查看: 4115|回复: 11
收起左侧

[病毒样本] vip

[复制链接]
专家
发表于 2007-9-4 21:35:28 | 显示全部楼层 |阅读模式
Http://md55.net/soft7/vip.exe
1688388728
发表于 2007-9-4 21:37:50 | 显示全部楼层
Kaspersky Internet Security 7.0
The requested URL http://md55.net/soft7/vip.exe is infected with Trojan-PSW.Win32.Delf.zh virus
ck2009159
发表于 2007-9-4 21:39:12 | 显示全部楼层
瑞星挂
专家
 楼主| 发表于 2007-9-4 22:00:36 | 显示全部楼层
http://219.129.239.219/vip.exe
http://219.129.239.191/cs/01mh.exe
http://219.129.239.191/cs/02jh.exe
http://219.129.239.191/cs/03ms.exe
http://219.129.239.191/cs/04wl.exe
http://18dd.net/new/1.exe
http://18dd.net/new/2.exe
http://18dd.net/new/3.exe
http://219.129.239.191/cs/05gj.exe
http://219.129.239.191/cs/06qj.exe
http://18dd.net/new/4.exe
http://www.guochan.net.cn/Chajian_005.exe
http://219.129.239.191/cs/07zx.exe
http://18dd.net/new/5.exe
http://219.129.239.191/cs/08zt.exe
http://www.520018.com/qq/cao.exe
http://jjj.jfhwfhw.com/pi/l.exe
http://down.dj7788.cn/www.exe
http://18dd.net/new/6.exe
http://www.851733.cn/htm/vip.exe
yurius
发表于 2007-9-4 22:52:34 | 显示全部楼层
hxxp://www.851733.cn/htm/vip.exe        probably a variant of Win32/PSW.Delf.NHI trojan
hxxp://18dd.net/new/6.exe        a variant of Win32/PSW.OnLineGames.YA trojan
hxxp://down.dj7788.cn/www.exe        probably a variant of Win32/Genetik trojan
hxxp://219.129.239.191/cs/08zt.exe        probably a variant of Win32/PSW.OnLineGames.NEP trojan
hxxp://18dd.net/new/5.exe        probably a variant of Win32/Genetik trojan
hxxp://219.129.239.191/cs/07zx.exe        probably unknown NewHeur_PE virus
hxxp://18dd.net/new/4.exe        probably a variant of Win32/PSW.OnLineGames.YA trojan
hxxp://219.129.239.191/cs/06qj.exe        probably a variant of Win32/Genetik trojan
hxxp://219.129.239.191/cs/05gj.exe        probably unknown NewHeur_PE virus
hxxp://18dd.net/new/3.exe        a variant of Win32/PSW.OnLineGames.NEN trojan
hxxp://18dd.net/new/2.exe        probably a variant of Win32/Genetik trojan
hxxp://18dd.net/new/1.exe        a variant of Win32/PSW.Agent.NEC trojan
hxxp://219.129.239.191/cs/04wl.exe        probably unknown NewHeur_PE virus
hxxp://219.129.239.191/cs/03ms.exe        probably a variant of Win32/PSW.OnLineGames.NEP trojan
hxxp://219.129.239.191/cs/02jh.exe        a variant of Win32/PSW.OnLineGames.YA trojan
hxxp://219.129.239.191/cs/01mh.exe        a variant of Win32/PSW.OnLineGames.YA trojan
hxxp://md55.net/soft7/vip.exe        a variant of Win32/PSW.Delf.NIY trojan
saga3721
发表于 2007-9-4 23:13:43 | 显示全部楼层
木马名称:Trojan-PSW.Win32.Delf.exb

程序:
C:\DOCUMENTS AND SETTINGS\X\LOCAL SETTINGS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\IFIXSUOK\VIP[1].EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

Virus or unwanted program 'TR/PSW.Delf.ZH [TR/PSW.Delf.ZH]'
欠妳緈諨
发表于 2007-9-5 00:00:24 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
yczhou
发表于 2007-9-5 00:04:31 | 显示全部楼层
看我的NOD32启发式多酷,刚COPY这个网址,就尼达姆!


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
taihuxian
发表于 2007-9-5 09:46:31 | 显示全部楼层
BitDefender

This web page has been blocked by BitDefender Antivirus Real-time Protection!

The blocked web page included objects that were either infected or likely to be infected with a virus. Your system has NOT been infected.
saga3721
发表于 2007-9-5 09:50:01 | 显示全部楼层
连ZA7都知道那是“谍网惊魂”的干活,向上还不让上弹框阻止了,看来够有名
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-16 13:21 , Processed in 0.123895 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表