查看: 4748|回复: 20
收起左侧

[病毒样本] 又一个不同于机器狗的穿还原的样本!

[复制链接]
byxxdrls
头像被屏蔽
发表于 2008-2-15 13:03:40 | 显示全部楼层 |阅读模式
此样本来自360论坛,我的一台电脑安装了还原精灵6.0,系统分区是NTFS格式,运行了此病毒后,病毒在启动项中的信息穿透了还原(即重启还原后启动项存在),但病毒文件似乎已损坏(也许和NTFS格式有关),无法读取,后来在进行磁盘扫描并修复后,此文件被系统删除。哪位高手有兴趣的话可以分析一下这个病毒。样本地址:http://bbs.360safe.com/attachment.php?aid=123514

[ 本帖最后由 qianwenxiang 于 2008-2-15 13:06 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
byxxdrls
头像被屏蔽
 楼主| 发表于 2008-2-15 13:05:09 | 显示全部楼层
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2008.2.15.11 2008.02.15 -
AntiVir 7.6.0.65 2008.02.14 TR/Delphi.Downloader.Gen
Authentium 4.93.8 2008.02.15 Possibly a new variant of W32/Downloader-WebExe-based!Maximus
Avast 4.7.1098.0 2008.02.14 -
AVG 7.5.0.516 2008.02.14 Downloader.Generic6.AIGZ
BitDefender 7.2 2008.02.15 Generic.Malware.Bdld.3324224C
CAT-QuickHeal None 2008.02.14 TrojanDownloader.Delf.epw
ClamAV 0.92.1 2008.02.15 -
DrWeb 4.44.0.09170 2008.02.14 DLOADER.Trojan
eSafe 7.0.15.0 2008.02.14 Win32.Delf.epw
eTrust-Vet 31.3.5538 2008.02.14 -
Ewido 4.0 2008.02.14 -
FileAdvisor 1 2008.02.15 -
Fortinet 3.14.0.0 2008.02.15 -
F-Prot 4.4.2.54 2008.02.14 W32/Downloader-WebExe-based!Maximus
F-Secure 6.70.13260.0 2008.02.15 Trojan-Downloader.Win32.Delf.epw
Ikarus T3.1.1.20 2008.02.15 Trojan-Spy.Win32.Delf.GI
Kaspersky 7.0.0.125 2008.02.15 Trojan-Downloader.Win32.Delf.epw
McAfee 5230 2008.02.14 -
Microsoft 1.3204 2008.02.14 TrojanDownloader:Win32/Small.gen!Z
NOD32v2 2876 2008.02.14 -
Norman 5.80.02 2008.02.14 -
Panda 9.0.0.4 2008.02.14 Suspicious file
Prevx1 V2 2008.02.15 -
Rising 20.31.30.00 2008.02.14 -
Sophos 4.26.0 2008.02.15 Mal/DelpDldr-F
Sunbelt 2.2.907.0 2008.02.14 -
Symantec 10 2008.02.15 -
TheHacker 6.2.9.220 2008.02.14 -
VBA32 3.12.6.1 2008.02.14 suspected of Embedded.Trojan-Downloader.Win32.Delf.eqf
VirusBuster 4.3.26:9 2008.02.14 -
Webwasher-Gateway 6.6.2 2008.02.14 Trojan.Delphi.Downloader.Gen
附加信息
File size: 20064 bytes
MD5: c374b4a7064b460b664d77ee533fc32b
SHA1: b604dc9faf6f4c4e4cb6b71b45ad77b21e1e913b
PEiD: -
packers: UPX
packers: UPX
packers: UPX
Joker
发表于 2008-2-15 13:06:54 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
挪威的冬天
发表于 2008-2-15 13:07:10 | 显示全部楼层
金山 MISS

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
taiw_1144
发表于 2008-2-15 13:07:37 | 显示全部楼层
木马名称:Trojan-Downloader.Win32.Delf.iwi

程序:
C:\DOCUMENTS AND SETTINGS\WO\LOCAL SETTINGS\TEMP\RAR$EX00.859\NETGUY_UPDATEFILE.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
spatra
发表于 2008-2-15 13:10:09 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\200821355546946.rar'
C:\Documents and Settings\Administrator\桌面\200821355546946.rar
  [0] Archive type: RAR
  --> netguy_updatefile.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
woai_jolin
发表于 2008-2-15 13:12:57 | 显示全部楼层

回复 2楼 byxxdrls 的帖子

norman报了的


Hello,

Thanks for taking the time to submit your samples to the Norman
Sandbox Information Center.  Customer delight is our top priority at
Norman.  With that in mind we have developed Sandbox Solutions for
organizations that are committed to speedy analysis and debugging.

Norman Sandbox Solutions give your organization the opportunity to
analyze files immediately in your own environment.

To find out how to bring the power of Norman Sandbox into your test
environments follow the links below.

Norman Sandbox Solutions
http://www.norman.com/Product/Sandbox-products/

Norman Sandbox Analyzer
http://www.norman.com/Product/Sandbox-products/Analyzer/

Norman Sandbox Analyzer Pro
http://www.norman.com/Product/Sandbox-products/Analyzer-pro/

Norman SandBox Reporter
http://www.norman.com/Product/Sandbox-products/Reporter/

netguy_updatefile.exe : Not detected by Sandbox (Signature: W32/Delf.BKHC)


[ DetectionInfo ]
    * Sandbox name: NO_MALWARE
    * Signature name: W32/Delf.BKHC
    * Compressed: YES
    * TLS hooks: YES
    * Executable type: Application
    * Executable file structure: OK

[ General information ]
    * Decompressing UPX.
    * Accesses executable file from resource section.
    * File length:        21504 bytes.
    * MD5 hash: b510f02190591c3a06ef2718c9157bd8.

[ Changes to filesystem ]
    * Creates file C:\WINDOWS\TEMP\~87.tmp.

[ Signature Scanning ]
    * C:\WINDOWS\TEMP\~87.tmp (10496 bytes) : no signature detection.



(C) 2004-2006 Norman ASA. All Rights Reserved.

The material presented is distributed by Norman ASA as an information source only.


************************************
Sent from an unmonitored email address.
Please DO NOT reply.
************************************
sharkkong
头像被屏蔽
发表于 2008-2-15 14:00:45 | 显示全部楼层
ACCESS DENIED
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://bbs.kafan.cn/attachment.php?aid=201108

The folowing error was encountered:

The requested object is INFECTED. The following viruses Trojan-Downloader.Win32.Delf.epw were found

Please contact your service provider if you feel this is incorrect.



--------------------------------------------------------------------------------

Generated Fri Feb 15 13:59:37 2008 by Kaspersky Anti-Virus 7.0
scottxzt
发表于 2008-2-15 14:09:26 | 显示全部楼层
木马名称:Trojan-Downloader.Win32.Delf.iwi

程序:
C:\DOCUMENTS AND SETTINGS\DELL\桌面\NETGUY_UPDATEFILE.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
scottxzt
发表于 2008-2-15 14:10:00 | 显示全部楼层

这个是运行病毒后再启动微点的,成功拦截!

程序:
C:\DOCUMENTS AND SETTINGS\DELL\桌面\NETGUY_UPDATEFILE.EXE
木马程序生成以下文件:
1) C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\启动\NETGUY_UPDATEFILE.EXE
2) C:\DOCUMENTS AND SETTINGS\DELL\LOCAL SETTINGS\TEMP\~42.TMP
是否删除木马程序及其衍生物?

[ 本帖最后由 scottxzt 于 2008-2-15 15:03 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-29 15:00 , Processed in 0.142283 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表