查看: 2312|回复: 10
收起左侧

[病毒样本] 4

[复制链接]
sam.to
发表于 2008-3-28 13:54:11 | 显示全部楼层 |阅读模式
Kaspersky Virus Scanner


Scanned file:   7.rar
7.rar/mipikq.sys - OK
7.rar/mipikq.sys - OK
7.rar/mipikq.dll - OK


Kaspersky Virus Scanner


Scanned file:   6.rar
6.rar/autorun.inf - OK
6.rar/MSDOS.bat - OK
6.rar/MSDOS.bat - OK
6.rar/MSDOS.bat - OK
6.rar/windows.ext - OK
6.rar/windows.ext - OK
6.rar/windows.ext - OK



上报卡巴

Hello,

autorun.inf

No malicious code was found in this file.

mipikq.dll - Backdoor.Win32.PcClient.cgf,
mipikq.sys4 - Backdoor.Win32.PcClient.cgg,
MSDOS.bat_, windows.ext4 - Worm.Win32.Otwycal.b

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Namestnikov Yury
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

[ 本帖最后由 kato9096 于 2008-3-28 15:22 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aerbeisi
发表于 2008-3-28 13:58:43 | 显示全部楼层
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        c:\test\6.rar->MSDOS.bat4->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        c:\test\6.rar->windows.ext4->(UPack)
mofunzone
发表于 2008-3-28 14:04:32 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\6.rar'
C:\Documents and Settings\Administrator\My Documents\
  6.rar
    [0] Archive type: RAR
    --> autorun.inf
      --> MSDOS.bat4
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
      --> windows.ext4
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
      [WARNING]   The file was ignored!
  6.rar:Zone.Identifier
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\7.rar'
C:\Documents and Settings\Administrator\My Documents\
  7.rar
    [0] Archive type: RAR
    --> mipikq.sys4
    --> mipikq.dll
        [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Pcclient.buu Backdoor server programs
      [WARNING]   The file was ignored!
  7.rar:Zone.Identifier


End of the scan: 2008年3月27日  23:04
Used time: 00:04 min

The scan has been done completely.

      0 Scanning directories
      9 Files were scanned
      3 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      6 Files not concerned
      2 Archives were scanned
      2 Warnings
      0 Notes
残缺的唯美
发表于 2008-3-28 14:05:33 | 显示全部楼层
D:\Documents and Settings\EKINCHENG\桌面\6.rar » RAR » MSDOS.bat4 - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\6.rar » RAR » windows.ext4 - probably a variant of Win32/Genetik trojan
挪威的冬天
发表于 2008-3-28 14:12:54 | 显示全部楼层
信息        2008-03-28  14:12:48        您此次查毒清除了1个病毒                       
信息        2008-03-28  14:12:48        您此次查毒共查出1个病毒以及危险代码                       
信息        2008-03-28  14:12:48        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件9个                       
信息        2008-03-28  14:12:48        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-03-28  14:12:48        D:\Desktop\7.rar\mipikq.dll        Win32.Troj.PcClientT.cz.95812        清除成功
kkgh
发表于 2008-3-28 14:43:21 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.Win32.Undef.dth   

用户来源:互联网

软件版本:20.37.40
allinwonderi
发表于 2008-3-28 19:45:25 | 显示全部楼层
全歼
[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\6.rar<RAR>:MSDOS.bat4<UPack>:MSDOS.bat4<DLLRES>:res0.exe <- Trojan.Downloader.Delf.Fsd : No action
C:\Documents and Settings\All Users\Documents\Test\6.rar<RAR>:windows.ext4<UPack>:windows.ext4<DLLRES>:res0.exe <- Trojan.Downloader.Delf.Fsd : No action
C:\Documents and Settings\All Users\Documents\Test\7.rar<RAR>:mipikq.sys4 <- Trojan.Rbot.Ecn : No action
C:\Documents and Settings\All Users\Documents\Test\7.rar<RAR>:mipikq.dll <- Trojan.Rbot.Ecn : No action



Scanned objects : 11

Infected objects : 4
sam.to
 楼主| 发表于 2008-3-28 21:12:35 | 显示全部楼层

回复 6楼 kkgh 的帖子

只有一个
qigang
发表于 2008-3-28 21:16:47 | 显示全部楼层

11/1

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.Win32.Undef.dth   

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.37.42
曲中求
发表于 2008-3-28 23:42:48 | 显示全部楼层
费尔:

第一包
E:\病毒\7.rar>>mipikq.dll        Trojan.Agent.ahjo.avpa.dll        木马        还未处理

第二包
E:\病毒\6.rar>>autorun.inf        INF.Autorun.d        病毒        还未处理
E:\病毒\6.rar>>MSDOS.bat4        Trojan.Cap832723.igoa        木马        还未处理
E:\病毒\6.rar>>windows.ext4        Trojan.Cap832723.igoa        木马        还未处理
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 11:39 , Processed in 0.164799 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表