查看: 3267|回复: 21
收起左侧

[病毒样本] 5个[MD5: 0B2744 1A15DA 6F0B50 F49569 F8C7B4]

[复制链接]
promised
发表于 2007-7-21 14:24:19 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
bjfhj
发表于 2007-7-21 14:31:02 | 显示全部楼层
蜘蛛发现两个
wangjay1980
发表于 2007-7-21 14:31:10 | 显示全部楼层
detected: Trojan program Trojan-PSW.Win32.Delf.je        File: C:\Documents and Settings\Owner\×ÀÃæ\virus.zip/virus/LoveQQ.exe
detected: virus Worm.Win32.Viking.lu        File: C:\Documents and Settings\Owner\×ÀÃæ\virus.zip/virus/1.exe//ExeStealth//#//UPack//PE_Patch
sb
发表于 2007-7-21 14:32:54 | 显示全部楼层
NOD32  发现3个
风雪
发表于 2007-7-21 14:35:39 | 显示全部楼层
1184999242,2007-7-21 14:27:22,Heuri.Possible/Packed,启发式扫描,mygood,D:\3\新建文件夹\新建文件夹\virus\1.exe,Manual scan
1184999242,2007-7-21 14:27:22,Heuri.Possible/Packed,启发式扫描,mygood,D:\3\新建文件夹\新建文件夹\virus\21.exe,Manual scan
1184999242,2007-7-21 14:27:22,TrojanPSW.Delf.je.ko,木马,mygood,D:\3\新建文件夹\新建文件夹\virus\LoveQQ.exe,Manual scan
1184999242,2007-7-21 14:27:22,Heuri.Possible/Packed,启发式扫描,mygood,D:\3\新建文件夹\新建文件夹\virus\Setup.exe,Manual scan
1184999260,2007-7-21 14:27:40,Heuri.Possible/Packed,启发式扫描,mygood,D:\3\新建文件夹\新建文件夹\virus\Setup.exe,Realtime scan
费尔
微点卫士
发表于 2007-7-21 14:36:05 | 显示全部楼层
金山报了3个毒
微点:
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX00.531\VIRUS\1.EXE
可疑程序生成以下文件:
1) C:\WINDOWS.0\UNINSTALL\RUNDL132.EXE
2) C:\WINDOWS.0\LOGO1_.EXE
3) C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\$$A13.BAT
4) C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\$$A13.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
其他微点无反应
zengmingwh
发表于 2007-7-21 14:43:12 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\bingdu\virus.zip'
F:\bingdu\virus.zip
  [0] Archive type: ZIP
  --> virus/QQ2007.exe
      [DETECTION] Is the Trojan horse TR/PSW.QQPass.WD.1
  --> virus/LoveQQ.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus/Setup.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> virus/21.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> virus/1.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.AF.2
      [WARNING]   The file was ignored!
woai_jolin
发表于 2007-7-21 14:46:47 | 显示全部楼层
2007/7/21 14:43:41        Scanning Log
2007/7/21 14:43:41        Version of virus signature database: 2410 (20070720)
2007/7/21 14:43:41        Date: 21.7.2007  Time: 14:43:41
2007/7/21 14:43:41        Scanned disks, folders and files: F:\v\
2007/7/21 14:43:46        F:\v\virus.zip - multiple threats - deleted - quarantined
2007/7/21 14:43:46        F:\v\virus.zip » ZIP » virus/QQ2007.exe - probably a variant of Win32/PSW.QQPass.VD trojan
2007/7/21 14:43:46        F:\v\virus.zip » ZIP » virus/LoveQQ.exe - probably unknown NewHeur_PE virus [7]
2007/7/21 14:43:46        F:\v\virus.zip » ZIP » virus/1.exe - probably a variant of Win32/Viking virus
2007/7/21 14:43:46        Number of scanned files: 6
2007/7/21 14:43:46        Number of threats found: 3
2007/7/21 14:43:46        Time of completion: 14:43:46  Total scanning time: 5 sec (00:00:05)
2007/7/21 14:43:46       
2007/7/21 14:43:46        Notes:
2007/7/21 14:43:46        [7] File is probably infected with an unknown virus.
欠妳緈諨
发表于 2007-7-21 14:47:31 | 显示全部楼层
4只

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1688388728
发表于 2007-7-21 15:12:05 | 显示全部楼层
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I0GU558Q\virus[1].zip\virus/QQ2007.exe - infected with Trojan.PWS.Qqpass.824
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I0GU558Q\virus[1].zip\virus/LoveQQ.exe - infected with Trojan.PWS.Qqpass.38

Archive contains 2 infected items
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-12 05:49 , Processed in 0.133430 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表