查看: 4991|回复: 21
收起左侧

[病毒样本] win32.iuhzu.a卤猪病毒 微点报警

[复制链接]
Nblock
发表于 2007-7-5 18:02:44 | 显示全部楼层 |阅读模式
  微点主动防御软件报警 发现新的未知木马!

HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ALERTER COM+\ IMAGEPATH  C:\WINDOWS\SYSTEM32\IME\SVCHOST.EXE

[ 本帖最后由 Nblock 于 2007-7-8 09:14 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-7-5 18:08:16 | 显示全部楼层
Scan performed at: 2007-7-5 18:07:57
Scanning Log
NOD32 version 2379 (20070704) NT
Command line: C:\Documents and Settings\EQ2\桌面\z.rar
Operating memory - is OK

Date: 5.7.2007  Time: 18:08:03
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\z.rar
C:\Documents and Settings\EQ2\桌面\z.rar ?ZIP ?Q W.com - probably a variant of Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\z.rar ?ZIP ?Trojan..com - probably a variant of Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\z.rar ?ZIP ?Server.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\z.rar ?ZIP ?too.exe - a variant of Win32/PSW.Lineage.ACN trojan
Number of scanned files: 6
Number of threats found: 4
Number of files cleaned: 1
Time of completion: 18:08:05 Total scanning time: 2 sec (00:00:02)

Notes:
[7] File is probably infected with an unknown virus.
剑指七星
发表于 2007-7-5 18:08:44 | 显示全部楼层
已检测到: 木马程序 Trojan-PSW.Win32.Maran.dy        URL: http:/bbs.kafan.cn/attachment.php?aid=96920/Q W.com

卡巴报了第一个
红心王子
发表于 2007-7-5 18:12:20 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\z.ra
r>>Q W.com        Trojan.PSW.Win32.Agent.c
C:\Documents and Settings\Administrator\桌面\z.ra
r>>Trojan..com        Trojan.PSW.Win32.OnlineGames.ae
C:\Documents and Settings\Administrator\桌面\z.ra
r>>Server.exe>>nspack       Win32.Iuhzu.a
C:\Documents and Settings\Administrator\桌面\z.ra
r>>too.exe>>packlz>>upx_c>>pe_patch(14        Trojan.PSW.Lineage.mug
Nblock
 楼主| 发表于 2007-7-5 18:15:32 | 显示全部楼层
原帖由 红心王子 于 2007-7-5 18:12 发表
r>>Server.exe>>nspack       Win32.Iuhzu.a



就是这支?!
promised
发表于 2007-7-5 18:18:16 | 显示全部楼层
C:\ABC\z.rar:\Q W.com - Signature 'Packed.Win32.NSAnti.p' found
C:\ABC\z.rar:\Trojan..com - Signature 'Packed.Win32.NSAnti.p' found
C:\ABC\z.rar:\Trojan....com - File is maybe corrupt
C:\ABC\z.rar:\Server.exe - Signature 'Backdoor.Win32.Agent.ahj' found
C:\ABC\z.rar:\too.exe - Signature 'Trojan.Popwin.R' found
C:\ABC\z.rar

        8 Files scanned
          (2 Archives with 6 files)
        4 Signatures found
        0 Suspect code-parts found
        Used time: 0:00.110
promised
发表于 2007-7-5 18:20:33 | 显示全部楼层
Trojan....com果然如IKARUS所说死了
taihuxian
发表于 2007-7-5 19:09:17 | 显示全部楼层
BitDefender

This web page has been blocked by BitDefender Antivirus Real-time Protection!

The blocked web page included objects that were either infected or likely to be infected with a virus. Your system has NOT been infected.
GenPack:Generic.Malware.SBdld.AAF99D6D
Packer.Malware.NSAnti.F
ccw8642
发表于 2007-7-5 19:12:02 | 显示全部楼层
AVAST报第一个!
rasis
发表于 2007-7-5 19:34:57 | 显示全部楼层
z.rar
  [0] Archive type: ZIP
  --> Q W.com
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> Trojan..com
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> Trojan....com
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Expressor). Please verify the origin of the file
  --> Server.exe
      [DETECTION] Contains signature of the worm WORM/Agent.AJ.23
  --> too.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.SE
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-6 15:18 , Processed in 0.141369 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表