楼主: 流清泉
收起左侧

[病毒样本] http://222.180.36.174/setup.exe

[复制链接]
hahacomcn
发表于 2008-4-23 20:37:49 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\haha\桌面\setup.exe'
C:\Documents and Settings\haha\桌面\setup.exe
  [0] Archive type: OVL
  --> Object
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/UPACK). Please verify the origin of the file
      [NOTE]      A backup was created as '48832df1.qua'  ( QUARANTINE )
      [NOTE]      The file was deleted!
tytyyyy
头像被屏蔽
发表于 2008-4-23 21:09:50 | 显示全部楼层
卡巴现在报了,4个。
挪威的冬天
发表于 2008-4-23 22:36:35 | 显示全部楼层
金山 0
mofunzone
发表于 2008-4-23 22:50:32 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\wm[1].zip'
C:\Documents and Settings\Administrator\My Documents\
  wm[1].zip
    [0] Archive type: ZIP
    --> wm[1].exe
        [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [NOTE]      The file was deleted!
sam.to
发表于 2008-4-24 00:05:38 | 显示全部楼层
Hello.
New malicious software was found in the attached file.
It's detection will be included in the next update. Thank you for your help.
-----------------
Regards, Namestnikov Yury
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com
Exia 该用户已被删除
发表于 2008-4-24 10:14:12 | 显示全部楼层

回复 9楼 Nblock 的帖子

Starting the file scan:

Begin scan in 'E:\新建文件夹 (2)\SGASPF080423.rar'
E:\新建文件夹 (2)\SGASPF080423.rar
  [0] Archive type: RAR
  --> SGASPF080423.EXE
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
      [NOTE]      The file was deleted!
Exia 该用户已被删除
发表于 2008-4-24 10:16:04 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\新建文件夹 (2)\setup.exe'
E:\新建文件夹 (2)\setup.exe
      [DETECTION] Is the Trojan horse TR/Dropper.743002
      [NOTE]      The file was deleted!
hui8du
发表于 2008-4-24 10:16:28 | 显示全部楼层
2008-4-24 10:14:26        恶意HTTP对象 <http://222.180.36.174/setup.exe//PE_Patch//UPack>:检测到:木马程序 'Trojan-Spy.Win32.Pophot.arl'。 
yunhan123
发表于 2008-4-24 10:21:25 | 显示全部楼层
原帖由 挪威的冬天 于 2008-4-23 22:36 发表
金山 0
试试行为拦截。。。
Exia 该用户已被删除
发表于 2008-4-24 15:26:47 | 显示全部楼层
The file 'LWIAS16_080423.DLL' has been determined to be 'MALWARE'. Our analysts named the threat TR/Spy.Pophot.arl. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 11:22 , Processed in 0.098405 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表