查看: 4398|回复: 19
收起左侧

[病毒样本] 一大包病毒

[复制链接]
chabosh
发表于 2008-6-3 17:08:00 | 显示全部楼层 |阅读模式
一大包病毒
病毒下载表:
2008-6-1=http://60.190.114.61/a1.exe
2008-6-1=http://60.190.114.61/a2.exe
2008-6-1=http://60.190.114.61/a3.exe
2008-6-1=http://60.190.114.61/a4.exe
2008-6-1=http://60.190.114.61/a5.exe
2008-6-1=http://60.190.114.61/a6.exe
2008-6-1=http://60.190.114.61/a7.exe
2008-6-1=http://60.190.114.61/a8.exe
2008-6-1=http://60.190.114.61/a9.exe
2008-6-1=http://60.190.114.61/a10.exe
2008-6-1=http://60.190.114.61/a11.exe
2008-6-1=http://60.190.114.61/a12.exe
2008-6-1=http://60.190.114.61/a13.exe
2008-6-1=http://60.190.114.61/a14.exe
2008-6-1=http://60.190.114.61/a15.exe
2008-6-1=http://60.190.114.61/a16.exe
2008-6-1=http://60.190.114.61/a17.exe
2008-6-1=http://60.190.114.61/a18.exe
2008-6-1=http://60.190.114.61/a19.exe
2008-6-1=http://59.34.198.190/a20.exe
2008-6-1=http://59.34.198.190/a21.exe
2008-6-1=http://59.34.198.190/a22.exe
2008-6-1=http://59.34.198.190/a23.exe
2008-6-1=http://59.34.198.190/a24.exe
2008-6-1=http://59.34.198.190/a25.exe
2008-6-1=http://59.34.198.190/a26.exe
2008-6-1=http://59.34.198.190/a27.exe
2008-6-1=http://59.34.198.190/a28.exe
2008-6-1=http://59.34.198.190/a29.exe

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
小邪邪
发表于 2008-6-3 17:14:29 | 显示全部楼层
AVK25

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lhc-yuan
发表于 2008-6-3 17:24:48 | 显示全部楼层
红伞,报!!!
lhc-yuan
发表于 2008-6-3 17:27:16 | 显示全部楼层
红伞,报!!!
HC303
发表于 2008-6-3 17:39:28 | 显示全部楼层
C:\Documents and Settings\桌面\6.2\dudu\0.exe
      [DETECTION] Is the Trojan horse TR/ATRAPS.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\15.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48730ff8.qua'!
C:\Documents and Settings\桌面\6.2\dudu\27.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\28.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48730ffb.qua'!
C:\Documents and Settings\桌面\6.2\dudu\5.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '48aa0ff1.qua'!
C:\Documents and Settings\桌面\6.2\dudu\bb.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\d32dx9.sys
      [DETECTION] Is the Trojan horse TR/Spy.KeySpy.U
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\gpr40D.exe
      [DETECTION] Is the Trojan horse TR/Agent.qsy.2
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\gpr458.exe
      [DETECTION] Is the Trojan horse TR/Agent.qsy.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapcb.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.crt
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapcq.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.crr
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapcqsj.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.cru
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapms.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.crs
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapmy.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.cmy
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimaptl.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.alae
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapwd.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.cni
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapwl.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.cnj
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapwm.dll
      [DETECTION] Is the Trojan horse TR/PSW.22164
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\midimapzx.dll
      [DETECTION] Is the Trojan horse TR/Inject.cky
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\rl.htm
      [DETECTION] Contains detection pattern of the Java script virus JS/Agent.ES
      [NOTE]      The file was deleted!
C:\Documents and Settings\桌面\6.2\dudu\updatax.exe
      [DETECTION] Is the Trojan horse TR/ATRAPS.Gen
      [NOTE]      The file was deleted!
余下的上报。
傻猪猪米走鸡
发表于 2008-6-3 17:39:46 | 显示全部楼层
一大堆解压错误的东东

2008-6-3 17:41:29        文件系统实时防护        文件        D:\firefox download\dudu\dudu\rl.htm        JS/Exploit.RealPlay.IX 特洛伊木马        通过删除清除 - 已隔离        NT AUTHORITY\SYSTEM        在应用程序新建的文件上发生事件: C:\Program Files\WinRAR\WinRAR.exe.
2008-6-3 17:41:27        文件系统实时防护        文件        D:\firefox download\dudu\dudu\0.exe        Win32/Delf.NLT 特洛伊木马        通过删除清除 - 已隔离        NT AUTHORITY\SYSTEM        在应用程序新建的文件上发生事件: C:\Program Files\WinRAR\WinRAR.exe.
2008-6-3 17:41:24        文件系统实时防护        文件        D:\firefox download\dudu\dudu\d32dx9.sys        Win32/Spy.KeySpy.U 特洛伊木马        通过删除清除 - 已隔离        NT AUTHORITY\SYSTEM        在应用程序新建的文件上发生事件: C:\Program Files\WinRAR\WinRAR.exe.
2008-6-3 17:41:21        文件系统实时防护        文件        D:\firefox download\dudu\dudu\gpr458.exe        Win32/Spy.KeySpy.U 特洛伊木马        通过删除清除 - 已隔离        NT AUTHORITY\SYSTEM        在应用程序新建的文件上发生事件: C:\Program Files\WinRAR\WinRAR.exe.
2008-6-3 17:41:16        文件系统实时防护        文件        D:\firefox download\dudu\dudu\updatax.exe        Win32/Delf.NLT 特洛伊木马        通过删除清除 - 已隔离        NT AUTHORITY\SYSTEM        在应用程序新建的文件上发生事件: C:\Program Files\WinRAR\WinRAR.exe.
solcroft
发表于 2008-6-3 17:42:19 | 显示全部楼层
下载包里垃圾太多了
303898443
发表于 2008-6-3 18:14:44 | 显示全部楼层
卡巴8无声???????
电影结束了
发表于 2008-6-3 18:19:57 | 显示全部楼层
TF把EXE砍了。。。。。
图不截了。。。
yangrui5201
发表于 2008-6-3 18:23:07 | 显示全部楼层
红伞,检出18,可疑3

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-2 10:52 , Processed in 0.135769 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表