查看: 1571|回复: 9
收起左侧

[病毒样本] Koobface 6X

[复制链接]
Sherry.ai
发表于 2009-4-8 19:51:56 | 显示全部楼层 |阅读模式
最近很流行~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Sebastian
发表于 2009-4-8 19:54:49 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\kafan\Koobface'
D:\kafan\Koobface\32B96EDE7F0E7AFF065D34017BA501AC.exe
    --> Object
      [DETECTION] Contains recognition pattern of the WORM/Koobface.fx worm
    [NOTE]      A backup was created as '4a1e911c.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\kafan\Koobface\910E8BD20D7CE6E9F197E887F1C15B31.exe
    --> Object
      [DETECTION] Contains recognition pattern of the WORM/Koobface.fx worm
    [NOTE]      A backup was created as '4a0c911b.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\kafan\Koobface\D20A3B637428F9A1C3C986867E80E00E.exe
    --> Object
      [DETECTION] Contains recognition pattern of the WORM/Koobface.fx worm
    [NOTE]      A backup was created as '4a0c911c.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年4月8日  19:56
Used time: 00:00 Minute(s)

The scan has been done completely.

      1 Scanned directories
      6 Files were scanned
      3 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      3 files were deleted
      0 Viruses and unwanted programs were repaired
      3 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      0 Archives were scanned
      0 Warnings
      3 Notes
Palkia
发表于 2009-4-8 19:57:56 | 显示全部楼层
病毒        2009-04-08  19:58:32        C:\Documents and Settings\Administrator\桌面\Koobface.rar\Koobface\D20A3B637428F9A1C3C986867E80E00E.exe        Worm.Koobface.fx.40960 (蠕虫病毒)        清除成功       
病毒        2009-04-08  19:58:32        C:\Documents and Settings\Administrator\桌面\Koobface.rar\Koobface\910E8BD20D7CE6E9F197E887F1C15B31.exe        Worm.Koobface.fx.40960 (蠕虫病毒)        清除成功       
病毒        2009-04-08  19:58:32        C:\Documents and Settings\Administrator\桌面\Koobface.rar\Koobface\32B96EDE7F0E7AFF065D34017BA501AC.exe        Worm.Koobface.fx.40960 (蠕虫病毒)        清除成功
BING126
头像被屏蔽
发表于 2009-4-8 21:02:16 | 显示全部楼层
McAfee miss
左手
发表于 2009-4-8 21:12:48 | 显示全部楼层
2009-04-08 21:12:22    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\5E4802415D245EAAC383772110BEFAAC.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe


2009-04-08 21:12:23    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\910E8BD20D7CE6E9F197E887F1C15B31.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe


2009-04-08 21:12:24    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\D20A3B637428F9A1C3C986867E80E00E.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe


2009-04-08 21:12:25    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\F23DD467C4AF3AF44F8343F40C5F2CC3.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe


2009-04-08 21:12:26    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\CA62F1D7EC58733B065864DE29291ECB.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe


2009-04-08 21:12:27    创建文件      操作:阻止并结束进程
进程路径:E:\virus\Koobface\32B96EDE7F0E7AFF065D34017BA501AC.exe
文件路径:C:\windows\ld03.exe
触发规则:应用程序规则->02-允许修改的程序->*.*->*\*.exe
黑衣~魂
发表于 2009-4-8 21:13:08 | 显示全部楼层
DW KILL ALL
32B96EDE7F0E7AFF065D34017BA501AC.exe - infected with Trojan.Popuper.14483
5E4802415D245EAAC383772110BEFAAC.exe - infected with Trojan.Proxy.origin
910E8BD20D7CE6E9F197E887F1C15B31.exe - infected with Trojan.Popuper.14483
CA62F1D7EC58733B065864DE29291ECB.exe - infected with Trojan.Proxy.origin
D20A3B637428F9A1C3C986867E80E00E.exe - infected with Trojan.Popuper.14483
F23DD467C4AF3AF44F8343F40C5F2CC3.exe - infected with Trojan.Proxy.origin
ledled
发表于 2009-4-8 23:45:47 | 显示全部楼层
All to VB
Sebastian
发表于 2009-4-9 06:16:48 | 显示全部楼层
D:\kafan\Koobface.rar/32B96EDE7F0E7AFF065D34017BA501AC.exe         已检测: Worm.Win32.Koobface!IK
D:\kafan\Koobface.rar/5E4802415D245EAAC383772110BEFAAC.exe         已检测: Worm.Win32.Koobface!IK
D:\kafan\Koobface.rar/910E8BD20D7CE6E9F197E887F1C15B31.exe         已检测: Worm.Win32.Koobface!IK
D:\kafan\Koobface.rar/CA62F1D7EC58733B065864DE29291ECB.exe         已检测: Worm.Win32.Koobface!IK
D:\kafan\Koobface.rar/D20A3B637428F9A1C3C986867E80E00E.exe         已检测: Worm.Win32.Koobface!IK
D:\kafan\Koobface.rar/F23DD467C4AF3AF44F8343F40C5F2CC3.exe         已检测: Worm.Win32.Koobface!IK
尤金卡巴斯基
发表于 2009-4-9 16:44:14 | 显示全部楼层
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.fx        G:\Temp\Virus\Koobface.rar/Koobface\D20A3B637428F9A1C3C986867E80E00E.exe//PE_Patch.UPX//UPX               
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.fx        G:\Temp\Virus\Koobface.rar/Koobface\910E8BD20D7CE6E9F197E887F1C15B31.exe//PE_Patch.UPX//UPX               
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.fx        G:\Temp\Virus\Koobface.rar/Koobface\32B96EDE7F0E7AFF065D34017BA501AC.exe//PE_Patch.UPX//UPX               
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.ga        G:\Temp\Virus\Koobface.rar/Koobface\CA62F1D7EC58733B065864DE29291ECB.exe//PE_Patch.UPX//UPX               
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.ga        G:\Temp\Virus\Koobface.rar/Koobface\F23DD467C4AF3AF44F8343F40C5F2CC3.exe//PE_Patch.UPX//UPX               
2009/4/9 16:43:25        已清除        病毒 Net-Worm.Win32.Koobface.ga        G:\Temp\Virus\Koobface.rar/Koobface\5E4802415D245EAAC383772110BEFAAC.exe//PE_Patch.UPX//UPX
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 17:35 , Processed in 0.188642 second(s), 4 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表