查看: 1864|回复: 9
收起左侧

[病毒样本] 跟新[08a9b1][f9b338][4dab17]

[复制链接]
wangjay1980
发表于 2007-7-22 17:06:35 | 显示全部楼层 |阅读模式
更新了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
红心王子
发表于 2007-7-22 17:11:18 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\3.zi
p>>123.exe>>avp.exe        Trojan.Win32.Agent.iok
只杀了一个 剩下的上报
l784588
发表于 2007-7-22 17:12:00 | 显示全部楼层
avast拦截了,报Win32:Delf-ECV [Trj]
woai_jolin
发表于 2007-7-22 17:14:05 | 显示全部楼层
已检测到: 病毒 Trojan.Generic (变种)        URL: http://bbs.kafan.cn/attachment.p ... ck//PE_Patch.MaskPE
The EQs
发表于 2007-7-22 17:14:46 | 显示全部楼层
Scan performed at: 2007-7-22 17:12:07
Scanning Log
NOD32 version 2411 (20070721) NT
Command line: C:\Documents and Settings\EQ2\桌面\3\123 C:\Documents and Settings\EQ2\桌面\3\mminstall.exe C:\Documents and Settings\EQ2\桌面\3\myself.exe
Operating memory - is OK

Date: 22.7.2007  Time: 17:12:12
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\3\123\; C:\Documents and Settings\EQ2\桌面\3\mminstall.exe; C:\Documents and Settings\EQ2\桌面\3\myself.exe
C:\Documents and Settings\EQ2\桌面\3\123\b-mke.exe - a variant of Win32/TrojanDownloader.Delf.AXB trojan
C:\Documents and Settings\EQ2\桌面\3\mminstall.exe - probably a variant of Win32/TrojanDownloader.QQHelper.NDF trojan
C:\Documents and Settings\EQ2\桌面\3\myself.exe - probably a variant of Win32/Genetik trojan
Number of scanned files: 4
Number of threats found: 3
Number of files cleaned: 3
Time of completion: 17:12:15 Total scanning time: 3 sec (00:00:03)
snakebone
头像被屏蔽
发表于 2007-7-22 17:14:57 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\3.zip'
C:\Documents and Settings\Administrator\桌面\
  3.zip
    [0] Archive type: ZIP
    --> mminstall.exe
    --> myself.exe
        [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 123.exe
        [INFO]      A backup was created as '471d1fcb.qua'  ( QUARANTINE )
        [INFO]      The file was deleted!
一个,不杀的上报。
微点卫士
发表于 2007-7-22 17:15:13 | 显示全部楼层
微点:
木马名称:Trojan.BAT.KillAV.o

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\IXP000.TMP\AVP.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX02.688\MMINSTALL.EXE
协议类型:TCP
本地地址:0.0.0.0
本地端口:2979
远端地址:58.211.7.35(江苏·苏州)
远端端口:80

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX04.610\MYSELF.EXE
木马程序生成以下文件:
1) D:\MYPLAYER.COM
2) C:\WINDOWS.0\SYSTEM32\ALXRES070721.EXE
3) C:\WINDOWS.0\SYSTEM32\INF\SCRSYS070721.SCR
是否删除木马程序及其衍生物?
木马名称:未知木马

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX06.125\MYSELF.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
mminstall是病毒么?
残缺的唯美
发表于 2007-7-22 17:26:25 | 显示全部楼层
晕  今天咖啡继续不报
欠妳緈諨
发表于 2007-7-22 17:55:50 | 显示全部楼层
2个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hj5abc
发表于 2007-7-22 20:17:46 | 显示全部楼层
avp.exe直接ws..

Scanned disks, folders and files: F:\3\
F:\3\b-mke.exe - a variant of Win32/TrojanDownloader.Delf.AXB trojan
F:\3\mminstall.exe - probably a variant of Win32/TrojanDownloader.QQHelper.NDF trojan
F:\3\myself.exe - probably a variant of Win32/Genetik trojan
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-12 06:05 , Processed in 0.143621 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表