查看: 2758|回复: 11
收起左侧

[病毒样本] 一个 质量一般

[复制链接]
beyondcloud
发表于 2008-3-4 16:33:16 | 显示全部楼层 |阅读模式
a-squared3.0.0.1262008.03.032008-03-03-
4.997
AntiVir7.6.0.737.0.2.2262008-03-04BDS/Hupigon.Gen
3.276
Arcavir1.0.42008030319352008-03-03Trojan.Ceckno.Tl
2.023
AVAST1.0.8080304-02008-03-04Win32:Delf-IHQ [Trj]
3.174
AVG7.5.51.442269.21.4/13092008-03-03Generic9.BELL
5.214
BitDefender7.60825.9851077.178542008-03-04-
11.415
CA (VET)9.0.0.14331.3.55852008-03-04-
7.821
ClamAV 0.9261152008-03-04-
0.440
Comodo2.112.0.0.4542008-03-04-
1.195
CP Secure1.1.0.7152008.03.042008-03-04Packed.W32.PolyCrypt.E
11.952
Dr.WEB4.44.0.91702008.03.042008-03-04MULDROP.Trojan
7.710
ewido4.0.0.22008.03.032008-03-03-
2.551
F-PROT4.4.1.52200803032008-03-03-
2.652
F-SECURE5.51.61002008.03.04.022008-03-04-
0.061
IKARUST3.1.01.202008.03.03.703982008-03-03Trojan.Win32.Delf.nf
2.923
Microsoft1.33012008.03.042008-03-04Trojan:Win32/Delf.FC
6.693
MKS_VIR2.012008.03.032008-03-03-
4.463
NORMAN5.91.105.902008-02-28-
9.332
nProtect2008-03-04.0011906462008-03-04Backdoor/W32.Hupigon.568832.E
4.759
PrevxV2200803042008-03-04-
3.462
QuickHeal9.002008.03.032008-03-03-
2.132
SOPHOS2.71.34.272008-03-04Mal/Emogen-Y
3.195
The Hacker6.2.9v002322008-03-03-
0.764
VBA323.12.6.220080303.22162008-03-03Embedded.Backdoor.Win32.Ceckno.sz (suspicious)
3.151
ViRobot200803032008.03.032008-03-03-
0.678
VirusBuster4.3.19:99.121.29/11.02008-03-03-
3.018
卡巴斯基5.5.102008.03.042008-03-04-
11.725
安博士V32008.03.04.002008.03.042008-03-04Win-Trojan/Hupigon.568832.E
1.385
江民杀毒10.00.6502008.03.032008-03-03Trojan/Delf.czt
1.479
熊猫卫士9.04.03.00012008.03.032008-03-03-
3.097
瑞星20.020.34.10.002008-03-04-
1.485
赛门铁克1.3.0.2420080303.0032008-03-03-
0.232
趋势8.500-10015.136.042008-03-03-
0.054
迈克菲5.2.0052432008-03-03-
6.451
金山毒霸2007.6.20.2492008.3.42008-03-04-
1.201
飞塔2.81-3.118.8122008-03-04-

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hahacomcn
发表于 2008-3-4 16:40:39 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\haha\桌面\svchost.rar'
C:\Documents and Settings\haha\桌面\svchost.rar
  [0] Archive type: RAR
    --> svchost.exe
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
      [INFO]      A backup was created as '48300b91.qua'  ( QUARANTINE )
wenfe
头像被屏蔽
发表于 2008-3-4 16:51:12 | 显示全部楼层
时间        名称        状态        原因
----        ----        ----        ----
2008-3-4 16:48:40        文件: C:\Documents and Settings\Administrator\My Documents\svchost.rar        档案文件RAR       
2008-3-4 16:48:42        文件: C:\Documents and Settings\Administrator\My Documents\svchost.rar/svchost.exe        正常        已扫描
2008-3-4 16:48:42        文件: C:\Documents and Settings\Administrator\My Documents\svchost.rar        正常        已扫描

卡巴又没有报
HC303
发表于 2008-3-4 16:54:37 | 显示全部楼层
不用测了,红伞报了。
wangjay1980
发表于 2008-3-4 16:55:51 | 显示全部楼层
TO KL

[ 本帖最后由 wangjay1980 于 2008-3-4 17:08 编辑 ]
ztly159
发表于 2008-3-4 17:02:06 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\svchost.rar>>svchost.exe>>emb-1.dll        Backdoor.Ceckno.sz.opbk.dll        后门        还未处理
费尔
beyondcloud
 楼主| 发表于 2008-3-4 17:43:01 | 显示全部楼层
少说一句   安博士。。。竟然报了
taiw_1144
发表于 2008-3-4 17:52:11 | 显示全部楼层
发现未知木马
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\RAR$EX00.187\LAST[1].EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\78A7761D.EXE
2) C:\WINDOWS\SYSTEM32\3AF4A3DA.DLL
是否删除木马程序及其衍生物?
wangjay1980
发表于 2008-3-4 18:56:18 | 显示全部楼层
Hello,

svchost.exe_ - Backdoor.Win32.Ceckno.ud

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Ermilov Maxim
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: svchost.rar
电影结束了
发表于 2008-3-4 19:10:28 | 显示全部楼层
Scan Log
Version of virus signature database: 2920 (20080304)
Date: 2008-3-4  Time: 19:10:16
Scanned disks, folders and files: C:\Documents and Settings\wangcheng\桌面\svchost.rar
C:\Documents and Settings\wangcheng\桌面\svchost.rar » RAR » svchost.exe - probably a variant of Win32/Genetik trojan
Number of scanned objects: 2
Number of threats found: 1
Time of completion: 19:10:16  Total scanning time: 0 sec (00:00:00)
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 22:32 , Processed in 0.125451 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表