查看: 4813|回复: 37
收起左侧

[病毒样本] 来一包

[复制链接]
东方妖妖梦
发表于 2015-4-6 10:13:51 | 显示全部楼层 |阅读模式
欧阳宣
头像被屏蔽
发表于 2015-4-6 10:19:55 | 显示全部楼层
诺顿检测3个,有一个重复了
[mw_shl_code=css,true]Resolved Threats:
W32.Ramnit.B!inf
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
27 Registry Entries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->DoNotAllowExceptions:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->DoNotAllowExceptions:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->DisableNotifications:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->DisableNotifications:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->EnableFirewall:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile->EnableFirewall:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->EnableLUA:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->EnableLUA:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UacDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UacDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Userinit:C:\WINDOWS\system32\userinit.exe, - Repaired
1 File
e:\virus\huge\malware\malware\f12366b5b78e62b5ae2f487d21109da125e0dd29500e5a314813d7dc7040c248.bin - Deleted
1 Browser Cache



Trojan.Gen.SMH
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\malware\malware\1a38e7347f94959e278ae551bcc8495db18b56c8892c895c8a3c883864855888.bin - Deleted
1 Browser Cache



Backdoor.Graybird
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Restart Required
-----------
14 Registry Entries
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableRegistryTools:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\->Start:2 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NofolderOptions:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
5 Files
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\installed.dat - Restart Required
C:\WINDOWS\SysWOW64\Installed.dat - Restart Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\installed.dat - Restart Required
C:\WINDOWS\SysWOW64\Installed.dat - Restart Required
e:\virus\huge\malware\malware\d95e105f66f4ea6d95577e54d212ccd950368918cd51e5a3aff17d01c54e5e66.bin - Deleted
1 Browser Cache

1 System Action[/mw_shl_code]
驭龙
发表于 2015-4-6 10:20:08 | 显示全部楼层
本帖最后由 驭龙 于 2015-4-6 10:28 编辑

MA杀两个,其中一个样本报两个名字,修复一次后再杀,实际上还是杀两个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
开开心心卖手机
发表于 2015-4-6 10:20:09 | 显示全部楼层
蛋挞杀四个
东方妖妖梦
 楼主| 发表于 2015-4-6 10:21:45 | 显示全部楼层
欧阳宣 发表于 2015-4-6 10:19
诺顿检测3个,有一个重复了
[mw_shl_code=css,true]Resolved Threats:
W32.Ramnit.B!inf

我的失误没注意,看到重复的自己排除一下吧
xcvbaby
发表于 2015-4-6 10:26:25 | 显示全部楼层
本帖最后由 xcvbaby 于 2015-4-6 10:30 编辑

金山毒霸 and百度卫士都是4个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
学雷锋做人
头像被屏蔽
发表于 2015-4-6 10:26:31 | 显示全部楼层
本帖最后由 学雷锋做人 于 2015-4-6 11:13 编辑

360安全卫士(关伞):9个,看来还是360云强大啊

FD,MS+VT+LFQ:7个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
skyboybone
发表于 2015-4-6 10:26:36 | 显示全部楼层
金山云5伞2

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
驭龙
发表于 2015-4-6 10:26:54 | 显示全部楼层
东方妖妖梦 发表于 2015-4-6 10:21
我的失误没注意,看到重复的自己排除一下吧

十四个文件,我没发现相同大小的文件,应该没有重复
cxy密斯
发表于 2015-4-6 10:27:48 | 显示全部楼层
本帖最后由 cxy密斯 于 2015-4-6 10:29 编辑

kes占个检测7个,剩余7个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 22:17 , Processed in 0.131332 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表