查看: 3798|回复: 26
收起左侧

[病毒样本] 内蒙古自治区环境保护局被挂大量木马

[复制链接]
绅博周幸
发表于 2007-9-15 15:00:53 | 显示全部楼层 |阅读模式
http://www.nmhbj.com/


RT, 红伞进去点到手酸, 提取了部分样本( 还没提完IE就崩溃了), 不怕死的就进去吧, 估计一般杀软很难挡住全部的.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jimmyleo
发表于 2007-9-15 15:01:25 | 显示全部楼层
这个网址 貌似很熟悉~
绅博周幸
 楼主| 发表于 2007-9-15 15:03:06 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\Documents and Settings\fuming1\My Documents\My Documents.rar'
E:\Documents and Settings\fuming1\My Documents\My Documents.rar
  [0] Archive type: RAR
  --> new82[1].htm
      [DETECTION] Contains suspicious code HEUR/Exploit.HTML
  --> 74[1].htm
      [DETECTION] Contains detection pattern of the Java script virus JS/Dldr.Agent.NV
  --> 9038[1].htm
      [DETECTION] Contains suspicious code HEUR/Exploit.HTML
  --> dd.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> dd[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> du[1].htm
      [DETECTION] Contains detection pattern of the Java script virus JS/Dldr.Small.BD
  --> 06014.htm
      [DETECTION] Contains detection pattern of the VBS script virus VBS/Psyme.CZ
      [INFO]      The file was deleted!


End of the scan: 2007年9月14日  23:46
Used time: 00:08 min

The scan has been done completely.

      0 Scanning directories
      8 Files were scanned
      5 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
风野胤
发表于 2007-9-15 15:03:57 | 显示全部楼层
依然毫无感觉地进出
大家换opera吧。。。。。
siman.yu
发表于 2007-9-15 15:04:12 | 显示全部楼层
去转了一圈,没事啊!!莫非给周总全抓啦?!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2007-9-15 15:07:21 | 显示全部楼层
detected: Trojan program Trojan-Downloader.JS.Agent.nv        File: C:\Documents and Settings\Owner\×ÀÃæ\My Documents.rar/74[1].htm
detected: Trojan program Trojan-Downloader.Win32.Baser.o        File: C:\Documents and Settings\Owner\×ÀÃæ\My Documents.rar/dd.exe
detected: Trojan program Trojan-Downloader.Win32.Baser.o        File: C:\Documents and Settings\Owner\×ÀÃæ\My Documents.rar/dd[1].exe
残缺的唯美
发表于 2007-9-15 15:17:13 | 显示全部楼层
Scan performed at: 2007-9-15 15:16:28
Scanning Log
NOD32 version 2531 (20070915) NT
Command line: D:\Documents and Settings\EKINCHENG\桌面\My Documents.rar

Date: 15.9.2007  Time: 15:16:31
Anti-Stealth technology is enabled.
Scanned disks, folders and files: D:\Documents and Settings\EKINCHENG\桌面\My Documents.rar
D:\Documents and Settings\EKINCHENG\桌面\My Documents.rar ?RAR ?dd.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\My Documents.rar ?RAR ?dd[1].exe - probably a variant of Win32/Genetik trojan
Number of scanned files: 8
Number of threats found: 2
Number of files cleaned: 1
Time of completion: 15:16:31 Total scanning time: 0 sec (00:00:00)
ashe_vaan
发表于 2007-9-15 15:56:47 | 显示全部楼层
卡6进去叫了2次
红心王子
发表于 2007-9-15 16:09:36 | 显示全部楼层
2007-9-15        16:08:19        1189843699        Administrator        3264        Sign of "Win32:Delf-FVX [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\My_Documents.rar\dd.exe" file.  
2007-9-15        16:08:24        1189843704        Administrator        3264        Sign of "Win32:Delf-FVX [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\My_Documents.rar\dd[1].exe" file.
wcaonima007
发表于 2007-9-15 16:14:16 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-4 07:42 , Processed in 0.134776 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表