楼主: qianwenxiang
收起左侧

[病毒样本] 捆绑了N个

[复制链接]
leonfg
发表于 2008-2-12 00:43:08 | 显示全部楼层
结果: 发现1个恶意软件
Trojan-Clicker.Win32.VB.ms (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809\20070809.exe 操作: 已重命名

结果: 发现7个恶意软件
Trojan-Downloader.Win32.Delf.axb (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\tan.exe
Trojan-Clicker.Win32.VB.mi (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\31.exe
Trojan-Clicker.Win32.VB.ms (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\AD2.exe
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\bo.exe
Trojan-Clicker.Win32.VB.lc (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\ad.exe
AdWare.Win32.BHO.av (adware)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\cpush.dll
Trojan.Win32.VB.amy (病毒)
C:\Documents and Settings\GUNDAM\桌面\20070809.rar\sys.exe
Graybird
发表于 2008-2-12 06:57:15 | 显示全部楼层

回复 2楼 yimike 的帖子

Starting the file scan:

Begin scan in 'E:\virus\20070809.rar'
E:\virus\20070809.rar
  [0] Archive type: RAR
  --> tan.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPI.Gen
  --> 31.exe
      [DETECTION] Is the Trojan horse TR/Click.VB.MI.1
  --> AD2.exe
      [DETECTION] Is the Trojan horse TR/Click.VB.MS.2
  --> ad.exe
      [DETECTION] Is the Trojan horse TR/Click.VB.LC
  --> bo.exe
      [DETECTION] Is the Trojan horse TR/Click.VB.MS
  --> cpush.dll
      [DETECTION] Is the Trojan horse TR/Adware.BHO.AV
  --> sys.exe
      [DETECTION] Is the Trojan horse TR/VB.amy.2
      [INFO]      The file was deleted!


End of the scan: 2008年2月12日  06:58
Used time: 00:11 min

The scan has been done completely.

      0 Scanning directories
      8 Files were scanned
      7 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes

Starting the file scan:

Begin scan in 'E:\virus\20070809.exe'
E:\virus\20070809.exe
      [DETECTION] Contains detection pattern of the dropper DR/Click.VB.MS.5
      [INFO]      The file was deleted!

[ 本帖最后由 Graybird 于 2008-2-12 08:35 编辑 ]
wangjay1980
发表于 2008-2-12 08:38:02 | 显示全部楼层
detected: Trojan program Trojan-Downloader.Win32.Delf.axb        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/tan.exe//NSPack//PE_Patch.MaskPE
detected: Trojan program Trojan-Clicker.Win32.VB.mi        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/31.exe
detected: Trojan program Trojan-Clicker.Win32.VB.ms        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/AD2.exe
detected: Trojan program Trojan-Clicker.Win32.VB.lc        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/ad.exe
detected: Trojan program Trojan-Clicker.Win32.VB.ms        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/bo.exe
detected: adware not-a-virus:AdWare.Win32.BHO.av        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/cpush.dll
detected: Trojan program Trojan.Win32.VB.amy        File: C:\Documents and Settings\Owner\×ÀÃæ\20070809.rar/sys.exe
qqq000@qq.com
头像被屏蔽
发表于 2008-2-12 09:12:51 | 显示全部楼层
----------
              [凝逸反毒] (http://hi.baidu.com/503165656)

       [凝逸.扫描病毒引擎-日志]       2008.2.12 9:12:28

文件:F:\080129\20070809\tan.ex# | 感染:BackDoor.Pigeon.1604 [5493>20070726_dw0001.axx]3(1.1)
操作:文件更名
文件:F:\080129\20070809\31.ex# | 感染:TrojanClicker.VB.bi [747>20070726_kv0001.axx]3(1.1)
操作:文件更名
文件:F:\080129\20070809\ad2.ex# | 感染:Trojan.Qqlame [5496>20070726_dw0001.axx]3(1.1)
操作:文件更名
文件:F:\080129\20070809\ad.ex# | 感染:Trojan.Click.1098 [5474>20070726_dw0001.axx]3(1.1)
操作:文件更名
文件:F:\080129\20070809\bo.ex# | 感染:Trojan.Click.1186 [5495>20070726_dw0001.axx]3(1.1)
操作:文件更名
文件:F:\080129\20070809\sys.ex# | 感染:Trojan.Click.1163 [5494>20070726_dw0001.axx]3(1.1)
操作:文件更名

扫描完成|病毒:6 文件:7|耗时:2594
----------
kkgh
发表于 2008-2-12 11:03:24 | 显示全部楼层
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ 创建时间:        11:08:28 2008-2-12

+ 扫描结果:       



C:\Documents and Settings\zh\桌面\cpush.dll -> Adware.BHO : 已清除.
C:\Documents and Settings\zh\桌面\tan.exe -> Downloader.Delf.azw : 已清除.
C:\Documents and Settings\zh\桌面\31.exe -> Hijacker.VB.lc : 已清除.
C:\Documents and Settings\zh\桌面\ad.exe -> Hijacker.VB.lc : 已清除.
C:\Documents and Settings\zh\桌面\AD2.exe -> Hijacker.VB.ms : 已清除.
C:\Documents and Settings\zh\桌面\bo.exe -> Hijacker.VB.ms : 已清除.
C:\Documents and Settings\zh\桌面\sys.exe -> Trojan.VB.amy : 已清除.


::报告结束

瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.DL.Delf.exq      
病毒: Trojan.Clicker.VB.of     
病毒: Trojan.Clicker.Mobo.b   
病毒: Trojan.Clicker.VB.jy     
病毒: Trojan.DL.VB.apw         
病毒: Trojan.Clicker.Agent.bdk
病毒: Trojan.DL.VB.apv         

用户来源:互联网

软件版本:20.30.60
hj5abc
发表于 2008-2-12 13:00:34 | 显示全部楼层
Sign of "Win32:Delf-DNR [Trj]" has been found in "F:\20070809.rar\tan.exe\[NsPack]" file.  
Sign of "Win32:VB-EZ [Trj]" has been found in "F:\20070809.rar\31.exe" file.  
Sign of "Win32:VB-ZO [Trj]" has been found in "F:\20070809.rar\AD2.exe" file.  
Sign of "Win32:VB-ZO [Trj]" has been found in "F:\20070809.rar\ad.exe" file.  
Sign of "Win32:Trojan-gen {VB}" has been found in "F:\20070809.rar\bo.exe" file.  
Sign of "Win32:Adware-gen [Adw]" has been found in "F:\20070809.rar\cpush.dll" file.  
Sign of "Win32:VB-APY [Trj]" has been found in "F:\20070809.rar\sys.exe" file.  
woai_jolin
发表于 2008-2-12 13:56:22 | 显示全部楼层

回复 8楼 qq65367032 的帖子

设置问题


2008-2-12 13:56:28 Real-time file system protection file G:\v\sys.exe Win32/VB.NEM trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:27 Real-time file system protection file G:\v\cpush.dll Win32/Adware.BHO.AV application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:26 Real-time file system protection file G:\v\bo.exe Win32/TrojanClicker.VB.MS trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:25 Real-time file system protection file G:\v\ad.exe Win32/TrojanClicker.VB.LC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:24 Real-time file system protection file G:\v\AD2.exe Win32/TrojanClicker.VB.MS trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:23 Real-time file system protection file G:\v\31.exe Win32/TrojanClicker.VB.MI trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
2008-2-12 13:56:21 Real-time file system protection file G:\v\tan.exe a variant of Win32/TrojanDownloader.Delf.AXB trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\WinRAR\WinRAR.exe.
saga3721
发表于 2008-2-12 14:06:27 | 显示全部楼层
原帖由 qq65367032 于 2008-2-12 00:13 发表
我晕.红伞.怎么一个不报.????

解压,运行,安装,然后你就会改口了
Hatry 该用户已被删除
发表于 2008-2-12 14:12:21 | 显示全部楼层
f-secure
Result: 7 malware found
Trojan-Downloader.Win32.Delf.axb (virus)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\tan.exe
Trojan-Clicker.Win32.VB.mi (virus)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\31.exe
Trojan-Clicker.Win32.VB.ms (virus)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\AD2.exe
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\bo.exe
Trojan-Clicker.Win32.VB.lc (virus)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\ad.exe
AdWare.Win32.BHO.av (adware)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\cpush.dll
Trojan.Win32.VB.amy (virus)
C:\Documents and Settings\Hatry.FAMILY-10EDEF61\®à­±\20070809.rar\sys.exe
HappyFish
发表于 2008-2-12 15:11:22 | 显示全部楼层
趋势2008发现6个病毒。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 08:29 , Processed in 0.111593 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表