查看: 4381|回复: 17
收起左侧

[病毒样本] 27x,F-PROT惨挂

[复制链接]
solcroft
发表于 2008-4-26 04:43:30 | 显示全部楼层 |阅读模式


[Found security risk] <W32/Injector.A.gen!Eldorado (not disinfectable, generic)> C:\Documents and Settings\Admin\Desktop\Virus\2004.exe->rsrcPE
[Found Trojan] <W32/Trojan2.AFTL (exact)> C:\Documents and Settings\Admin\Desktop\Virus\alexey.exe
[Found downloader] <W32/Downldr2.BWQG (exact)> C:\Documents and Settings\Admin\Desktop\Virus\bhos.exe
[Found Trojan] <W32/Trojan2.AIYN (exact)> C:\Documents and Settings\Admin\Desktop\Virus\inst250.exe
[Found Trojan] <W32/Small.DT (exact)> C:\Documents and Settings\Admin\Desktop\Virus\krab.exe
[Found downloader] <W32/Downldr2.BVCW (exact)> C:\Documents and Settings\Admin\Desktop\Virus\ldig005.exe
[Found possible virus] <W32/NewMalware-Rootkit-PX-based!Maximus> C:\Documents and Settings\Admin\Desktop\Virus\pinch.exe->(UPX)
---------------------------------------------------------------------
Scan ended: 26/04/2008
Duration: 0:00:07
Scan result:
Scanned files:   27
Infected objects:  7
Disinfected objects:  5
Quarantined files:  2
---------------------------------------------------------------------

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2008-4-26 04:53:25 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\1'
C:\Documents and Settings\Administrator\My Documents\1\
  2004.exe
    [0] Archive type: RSRC
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
      [NOTE]      The file was deleted!
  208.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  211.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  388888.exe
      [DETECTION] Is the Trojan horse TR/Agent.9728
      [NOTE]      The file was deleted!
  alexey.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  atool.txt
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
  bar.txt
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  bho.exe
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Bho.ajs
      [NOTE]      The file was deleted!
  bhos.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Cryptic.JV
      [NOTE]      The file was deleted!
  bz.exe
    [0] Archive type: RSRC
    --> Object
        [DETECTION] Is the Trojan horse TR/Dldr.Tipikit.F.53
    --> Object
      [NOTE]      The file was deleted!
  dd.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  dump.txt
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  ea.exe
      [DETECTION] Contains detection pattern of the dropper DR/MicroJoiner.Gen
      [NOTE]      The file was deleted!
  hypney.exe
      [DETECTION] Is the Trojan horse TR/Drop.Small.bla
      [NOTE]      The file was deleted!
  inst250.exe
      [DETECTION] Is the Trojan horse TR/Pakes.cjt
      [NOTE]      The file was deleted!
  krab.exe
      [DETECTION] Is the Trojan horse TR/Agent.7680.95
      [NOTE]      The file was deleted!
  Launcher.206.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
  ldig005.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.NAC.1
      [NOTE]      The file was deleted!
  m.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  p.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [NOTE]      The file was deleted!
  pinch.exe
      [DETECTION] Contains detection pattern of the worm WORM/Socks.FA.1
      [NOTE]      The file was deleted!
  pinch2.exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
      [NOTE]      The file was deleted!
  serv.txt
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.AQ
      [NOTE]      The file was deleted!
  sev.exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.AQ
      [NOTE]      The file was deleted!
  xbox.txt
      [DETECTION] Is the Trojan horse TR/Spy.ZBot.aug.1
      [NOTE]      The file was deleted!
  yoyo.exe
      [DETECTION] Is the Trojan horse TR/Clicker.Agent.TP
      [NOTE]      The file was deleted!
  zloi.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
      [NOTE]      The file was deleted!


End of the scan: 2008年4月25日  13:53
Used time: 00:05 min

The scan has been done completely.

      1 Scanning directories
     27 Files were scanned
     27 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     26 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
     26 Notes
mofunzone
发表于 2008-4-26 04:54:26 | 显示全部楼层
The file 'Launcher.206.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Drop.Agent.VXA. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
醉一生爱妍
发表于 2008-4-26 06:26:35 | 显示全部楼层
江民杀毒软件报告文件

        北京江民新科技术有限公司

        扫描引擎 11.00.703
        病毒库日期 2008-04-25
        更新日期 2008-04-10

扫描目标 C:\Documents and Settings\Administrator\桌面\1.zip

扫描目标 C:\Documents and Settings\Administrator\桌面\2.zip

开始时间 2008-04-10 17:59:55

在 C:\Documents and Settings\Administrator\桌面\2.zip->inst250.exe 中发现 Trojan/Pakes.asv 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->2004.exe 中发现 TrojanProxy.Xorpix.aj 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\2.zip->krab.exe 中发现 TrojanDownloader.Small.ltq 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->alexey.exe 中发现 TrojanClicker.Costrat.bu 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\2.zip->ldig005.exe 中发现 TrojanDownloader.Agent.agmd 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->bar.txt 中发现 Packed.Monder.bx 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->bhos.exe 中发现 TrojanDownloader.Cryptic.is 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->bz.exe 中发现 TrojanDropper.Delf.bov 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\1.zip->dump.txt 中发现 Trojan/Srizbi.j 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\2.zip->yoyo.exe 中发现 Adware/Clicker.fpl 病毒, 已删除
正常结束。

扫描结果:
                 文件数 :29                                  病毒体 :10        
                   删除 :10                                    解毒 :0         
    扫描速度(千字节/秒) :563                               扫描时间 :00:00:05
    扫描文件速度(个/秒) :5

    - - - - -   - - - - - - -   - - - - - - -    - - - - - - -    - - - - - - -     - - - - - - -   - - - - -

其余上报KV
郁冰兰雪
发表于 2008-4-26 07:08:51 | 显示全部楼层
EAV 发现21个
D:\病毒样本\2.zip > ZIP > inst250.exe - Win32/Srizbi.Gen 特洛伊木马
D:\病毒样本\2.zip > ZIP > krab.exe - Win32/KillAV.NBO 特洛伊木马
D:\病毒样本\2.zip > ZIP > ldig005.exe - Win32/TrojanDropper.Small.NHE 特洛伊木马
D:\病毒样本\2.zip > ZIP > m.exe - 未查明的 NewHeur_PE 病毒
D:\病毒样本\2.zip > ZIP > p.exe - 未查明的 NewHeur_PE 病毒
D:\病毒样本\2.zip > ZIP > pinch.exe - Win32/Socks.FA 蠕虫
D:\病毒样本\2.zip > ZIP > serv.txt - Win32/TrojanDownloader.Agent.NYD 特洛伊木马
D:\病毒样本\2.zip > ZIP > xbox.txt - Win32/Spy.Agent.NGD 特洛伊木马
D:\病毒样本\2.zip > ZIP > yoyo.exe - Win32/TrojanDownloader.Agent.BER 特洛伊木马
D:\病毒样本\2.zip > ZIP > zloi.exe - Win32/TrojanDownloader.Wigon.G 特洛伊木马 的变种
D:\病毒样本\2.zip > ZIP > ea.exe - Win32/TrojanDropper.Agent.FCU 特洛伊木马
D:\病毒样本\1.zip > ZIP > 2004.exe - Win32/Agent.OH 特洛伊木马
D:\病毒样本\1.zip > ZIP > 388888.exe - Win32/Tiny.NAD 特洛伊木马
D:\病毒样本\1.zip > ZIP > alexey.exe - Win32/Rustock.NDY 特洛伊木马
D:\病毒样本\1.zip > ZIP > atool.txt - Win32/TrojanDownloader.Wigon.N 特洛伊木马
D:\病毒样本\1.zip > ZIP > bar.txt - Win32/TrojanDownloader.Agent.NYE 特洛伊木马
D:\病毒样本\1.zip > ZIP > bho.exe - Win32/TrojanClicker.BHO.NAU 特洛伊木马
D:\病毒样本\1.zip > ZIP > bhos.exe - Win32/TrojanDownloader.Small.OBK 特洛伊木马
D:\病毒样本\1.zip > ZIP > bz.exe - Win32/SpamTool.Agent.IP 特洛伊木马
D:\病毒样本\1.zip > ZIP > dd.exe - Win32/Obfuscated.NBH 特洛伊木马
D:\病毒样本\1.zip > ZIP > dump.txt - Win32/Srizbi.Gen 特洛伊木马
我是小行
发表于 2008-4-26 07:33:03 | 显示全部楼层
到处都是毒啊

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
风野胤
发表于 2008-4-26 08:14:22 | 显示全部楼层
eset 网络监控 23
wangjay1980
发表于 2008-4-26 09:02:28 | 显示全部楼层
K

Hello,

15e932aeb1a9e426b1389d23c9b0dda9.exe_ - Trojan.Win32.Inject.bdm,
1b1f7ef245f9986ac03bc710116ca1cd.exe_ - Trojan.Win32.Inject.bdl,
208.exe_ - Trojan-Dropper.Win32.Small.blf,
211.exe_ - Trojan-Dropper.Win32.Small.blg,
4078bed239e0661466c6a67706649c9b.exe_ - Trojan-PSW.Win32.Delf.bij,
d4334c5ae7c99c9b388bf2cb4168515d.exe_ - Trojan-PSW.Win32.Nilage.cim,
Launcher.206.exe_ - Trojan.Win32.Agent.kve,
zloi.exe_ - Trojan-Dropper.Win32.Small.blh

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

669c8613a839d1ce5443e4cad3f92130.dll - Trojan-PSW.Win32.Nilage.cil,
9300fe60a34b0d232857fd41dadb8c51.exe_ - Trojan.Win32.Inject.bdj

These files are already detected. Please update your antivirus bases.

Please quote all when answering.

--
Best regards, Evgeny Aseev
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

> Attachment: Unknown.zip
[:1:]

[ 本帖最后由 wangjay1980 于 2008-4-26 19:21 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
平淡
发表于 2008-4-26 09:23:55 | 显示全部楼层

25

F:\病毒\1.zip>>2004.exe        TrojanProxy.Xorpix.eb.xbhs        木马        还未处理
F:\病毒\1.zip>>208.exe        Trojan.Vmbcsx.fdex        木马        还未处理
F:\病毒\1.zip>>211.exe        Trojan.Wgvfce.zfhs        木马        还未处理
F:\病毒\1.zip>>388888.exe        Trojan.Agent.kpn.mfot.arc        木马        还未处理
F:\病毒\1.zip>>alexey.exe        TrojanClicker.Costrat.es.sqpl        木马        还未处理
F:\病毒\1.zip>>atool.txt        TrojanDownloader.Wigon.N.nkwu        木马        还未处理
F:\病毒\1.zip>>bar.txt        Packed.Monder.gen.eoud        可疑程序        还未处理
F:\病毒\1.zip>>bho.exe        Adware.BHO.ajs.ndkf        广告程序        还未处理
F:\病毒\1.zip>>bhos.exe        TrojanDownloader.Cryptic.jv.awns        木马        还未处理
F:\病毒\1.zip>>bz.exe        TrojanDownloader.Tibs.jew.feqm        木马        还未处理
F:\病毒\1.zip>>dd.exe        Trojan.Inject.bcj.rfuz        木马        还未处理
F:\病毒\1.zip>>dump.txt        Trojan.Srizbi.z.cpkp        木马        还未处理
F:\病毒\2.zip>>ea.exe        TrojanDropper.Agent.NIK.cgob        木马        还未处理
F:\病毒\2.zip>>hypney.exe        Backdoor.Agent.gxa.eamd        后门        还未处理
F:\病毒\2.zip>>inst250.exe        Trojan.Pakes.cjt.xxpx        木马        还未处理
F:\病毒\2.zip>>krab.exe        TrojanDownloader.Small.cib.ufcr        木马        还未处理
F:\病毒\2.zip>>ldig005.exe        TrojanDownloader.Agent.nac.smqo        木马        还未处理
F:\病毒\2.zip>>m.exe        TrojanPSW.LdPinch.tcr.nmmv        木马        还未处理
F:\病毒\2.zip>>p.exe        TrojanPSW.LdPinch.tcr.nmmv        木马        还未处理
F:\病毒\2.zip>>pinch.exe        Worm.Socks.fa.lfvz        病毒        还未处理
F:\病毒\2.zip>>pinch2.exe        W32.Zhelatin.xz.xczm        病毒        还未处理
F:\病毒\2.zip>>serv.txt        TrojanDownloader.Cntr.q.ntli        木马        还未处理
F:\病毒\2.zip>>sev.exe        TrojanDownloader.Cntr.q.kokh        木马        还未处理
F:\病毒\2.zip>>xbox.txt        TrojanSpy.Zbot.aug.wfaf        木马        还未处理
F:\病毒\2.zip>>yoyo.exe        TrojanClicker.Agent.tp.adqf        木马        还未处理
hellobaby
发表于 2008-4-26 09:31:43 | 显示全部楼层
毒霸扫两个压缩包,总共发现六个。另外请问,提供的样本是分卷压缩包吗?谁高人指点下载后如何合并分卷压缩包?谢谢!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-21 21:42 , Processed in 0.079500 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表