查看: 1781|回复: 8
收起左侧

[病毒样本] 24个病毒样本

[复制链接]
chima287
发表于 2009-3-3 11:22:41 | 显示全部楼层 |阅读模式
24个病毒样本,NOD32也查出了24个病毒样本

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ledled
发表于 2009-3-3 11:59:14 | 显示全部楼层
VirusBuster Kill 15
413055156
发表于 2009-3-3 12:36:45 | 显示全部楼层
国产货瑞星全杀 a-squared Free报13个
leonfg
发表于 2009-3-3 12:45:53 | 显示全部楼层
eset 24 但是省了俩文件
C:\Documents and Settings\GUNDAM\桌面\24\1(1).exe - probably a variant of Win32/Genetik trojan - cleaned by deleting - quarantined
C:\Documents and Settings\GUNDAM\桌面\24\1(2).exe - probably a variant of Win32/Genetik trojan - cleaned by deleting - quarantined
C:\Documents and Settings\GUNDAM\桌面\24\1(3).exe - a variant of Win32/AutoRun.ADC worm - cleaned by deleting - quarantined
C:\Documents and Settings\GUNDAM\桌面\24\1.exe - Win32/PcClient.IHJ trojan - cleaned by deleting - quarantined
C:\Documents and Settings\GUNDAM\桌面\24\10(1).exe » NSIS » IETimber.dll - Win32/Adware.Zhongsou application
C:\Documents and Settings\GUNDAM\桌面\24\10.exe » NSIS » IETimber.dll - Win32/Adware.Zhongsou application
C:\Documents and Settings\GUNDAM\桌面\24\2(1).exe » NSIS » 162.exe » NSIS » 龏
kingmuro
头像被屏蔽
发表于 2009-3-3 15:41:08 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Palkia
发表于 2009-3-3 19:14:47 | 显示全部楼层
miss to rs
尤金卡巴斯基
发表于 2009-3-3 23:32:40 | 显示全部楼层
2009/3/3 23:32:08        已清除        广告软件 not-a-virus:AdWare.Win32.BHO.fne        G:\Temp\Virus\24.rar/24\6.exe//stream               
2009/3/3 23:32:08        已清除        广告软件 not-a-virus:AdWare.Win32.BHO.fne        G:\Temp\Virus\24.rar/24\6.exe               
2009/3/3 23:32:08        已清除        广告软件 not-a-virus:AdWare.Win32.BHO.fne        G:\Temp\Virus\24.rar/24\6(1).exe//stream//data0001               
2009/3/3 23:32:08        已清除        广告软件 not-a-virus:AdWare.Win32.AdMedia.ed        G:\Temp\Virus\24.rar/24\2.exe               
2009/3/3 23:32:08        已清除        广告软件 not-a-virus:AdWare.Win32.AdMedia.ed        G:\Temp\Virus\24.rar/24\2(1).exe               
2009/3/3 23:32:08        已隔离        恶意程序 Suspicious.Packer        G:\Temp\Virus\24.rar/24\sanet.gif               
2009/3/3 23:32:08        已隔离        恶意程序 Suspicious.Packer        G:\Temp\Virus\24.rar/24\sanet.gif//BeRo//PE_Patch.UPX//UPX//PE_Patch.AvSpoof               
2009/3/3 23:32:08        已清除        木马程序 Trojan.Win32.Buzus.aofb        G:\Temp\Virus\24.rar/24\baksak.gif               
2009/3/3 23:32:08        已清除        木马程序 Trojan.Win32.Agent.bsmy        G:\Temp\Virus\24.rar/24\ie.exe               
2009/3/3 23:32:08        已清除        木马程序 Trojan-PSW.Win32.QQPass.gio        G:\Temp\Virus\24.rar/24\hudst.gif               
2009/3/3 23:32:08        已清除        木马程序 Trojan-GameThief.Win32.OnLineGames.usbz        G:\Temp\Virus\24.rar/24\kudst.gif               
2009/3/3 23:32:08        已清除        木马程序 Trojan-GameThief.Win32.OnLineGames.usay        G:\Temp\Virus\24.rar/24\9.exe//NSPack//PE-Crypt.Morf               
2009/3/3 23:32:08        已清除        木马程序 Trojan-GameThief.Win32.OnLineGames.usay        G:\Temp\Virus\24.rar/24\9(1).exe//NSPack//PE-Crypt.Morf               
2009/3/3 23:32:08        已清除        木马程序 Trojan-Dropper.Win32.Agent.aimw        G:\Temp\Virus\24.rar/24\1(2).exe               
2009/3/3 23:32:08        已清除        木马程序 Trojan-Dropper.Win32.Agent.aimw        G:\Temp\Virus\24.rar/24\1(1).exe               
2009/3/3 23:32:08        已清除        木马程序 Trojan-Downloader.Win32.Agent.bjnp        G:\Temp\Virus\24.rar/24\SafeSys.exe//UPack               
2009/3/3 23:32:08        已清除        木马程序 Trojan-Downloader.Win32.Agent.bjnp        G:\Temp\Virus\24.rar/24\1(3).exe//UPack               
2009/3/3 23:32:08        已清除        木马程序 Exploit.Win32.Agent.ce        G:\Temp\Virus\24.rar/24\~sdoog.tmp               
2009/3/3 23:32:08        已清除        木马程序 Backdoor.Win32.PcClient.ihj        G:\Temp\Virus\24.rar/24\1.exe               
2009/3/3 23:32:08        已清除        病毒 Worm.Win32.AutoRun.abii        G:\Temp\Virus\24.rar/24\x.gif/照片                                                                                                             .exe               
2009/3/3 23:32:08        已清除        病毒 Rootkit.Win32.Agent.hsr        G:\Temp\Virus\24.rar/24\swmfb.fon               

To KL
nosferatu
头像被屏蔽
发表于 2009-3-3 23:36:35 | 显示全部楼层

20+2

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\24'
C:\Documents and Settings\Administrator\桌面\24\1(1).exe
      [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\1(2).exe
      [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\1(3).exe
      [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\1.exe
    [DETECTION] Contains recognition pattern of the DR/PcClient.Gen dropper
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\10(1).exe
    [0] Archive type: NSIS
    --> [ProgramFilesDir]/Internet Explorer/IETimber/IETimber.dll
      [DETECTION] Contains recognition pattern of the ADSPY/Timber.BHO adware or spyware
    [DETECTION] Contains recognition pattern of the DR/Timber.RT dropper
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\10.exe
    [0] Archive type: NSIS
    --> [ProgramFilesDir]/Internet Explorer/IETimber/IETimber.dll
      [DETECTION] Contains recognition pattern of the ADSPY/Timber.BHO adware or spyware
    [DETECTION] Contains recognition pattern of the DR/Timber.RT dropper
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\2(1).exe
    [0] Archive type: NSIS
    --> 52D77ECE7B32424dB93B9A6EFBDDB0DF/[TempDir]/162.exe
      [DETECTION] Contains recognition pattern of the DR/Cinmus.amaw dropper
    [DETECTION] Contains recognition pattern of the ADSPY/AdMedia.ED.304 adware or spyware
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\2.exe
    [0] Archive type: NSIS
    --> 52D77ECE7B32424dB93B9A6EFBDDB0DF/[TempDir]/162.exe
      [DETECTION] Contains recognition pattern of the DR/Cinmus.amaw dropper
    [DETECTION] Contains recognition pattern of the ADSPY/AdMedia.ED.304 adware or spyware
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\6(1).exe
    [0] Archive type: NSIS
    --> SOFTWARE/MicroPlugins/Common/cpush.dll
      [DETECTION] Contains recognition pattern of the ADSPY/Bho.fne adware or spyware
    --> SOFTWARE/MicroPlugins/Common/cpush.tmp
      [DETECTION] Contains recognition pattern of the ADSPY/Bho.fne adware or spyware
    [DETECTION] Contains recognition pattern of the DR/BHO.fne.47 dropper
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\6.exe
    [0] Archive type: NSIS
    --> SOFTWARE/MicroPlugins/Common/cpush.dll
      [DETECTION] Contains recognition pattern of the ADSPY/Bho.fne adware or spyware
    --> SOFTWARE/MicroPlugins/Common/cpush.tmp
      [DETECTION] Contains recognition pattern of the ADSPY/Bho.fne adware or spyware
    [DETECTION] Contains recognition pattern of the DR/BHO.fne.47 dropper
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\9(1).exe
    [DETECTION] Is the TR/PSW.OnlineGames.usay Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\9.exe
    [DETECTION] Is the TR/PSW.OnlineGames.usay Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\baksak.gif
    [DETECTION] Is the TR/Crypt.CFI.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\hudst.gif
    [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      The file was moved to '4a114ea5.qua'!
C:\Documents and Settings\Administrator\桌面\24\ie.exe
    [0] Archive type: RSRC
    --> Object
      [DETECTION] Is the TR/Agent.bfof Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\kudst.gif
    [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      The file was moved to '4a114ea6.qua'!
C:\Documents and Settings\Administrator\桌面\24\SafeSys.exe
      [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\sanet.gif
    [DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.Gen back-door program
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\sNiu.dll
      [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\swmfb.fon
    [DETECTION] Is the TR/Vtool.Rootkitdrv.KL Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\x.gif
    [0] Archive type: RAR
    --> ᅰᅰᅥᆲ                                                                                                             .exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\24\~sdoog.tmp
    [DETECTION] Is the TR/Expl.Agent.CE.3 Trojan
    [NOTE]      The file was deleted!


End of the scan: 星期二 2009年3月3日  23:35
Used time: 00:27 Minute(s)

The scan has been done completely.

      1 Scanning directories
     45 Files were scanned
     28 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
     20 files were deleted
      0 files were repaired
      2 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     15 Files not concerned
      7 Archives were scanned
      0 Warnings
     22 Notes
File ID         Filename        Size (Byte)        Result
25278000         frsii         8 KB         UNDER ANALYSIS
25277999         ~ahljs.bat         82 Byte         UNDER ANALYSIS
25277480         hudst.gif         103.5 KB         UNDER ANALYSIS
25277481         kudst.gif         106.5 KB         UNDER ANALYSIS

[ 本帖最后由 nosferatu 于 2009-3-3 23:40 编辑 ]
尤金卡巴斯基
发表于 2009-3-3 23:47:05 | 显示全部楼层
Hello,

10(1).exe_, frsii, x.gif_, ~ahljs.bat_

No malicious code were found in these files.

sNiu.dll - Backdoor.Win32.Small.hpq

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

Regards, Andrey Ladikov
Virus Analyst, Kaspersky Lab.

10/1, 1st Volokolamsky Proezd, Moscow, 123060, Russia
Tel./Fax: + 7 (495) 797 8700
http://www.kaspersky.com http://www.viruslist.com
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 05:10 , Processed in 0.090442 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表