查看: 4614|回复: 11
收起左侧

[病毒样本] 同学电脑上扫出来一碓病毒 飞塔回复最快

[复制链接]
起点
发表于 2007-1-29 09:08:59 | 显示全部楼层 |阅读模式
下面这个有点意思,其他估计都是老病毒了,不过这个已经上报avira 为  faulse positive 了
  1. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\
  2. Content.IE5\WXYBGD6N\liveexup[1].cab
  3.   [0] Archive type: CAB (Microsoft)
  4.   --> alLiveEx.dll
  5.       [DETECTION] Contains suspicious code HEUR/Malware
  6.       [INFO]      The file was moved to '46333fc2.qua'!
复制代码


最近试着上报了一些杀软,回复速度 Fortinet  > Avira Antivir >= Kaspersky

  1. 飞塔的回复Dear Navigateqd,

  2. Our analysts have analyzed the samples you provided. We will add detection for them in the next update.

  3. The sample you submitted will be detected as follows:

  4. 0524-bt130[1].swf -- Adware/Small
  5. helperup[1].cab          -- Spy/Agent
  6. keepmainM[1].cab --  Misc/PUP
  7. CnsMinExM[1].cab --  Adware/Cnsmin

  8. Best Regards,

  9. AV Lab - Lzxia

  10. To submit a suspicious file to Fortinet:
  11. http://www.fortinet.com/FortiGuardCenter/virus_scanner.html
复制代码




  1. Antivir Scan Report

  2. Starting the file scan:
  3. Begin scan in 'C:\'
  4. C:\WINDOWS\system32\cns.exe
  5.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  6.       [INFO]      The file was deleted!
  7. C:\WINDOWS\system32\cns.dll
  8.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  9.       [INFO]      The file was moved to '46303f1a.qua'!
  10. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W9ENS12F\helperup[1].cab
  11.   [0] Archive type: CAB (Microsoft)
  12.   --> helper.dll
  13.       [DETECTION] Is the Trojan horse TR/Dldr.Agen.rs.2.A
  14.       [INFO]      The file was moved to '46293fa7.qua'!
  15. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W9ENS12F\keepmainM[1].cab
  16.   [0] Archive type: CAB (Microsoft)
  17.   --> cns1.dll
  18.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  19.   --> cns1.exe
  20.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  21.   --> cnsminkp.vxd
  22.       [DETECTION] Contains signature of the application APPL/Inst.Yok.6
  23.       [INFO]      The file was moved to '46223fa8.qua'!
  24. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W9ENS12F\patch21[1].cab
  25.   [0] Archive type: CAB (Microsoft)
  26.   --> patch21.dll
  27.       [DETECTION] Is the Trojan horse TR/Agent.PS.1
  28.       [INFO]      The file was moved to '46313fa6.qua'!
  29. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W9ENS12F\0524-bt130[1].swf
  30.       [DETECTION] Contains the SWF virus SWF/Small.B
  31.       [INFO]      The file was moved to '45ef3f7c.qua'!
  32. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYNOH6Z\askeepmain[1].cab
  33.   [0] Archive type: CAB (Microsoft)
  34.   --> cns1.dat
  35.       [DETECTION] Contains signature of the application APPL/Inst.Yok.3
  36.   --> CNS1.dll
  37.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  38.   --> CNS1.exe
  39.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  40.   --> CnsMinKP2K.sys
  41.       [DETECTION] Is the Trojan horse TR/Agent.BJJ
  42.   --> CnsminKP.vxd
  43.       [DETECTION] Contains signature of the application APPL/Inst.Yok.6
  44.       [INFO]      The file was moved to '46283fc1.qua'!
  45. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYNOH6Z\CnsMinUpM[1].cab
  46.   [0] Archive type: CAB (Microsoft)
  47.   --> CnsMin.dll
  48.       [DETECTION] Is the Trojan horse TR/Drop.ZSKiller.1
  49.       [INFO]      The file was moved to '46303fbd.qua'!
  50. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYNOH6Z\CnsMinExM[1].cab
  51.   [0] Archive type: CAB (Microsoft)
  52.   --> CnsMinEx.dll
  53.       [DETECTION] Is the Trojan horse TR/Dloader.Q
  54.       [INFO]      The file was moved to '47a3f0aa.qua'!
  55. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYNOH6Z\keepmainM[1].cab
  56.   [0] Archive type: CAB (Microsoft)
  57.   --> cns1.dll
  58.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  59.   --> cns1.exe
  60.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  61.   --> cnsminkp.vxd
  62.       [DETECTION] Contains signature of the application APPL/Inst.Yok.6
  63.       [INFO]      The file was moved to '46223fb5.qua'!
  64. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WXYBGD6N\liveexup[1].cab
  65.   [0] Archive type: CAB (Microsoft)
  66.   --> alLiveEx.dll
  67.       [DETECTION] Contains suspicious code HEUR/Malware
  68.       [INFO]      The file was moved to '46333fc2.qua'!
  69. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W9ANSPYR\helperup[1].cab
  70.   [0] Archive type: CAB (Microsoft)
  71.   --> helper.dll
  72.       [DETECTION] Is the Trojan horse TR/Dldr.Agen.rs.2.A
  73.       [INFO]      The file was moved to '46293fc8.qua'!
  74. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP4\A0000484.dll
  75.       [DETECTION] Is the Trojan horse TR/Dldr.Agen.rs.2.A
  76.       [INFO]      The file was moved to '45ed4064.qua'!
  77. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP4\A0000490.exe
  78.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  79.       [INFO]      The file was moved to '447dfea1.qua'!
  80. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP4\A0000491.dll
  81.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  82.       [INFO]      The file was moved to '45ed4066.qua'!
  83. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP5\A0000649.DLL
  84.       [DETECTION] Contains suspicious code HEUR/Malware
  85.       [INFO]      The file was moved to '45ed4067.qua'!
  86. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP5\A0000796.dll
  87.       [DETECTION] Is the Trojan horse TR/Dldr.Agen.rs.2.A
  88.       [INFO]      The file was moved to '45ed406a.qua'!
  89. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP6\A0001011.exe
  90.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  91.       [INFO]      The file was moved to '45ed406e.qua'!
  92. C:\System Volume Information\_restore{36F871F3-CC96-46CA-9A5F-49F788BA0279}\RP6\A0001012.dll
  93.       [DETECTION] Is the Trojan horse TR/Dldr.Baido
  94.       [INFO]      The file was moved to '45ed406f.qua'!
  95. Begin scan in 'D:\'
  96. D:\pagefile.sys
  97.       [WARNING]   The file could not be opened!
  98. Begin scan in 'E:\'
  99. Begin scan in 'A:\'
  100. The path A:\ could not be found!
  101. 设备未就绪。
  102. Begin scan in 'F:\'
  103. The path F:\ could not be found!
  104. 设备未就绪。
复制代码

[ 本帖最后由 navigateqd 于 2007-1-29 10:35 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
asdasd
发表于 2007-1-29 09:11:01 | 显示全部楼层
LZ能发几个厉害的病毒吗?


我想试试.


现在的病毒都类似阳痿... 没有一点刺激性啊.


LZ发点厉害的.
丫头
发表于 2007-1-29 09:11:04 | 显示全部楼层
拿去玩玩~~~~
起点
 楼主| 发表于 2007-1-29 09:26:34 | 显示全部楼层
原帖由 asdasd 于 2007-1-29 09:11 发表
LZ能发几个厉害的病毒吗?


我想试试.


现在的病毒都类似阳痿... 没有一点刺激性啊.


LZ发点厉害的.

这个需要找自己电脑上有“病毒库”的,不过传播病毒是违法的
希望大家发扬本仅仅用于上报
shx19821006
发表于 2007-1-29 16:30:53 | 显示全部楼层
偶的红伞干掉了
hsjj2005
发表于 2007-1-30 13:02:07 | 显示全部楼层
费尔如图。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
waterou
发表于 2007-1-30 16:58:51 | 显示全部楼层
阳痿。。。某楼的兄弟真牛啊~
景圣临
发表于 2007-1-30 17:45:35 | 显示全部楼层
3721?
泊远
发表于 2007-2-18 20:16:32 | 显示全部楼层
一点飞塔就拦截了
ALEXBLAIR
发表于 2007-2-18 21:50:57 | 显示全部楼层
卡巴对3721 cns这些东西不感兴趣
那个flash被检测为Trojan program Trojan-Clicker.SWF.Small.a
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-6 10:13 , Processed in 0.136201 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表