查看: 2470|回复: 13
收起左侧

[病毒样本] 老病毒与广告各一

[复制链接]
千里同风
发表于 2008-1-25 17:30:43 | 显示全部楼层 |阅读模式
广告是蕃花集成在XP内的,最近微点指出就摁了,另一个是老毒物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zwl2828
发表于 2008-1-25 17:36:28 | 显示全部楼层

Avira AntiVir

C:\Users\Wesley\Downloads\HOTUNIST.rar
  [0] Archive type: RAR
  --> HOTUNIST.EXE
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Bho.CA.4
  --> RavMon.exe
      [DETECTION] Is the Trojan horse TR/Agent.Abt.3
llgiggs
头像被屏蔽
发表于 2008-1-25 17:37:52 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\HOTUNIST.rar'
C:\Documents and Settings\Administrator\桌面\HOTUNIST.rar
  [0] Archive type: RAR
  --> RavMon.exe
      [DETECTION] Is the Trojan horse TR/Agent.Abt.3
      [INFO]      A backup was created as '47edae3e.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!


為何比樓上少殺一個

[ 本帖最后由 llgiggs 于 2008-1-25 17:39 编辑 ]
醉一生爱妍
发表于 2008-1-25 17:38:36 | 显示全部楼层
nod all kill

.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hj5abc
发表于 2008-1-25 17:44:42 | 显示全部楼层

回复 3楼 llgiggs 的帖子

他的是P版.

avast 比全部更多 ..

Sign of "Win32:Agent-HHM [Trj]" has been found in "F:\HOTUNIST.rar\RavMon.exe" file.

Sign of "Win32:Trojan-gen {Other}" has been found in "F:\HOTUNIST.rar\HOTUNIST.EXE" file.
Sign of "Win32:Adware-gen [Adw]" has been found in "F:\HOTUNIST.rar\HOTUNIST.EXE\[Embedded#44f5c]\[NsPack]" file.  
Sign of "Win32:Adware-gen [Adw]" has been found in "F:\HOTUNIST.rar\HOTUNIST.EXE\[Embedded#5195c]\[NsPack]" file.  
Sign of "Win32:Agent-MYN [Adw]" has been found in "F:\HOTUNIST.rar\HOTUNIST.EXE\[Embedded#6994c]\[NsPack]" file.

[ 本帖最后由 hj5abc 于 2008-1-25 17:50 编辑 ]
woai_jolin
发表于 2008-1-25 17:48:46 | 显示全部楼层
Scan Log
Version of virus signature database: 2821 (20080124)
Date: 2008-1-25  Time: 17:48:46
Scanned disks, folders and files: G:\v\HOTUNIST.rar
G:\v\HOTUNIST.rar » RAR » HOTUNIST.EXE - probably a variant of Win32/Adware.BHO application - was a part of the deleted object
G:\v\HOTUNIST.rar » RAR » RavMon.exe - Win32/Agent.NAV worm - was a part of the deleted object
Number of scanned objects: 3
Number of threats found: 2
Time of completion: 17:48:49  Total scanning time: 3 sec (00:00:03)
ballakay
发表于 2008-1-25 17:54:30 | 显示全部楼层
Scanning Report
25 January 2008 17:54:15 - 17:54:17
Computer name: PUMA-PC
Scanning type: Scan target
Target: C:\Users\Administrator\Desktop\HOTUNIST.rar


--------------------------------------------------------------------------------

Result: 2 malware found
AdWare.Win32.BHO.ca (adware)
C:\Users\Administrator\Desktop\HOTUNIST.rar\HOTUNIST.EXE
Trojan.Win32.Agent.abt (virus)
C:\Users\Administrator\Desktop\HOTUNIST.rar\RavMon.exe




--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 3
Not scanned: 0
Result:
Viruses: 1
Spyware: 1
Suspicious items: 0
Riskware: 0
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0


--------------------------------------------------------------------------------

Options
Definitions version:
Viruses: 2008-01-25_02
Spyware: 2008-01-25_02
Scanning Engines:
F-Secure AVP: 7.00.171, 2008-01-25
F-Secure Libra: 2.04.01, 2008-01-24
F-Secure Orion: 1.02.37, 2008-01-25
F-Secure Draco: 1.00.35, 2008-01-14
Scanning options:
Scan all files
Scan inside archives
Actions:
Viruses: Delete infected files
Spyware: Delete infected files
492052134
发表于 2008-1-25 19:56:15 | 显示全部楼层
已删除:广告程序 not-a-virus:AdWare.Win32.BHO.ca        文件 : C:\Documents and Settings\Administrator\桌面\HOTUNIST.rar/HOTUNIST.EXE
已删除:木马程序 Trojan.Win32.Agent.abt        文件 : C:\Documents and Settings\Administrator\桌面\HOTUNIST.rar/RavMon.exe//NPack
冷冷
发表于 2008-1-25 20:07:44 | 显示全部楼层

I:\virus\test\HOTUNIST.EXE - Signature 'not-a-virus:AdWare.Win32.BHO.ca' found
I:\virus\test\RavMon.exe - Signature 'Trojan.Win32.Agent.abt' found
2 Files scanned
   (0 Archives with 0 files)
2 Signatures found
0 Suspect code-parts found
Used time: 0:00.000
-------------------------------------------------------------------------------

I:\virus\test/RavMon.exe: Trojan.Agent-1914 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 195751
Engine version: 0.92
Scanned directories: 1
Scanned files: 2
Infected files: 1
Data scanned: 1.12 MB
Time: 7.687 sec (0 m 7 s)



会感染U盘之类的,每个盘都生成AUTORUN.INF
00009330   00409330      0   shell\explore\Command
00009348   00409348      0   "RavMon.exe -e"
00009358   00409358      0   shell\explore
00009378   00409378      0   shell\open\Command
0000938C   0040938C      0   shell\open
000093A4   004093A4      0   AutoRun
000093AC   004093AC      0   RavMon.exe
000093B8   004093B8      0   AutoRun.inf


[ 本帖最后由 冷_冷 于 2008-1-25 20:19 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
BING126
头像被屏蔽
发表于 2008-1-25 20:30:47 | 显示全部楼层
McAfee全杀了!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 15:52 , Processed in 0.121576 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表