查看: 2873|回复: 16
收起左侧

[病毒样本] 123【MD5:dc6cf2】

[复制链接]
wangjay1980
发表于 2007-7-16 10:51:38 | 显示全部楼层 |阅读模式
东东

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
FBAV
发表于 2007-7-16 10:55:34 | 显示全部楼层
风暴胜者V2 贺岁精简网络版本
_________您的安全是我们的责任_______________
作者:Sanhuan222@163.com   TM:469428271
个人Blog:http://hi.baidu.com/迅者/



===============================================
   ___________病毒查杀结果__________________


===============================================

2007年5月16日10时56分11秒 开始查杀C:\Documents and Settings\Administrator\桌面\123
C:\Documents and Settings\Administrator\桌面\123\123\ie.exe 发现未知可疑文件:Win32.NkHack.BDX.A 操作:阻止运行
****************************
您应该引起注意的文件:

-----------------------------------------


=========================================

_________文件性质分析结果________________
"带壳"仅指文件性质,仅供专业人员分析使用。


-----------------------------------------

2007年5月16日10时56分11秒收起线程…100% 查杀完毕!
扫描文件:3查杀病毒:1
tracydk
发表于 2007-7-16 10:59:33 | 显示全部楼层
红伞挂....上报..
tracydk
发表于 2007-7-16 11:04:39 | 显示全部楼层
AhnLab-V32007.7.14.02007.07.14no virus found
AntiVir7.4.0.422007.07.15no virus found
Authentium4.93.82007.07.13no virus found
Avast4.7.997.02007.07.16Win32:Delf-DNR
AVG7.5.0.4762007.07.15no virus found
BitDefender7.22007.07.16BehavesLike:Win32.ExplorerHijack
CAT-QuickHeal9.002007.07.14no virus found
ClamAVdevel-200704162007.07.16no virus found
DrWeb4.332007.07.15Trojan.MulDrop.6952
eSafe7.0.15.02007.07.10suspicious Trojan/Worm
eTrust-Vet30.8.37842007.07.14no virus found
Ewido4.02007.07.14Dropper.DN
FileAdvisor12007.07.16no virus found
Fortinet2.91.0.02007.07.14no virus found
F-Prot4.3.2.482007.07.13no virus found
IkarusT3.1.1.82007.07.15no virus found
Kaspersky4.0.2.242007.07.16no virus found
McAfee50742007.07.13no virus found
Microsoft1.27042007.07.16Trojan:Win32/Agent.gen!J
NOD32v223992007.07.14no virus found
Norman5.80.022007.07.13W32/Hupigon.gen67
Panda9.0.0.42007.07.15no virus found
Sophos4.19.02007.07.06Mal/Packer
Sunbelt2.2.907.02007.07.14no virus found
Symantec102007.07.16no virus found
TheHacker6.1.6.1462007.07.13no virus found
VBA323.12.0.22007.07.16MalwareScope.Trojan-PSW.Game.14
VirusBuster4.3.23:92007.07.15
Webwasher-Gateway6.0.12007.07.16Trojan.Crypt.NSPI.Gen
tracydk
发表于 2007-7-16 11:05:28 | 显示全部楼层
最近ONECARE还挺猛的啊..
SONGBOWEN
发表于 2007-7-16 11:09:56 | 显示全部楼层
解压后有两个文件,分别是avp.exe(怎么有点像卡巴的文件名?!混淆视听吗?)和ie.exe(用这个文件名对付菜鸟还行,稍有经验的人都知道,IE的进程是iexplore.exe,而不是ie.exe……),应该是新变种,卡巴飘过了……
蓝色牛仔裤
发表于 2007-7-16 11:12:35 | 显示全部楼层
[Scan path] C:\Documents and Settings\Administrator\桌面\123.zip
>>C:\Documents and Settings\Administrator\桌面\123.zip\123.exe\avp.exe infected with Trojan.MulDrop.6952
>>C:\Documents and Settings\Administrator\桌面\123.zip\123.exe\ie.exe infected with BackDoor.Pigeon.1604
>C:\Documents and Settings\Administrator\桌面\123.zip\123.exe - archive contains infected objects
C:\Documents and Settings\Administrator\桌面\123.zip - archive contains infected objects

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 4
Infected objects found: 2
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 0
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 0
Objects moved: 0
Objects ignored: 0
Scan speed: 29 Kb/s
Scan time: 00:00:00
红心王子
发表于 2007-7-16 11:15:45 | 显示全部楼层
看 norman的扫描结果超强  [:27:] [:27:]

Scan taken on 16 Jul 2007 03:13:48 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found BehavesLike:Win32.ExplorerHijack (probable variant)
ClamAV Found nothing
Dr.Web Found Trojan.MulDrop.6952, BackDoor.Pigeon.1604
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found Sandbox: W32/Hupigon.gen67; [ General information ]

* Creating several executable files on hard-drive.
* File length: 83456 bytes.

[ Changes to filesystem ]
* Deletes directory C:\WINDOWS\TEMP\IXP0.TMP.
* Creates directory C:\WINDOWS\TEMP\IXP0.TMP.
* Creates file C:\WINDOWS\TEMP\IXP0.TMP\TMP4351$.TMP.
* Creates file C:\WINDOWS\TEMP\IXP0.TMP\avp.exe.
* Creates file C:\WINDOWS\TEMP\IXP0.TMP\ie.exe.
* Deletes file C:\WINDOWS\TEMP\IXP0.TMP\ie.exe.
* Deletes file C:\WINDOWS\TEMP\IXP0.TMP\avp.exe.
* Deletes file C:\WINDOWS\TEMP\IXP0.TMP\TMP4351$.TMP.
* Deletes directory C:\WINDOWS\TEMP\IXP0.TMP\.
* Creates file C:\WINDOWS\winllogon.exe.
* Creates file C:\WINDOWS\Deleteme.bat.

[ Changes to registry ]
* Creates key "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce".
* Sets value "wextract_cleanup0"="rundll32.exe C:\WINDOWS\SYSTEM32\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\TEMP\IXP0.TMP\"" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce".
* Deletes value "wextract_cleanup0" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce".
* Creates key "HKLM\System\CurrentControlSet\Services\IE_WinServerName".
* Sets value "ImagePath"="C:\WINDOWS\winllogon.exe" in key "HKLM\System\CurrentControlSet\Services\IE_WinServerName".
* Sets value "DisplayName"="Windows CreaterIE" in key "HKLM\System\CurrentControlSet\Services\IE_WinServerName".

[ Process/window information ]
* Attempts to access service "IE_WinServerName".
* Creates service "IE_WinServerName (Windows CreaterIE)" as "C:\WINDOWS\winllogon.exe".
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found Mal/Packer
VirusBuster Found Packed/NSPack
VBA32 Found MalwareScope.Trojan-PSW.Game.14
The EQs
发表于 2007-7-16 11:22:12 | 显示全部楼层
Scan performed at: 2007-7-16 11:21:50
Scanning Log
NOD32 version 2399 (20070714) NT
Command line: C:\Documents and Settings\EQ2\桌面\123\123
Operating memory - is OK

Date: 16.7.2007  Time: 11:21:58
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\123\123\
C:\Documents and Settings\EQ2\桌面\123\123\ie.exe - a variant of Win32/TrojanDownloader.Delf.AXB trojan
Number of scanned files: 2
Number of threats found: 1
Number of files cleaned: 1
Time of completion: 11:21:58 Total scanning time: 0 sec (00:00:00)
一派胡言
发表于 2007-7-16 11:29:26 | 显示全部楼层
kv2007飘了。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-9 06:16 , Processed in 0.127770 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表