查看: 11821|回复: 77
收起左侧

[病毒样本] Maganias病毒更新帖(去除重复和无毒文件)(03.13第三十九次更新)

[复制链接]
sbbdms
发表于 2009-1-10 19:35:40 | 显示全部楼层 |阅读模式
0109样本:
0109生成:
0111样本:
0111生成:
0112样本:
0112生成:
0114样本:
0114生成:
0115样本:
0115生成:
0116样本:
0116生成:
0116第二次样本:
0116第二次生成:
0117样本:
0117生成:
0117第二次样本:
0117第二次生成:
0118样本:
0118生成:
0120样本:
0120生成:
0121样本:
0121生成:
0122样本:
0122生成:
0123样本:
0123生成:
0125样本(感谢qianwenxiang帮忙下载)
0125生成(感谢qianwenxiang帮忙下载)
0125第二次样本(感谢qianwenxiang帮忙下载)
0125第二次生成(感谢qianwenxiang帮忙下载)
0130样本:
0130生成:
0201样本:
0201生成:
0203样本:
0203生成:
0204样本:
0204生成:
0205样本:
0205生成:
0206样本:
0206生成:
0207样本:
0207生成:
0208样本:
0208生成:
0210样本:
0210生成:
0211样本:
0211生成:
0213样本:
0213生成:
0214样本:
0214生成:
0215样本:
0215生成:
0216样本:
0216生成:
0217样本:
0217生成:
0218样本:
0218生成:
0219样本:
0219生成:
0220样本:
0220生成:
0221样本:
0221生成:
0224样本:
0224生成:
0228样本:
0228生成:
0308样本:
0308生成:
0313样本:
0313生成:
不报的都已TO KL

[ 本帖最后由 sbbdms 于 2009-3-14 17:48 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 5经验 +5 人气 +4 收起 理由
尤金卡巴斯基 + 1 加分鼓励
935623508 + 1 版区有你更精彩: )
luxiao200888 + 1 感谢支持,欢迎常来: )
qianwenxiang + 5 加分鼓励
sam.to + 1 版区有你更精彩: )

查看全部评分

Kitman
发表于 2009-1-10 19:37:55 | 显示全部楼层
Begin scan in 'C:\Users\Kitman\Desktop\0109maganias'
C:\Users\Kitman\Desktop\0109maganias\help.exe
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      A backup was created as '49d4895d.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109maganias\ll.exe
    [DETECTION] Contains HEUR/Crypted suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      A backup was created as '49968964.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109maganias\uu.exe
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      A backup was created as '4996896d.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!

[ 本帖最后由 Kitman 于 2009-1-10 19:40 编辑 ]
Kitman
发表于 2009-1-10 19:50:10 | 显示全部楼层
Begin scan in 'C:\Users\Kitman\Desktop\0109created'
C:\Users\Kitman\Desktop\0109created\amvo.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49de8a52.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\cvnmhg0.dll
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49d68a5b.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\dse235rgd0.dll
    [DETECTION] Is the TR/Vundo Trojan
    [NOTE]      A backup was created as '49cd8a58.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\hg.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49968a4c.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\kxvo.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49de8a5d.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\mg.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4d97b755.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\mmvo.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4ddfb74b.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\mmvo0.dll
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49de8a54.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\nod172.tmp
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      A backup was created as '49cc8a54.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\nod173.tmp
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      A backup was created as '4dcdb74d.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\nod174.tmp
    [DETECTION] Contains HEUR/Crypted suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      A backup was created as '49cc8a56.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\rb.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49968a47.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\Kitman\Desktop\0109created\wedasgads0.dll
    [DETECTION] Contains HEUR/Crypted suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      A backup was created as '49cc8a4a.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年1月10日  19:43
Used time: 00:02 Minute(s)

The scan has been done completely.

      1 Scanning directories
     14 Files were scanned
     11 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
     13 files were deleted
      0 files were repaired
     13 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      0 Archives were scanned
      0 Warnings
     13 Notes
Sherry.ai
发表于 2009-1-10 20:02:12 | 显示全部楼层
星星To KL A lot of Packer
sbbdms
 楼主| 发表于 2009-1-11 12:42:46 | 显示全部楼层
0111第二次更新
luxiao200888
发表于 2009-1-11 13:02:20 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Owner\桌面\新建文件夹'
C:\Documents and Settings\Owner\桌面\新建文件夹\amvo.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '49df7e9a.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\cvnmhg0.dll
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '49d77ea7.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\dse235rgd0.dll
    [DETECTION] Is the TR/Vundo Trojan
    [NOTE]      The file was moved to '49ce7ea8.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\mg.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '49977e9e.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\mmvo.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '49df7ea7.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\nod1D5.tmp
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      The file was moved to '49cd7eac.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\nod1D6.tmp
    [DETECTION] Contains HEUR/Crypted suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      The file was moved to '49cd7eb0.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\nod1D7.tmp
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      The file was moved to '49cd7eb3.qua'!
C:\Documents and Settings\Owner\桌面\新建文件夹\rb.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '49977ea8.qua'!


End of the scan: 2009年1月11日  13:06
Used time: 00:36 Minute(s)

The scan has been done completely.

      1 Scanning directories
     14 Files were scanned
      8 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      9 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      5 Files not concerned
      0 Archives were scanned
      0 Warnings
      9 Notes
killloop
发表于 2009-1-11 13:15:24 | 显示全部楼层
KV 0
su-tt
发表于 2009-1-11 13:32:07 | 显示全部楼层
上报ESET
sbbdms
 楼主| 发表于 2009-1-12 23:02:03 | 显示全部楼层
0112第三次更新
su-tt
发表于 2009-1-12 23:03:19 | 显示全部楼层

回复 9楼 sbbdms 的帖子

C:\Documents and Settings\Administrator\桌面\0112maganias.rar > RAR > uu.exe - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\0112maganias.rar > RAR > help(1).exe - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\0112maganias.rar > RAR > ll.exe - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种

生成物之查出3个tmp
C:\Documents and Settings\Administrator\桌面\0112created[1]\nod155.tmp - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种 - 通过删除清除 - 已隔离 [1]
C:\Documents and Settings\Administrator\桌面\0112created[1]\nod156.tmp - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种 - 通过删除清除 - 已隔离 [1]
C:\Documents and Settings\Administrator\桌面\0112created[1]\nod157.tmp - Win32/TrojanDropper.Agent.NJV 特洛伊木马 的变种 - 通过删除清除 - 已隔离 [1]

[ 本帖最后由 su-tt 于 2009-1-12 23:05 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-21 03:22 , Processed in 0.125740 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表