12
返回列表 发新帖
楼主: FLogo
收起左侧

[病毒样本] 10x 恶意网址 1x 病毒下载地址

[复制链接]
电影结束了
发表于 2009-2-5 15:17:08 | 显示全部楼层
扫描系统区域...
扫描所选择的目录和文件...
对象: flink.html
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.JS.Redirector.E (BD 引擎)
对象: fx.htm
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.Exploit.ANPI (BD 引擎)
对象: glworld.html
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.HTML.Agent.P (BD 引擎)
对象: ilink.html
        路径: E:\收集区\TDDOWNLOAD
        Status: 可疑病毒
        病毒: Trojan.Exploit.SSX (BD 引擎)
对象: no.htm
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.JS.Downloader.BHJ (BD 引擎)
对象: real.html
        路径: E:\收集区\TDDOWNLOAD
        Status: 可疑病毒
        病毒: Trojan.JS.PXX (BD 引擎)
对象: sina.htm
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.JS.Downloader.BHI (BD 引擎)
对象: ss(1).htm
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.JS.PXY (BD 引擎)
对象: ss.htm
        路径: E:\收集区\TDDOWNLOAD
        Status: 已发现病毒
        病毒: Trojan.JS.PXY (BD 引擎)
扫描完成: 2009-2-5 15:18
    已检查 10 个文件
    已发现 7 个染毒文件
    发现 2 个可疑文件

miss 1
Sherry.ai
发表于 2009-2-5 19:27:19 | 显示全部楼层
Ka8 Kill[:26:]
一下子丫
发表于 2009-2-5 20:18:41 | 显示全部楼层
D:\TDDOWNLOAD\TDDOWNLOAD.zip.zip
    [0] Archive type: ZIP
    --> flink.html
      [DETECTION] Contains recognition pattern of the JS/Dldr.Agent.UW Java script virus
    --> glworld.html
      [DETECTION] Contains recognition pattern of the HTML/Shellcode.Gen HTML script virus
    --> real.htm
      [DETECTION] Contains recognition pattern of the HTML/Rce.Gen HTML script virus
    --> real.html
      [DETECTION] Contains recognition pattern of the HTML/Rce.Gen HTML script virus
    --> sina.htm
      [DETECTION] Contains recognition pattern of the JS/Dldr.Agent.afr Java script virus
    --> ss(1).htm
      [DETECTION] Contains recognition pattern of the EXP/XMLPars.B exploit
    --> ss.htm
      [DETECTION] Contains recognition pattern of the EXP/XMLPars.B exploit
    [NOTE]      A backup was created as '49ced947.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!

End of the scan: 2009年2月5日  20:18
Used time: 00:05 Minute(s)

The scan has been done completely.

      0 Scanning directories
     11 Files were scanned
      7 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      0 Warnings
      1 Notes

[ 本帖最后由 一下子丫 于 2009-2-5 20:22 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
FLogo
 楼主| 发表于 2009-2-6 06:51:59 | 显示全部楼层

回复 13楼 一下子丫 的帖子

无法返回请求的网页

试图访问的网页:

http://bbs.kafan.cn/attachment.php?aid=
458352&k=f5bedfcee2f4010b6b8459b93396a47
b&t=1233874232

发生下列错误:

请求的对象被感染,发现下列病毒 Trojan.JS.Agent.no


如有疑问,请联系您的技术支持
创建日期:
Fri Feb 06 06:52:07 2009
Kaspersky Lab
tracydk
发表于 2009-2-6 08:45:17 | 显示全部楼层
Your Submission Has Been Sent
Your submission has been sent Thu Feb 5 16:49:59 PST 2009. You will receive an email message from Symantec with a tracking number that will enable you to check the status of this submission.
tracydk
发表于 2009-2-6 08:59:01 | 显示全部楼层
Dear tracydk tracydk,

We have analyzed your submission.  The following is a report of our
findings for each file you have submitted:

filename:  D:\\TDDOWNLOAD.zip
machine: Machine
result: See the developer notes

filename: sina.htm
machine: Machine
result: See the developer notes

filename: ilink.html
machine: Machine
result: See the developer notes

filename: fx.htm
machine: Machine
result: See the developer notes

filename: flink.html
machine: Machine
result: See the developer notes

filename: real.html
machine: Machine
result: This file is detected as Downloader. http://www.symantec.com/avcenter/venc/data/downloader.html

filename: glworld.html
machine: Machine
result: See the developer notes

filename: no.htm
machine: Machine
result: See the developer notes

filename: real.htm
machine: Machine
result: See the developer notes

filename: ss(1).htm
machine: Machine
result: See the developer notes

filename: ss.htm
machine: Machine
result: See the developer notes

Customer notes:



Developer notes:
D:\\TDDOWNLOAD.zip is a container file of type  ZIP
sina.htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
ilink.html Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
fx.htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
flink.html Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
real.html is a non-repairable threat. Please delete this file and replace it if necessary. Please follow the instruction at the end of this email message to install the latest available definitions.  This file is contained by   D:\\TDDOWNLOAD.zip
glworld.html Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
no.htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
real.htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
ss(1).htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip
ss.htm Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis  This file is contained by   D:\\TDDOWNLOAD.zip



The current definitions are capable of detecting this virus.  Please update your definitions by clicking the "LiveUpdate" button in your NAV program.

Should you have any questions about your submission, please contact
your regional technical support from the Symantec website and give them
the tracking number in the subject of this message.

-----------------------------------------------------------------------
This message was generated by Symantec Security Response automation.

For USA:
For electronic support options, Symantec provides On-Line Services at
http://www.symantec.com/techsupp/
tracydk
发表于 2009-2-6 09:01:27 | 显示全部楼层
symantec只分析出一个是下载者
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 06:47 , Processed in 0.095662 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表