查看: 3150|回复: 14
收起左侧

[病毒样本] Q上看到的网页挂的一堆

[复制链接]
dikex
发表于 2007-11-5 17:41:34 | 显示全部楼层 |阅读模式
Q上看到的网页:http://www.loveyou250.cn


在最下面挂了一堆,还有就是它们下载的,这些是被卡巴(2007-11-05 10:38:17)砍剩的

密码:virus

[ 本帖最后由 dikex 于 2007-12-28 00:23 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hahacomcn
发表于 2007-11-5 17:48:25 | 显示全部楼层
红伞报了7个,剩下了00027.exe等几个没报。

上报看看。

LZ不要加密哦~!
nosferatu
头像被屏蔽
发表于 2007-11-5 17:50:17 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\TEMP'
C:\Documents and Settings\Administrator\桌面\TEMP\DownSetup.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TEMP\NewTemp.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '47a5e793.qua'!
C:\Documents and Settings\Administrator\桌面\TEMP\NewTemp.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TEMP\soft210.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TEMP\tg.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TEMP\WinD.tmp.exe.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [INFO]      The file was deleted!


End of the scan: 星期一 2007年11月5日  17:49
Used time: 00:05 min

The scan has been done completely.

      1 Scanning directories
     11 Files were scanned
      5 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
dikex
 楼主| 发表于 2007-11-5 17:52:11 | 显示全部楼层
原帖由 hahacomcn 于 2007-11-5 17:48 发表
红伞报了7个,剩下了00027.exe等几个没报。

上报看看。

LZ不要加密哦~!



有的论坛要密码;

一起发上去,所以就加了
tonguewiz
发表于 2007-11-5 17:54:40 | 显示全部楼层
ENA六只
C:\Documents and Settings\David\Desktop\TEMP\00027.exe - a variant of Win32/TrojanDropper.Small.NGH trojan
C:\Documents and Settings\David\Desktop\TEMP\NewTemp.dll - probably a variant of Win32/PSW.OnLineGames.NBR trojan
C:\Documents and Settings\David\Desktop\TEMP\NewTemp.exe - probably a variant of Win32/PSW.Delf.NHI trojan
C:\Documents and Settings\David\Desktop\TEMP\rxjh.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\David\Desktop\TEMP\tg.exe - a variant of Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\David\Desktop\TEMP\WinD.tmp.exe.exe - probably a variant of Win32/TrojanDownloader.Delf.NSA trojan
caocao
发表于 2007-11-5 18:19:35 | 显示全部楼层
KIS7
已清除:木马程序 Trojan.Win32.Agent.cne        文件: D:\Downloads\TEMP.rar/00027.exe//#/Setup.exe
已隔离:病毒 Heur.Trojan.Generic (修改)        文件: D:\Downloads\TEMP.rar/tg.exe
已隔离:病毒 Heur.Trojan.Generic (修改)        文件: D:\Downloads\TEMP.rar/WinD.tmp.exe.exe//PE_Patch.UPX
wangfeng66
发表于 2007-11-5 19:05:50 | 显示全部楼层
C:\\NewTemp.dll - probably infected with DLOADER.Trojan
C:\\NewTemp.exe - infected with Win32.HLLW.Autoruner.origin
C:\\soft210.exe - infected with Trojan.DownLoader.origin
C:\\WinD.tmp.exe.exe - infected with Win32.HLLW.Autoruner.origin

drweb 4.44
haol
发表于 2007-11-5 19:11:10 | 显示全部楼层
trend found 2 threats(possible_infostl)
曲中求
发表于 2007-11-5 19:14:42 | 显示全部楼层
opera没得反应,非得要用IE内核的才行

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangjay1980
发表于 2007-11-5 21:53:56 | 显示全部楼层
detected: Trojan program Trojan.Win32.Agent.cnl        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/00027.exe
detected: Trojan program Trojan-Downloader.Win32.Delf.cul        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/DownSetup.exe//ASPack
detected: virus Worm.Win32.AutoRun.bd        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/NewTemp.dll//UPX//PEPatch
detected: virus Worm.Win32.AutoRun.be        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/NewTemp.exe//UPX//PEPatch
detected: Trojan program Trojan.Win32.StartPage.atq        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/rxjh.exe
detected: Trojan program Trojan-Downloader.Win32.Delf.cun        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/soft210.exe
detected: Trojan program Trojan-Downloader.Win32.Flux.ah        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/tg.exe
detected: Trojan program Trojan-Downloader.Win32.Agent.eux        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/WinD.tmp.exe.exe
detected: Trojan program Backdoor.Win32.Agent.cmg        File: C:\Documents and Settings\Owner\×ÀÃæ\TEMP.rar/zt.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-16 23:30 , Processed in 0.120215 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表