楼主: zxxwind
收起左侧

[病毒样本] 一个很强的木马,众多杀毒软件均无反应!!!

[复制链接]
mofunzone
发表于 2009-2-28 15:59:49 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\Administrator\Desktop\17sui.rar'
C:\Users\Administrator\Desktop\17sui.rar
  [0] Archive type: RAR
    [NOTE]      The file was deleted!
    --> setup.exe
      [1] Archive type: NSIS
      [DETECTION] Is the TR/Drop.Agent.apd Trojan
      --> [ProgramFilesDir]/snav/Snav.dll
        [DETECTION] Contains recognition pattern of the ADSPY/Bho.aer adware or spyware
utfhv
发表于 2009-2-28 16:14:17 | 显示全部楼层
KV09不报,=看看主防
sharkkong
头像被屏蔽
发表于 2009-2-28 17:06:54 | 显示全部楼层
很一般。
建立一个DLL,然后写注册表,全部被卡巴拦截,然后就死了。不像木马,估计就是一广告
2009-2-28 16:56:51        System Security                Create        C:\Sandbox\apple\DefaultBox\drive\C\Program Files\snav\Snav.dll       
2009-2-28 16:56:51        Application Filtering        Denied: KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO        Modification        hkey_users\SANDBOX_apple_DEFAULTBOX\machine\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{635A7AFA-FB22-4A4E-8AB8-C85CFAB14626}        KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO       
2009-2-28 16:56:51        Application Filtering        Denied: KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO        Modification        hkey_users\SANDBOX_apple_DEFAULTBOX\machine\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{635A7AFA-FB22-4A4E-8AB8-C85CFAB14626}        KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO       
2009-2-28 16:56:51        Application Filtering        Denied: KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO        Modification        hkey_users\SANDBOX_apple_DEFAULTBOX\machine\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{635A7AFA-FB22-4A4E-8AB8-C85CFAB14626}        KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO       
2009-2-28 16:56:51        Application Filtering        Denied: KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO        Modification        hkey_users\SANDBOX_apple_DEFAULTBOX\machine\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{635A7AFA-FB22-4A4E-8AB8-C85CFAB14626}        KLPrivateData/KLOtherSoft/KLInternetBrowsers/Internet Explorer/BHO       
2009-2-28 16:56:52        System Security                Process exit        C:\Sandbox\apple\DefaultBox\user\current\Local Settings\Temp\Rar$EX00.547\setup.exe
lsgster
发表于 2009-2-28 17:10:56 | 显示全部楼层
迈克菲给杀了
zjys
发表于 2009-2-28 17:16:43 | 显示全部楼层
TO KL
黑衣~魂
发表于 2009-2-28 17:35:24 | 显示全部楼层
DR.WEB
setup.exe\data002---\setup.exe;Adware.Bho.86
wrq
发表于 2009-2-28 18:12:49 | 显示全部楼层
Access to the data has been denied!
Warning: A virus or unwanted program has been found in the HTTP Data.

Requested URL:  http://bbs.kafan.cn/attachment.p ... be&t=1235815894
Information:  Is the TR/Drop.Agent.apd Trojan  


--------------------------------------------------------------------------------
Generated by AntiVir WebGuard 8.0.15.0, AVE 8.2.0.98, VDF 7.1.2.95
qwer9909
发表于 2009-2-28 18:14:44 | 显示全部楼层
[扫描路径] C:\Documents and Settings\Administrator\桌面\17sui.rar
C:\Documents and Settings\Administrator\桌面\17sui.rar - 压缩文件 RAR
>C:\Documents and Settings\Administrator\桌面\17sui.rar/setup.exe 已加壳,方式: BINARYRES
>>C:\Documents and Settings\Administrator\桌面\17sui.rar/setup.exe - 压缩文件 NSIS
>>>C:\Documents and Settings\Administrator\桌面\17sui.rar/setup.exe/data001 - 确定
>>>C:\Documents and Settings\Administrator\桌面\17sui.rar/setup.exe/data002 是广告软件 Adware.Bho.86
>>C:\Documents and Settings\Administrator\桌面\17sui.rar/setup.exe - 发现压缩文件中有被感染的对象
C:\Documents and Settings\Administrator\桌面\17sui.rar - 发现压缩文件中有被感染的对象
C:\Documents and Settings\Administrator\桌面\17sui.rar:Zone.Identifier - 确定
allinwonderi
发表于 2009-2-28 19:10:30 | 显示全部楼层

ArcaVir 2009

C:\Test\17sui.rar<RAR>:setup.exe<NSIS>:Snav.dll <- Adware.Bho.Dbk : No action
变成经典
发表于 2009-2-28 19:45:53 | 显示全部楼层
真的那么厉害啊,我可不想被病毒感染电脑,电脑不能用就要小心饭碗了!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 04:50 , Processed in 0.096712 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表