查看: 2014|回复: 5
收起左侧

[病毒样本] 金山发威[fb86f5]

[复制链接]
promised
发表于 2007-10-21 13:11:23 | 显示全部楼层 |阅读模式
a-squared3.0.0.1262007.10.192007-10-19-
10.441
AntiVir7.6.0.277.0.0.1122007-10-20-
2.551
Arcavir1.0.42007102018282007-10-20-
1.458
AVAST1.0.8000782-42007-10-20-
3.049
AVG7.5.49.442269.15.3/10822007-10-20-
1.789
BitDefender7.60825.9334377.153962007-10-21Dropped:Trojan.Agent.AFNF
4.355
CA (VET)8.4.0.2431.2.52252007-10-20-
1.354
ClamAV 0.91.245462007-10-20-
0.769
Comodo2.112.0.0.3192007-10-20-
1.507
Dr.WEB4.332007.10.202007-10-20-
9.500
ewido4.0.0.22007.10.202007-10-20-
4.582
F-PROT4.4.0.50200710182007-10-18-
4.284
F-SECURE5.51.61002007.10.19.072007-10-19Trojan-Downloader.Win32.Agent.ehg [AVP]
5.299
IKARUST3.1.1.122007.10.20.696942007-10-20Trojan.Win32.Inject.bn
1.440
MKS_VIR2.012007.10.202007-10-20-
2.798
NOD322.70.1026042007-10-19-
0.187
NORMAN5.91.085.902007-10-19-
29.538
nProtect2007-10-19.009833652007-10-19Dropped:Trojan.Agent.AFNF
32.414
PrevxV2200710212007-10-21-
10.414
QuickHeal9.002007.10.202007-10-20-
4.232
SOPHOS2.49.14.212007-10-21-
3.706
The Hacker6.2.9v001012007-10-20-
1.645
VBA323.12.2.420071019.19392007-10-19-
0.810
ViRobot200710192007.10.192007-10-19-
0.474
VirusBuster4.3.19:99.112.1/11.02007-10-20-
4.027
卡巴斯基5.5.102007.10.212007-10-21Trojan-Downloader.Win32.Agent.ehg
6.212
安博士V32007.10.20.002007.10.202007-10-20-
1.009
江民杀毒10.00.6502007.10.202007-10-20-
1.947
熊猫卫士9.04.03.00012007.10.202007-10-20-
0.452
瑞星19.019.45.60.002007-10-20-
1.604
赛门铁克1.3.0.2420071020.0062007-10-20-
14.160
趋势8.500-10014.786.182007-10-20-
0.046
迈克菲5.2.0051452007-10-19-
1.027
金山毒霸2007.6.20.2492007.10.202007-10-20Win32.Troj.Downloader.dn.53248
1.212
飞塔2.81-3.118.2512007-10-18-
1.239

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
微点卫士
发表于 2007-10-21 13:12:52 | 显示全部楼层
木马名称:Trojan-Downloader.Win32.Adload.ajh

程序:
C:\PROGRAM FILES\WINABLE\WINABLE.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\B122.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\TEMPORARY\WININSTALL.EXE
2) C:\PROGRAM FILES\WINABLE\WINABLE.EXE
是否删除木马程序及其衍生物?
The EQs
发表于 2007-10-21 13:27:07 | 显示全部楼层
新建文件:C:\Program Files\Temporary\wininstall.exe.lzma
C:\Program Files\Temporary\wininstall.exe
C:\Program Files\WinAble\winable.exe.lzma
C:\Program Files\WinAble\winable.exe
删除文件:C:\Program Files\Temporary\wininstall.exe.lzma
C:\Program Files\WinAble\winable.exe.lzma
修改注册表:HKEY_CURRENT_USER\Software\WinAble "remove" = ok
HKEY_CURRENT_USER\Software\Classes\CLSID\{F0060354-067B-1033-0720-041028030001} "b122" = yes
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WinAble" = C:\Program Files\WinAble\winable.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAble "DisplayName" = WinAble
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAble "UninstallString" = "C:\Program Files\WinAble\winable.exe" -uninstall
HKEY_CURRENT_USER\Software\Classes\CLSID\{20060354-067B-1033-0720-041028030001} "Param3" = MTA=
HKEY_CURRENT_USER\Software\Classes\CLSID\{20060354-067B-1033-0720-041028030001} "Param4" = MzAw
HKEY_CURRENT_USER\Software\Classes\CLSID\{20060354-067B-1033-0720-041028030001} "Param2" = MA==
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow "*.starsdoor.com" = [REG_BINARY, size: 0 bytes]
HKEY_CURRENT_USER\Software\Classes\CLSID\{20060354-067B-1033-0720-041028030001} "Param1" = MTI4Mzc0MjcyMDAwMDAwMDAw



不是下载者吧,没看到下东西
uhthn2002
发表于 2007-10-21 15:40:01 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 656
Paranoia Database - 48035
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\uhthn\Desktop\b122.exe

C:\Documents and Settings\uhthn\Desktop\b122.exe - Suspected Trojan-Downloader.Agent.2

1 Files scanned
0 Infected files found
1 Suspected files found
0 Files cured
0 Files deleted
398566384
头像被屏蔽
发表于 2007-10-21 18:00:16 | 显示全部楼层
瑞星pass
Nerazzurri
发表于 2007-10-21 18:03:09 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-1 23:12 , Processed in 0.111314 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表