查看: 2640|回复: 11
收起左侧

[病毒样本] 多重感染??

[复制链接]
基哥
发表于 2007-10-25 17:42:21 | 显示全部楼层 |阅读模式
刚刚想找点XP主题时找到的..
http://www.down101.com/soft/Setup_611.exe
红心王子
发表于 2007-10-25 17:44:56 | 显示全部楼层
2007-10-25        17:43:39        1193305419        Administrator        1208        Sign of "Win32:Agent-BFG [Trj]" has been found in "D:\Downloads\Setup_611.exe" file.
浪滔天
发表于 2007-10-25 17:45:17 | 显示全部楼层
卡巴 125

已检测到: 广告程序 not-a-virus:AdWare.Win32.Boran.w        URL: http://www.down101.com/soft/Setup_611.exe//data0002//stream//data0001
dikex
发表于 2007-10-25 18:37:03 | 显示全部楼层
广告+小马

分离了几个出来

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
浪滔天
发表于 2007-10-25 19:09:06 | 显示全部楼层
原帖由 dikex 于 2007-10-25 18:37 发表
广告+小马

分离了几个出来


卡巴全干了

已删除: 广告程序 not-a-virus:AdWare.Win32.Agent.ap 文件: F:\病毒样本\TEMP.zip/InShell.exe
已删除: 广告程序 not-a-virus:AdWare.Win32.Boran.s 文件: F:\病毒样本\TEMP.zip/R0
已删除: 广告程序 not-a-virus:AdWare.Win32.Boran.w 文件: F:\病毒样本\TEMP.zip/insshell.exe
已删除: 广告程序 not-a-virus:AdWare.Win32.Boran.w 文件: F:\病毒样本\TEMP.zip/albus.dll//UPX
已删除: 木马程序 Trojan-Downloader.Win32.QQHelper.va 文件: F:\病毒样本\TEMP.zip/tongji.exe
残缺的唯美
发表于 2007-10-25 19:28:54 | 显示全部楼层
Malicious code found in file C:\Users\Administrator\AppData\Local\Temp\tongji.exe.
Infection: Trojan-Downloader.Win32.QQHelper.va
Action: The file was deleted.
  
扫描不报 运行报
残缺的唯美
发表于 2007-10-25 19:29:34 | 显示全部楼层
Result: 1 malware found
Trojan-Downloader.Win32.QQHelper.va (virus)
C:\Users\Administrator\Desktop\Setup_611.exe Action: deleted
然后扫描继续报=。=
uhthn2002
发表于 2007-10-25 21:34:28 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 692
Paranoia Database - 48194
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\Uhthn\Desktop\New Folder (2)

C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\tongji.exe - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\R0 - Infected ADWARE.BORAN.5 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\albus.dll - Infected TROJAN-DOWNLOADER.AGENT.19 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\InShell.exe - Suspected TROJAN-DOWNLOADER.AGENT.1
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\insshell.exe - Infected TROJAN-DOWNLOADER.AGENT.19 - Deleted

5 Files scanned
3 Infected files found
2 Suspected files found
0 Files cured
3 Files deleted
The EQs
发表于 2007-10-25 21:38:19 | 显示全部楼层

5个

C:\Documents and Settings\Don johnson\桌面\TEMP.zip » ZIP » tongji.exe - probably a variant of Win32/TrojanDownloader.QQHelper trojan
C:\Documents and Settings\Don johnson\桌面\TEMP.zip » ZIP » R0 - Win32/Adware.Boran application
C:\Documents and Settings\Don johnson\桌面\TEMP.zip » ZIP » albus.dll - Win32/Adware.Boran application
C:\Documents and Settings\Don johnson\桌面\TEMP.zip » ZIP » InShell.exe - probably a variant of Win32/Adware.Agent application
C:\Documents and Settings\Don johnson\桌面\TEMP.zip » ZIP » insshell.exe - Win32/Adware.Boran application
mofunzone
发表于 2007-10-25 22:48:13 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\TDDOWNLOAD\Setup_611.exe'
C:\TDDOWNLOAD\
  Setup_611.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.QQHelper.VA.35
      [INFO]      The file was deleted!

Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\TEMP.zip'
C:\Users\morgan\Documents\
  TEMP.zip
    [0] Archive type: ZIP
    --> tongji.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Harnig.5
        [WARNING]   Infected files in archives cannot be repaired!
    --> R0
        [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Boran.S
        [WARNING]   Infected files in archives cannot be repaired!
    --> albus.dll
        [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/BDSearch.A.3
        [WARNING]   Infected files in archives cannot be repaired!
    --> InShell.exe
        [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Boran.AC.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> insshell.exe
        [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Bor.X.19.C.4
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      The file was deleted!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 11:29 , Processed in 0.167546 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表