查看: 3029|回复: 12
收起左侧

[病毒样本] 7x 【5楼 >不完整的木马群病毒样本】

[复制链接]
幸福的猪猪
发表于 2009-3-10 06:51:55 | 显示全部楼层 |阅读模式
hxxp://www.downpao.com/setup.rar
hxxp://333.8585le.com/00/2.exe
hxxp://www.6oo7.cn/a/34.exe
hxxp://qdvod.dcv2.cn/tj2/t2.exe
hxxp://qdvod.dcv2.cn/tj2/css.exe

hxxp://www.6oo7.cn/d/166.exe
hxxp://qdvod.dcv2.cn/root/mmc.exe

解压密码为:
infected

kaba miss setup.rar ,to kill !

Hello,


de.exe - Trojan-Downloader.Win32.Agent.bklk

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.


[ 本帖最后由 幸福的猪猪 于 2009-3-10 08:09 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
nosferatu
头像被屏蔽
发表于 2009-3-10 07:05:15 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD'
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\166.exe
    [DETECTION] Contains a recognition pattern of the (harmful) BDS/Agent.aber.43 back-door program
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\2.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\34.exe
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Contains a recognition pattern of the (harmful) BDS/Delf.cas back-door program
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\css.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\mmc.exe
      [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\t2.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
25283561  de.exe  234 KB  UNDER ANALYSIS
ledled
发表于 2009-3-10 07:13:52 | 显示全部楼层
de.exe to VB
Sebastian
发表于 2009-3-10 07:25:09 | 显示全部楼层

Avira Premium Security Suite 9

Starting the file scan:

Begin scan in 'D:\TDDOWNLOAD'
D:\TDDOWNLOAD\166.exe
    [DETECTION] Contains a recognition pattern of the (harmful) BDS/Agent.aber.43 back-door program
    [NOTE]      A backup was created as '49eba596.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\2.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a1aa58e.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\34.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Contains a recognition pattern of the (harmful) BDS/Delf.cas back-door program
    [NOTE]      A backup was created as '49e3a594.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\css.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4a28a5d3.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\mmc.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
    [NOTE]      A backup was created as '4a18a5ce.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\t2.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '49e3a593.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年3月10日  07:25
Used time: 00:01 Minute(s)

The scan has been done completely.

      1 Scanned directories
      7 Files were scanned
      6 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      6 files were deleted
      0 Viruses and unwanted programs were repaired
      6 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      0 Archives were scanned
      0 Warnings
      6 Notes
幸福的猪猪
 楼主| 发表于 2009-3-10 07:35:45 | 显示全部楼层
再来12x  
kaba miss 5x ,to kill !【由于某些特殊原因,病毒下载地址不完整,可以说又是一个木马群!】

hxxp://temp.838wg.cn/pp/my.exe
hxxp://don.b1du.net/down/gbjxsj.exe
hxxp://don.b1du.net/down/lazx.exe
hxxp://don.b1du.net/down/gbdj.exe
hxxp://don.b1du.net/down/lacb.exe
hxxp://don.b1du.net/down/lawow.exe
hxxp://don.b1du.net/down/gbdh2.exe
hxxp://don.b1du.net/down/gzdh3.exe
hxxp://don.b1du.net/down/gbdnf.exe
hxxp://don.b1du.net/down/gzjr.exe
hxxp://don.b1du.net/down/gbwd.exe
hxxp://don.b1du.net/down/gbwmgj.exe

样本全部打包上报!

kaba miss 5x的回信:

Hello,


gbjxsj.exe - Trojan-GameThief.Win32.WOW.gbr

This file is already detected. Please update your antivirus bases.

lacb.exe - Trojan-GameThief.Win32.WOW.gbx
lawow.exe - Trojan-GameThief.Win32.WOW.gci
lazx.exe - Trojan-GameThief.Win32.WOW.gce
my.exe - Trojan-GameThief.Win32.WOW.gcl

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.




解压密码为:infected

[ 本帖最后由 幸福的猪猪 于 2009-3-10 14:58 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Sebastian
发表于 2009-3-10 07:37:23 | 显示全部楼层

回复 5楼 幸福的猪猪 的帖子

avira premium security suite 9

Starting the file scan:

Begin scan in 'D:\TDDOWNLOAD'
D:\TDDOWNLOAD\gbdh2.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a19a8ee.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gbdj.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4b986eff.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gbdnf.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a19a910.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gbjxsj.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a1fa8ee.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gbwd.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a2ca8ee.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gbwmgj.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4bad6eff.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gzdh3.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a19a906.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\gzjr.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a1fa906.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\lacb.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a18a8ed.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\lawow.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a2ca8ed.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\lazx.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4a2fa8ed.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\TDDOWNLOAD\my.exe
    [DETECTION] Is the TR/BHO.Gen Trojan
    [NOTE]      A backup was created as '49e3a905.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年3月10日  07:38
Used time: 00:00 Minute(s)

The scan has been done completely.

      1 Scanned directories
     12 Files were scanned
     12 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
     12 files were deleted
      0 Viruses and unwanted programs were repaired
     12 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
     12 Notes
wcj20236
头像被屏蔽
发表于 2009-3-10 07:47:17 | 显示全部楼层

回复 5楼 幸福的猪猪 的帖子

微点全杀。。。
ledled
发表于 2009-3-10 07:48:59 | 显示全部楼层

回复 5楼 幸福的猪猪 的帖子

MISS 4 to VB
kingmuro
头像被屏蔽
发表于 2009-3-10 08:48:46 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Palkia
发表于 2009-3-10 20:15:08 | 显示全部楼层
miss to rs
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 06:54 , Processed in 0.080915 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表