查看: 3933|回复: 14
收起左侧

[病毒样本] u盘传播,一个bat

[复制链接]
ldeyw
发表于 2008-3-26 13:35:24 | 显示全部楼层 |阅读模式
a-squared3.0.0.1262008.03.242008-03-24-
5.445
AntiVir7.6.0.757.0.3.732008-03-25-
6.002
Arcavir1.0.42008032518122008-03-25-
4.252
AVAST1.0.8080325-02008-03-25Win32:DNSChanger-SL [Trj]
9.321
AVG7.5.51.442269.21.8/13432008-03-25Worm/Generic.ETF
6.519
BitDefender7.60825.10233907.181912008-03-26-
6.509
CA (VET)9.0.0.14331.3.56432008-03-26-
29.894
ClamAV 0.9263922008-03-25-
0.049
Comodo2.112.0.0.4752008-03-25-
1.862
CP Secure1.1.0.7152008.03.262008-03-26-
14.879
Dr.WEB4.44.0.91702008.03.252008-03-25DLOADER.Trojan
8.296
ewido4.0.0.22008.03.252008-03-25-
13.529
F-PROT4.4.1.52200803252008-03-25W32/Backdoor2.GJB (exact)
5.072
F-SECURE5.51.61002008.03.25.092008-03-25-
13.578
IKARUST3.1.01.202008.03.24.704982008-03-24Virus.Win32.DNSChanger.SL
6.336
Microsoft1.33012008.03.252008-03-25-
12.305
MKS_VIR2.012008.03.252008-03-25-
12.612
NORMAN5.91.105.902008-03-25-
27.410
nProtect2008-03-26.0012509172008-03-26-
5.523
PrevxV2200803262008-03-26-
29.168
QuickHeal9.002008.03.252008-03-25-
3.051
SOPHOS2.71.34.272008-03-25-
11.637
The Hacker6.2.92v002552008-03-25Trojan/Small.autorun
2.448
VBA323.12.6.320080325.20402008-03-25-
3.644
ViRobot200803252008.03.252008-03-25-
1.111
VirusBuster4.3.19:99.123.21/11.02008-03-25-
4.133
卡巴斯基5.5.102008.03.262008-03-26-
22.446
安博士V32008.03.26.002008.03.262008-03-26-
2.007
江民杀毒10.00.6502008.03.252008-03-25Trojan/DiskAutorun.avy
1.787
熊猫卫士9.04.03.00012008.03.252008-03-25-
8.290
瑞星20.020.37.02.002008-03-24-
2.259
赛门铁克1.3.0.2420080325.0032008-03-25W32.SillyFDC
1.795
趋势8.500-10015.188.022008-03-25Mal_Otorun2
0.059
迈克菲5.2.0052582008-03-24-
7.888
金山毒霸2007.6.20.2492008.3.262008-03-26-
3.441
飞塔2.81-3.118.8872008-03-26-
6.806
顺便一提,nod32和微点预升级都对它没反应,我信赖的三个杀软都被它过了
装上hips运行bat粗略看了一下,在C盘下建立了一个隐藏文件,修改几项注册表,其他就没有动作了.

[ 本帖最后由 ldeyw 于 2008-3-26 13:55 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
gaojun7206
发表于 2008-3-26 15:08:16 | 显示全部楼层
Trojan.DiskAutorun.avy.ivfl
深红的雪
发表于 2008-3-26 15:15:38 | 显示全部楼层
这个不是bat,试试改成exe后缀看看

delautorun 它自己说的


另外,红伞不认识

[ 本帖最后由 rappar 于 2008-3-26 19:15 编辑 ]
ldeyw
 楼主| 发表于 2008-3-26 15:35:22 | 显示全部楼层
改了后图标就出现了,而且还很有时尚感
ldeyw
 楼主| 发表于 2008-3-26 15:58:27 | 显示全部楼层
咬牙运行了,这到底是什么
怎么看起来像一个好人

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sanhu35
发表于 2008-3-26 15:59:32 | 显示全部楼层
The scan has been done completely.

      0 Scanning directories
      5 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      5 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
傻猪猪米走鸡
发表于 2008-3-26 16:02:47 | 显示全部楼层
D:\firefox download\Autorun.rar > RAR > Autorun.inf - 正常
D:\firefox download\Autorun.rar > RAR > delautorun.bat - 正常
D:\firefox download\Autorun.rar > RAR > delautorun.ini - 正常
D:\firefox download\Autorun.rar:Zone.Identifier - 正常
ldeyw
 楼主| 发表于 2008-3-26 16:03:38 | 显示全部楼层
难道这程序其实是想做个好人,而我却没有给它机会?
难怪Autorun会在右键添加一个"杀毒"的选项.
不过怎么看都不是一个能让人安心的东西.虽然它的自我介绍很让人安心

[ 本帖最后由 ldeyw 于 2008-3-26 16:12 编辑 ]
allinwonderi
发表于 2008-3-26 20:50:24 | 显示全部楼层
-----------------------------SCAN REPORT-----------------------------
F-PROT Antivirus for Windows

Antivirus Scanning Engine version number: 4.4.2
Virus signature file from: 2008-3-26, 15:02

Scan name: Virus Tester
Path to scan: C:\Documents and Settings\All Users\Documents\Test\|

Normal scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2008-3-26, 20:49:58
---------------------------------------------------------------------


[Found backdoor]         <W32/Backdoor2.GJB (exact, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\Autorun.rar->delautorun.bat

---------------------------------------------------------------------
Scan ended:        2008-3-26, 20:49:59
Duration:        0:00:01

Scan result:

Scanned files:                 6
Infected objects:         1
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------

[Warning]        <Could not open file>
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 09:16 , Processed in 0.134677 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表