查看: 2741|回复: 19
收起左侧

[病毒样本] bluedit x 6

[复制链接]
qianwenxiang
发表于 2008-3-22 22:47:55 | 显示全部楼层 |阅读模式
bluedit2.rar : 昨天更新的
bluedit22.rar : 今天更新的
今天的更新网址
http://www.squirn.com/080322/xia.exe
http://www.squirn.com/080322/080322.exe

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Joker
发表于 2008-3-22 22:49:47 | 显示全部楼层
4
deleted: Trojan program Trojan-Downloader.Win32.VB.cco        File: C:\Documents and Settings\Administrator\×ÀÃæ\bluedit2.rar/jizhong11.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.cds        File: C:\Documents and Settings\Administrator\×ÀÃæ\bluedit2.rar/jizhong16.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.ceb        File: C:\Documents and Settings\Administrator\×ÀÃæ\bluedit2.rar/jizhong26.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.cdc        File: C:\Documents and Settings\Administrator\×ÀÃæ\bluedit2.rar/jizhong02.exe
红心王子
发表于 2008-3-22 22:51:27 | 显示全部楼层
木马名称:Trojan-Downloader.Win32.VB.eke

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\JIZHONG11.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?


木马名称:Trojan-Downloader.Win32.VB.dzq

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\JIZHONG16.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?


木马名称:Trojan-Downloader.Win32.VB.eki

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\JIZHONG26.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

木马名称:Trojan-Clicker.Win32.Pamere.a

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\JIZHONG02.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
testhawk
发表于 2008-3-22 22:54:42 | 显示全部楼层
bluedit2.rar » RAR » jizhong11.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
bluedit2.rar » RAR » jizhong16.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
bluedit2.rar » RAR » jizhong26.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
bluedit2.rar » RAR » jizhong02.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
Bluedit22.rar » RAR » xia.exe - a variant of Win32/TrojanDownloader.VB.AHQ trojan
Bluedit22.rar » RAR » 080322.exe - a variant of Win32/TrojanClicker.VB.NCJ trojan
woai_jolin
发表于 2008-3-22 22:55:16 | 显示全部楼层
Scan Log
Version of virus signature database: 2967 (20080321)
Date: 2008/3/22  Time: 22:55:32
Scanned disks, folders and files: G:\v\Bluedit22.rar
G:\v\Bluedit22.rar » RAR » xia.exe - a variant of Win32/TrojanDownloader.VB.AHQ trojan - was a part of the deleted object
G:\v\Bluedit22.rar » RAR » 080322.exe - a variant of Win32/TrojanClicker.VB.NCJ trojan - was a part of the deleted object
Number of scanned objects: 3
Number of threats found: 2
Time of completion: 22:55:32  Total scanning time: 0 sec (00:00:00)
woai_jolin
发表于 2008-3-22 22:55:31 | 显示全部楼层
Scan Log
Version of virus signature database: 2967 (20080321)
Date: 2008/3/22  Time: 22:55:46
Scanned disks, folders and files: G:\v\bluedit2.rar
G:\v\bluedit2.rar » RAR » jizhong11.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan - was a part of the deleted object
G:\v\bluedit2.rar » RAR » jizhong16.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan - was a part of the deleted object
G:\v\bluedit2.rar » RAR » jizhong26.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan - was a part of the deleted object
G:\v\bluedit2.rar » RAR » jizhong02.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan - was a part of the deleted object
Number of scanned objects: 5
Number of threats found: 4
Time of completion: 22:55:47  Total scanning time: 1 sec (00:00:01)
无尽藏海
发表于 2008-3-22 23:00:32 | 显示全部楼层
E:\VIRUS\bluedit2\jizhong02.exe        TrojanDownloader.VB.yok.jjif        木马        还未处理
E:\VIRUS\bluedit2\jizhong11.exe        TrojanDownloader.VB.ynw.yihy        木马        还未处理
E:\VIRUS\bluedit2\jizhong16.exe        TrojanDownloader.VB.cds.jawz        木马        还未处理
E:\VIRUS\bluedit2\jizhong26.exe        TrojanDownloader.VB.ceb.joel        木马        还未处理
Exia 该用户已被删除
发表于 2008-3-22 23:06:44 | 显示全部楼层

five

Starting the file scan:

Begin scan in 'E:\AVIRA\bluedit2.rar'
E:\AVIRA\bluedit2.rar
  [0] Archive type: RAR
  --> jizhong11.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.cco
  --> jizhong16.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.cds
  --> jizhong26.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.ceb
  --> jizhong02.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.cdc
      [INFO]      The file was deleted!
Begin scan in 'E:\AVIRA\Bluedit22.rar'
E:\AVIRA\Bluedit22.rar
  [0] Archive type: RAR
  --> xia.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was deleted!

The file 'xia.exe' has been determined to be 'UNDER ANALYSIS'.
The file '080322.exe' has been determined to be 'UNDER ANALYSIS'.

[ 本帖最后由 Exia 于 2008-3-22 23:16 编辑 ]
The EQs
发表于 2008-3-22 23:10:35 | 显示全部楼层
Scan Log
Version of virus signature database: 2967 (20080321)
Date: 2008-3-22  Time: 23:10:19
Scanned disks, folders and files: C:\Documents and Settings\Don johnson\桌面\Bluedit22.rar;C:\Documents and Settings\Don johnson\桌面\bluedit2.rar
C:\Documents and Settings\Don johnson\桌面\Bluedit22.rar » RAR » xia.exe - a variant of Win32/TrojanDownloader.VB.AHQ trojan
C:\Documents and Settings\Don johnson\桌面\Bluedit22.rar » RAR » 080322.exe - a variant of Win32/TrojanClicker.VB.NCJ trojan
C:\Documents and Settings\Don johnson\桌面\bluedit2.rar » RAR » jizhong11.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
C:\Documents and Settings\Don johnson\桌面\bluedit2.rar » RAR » jizhong16.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
C:\Documents and Settings\Don johnson\桌面\bluedit2.rar » RAR » jizhong26.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
C:\Documents and Settings\Don johnson\桌面\bluedit2.rar » RAR » jizhong02.exe - a variant of Win32/TrojanDownloader.VB.NKB trojan
Number of scanned objects: 6
Number of threats found: 6
Time of completion: 23:10:19  Total scanning time: 0 sec (00:00:00)
冷冷
发表于 2008-3-22 23:14:45 | 显示全部楼层
IK

I:\virus\March\23\新建文件夹\bluedit2.rar:\jizhong11.exe - Signature 'Virus.Win32.VB.HKF' found
I:\virus\March\23\新建文件夹\bluedit2.rar:\jizhong16.exe - Signature 'Virus.Win32.VB.HKF' found
I:\virus\March\23\新建文件夹\bluedit2.rar:\jizhong26.exe - Signature 'Virus.Win32.VB.HKF' found
I:\virus\March\23\新建文件夹\bluedit2.rar:\jizhong02.exe - Signature 'Virus.Win32.VB.HKF' found

I:\virus\March\23\新建文件夹\bluedit2.rar
I:\virus\March\23\新建文件夹\Bluedit22.rar:\xia.exe - Signature 'Trojan-Downloader.Win32.VB.ahq' found
I:\virus\March\23\新建文件夹\Bluedit22.rar:\080322.exe - Signature 'Trojan-Clicker.Win32.VB.qs' found

I:\virus\March\23\新建文件夹\Bluedit22.rar

8 Files scanned
   (2 Archives with 6 files)
6 Signatures found
0 Suspect code-parts found
Used time: 0:00.110
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-14 18:24 , Processed in 0.131861 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表