楼主: promised
收起左侧

[病毒样本] [MD5: 4A8B67 6D521F 0959C6 9C6E25 3AAF9F D7C27D 8EAAE8 D63592 90D80D]

[复制链接]
镭风
发表于 2007-8-16 12:26:49 | 显示全部楼层
费尔叫的稀烂啊

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2007-8-16 12:57:28 | 显示全部楼层
BitDefender Log File
Product : Bitdefender Internet Security
Version : BitDefender UIScanner v.11
Log date : 12:57:09 16/08/2007
Log path : C:\Documents and Settings\Administrator\Application Data\BitDefender\Desktop\Profiles\Logs\contextual\1187240229_9_02.xml

Scan Paths: Path0000: F:\v\v1\样本5.rar


Scan Options: Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : No


Target selection options: Scan registry keys : No
Scan cookies : No
Scan boot sectors : No
Scan memory processes : No
Scan archives : Yes
Scan runtime packers : Yes
Scan email : Yes
Scan all files : No
Heuristic Scan : Yes
Scanned extenstions : (null)
Exclude extensions :  


Target Processing Default action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None


Scan engines summary Number of virus signatures : 754472
Archive plugins : 40
Email plugins : 6
Scan plugins : 12
Archive plugins : 40
System plugins : 4
Unpack plugins : 6


Overall scan summary Scanned items : 20
Infected items : 12
Suspicious items : 0
Resolved items : 0
Individual viruses found : 12
Scanned directories : 0
Scanned boot sectors : 0
Scanned archives : 2
Input-output errors : 0
Scan time : 00:00:00:06
Files per second : 3


Scanned files summary Scanned : 20
Infected : 12


Scanned processes summary Scanned : 0
Infected : 0


Scanned registry keys summary Scanned : 0
Infected : 0


Scanned cookies summary Scanned : 0
Infected : 0


Remaining issues:Object Name Threat Name  Final Status


Resolved issues:Object Name Threat Name  Final Status
F:\v\v1\样本5.rar BehavesLike:Win32.ExplorerHijack Deleted
F:\v\v1\样本5.rar DeepScan:Generic.Malware.SBdldspg.98006DC0 Deleted
F:\v\v1\样本5.rar Dialer.Gbdialer.I Deleted
F:\v\v1\样本5.rar Dropped:Generic.Malware.PWS.99809822 Deleted
F:\v\v1\样本5.rar GenPack:Generic.Popwin.67B27D8E Deleted
F:\v\v1\样本5.rar GenPack:Generic.Popwin.AC61DAB6 Deleted
欠妳緈諨
发表于 2007-8-16 13:00:15 | 显示全部楼层
7只

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2007-8-16 14:17:33 | 显示全部楼层
===================================================================================================
NVCOD On Demand Scanner 5.80.02

NSE revision 5.91.04
nvcbin.def revision 5.90.00 of 2007/08/15 19:07:26 (829574 variants)
nvcmacro.def revision 5.90.00 of 2007/08/06 19:46:49 (20358 variants)
Total number of variants: 849932
Command line: "@C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~OD9E.tmp"
===================================================================================================

       Time  Filename                                                     Virus name
---------------------------------------------------------------------------------------------------
- Scanning files matching: F:\v\v1\husjdd8s.exe
       15 ms F:\v\v1\husjdd8s.exe                                         Trojan Hupigon.gen66 ()
        0 ms F:\v\v1\husjdd8s.exe:Zone.Identifier                        
- Scanning files matching: F:\v\v1\kernelwind32.exe
       15 ms F:\v\v1\kernelwind32.exe                                     Trojan Tibs.gen122 ()
        0 ms F:\v\v1\kernelwind32.exe:Zone.Identifier                    
- Scanning files matching: F:\v\v1\max1d1164v.exe
       16 ms F:\v\v1\max1d1164v.exe                                       Trojan W32/Dialer.gen7 ()
        0 ms F:\v\v1\max1d1164v.exe:Zone.Identifier                     
- Scanning files matching: F:\v\v1\netdde32.exe
       16 ms F:\v\v1\netdde32.exe                                         Trojan W32/Malware.AETG ()
        0 ms F:\v\v1\netdde32.exe:Zone.Identifier                        
- Scanning files matching: F:\v\v1\RAV00A0.exe
        0 ms F:\v\v1\RAV00A0.exe                                          Security Risk W32/Suspicious_U.gen ()
       15 ms F:\v\v1\RAV00A0.exe:Zone.Identifier                        
- Scanning files matching: F:\v\v1\RAVZXMON.exe
        0 ms F:\v\v1\RAVZXMON.exe                                         Security Risk W32/Suspicious_U.gen ()
        0 ms F:\v\v1\RAVZXMON.exe:Zone.Identifier                        
- Scanning files matching: F:\v\v1\Server.exe
     15360 ms F:\v\v1\Server.exe                                          
        0 ms F:\v\v1\Server.exe:Zone.Identifier                          
- Scanning files matching: F:\v\v1\A65461A2.EXE
       15 ms F:\v\v1\A65461A2.EXE                                         Trojan Hupigon.gen66 ()
        0 ms F:\v\v1\A65461A2.EXE:Zone.Identifier                        
- Scanning files matching: F:\v\v1\EE99C835.EXE
        0 ms F:\v\v1\EE99C835.EXE                                         Trojan Hupigon.gen66 ()
        0 ms F:\v\v1\EE99C835.EXE:Zone.Identifier                        
- File F:\v\v1\husjdd8s.exe quarantined.
- File F:\v\v1\husjdd8s.exe deleted.
- File F:\v\v1\kernelwind32.exe quarantined.
- File F:\v\v1\kernelwind32.exe deleted.
- File F:\v\v1\max1d1164v.exe quarantined.
- File F:\v\v1\max1d1164v.exe deleted.
- File F:\v\v1\netdde32.exe quarantined.
- File F:\v\v1\netdde32.exe deleted.
- File F:\v\v1\RAV00A0.exe quarantined.
- File F:\v\v1\RAV00A0.exe deleted.
- File F:\v\v1\RAVZXMON.exe quarantined.
- File F:\v\v1\RAVZXMON.exe deleted.
- File F:\v\v1\A65461A2.EXE quarantined.
- File F:\v\v1\A65461A2.EXE deleted.
- File F:\v\v1\EE99C835.EXE quarantined.
- File F:\v\v1\EE99C835.EXE deleted.

===================================================================================================

The scanning started: 2007/08/16 14:17:01
               ended: 2007/08/16 14:17:16
Logged on as        : Administrator
on hostname         : 2FF87FC2B9AB46F

Scanning results:
   Total number of files found..............................:      18
   Number of files scanned..................................:      18
   Number of files/directories skipped due to exclude list..:       0
   Number of files that could not be opened.................:       0
   Number of archive files unpacked.........................:       0
   Number of archive files not unpacked.....................:       0
   Number of infections.....................................:       8

Copyright (c) 1993-2005 Norman ASA.
don_19
发表于 2007-8-16 15:10:58 | 显示全部楼层
2007-8-16 15:08:20 don 212 Sign of "Win32:Agent-IPV [Trj]" has been found in "E:\样本5.rar\husjdd8s.exe\[NsPack]\[Embedded#04010]\[Embedded#06000]\[NsPack]" file.  
2007-8-16 15:08:25 don 212 Sign of "Win32:Tibs-BED [Trj]" has been found in "E:\样本5.rar\kernelwind32.exe" file.  
2007-8-16 15:08:27 don 212 Sign of "Win32:Dialer-407 [Trj]" has been found in "E:\样本5.rar\max1d1164v.exe" file.  
2007-8-16 15:08:28 don 212 Sign of "Win32:Onlinegames-ATD [Trj]" has been found in "E:\样本5.rar\RAV00A0.exe\[Upack]\[Embedded#5060]\[Upack]" file.  
2007-8-16 15:08:29 don 212 Sign of "Win32:Small-GND [Trj]" has been found in "E:\样本5.rar\Server.exe" file.  
2007-8-16 15:08:30 don 212 Sign of "Win32:Agent-JOF [Trj]" has been found in "E:\样本5.rar\A65461A2.EXE\[NsPack]\[Embedded#04010]" file.  
2007-8-16 15:08:31 don 212 Sign of "Win32:Agent-JOF [Trj]" has been found in "E:\样本5.rar\EE99C835.EXE\[NsPack]\[Embedded#04010]" file.
yurius
发表于 2007-8-16 15:45:36 | 显示全部楼层
C:\virus\样本5\husjdd8s.exe - infected with Trojan.Popwin.629
C:\virus\样本5\kernelwind32.exe - infected with Trojan.Packed.142
C:\virus\样本5\max1d1164v.exe - infected with Dialer.Maxd
C:\virus\样本5\netdde32.exe - probably infected with DLOADER.Trojan
C:\virus\样本5\RAV00A0.exe - infected with Trojan.PWS.Wsgame
C:\virus\样本5\RAVZXMON.exe - infected with Trojan.MulDrop.8236
C:\virus\样本5\Server.exe - infected with DDoS.Bonke
C:\virus\样本5\EE99C835.EXE - infected with Trojan.Popwin
taihuxian
发表于 2007-8-16 16:06:19 | 显示全部楼层
Result: 5 malware found
Email-Worm.Win32.Zhelatin.gv (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾5.rar\kernelwind32.exe
Porn-Dialer.Win32.GBDialer.i (pornware)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾5.rar\max1d1164v.exe
Trojan-Downloader.Win32.QQHelper.vn (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾5.rar\netdde32.exe
Trojan-Downloader.Win32.Agent.bxg (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾5.rar\RAV00A0.exe
Trojan-PSW.Win32.OnLineGames.aci (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾5.rar\RAVZXMON.exe
taihuxian
发表于 2007-8-16 16:07:22 | 显示全部楼层
Scan performed at: 2007-8-16 16:06:51
Scanning Log
NOD32 version 2465 (20070816) NT
Command line: C:\Documents and Settings\Administrator\桌面\样本5.rar
Operating memory - is OK

Date: 16.8.2007  Time: 16:06:53
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\Administrator\桌面\样本5.rar
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?husjdd8s.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?kernelwind32.exe - Win32/Nuwar.Gen worm
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?max1d1164v.exe - Win32/Dialer.NAD trojan - was a part of the deleted object
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?netdde32.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?RAV00A0.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?RAVZXMON.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?Server.exe - a variant of Win32/Agent.NEJ trojan
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?A65461A2.EXE - probably a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\Administrator\桌面\样本5.rar ?RAR ?EE99C835.EXE - probably a variant of Win32/Agent.NEO trojan
Number of scanned files: 10
Number of threats found: 9
Number of files cleaned: 1
Time of completion: 16:06:57 Total scanning time: 4 sec (00:00:04)

Notes:
[7] File is probably infected with an unknown virus.
uhthn2002
发表于 2007-8-16 16:24:57 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
我爱舒畅
发表于 2007-8-16 16:28:47 | 显示全部楼层
瑞星2008

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 20:39 , Processed in 0.100588 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表