查看: 2591|回复: 14
收起左侧

[病毒样本] down[MD5: D8E1A2]

[复制链接]
xxwpk007
头像被屏蔽
发表于 2007-8-8 11:19:44 | 显示全部楼层 |阅读模式
RT

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
yurius
发表于 2007-8-8 11:38:03 | 显示全部楼层
C:\virus\down.rar »RAR »down.exe - a variant of Win32/Delf.CC worm
pine
发表于 2007-8-8 12:00:21 | 显示全部楼层
Begin scan in 'F:\down.rar'
F:\down.rar
  [0] Archive type: RAR
  --> down.exe
      [DETECTION] Contains signature of the worm WORM/Delf.CC.9
      [INFO]      The file was deleted!
flowerpig
发表于 2007-8-8 12:04:43 | 显示全部楼层
a-squared3.0.0.1232007.08.072007-08-07没有检测到病毒
3.518
Arcavir1.0.42007080717542007-08-07没有检测到病毒
1.186
AVAST1.0.8000764-12007-08-07Win32:Lineage-590 [Trj]
3.042
AVG7.5.48.442269.11.8/9412007-08-07没有检测到病毒
1.412
BitDefender7.60825.7540277.142462007-08-08Trojan.PWS.OnlineGames.ATU
2.730
CA (VET)8.4.0.2431.1.50422007-08-08没有检测到病毒
0.798
ClamAV 0.91.138912007-08-08没有检测到病毒
0.024
ewido4.0.0.22007.08.072007-08-07Worm.Delf.cc
2.246
F-SECURE5.51.61002007.08.07.032007-08-07没有检测到病毒
2.485
IKARUST3.1.1.122007.08.07.693182007-08-07Trojan.Win32.Small.mj
3.991
MKS_VIR2.012007.08.062007-08-06没有检测到病毒
2.161
NOD322.70.724422007-08-07a variant of Win32/Delf.CC worm
1.922
SOPHOS2.47.04.192007-08-08Troj/Hook-Gen
2.848
VBA323.12.2.220070807.04272007-08-07Worm.Win32.Delf.cc
1.118
VirusBuster4.3.19:99.095.2/11.02007-08-07Packed/NSPack
1.160
冰岛杀毒3.16.162007.08.032007-08-03W32/Threat-IKNP-based!Maximus
2.273
卡巴斯基5.5.102007.08.082007-08-08没有检测到病毒
0.056
大蜘蛛4.332007.08.082007-08-08Win32.HLLW.Autoruner
5.591
小红伞7.4.0.576.39.0.2192007-08-07WORM/Delf.CC.9
2.292
熊猫卫士9.00.002007.08.072007-08-07Suspicious file
3.938
瑞星19.019.35.20.002007-08-07Trojan.PSW.Delf.eze
1.909
诺曼5.90.375.902007-08-07没有检测到病毒
5.360
赛门铁克1.3.0.2420070807.0182007-08-07Infostealer.Gampass
0.441
趋势8.500-10014.637.002007-08-06没有检测到病毒
0.040
迈克菲5.1.0050922007-08-07New Malware.aq
0.706
金山毒霸2007.6.20.2492007.8.82007-08-08Worm.Delf.cc.127044
0.84
woai_jolin
发表于 2007-8-8 12:54:06 | 显示全部楼层
//-----------------------------------------------------------------
//
//        Product: BitDefender 8 Standard
//        Version: 8.0
//
//        Created on:        08/08/2007        12:53:40
//
//-----------------------------------------------------------------


Statistics

Scan path        : F:\v\down.rar
Folders        : 0
Files        :  10
Archives        : 1
Packed files        : 1
Identified viruses        : 1
Infected files        : 1
Warnings        : 0
Suspect files        : 0
Disinfected files        : 0
Deleted files        : 0
Copied files        : 0
Moved files        : 0
Renamed files        : 0
I/O errors        : 0
Scan time        : 00:00:01
Scan speed (files/sec)        : 10

Virus definitions        : 690131
Scan plugins        : 14
Archive plugins        : 38
Unpack plugins        : 6
Mail plugins        : 6
System plugins        : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[ ] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[X] Prompt user

Second action
[X] Ignore
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[X] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report

Summary:

F:\v\down.rar=>down.exe        Infected Trojan.PWS.OnlineGames.ATU

Scanned files

C:\=>Master Boot Record        OK
C:\=>Primary partition 1 (Active)        OK
C:\=>Logical partition 1        OK
C:\=>Logical partition 2        OK
C:\=>Logical partition 3        OK
C:\=>Logical partition 4        OK
C:\=>Logical partition 5        OK
F:\v\down.rar        OK
F:\v\down.rar=>down.exe        Infected Trojan.PWS.OnlineGames.ATU
F:\v\down.rar=>:Zone.Identifier        OK
king6808
发表于 2007-8-8 13:50:59 | 显示全部楼层
卡巴不报我去上报
19/32 (59.38%)
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2007.8.3.0 2007.08.08 -
AntiVir 7.4.0.57 2007.08.07 Worm/Delf.CC.9
Authentium 4.93.8 2007.08.07 Possibly a new variant of W32/Threat-IKNP-based!Maximus
Avast 4.7.1029.0 2007.08.07 Win32:Lineage-590
AVG 7.5.0.476 2007.08.07 -
BitDefender 7.2 2007.08.08 Trojan.PWS.OnlineGames.ATU
CAT-QuickHeal 9.00 2007.08.07 (Suspicious) - DNAScan
ClamAV 0.91 2007.08.08 -
DrWeb 4.33 2007.08.08 Win32.HLLW.Autoruner
eSafe 7.0.15.0 2007.07.31 suspicious Trojan/Worm
eTrust-Vet 31.1.5042 2007.08.08 -
Ewido 4.0 2007.08.07 Worm.Delf.cc
FileAdvisor 1 2007.08.08 -
Fortinet 2.91.0.0 2007.08.08 -
F-Prot 4.3.2.48 2007.08.07 W32/Threat-IKNP-based!Maximus
F-Secure 6.70.13030.0 2007.08.08 -
Ikarus T3.1.1.12 2007.08.08 Trojan.Win32.Small.mj
Kaspersky 4.0.2.24 2007.08.08 -
McAfee 5092 2007.08.07 New Malware.aq
Microsoft 1.2704 2007.08.08 -
NOD32v2 2442 2007.08.07 a variant of Win32/Delf.CC
Norman 5.80.02 2007.08.07 -
Panda 9.0.0.4 2007.08.07 Suspicious file
Prevx1 V2 2007.08.08 -
Rising 19.35.20.00 2007.08.08 Trojan.PSW.Delf.eze
Sophos 4.19.0 2007.08.01 Troj/Hook-Gen
Sunbelt 2.2.907.0 2007.08.07 VIPRE.Suspicious
Symantec 10 2007.08.08 Infostealer.Gampass
TheHacker 6.1.7.163 2007.08.07 -
VBA32 3.12.2.2 2007.08.07 Worm.Win32.Delf.cc
VirusBuster 4.3.26:9 2007.08.07 -
Webwasher-Gateway 6.0.1 2007.08.08 Worm.Delf.CC.9
微点卫士
发表于 2007-8-8 13:57:43 | 显示全部楼层
微点:
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\DOWN.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\46A7B4C1.DLL
2) C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\46A7B4C1.DAT
3) C:\WINDOWS.0\HELP\46A7B4C1.CHM
是否删除木马程序及其衍生物?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2007-8-8 13:59:42 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1688388728
发表于 2007-8-8 15:43:11 | 显示全部楼层
BitDefender

This web page has been blocked by BitDefender Antivirus Real-time Protection!

The blocked web page included objects that were either infected or likely to be infected with a virus. Your system has NOT been infected.
sharkkong
头像被屏蔽
发表于 2007-8-8 15:45:12 | 显示全部楼层
已检测到: 病毒 Worm.Win32.Delf.cc        URL: http://bbs.kafan.cn/attachment.p ... down.exe//NSPack//#
KIS阉割版
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 03:15 , Processed in 0.133685 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表