查看: 3085|回复: 10
收起左侧

[病毒样本] WINDOWS.rar [md5:d953fb3]

[复制链接]
mofunzone
发表于 2008-1-25 15:52:53 | 显示全部楼层 |阅读模式
File: WINDOWS.rar
Status: INFECTED/MALWARE
MD5: d953fb3edd0d71c3b30151755406276a
Packers detected: -
Bit9 reports: File not found
Scanner results
Scan taken on 25 Jan 2008 07:51:01 (GMT)
A-Squared Found nothing
AntiVir Found TR/Crypt.ULPM.Gen
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found Downloader.Tibs
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found Trojan.DownLoader.origin
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Trojan-Downloader:W32/Agent.FUL, Trojan-Downloader.Win32.Agent.hvx
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Agent.hvx
NOD32 Found a variant of Win32/TrojanDownloader.Agent.BLS
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found Troj/Agent-GNJ
VirusBuster Found nothing
VBA32 Found nothing

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zwl2828
发表于 2008-1-25 15:53:50 | 显示全部楼层

Avira AntiVir

C:\Users\Wesley\Downloads\WINDOWS.rar
  [0] Archive type: RAR
  --> mrofinu1000106.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
28654621
头像被屏蔽
发表于 2008-1-25 15:58:45 | 显示全部楼层
D:\download\WINDOWS.rar>>mrofinu1000106.exe        TrojanDownloader.Agent.hvx.aqqh        木马        还未处理
Nblock
发表于 2008-1-25 17:01:16 | 显示全部楼层
微点发现未知邮件蠕虫

HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\        RUNNER1                C:\WINDOWS\MROFINU.EXE         E:\MROFINU1000106.EXE
协议类型:TCP
本地地址:0.0.0.0
本地端口:3207
远端地址:194.90.224.86(以色列)
远端端口:80

[ 本帖最后由 Nblock 于 2008-1-25 17:02 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
醉一生爱妍
发表于 2008-1-25 17:54:05 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\WINDOWS.rar >>RAR >>mrofinu1000106.exe - Win32/TrojanDownloader.Agent.BLS 木马的变种
ballakay
发表于 2008-1-25 18:03:59 | 显示全部楼层
Scanning Report
25 January 2008 18:03:49 - 18:03:49
Computer name: PUMA-PC
Scanning type: Scan target
Target: C:\Users\Administrator\Desktop\WINDOWS.rar


--------------------------------------------------------------------------------

Result: 1 malware found
Trojan-Downloader.Win32.Agent.hvx (virus)
C:\Users\Administrator\Desktop\WINDOWS.rar\mrofinu1000106.exe




--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 2
Not scanned: 0
Result:
Viruses: 1
Spyware: 0
Suspicious items: 0
Riskware: 0
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0


--------------------------------------------------------------------------------

Options
Definitions version:
Viruses: 2008-01-25_02
Spyware: 2008-01-25_02
Scanning Engines:
F-Secure AVP: 7.00.171, 2008-01-25
F-Secure Libra: 2.04.01, 2008-01-24
F-Secure Orion: 1.02.37, 2008-01-25
F-Secure Draco: 1.00.35, 2008-01-14
Scanning options:
Scan all files
Scan inside archives
Actions:
Viruses: Delete infected files
Spyware: Delete infected files
qigang
发表于 2008-1-25 21:10:51 | 显示全部楼层
Rising20.28.42未杀!
PC0amera
头像被屏蔽
发表于 2008-1-25 21:23:19 | 显示全部楼层
微点和红伞表现确实不错...
悠柚
发表于 2008-1-25 21:25:16 | 显示全部楼层
BD Miss
492052134
发表于 2008-1-25 21:34:37 | 显示全部楼层
检测到:木马程序 Trojan.Win32.Agent.dsj        URL: http://bbs.kafan.cn/attachment.php?aid=190221//1.exe//ASPack
检测到:木马程序 Backdoor.Win32.Hupigon.aqde        URL: http://bbs.kafan.cn/attachment.php?aid=190281//新建文件夹/TASKMAN32.EXE
检测到:木马程序 Trojan-PSW.Win32.OnLineGames.isb        URL: http://bbs.kafan.cn/attachment.php?aid=190209//0.79048.exe
检测到:木马程序 Trojan-Downloader.JS.Agent.apx        URL: http://3.kv8.info/index.htm
检测到:木马程序 Trojan-Downloader.Win32.Agent.hvx        URL: http://bbs.kafan.cn/attachment.php?aid=190131//mrofinu1000106.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 16:31 , Processed in 0.138413 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表