engine (BD 16.864)
Heuristic: On
Archives: On
System areas: On
Check system areas...
Check selected directories and files...
Object: 100224.exe
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\1\SYS32\Kuco_100224
Status: Virus could not be removed
Virus: Trojan-Downloader.Win32.Small.cjh (KAV engine), Trojan.Downloader.Small.CJH (BD-Engine)
Object: toole.exe
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹
Status: Virus could not be removed
Virus: Rootkit.Win32.Agent.df (KAV engine), Trojan.Agent.AKN (BD-Engine)
Object: 10062_setup.exe
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP
Status: Virus could not be removed
Virus: Trojan.Win32.StartPage.aks (KAV engine), Trojan.Clicker.Small.LL (BD-Engine)
Object: sctongjia.dll
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR
Status: Virus could not be removed
Virus: not-a-virus:AdWare.Win32.SeeCha.a (KAV engine), Adware.SeeCha.A (BD-Engine)
Object: HTTPDll.dll
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
Status: Virus could not be removed
Virus: Trojan.BHO.Agent.B (BD-Engine)
Object: lrcsys.exe
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
Status: Virus could not be removed
Virus: Trojan.BHO.Agent.B (BD-Engine)
Object: YHBO.dll
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
Status: Virus could not be removed
Virus: Trojan.BHO.Agent.B (BD-Engine)
Object: tools.exe
Path: C:\Documents and Settings\Administrator\桌面\新建文件夹[1]\新建文件夹\新建文件夹\v2\$WINDIR
Status: Virus could not be removed
Virus: Backdoor.Win32.SdBot.ajk (KAV engine), Backdoor.Sdbot.DERM (BD-Engine)
Analysis complete: 2007-7-3 23:52
    10 files checked
    8 infected files detected
    0 suspected files detected

[ 本帖最后由 mingwang69 于 2007-7-3 23:52 编辑 ]
wangjay1980
发表于 2007-7-3 23:52:59 | 显示全部楼层
Hello,

HTTPDll.dll, lrcsys.exek, YHBO.dll, ZW.exek

No malicious code were found in these files.

msg.dll - Trojan.Win32.Agent.arj

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Vladimir Krylov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
rasis
发表于 2007-7-4 00:25:25 | 显示全部楼层
Begin scan in 'tools.exe'
tools.exe
      [DETECTION] Contains signature of the worm WORM/Sdbot.209920.13
      [WARNING]   The file was ignored!
Begin scan in 'toole.exe'
toole.exe
      [DETECTION] Is the Trojan horse TR/Agent.AKN.2
      [WARNING]   The file was ignored!
Begin scan in '100224.exe'
100224.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Sma.cjh.7.A
      [WARNING]   The file was ignored!
Begin scan in 'ZW.exe'
ZW.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Cdnup.A.1
      [WARNING]   The file was ignored!
Begin scan in 'sctongjia.dll'
sctongjia.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/SeeCha.A
      [WARNING]   The file was ignored!
Begin scan in 'HTTPDll.dll'
HTTPDll.dll
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B
      [WARNING]   The file was ignored!
Begin scan in 'lrcsys.exe'
lrcsys.exe
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B.1
      [WARNING]   The file was ignored!
Begin scan in 'YHBO.dll'
YHBO.dll
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B.3
      [WARNING]   The file was ignored!
Begin scan in '10062_setup.exe'
10062_setup.exe
      [DETECTION] Is the Trojan horse TR/Startpage.AKS
      [WARNING]   The file was ignored!
Begin scan in 'msg.dll'
msg.dll
      [DETECTION] Contains suspicious code HEUR/Crypted
      [WARNING]   The file was ignored!


End of the scan: 2007年7月4日  00:24
Used time: 00:09 min

The scan has been done completely.

      0 Scanning directories
     10 Files were scanned
     10 viruses and/or unwanted programs were found
      1 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -1 Files not concerned
      0 Archives were scanned
     10 Warnings
      0 Notes
      0 Hidden objects were found
欠妳緈諨
发表于 2007-7-4 00:33:16 | 显示全部楼层
AVAST干掉8个
2007-7-4        0:31:55        1183480315        LuckyStar        2012        Sign of "Win32:Small-ABW [Trj]" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\1\SYS32\Kuco_100224\100224.exe" file.  
2007-7-4        0:32:08        1183480328        LuckyStar        2012        Sign of "Win32:Trojan-gen. {Other}" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\toole.exe" file.  
2007-7-4        0:32:08        1183480328        LuckyStar        2012        Sign of "Win32:Small-BHL [Trj]" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$TEMP\10062_setup.exe" file.  
2007-7-4        0:32:10        1183480330        LuckyStar        2012        Sign of "Win32:Adware-gen. [Adw]" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR\sctongjia.dll\[UPX]\[Embedded#083108]" file.  
2007-7-4        0:32:11        1183480331        LuckyStar        2012        Sign of "Win32:Trojan-gen. {Other}" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32\HTTPDll.dll" file.  
2007-7-4        0:32:11        1183480331        LuckyStar        2012        Sign of "Win32:Trojan-gen. {Other}" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32\lrcsys.exe" file.  
2007-7-4        0:32:11        1183480331        LuckyStar        2012        Sign of "Win32:Trojan-gen. {Other}" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32\YHBO.dll" file.  
2007-7-4        0:32:12        1183480332        LuckyStar        2012        Sign of "Win32:Agent-CNM [Trj]" has been found in "D:\病毒测试\解压\样本\新建文件夹\新建文件夹\v2\$WINDIR\tools.exe\[ASProtect]" file.

[ 本帖最后由 欠你幸福 于 2007-7-4 00:35 编辑 ]
1688388728
发表于 2007-7-4 00:48:03 | 显示全部楼层
反病毒专家 AntiVirusKit 2007 扫描病毒日志记录
版本
双引擎反病毒签名 7/3/2007
开始时间: 7/4/2007 00:46
引擎: KAV 引擎 (AVK 17.5837), AVST 引擎 (AVKB 17.285)
高启发式: 打开
压缩文件: 打开
系统区域: 打开

扫描系统区域...
扫描所选择的目录和文件...
对象: 100224.exe
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\1\SYS32\Kuco_100224
狀態: 无法清除病毒
        病毒: Trojan-Downloader.Win32.Small.cjh (KAV 引擎), Win32:Small-ABW [Trj] (AVST 引擎)
对象: toole.exe
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹
狀態: 无法清除病毒
        病毒: Rootkit.Win32.Agent.df (KAV 引擎), Win32:Trojan-gen. {Other} (AVST 引擎)
对象: 10062_setup.exe
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP
狀態: 无法清除病毒
        病毒: Trojan.Win32.StartPage.aks (KAV 引擎), Win32:Small-BHL [Trj] (AVST 引擎)
对象: sctongjia.dll
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR
狀態: 无法清除病毒
        病毒: not-a-virus:AdWare.Win32.SeeCha.a (KAV 引擎)
对象: HTTPDll.dll
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
狀態: 无法清除病毒
        病毒: Win32:Trojan-gen. {Other} (AVST 引擎)
对象: lrcsys.exe
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
狀態: 无法清除病毒
        病毒: Win32:Trojan-gen. {Other} (AVST 引擎)
对象: YHBO.dll
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32
狀態: 无法清除病毒
        病毒: Win32:Trojan-gen. {Other} (AVST 引擎)
对象: tools.exe
        路径: E:\病毒库\新建文件夹[1]\新建文件夹\新建文件夹\v2\$WINDIR
狀態: 无法清除病毒
        病毒: Backdoor.Win32.SdBot.ajk (KAV 引擎), Win32:Agent-CNM [Trj] (AVST 引擎)
扫描完成: 7/4/2007 00:46
    已检查 10 个文件
    已发现 8 个染毒文件
    发现 0 个可疑文件
mofunzone
发表于 2007-7-4 01:21:41 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\新建文件夹'
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\
  toole.exe
      [DETECTION] Is the Trojan horse TR/Agent.AKN.2
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\1\SYS32\
  ZW.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Cdnup.A.1
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\1\SYS32\Kuco_100224\
  100224.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Sma.cjh.7.A
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\v2\$TEMP\
  10062_setup.exe
      [DETECTION] Is the Trojan horse TR/Startpage.AKS
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR\
  sctongjia.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/SeeCha.A
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\v2\$TEMP\song\$WINDIR\system32\
  HTTPDll.dll
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B
      [INFO]      The file was deleted!
  lrcsys.exe
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B.1
      [INFO]      The file was deleted!
  YHBO.dll
      [DETECTION] Is the Trojan horse TR/BHO.Agent.B.3
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\My Documents\新建文件夹\新建文件夹\v2\$WINDIR\
  msg.dll
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '46f1861d.qua'!
  tools.exe
      [DETECTION] Contains signature of the worm WORM/Sdbot.209920.13
      [INFO]      The file was deleted!


End of the scan: 2007年7月3日  10:21
Used time: 00:08 min

The scan has been done completely.

     13 Scanning directories
     10 Files were scanned
     10 viruses and/or unwanted programs were found
      1 classified as suspicious:
      9 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -1 Files not concerned
      0 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
woai_jolin
发表于 2007-7-4 09:13:21 | 显示全部楼层
时间        模块        对象        名称        病毒        操作        用户名称        信息
2007/7/4 9:10:58        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR\sctongjia.dll        Win32/Adware.SeeCha 应用程序        已隔离 - 已删除        Jason-PC\Jason        程序新建文件时发生事件: C:\Program Files\WinRAR\WinRAR.exe. 文件已被移入隔离区。您可以关闭本窗口。
2007/7/4 9:10:56        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\v2\$TEMP\sctongjia\$SYSDIR\sctongjia.dll        Win32/Adware.SeeCha 应用程序        已隔离 - 已删除        Jason-PC\Jason        程序新建文件时发生事件: C:\Program Files\WinRAR\WinRAR.exe. 文件已被移入隔离区。您可以关闭本窗口。
2007/7/4 9:10:55        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\v2\$TEMP\10062_setup.exe        Win32/TrojanDownloader.VB.NFU 木马        已隔离 - 已删除        Jason-PC\Jason        程序新建文件时发生事件: C:\Program Files\WinRAR\WinRAR.exe. 文件已被移入隔离区。您可以关闭本窗口。
2007/7/4 9:10:53        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\1\SYS32\KUCO_100224\100224.EXE        Win32/TrojanDownloader.Small.NLT 木马        已删除        NT AUTHORITY\SYSTEM        尝试访问文件时发生事件: C:\Program Files\Micropoint\MPSVC2.exe.
2007/7/4 9:10:53        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\v2\$WINDIR\tools.exe        Win32/TrojanDownloader.Agent.NPH 木马        已隔离 - 已删除        Jason-PC\Jason        程序新建文件时发生事件: C:\Program Files\WinRAR\WinRAR.exe. 文件已被移入隔离区。您可以关闭本窗口。
2007/7/4 9:10:48        AMON        文件        D:\病毒上报\新建文件夹\新建文件夹\1\SYS32\Kuco_100224\100224.exe        Win32/TrojanDownloader.Small.NLT 木马        已隔离 - 已删除        Jason-PC\Jason        程序新建文件时发生事件: C:\Program Files\WinRAR\WinRAR.exe. 文件已被移入隔离区。您可以关闭本窗口。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-17 16:27 , Processed in 0.090679 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表