查看: 3734|回复: 14
收起左侧

[病毒样本] 一堆

[复制链接]
xxwpk007
头像被屏蔽
发表于 2007-7-22 22:42:02 | 显示全部楼层 |阅读模式
一堆[MD5: C047DA 409B8F 65E2F6 19346D B8B256 EC6221 0788C3 AE6261 1E9220 120EA5 193C05 0919B7 3D8B43 CC9D1D 2E5CC4 4EE1D8 BD1CE5 29EF55 5F4B01]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-7-22 22:45:08 | 显示全部楼层
Scan performed at: 2007-7-22 22:44:24
Scanning Log
NOD32 version 2411 (20070721) NT
Command line: C:\Documents and Settings\EQ2\桌面\新建文件夹
Operating memory - is OK

Date: 22.7.2007  Time: 22:44:30
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\新建文件夹\
C:\Documents and Settings\EQ2\桌面\新建文件夹\ad_2216.exe ?NSIS ?Insshell.exe - Win32/Adware.Boran application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\新建文件夹\iExplorer.exe - Win32/Adware.Boran application - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionmf.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionrx.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionwl.dll - probably a variant of Win32/PSW.Delf.NDI trojan
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionwm.dll - probably a variant of Win32/PSW.Delf.NDI trojan
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionzx.dll - probably a variant of Win32/PSW.Delf.NDI trojan
C:\Documents and Settings\EQ2\桌面\新建文件夹\kulionzx.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\netdde32.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\winow.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\winwl.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\winwm.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\新建文件夹\wmsj.exe - probably unknown NewHeur_PE virus [7]
Number of scanned files: 20
Number of threats found: 13
Number of files cleaned: 13
Time of completion: 22:44:34 Total scanning time: 4 sec (00:00:04)

Notes:
[7] File is probably infected with an unknown virus.
promised
发表于 2007-7-22 22:46:09 | 显示全部楼层
C:\ABC\新建文件夹\iExplorer.exe - 特征码 'Trojan-PWS.Lineage' 被发现
C:\ABC\新建文件夹\klif.spi
C:\ABC\新建文件夹\kulionmf.dll - 特征码 'Trojan.Delf.NEB' 被发现
C:\ABC\新建文件夹\kulionmf.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\kulionrx.dll - 特征码 'Trojan-PWS.Win32.Nilage.bga' 被发现
C:\ABC\新建文件夹\kulionrx.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\kulionwl.dll - 特征码 'Trojan-PWS.Win32.Lmir.bjh' 被发现
C:\ABC\新建文件夹\kulionwm.dll - 特征码 'Generic.PWStealer' 被发现
C:\ABC\新建文件夹\kulionzx.dll - 特征码 'Trojan-PWS.Win32.Lmir.bjh' 被发现
C:\ABC\新建文件夹\kulionzx.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\netdde32.exe - 可疑代码段 被发现 (Level: 10)
C:\ABC\新建文件夹\video.dll - 特征码 'Generic.PWStealer' 被发现
C:\ABC\新建文件夹\winow.dll - 特征码 'Trojan-PWS.Win32.Delf.HG' 被发现
C:\ABC\新建文件夹\winow.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\winwl.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\winwm.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\wmsj.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\新建文件夹\ad_2216\[NSIS].nsi
C:\ABC\新建文件夹\ad_2216\$TEMP\Insshell.exe - 特征码 'Application.Win32.AdWare.Boran' 被发现
C:\ABC\新建文件夹\d03\[NSIS].nsi
C:\ABC\新建文件夹\d03\$COMMONFILES\CPUSH\cpush.tmp - 特征码 'not-a-virus:AdWare.Win32.BHO.av' 被发现

        21 个文件被扫描
          (0 个压缩档 0 个文件)
        17 个特征码被侦测
        1 个可疑代码段被发现
        耗时: 0:00.281
漏一个奇怪的SPI
The EQs
发表于 2007-7-22 22:47:12 | 显示全部楼层
发现nod32的病毒库相比其他厂商来说很小。。。。13个里面还报了7个未知。。。
微点卫士
发表于 2007-7-22 22:47:27 | 显示全部楼层
微点:
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX00.656\IEXPLORER.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\SYSTEM32\DRIVERS\IEXPLORER.EXE
2) C:\WINDOWS.0\SYSTEM32\AD_2216.EXE
3) C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\AIS_2216_0.EXE
是否删除木马程序及其衍生物?
木马名称:未知间谍软件

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX02.797\AD_2216.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:未知间谍软件

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX02.797\IEXPLORER.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:未知间谍软件

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX03.094\AD_2216.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
广告软件名称:AdWare.Win32.BHO.my

程序:
C:\PROGRAM FILES\COMMON FILES\CPUSH\CPUSH.DLL
是广告软件!
已成功阻止其运行,是否要删除此文件?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX02.797\D03.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\COMMON FILES\CPUSH\UNINST.EXE
是否删除木马程序及其衍生物?
木马名称:未知间谍软件

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX03.094\IEXPLORER.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX07.078\WINOW.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\WINOW.DLL
2) C:\WINDOWS.0\WINOW.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX09.640\WMSJ.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\VIDEO.DLL
2) C:\WINDOWS.0\WMSJ.EXE
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX11.609\NETDDE32.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\NETDDE32.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX13.687\KULIONZX.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\KULIONZX.DLL
2) C:\WINDOWS.0\KULIONZX.EXE
是否删除木马程序及其衍生物?

我发现微点可以杀广告了
moonsilver
发表于 2007-7-22 22:47:32 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Dropper.Win32.Agent.nux  
病毒: Trojan.PSW.Win32.YBOnline.m
病毒: Trojan.PSW.Win32.YBOnline.m
病毒: Trojan.PSW.Win32.WorldOnline.jk
病毒: Trojan.PSW.Win32.ZhuXian.w
病毒: Trojan.PSW.Win32.ZhuXian.w
病毒: Trojan.DL.Win32.AdLoad.ka
病毒: Trojan.PSW.Win32.WorldOnline.jj
病毒: Trojan.PSW.Win32.WoWar.sm
病毒: Trojan.PSW.Win32.WoWar.sm
病毒: Trojan.PSW.Win32.WLOnline.jhp
病毒: Trojan.PSW.Win32.WorldOnline.jk
病毒: Trojan.PSW.Win32.WorldOnline.jj

用户来源:互联网

软件版本:19.32.62



15个
微点卫士
发表于 2007-7-22 22:47:56 | 显示全部楼层
费尔也杀了很多

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-7-22 22:48:32 | 显示全部楼层
费尔杀了11个壳
moonsilver
发表于 2007-7-22 22:49:12 | 显示全部楼层
微点一个个运行,累不累啊?
scottxzt
发表于 2007-7-22 22:54:57 | 显示全部楼层
Begin scan in 'D:\Documents and Settings\dell\桌面\新建文件夹'
D:\Documents and Settings\dell\桌面\新建文件夹\d03.exe
      [DETECTION] Contains signature of the dropper DR/BHO.AV.407
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\iExplorer.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionmf.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionmf.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionrx.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionrx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.24525
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionwl.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionwm.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionzx.dll
      [DETECTION] Is the Trojan horse TR/Spy.Delf.UH.47
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\kulionzx.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\netdde32.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\video.dll
      [DETECTION] Is the Trojan horse TR/PSW.Steal.32768.1
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\winow.dll
      [DETECTION] Is the Trojan horse TR/PSW.WOW.RN
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\winow.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\winwl.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\winwm.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\wmsj.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [WARNING]   The file was ignored!


End of the scan: 2007年7月22日  22:53
Used time: 00:13 min

The scan has been done completely.

      1 Scanning directories
     19 Files were scanned
     17 viruses and/or unwanted programs were found
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-12 05:26 , Processed in 0.170087 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表