查看: 3858|回复: 9
收起左侧

[病毒样本] 几个AUTO病毒

[复制链接]
chabosh
发表于 2008-10-26 14:28:09 | 显示全部楼层 |阅读模式
几个AUTO病毒

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
无尽藏海
发表于 2008-10-26 14:39:06 | 显示全部楼层
Scan Stats:
  Scan Time: 110 seconds
  Scan Options:
  Scan Targets: D:\Virus\Dudu26
  Counts:
   Total items scanned: 8
   - Files & Directories: 8
   - Registry Entries: 0
   - Processes & Start-up Items: 0
   - Network & Browser Items: 0
   - Other: 0
   - Trusted Files: 0
   - Skipped Files: 0

   Total security risks detected: 5
   Total items resolved: 5
   Total items that require attention: 0

Resolved Threats:
VBS.Runauto
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\dudu26\dudu\'.vbs - Deleted


VBS.Runauto.B
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\virus\dudu26\dudu\.vbs - Deleted
d:\virus\dudu26\dudu\2.vbs - Deleted


W32.SillyFDC
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Restart Required
-----------
54 Registry Entries
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:149 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0 - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule->ImagePath:%SystemRoot%\System32\svchost.exe -k netsvcs - Repaired
HKEY_CLASSES_ROOT\MSCFile\Shell\Open\Command - Repaired
HKEY_CLASSES_ROOT\regfile\shell\open\command - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->DisableStatusMessages:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL->CheckedValue:1 - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Control Panel\Desktop->AutoEndTasks:... - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Control Panel\Desktop->AutoEndTasks:... - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Control Panel\Desktop->ScreenSaveTimeOut:600 - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Control Panel\Desktop->ScreenSaveTimeOut:600 - Repaired
HKEY_CLASSES_ROOT\comfile\shell\open\command - Repaired
HKEY_CLASSES_ROOT\txtfile\shell\open\command\ - Repaired
HKEY_CLASSES_ROOT\exefile - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt->UncheckedValue:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden->UncheckedValue:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideFileExt->CheckedValue:0 - Repaired
HKEY_CLASSES_ROOT\batfile\shell\edit\command\ - Repaired
HKEY_CLASSES_ROOT\comfile\ - Repaired
HKEY_CLASSES_ROOT\inifile\shell\open\command\ - Repaired
HKEY_CLASSES_ROOT\piffile\shell\open\command\ - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Shell:Explorer.exe - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Userinit:C:\Windows\system32\userinit.exe, - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0 - Repaired
[Restricted item (permission required)] - N/A
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\->AlternateShell:cmd.exe - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore\->DisableConfig:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore\->DisableSR:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\->LimitSystemRestoreCheckpointing:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\->DisableMSI:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Classes\exefile\ - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
10 Files
d:\virus\dudu26\dudu\delautorun.bat - Deleted
c:\users\无尽藏海\appdata\local\temp\~df1921.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df4e35.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df5df2.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df7dc8.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df84ea.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~dfa4ad.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~dfb71c.tmp - Restart Required
c:\windows\setup\state - Restart Required
C:\Windows\setup - Restart Required


W32.Rajump
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
1 Registry Entry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL->CheckedValue:1 - Repaired
1 File
d:\virus\dudu26\dudu\ravmon.exe - Deleted


Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)  
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\dudu26\dudu\recycled.exe - Deleted
Kitman
发表于 2008-10-26 15:03:13 | 显示全部楼层
Begin scan in 'C:\Users\TOSHIBA\Downloads\Dudu'
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\'.vbs
    [DETECTION] Contains recognition pattern of the WORM/Autorun.E.1 worm
    [NOTE]      A backup was created as '497a161f.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\.vbs
    [DETECTION] Contains recognition pattern of the VBS/Autorun.VF VBS script virus
    [NOTE]      A backup was created as '4abbb5a8.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\2.vbs
    [DETECTION] Contains recognition pattern of the VBS/Autorun.VF VBS script virus
    [NOTE]      A backup was created as '497a1621.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\delautorun.bat
    [DETECTION] Contains recognition pattern of the WORM/Autorun.ETF worm
    [NOTE]      A backup was created as '49701656.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\RavMon.exe
    [DETECTION] Is the TR/Agent.Abt.3 Trojan
    [NOTE]      A backup was created as '497a1652.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\Dudu\Dudu\Recycled.exe
    [DETECTION] Is the TR/Dldr.VB.fxs Trojan
    [NOTE]      A backup was created as '49671656.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2008年10月26日  15:02
Used time: 00:05 Minute(s)

The scan has been done completely.

      2 Scanning directories
      6 Files were scanned
      6 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      6 files were deleted
      0 files were repaired
      6 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
      6 Notes
syfwxmh
发表于 2008-10-26 16:19:16 | 显示全部楼层
kaspersky miss 1 to kl
kingmuro
头像被屏蔽
发表于 2008-10-26 17:07:04 | 显示全部楼层
mcafee8。7

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
KOI9009
发表于 2008-10-26 17:13:27 | 显示全部楼层
卡巴+红伞 全灭
lingbo110120
发表于 2008-10-26 17:40:12 | 显示全部楼层
NOD 全灭
'.vbs - VBS/AutoRun.O 蠕虫 - 通过删除清除 - 已隔离
.vbs - VBS/AutoRun.G 蠕虫 - 通过删除清除 - 已隔离
2.vbs - VBS/AutoRun.G 蠕虫 - 通过删除清除 - 已隔离
delautorun.bat - Win32/AutoRun.MF 蠕虫 的变种 - 通过删除清除 - 已隔离
RavMon.exe - Win32/Agent.NAV 蠕虫 - 通过删除清除 - 已隔离
Recycled.exe - 可能是 Win32/TrojanDownloader.VB 特洛伊木马 的变种 - 通过删除清除 - 已隔离
syfwxmh
发表于 2008-10-26 17:52:45 | 显示全部楼层
卡巴不报的回信
Hello.
No malicious software was found in the attached file.

Please quote all when answering.


-----------------
Regards, Kirill Erakhtin
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
http://www.kaspersky.com/trials - trial version


> Attachment: delautorun.rar
欠妳緈諨
发表于 2008-10-26 22:09:32 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
david0921
发表于 2008-10-27 19:46:26 | 显示全部楼层
还没有解压缩就被NIS2009干掉了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-18 10:47 , Processed in 0.129717 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表