查看: 1757|回复: 9
收起左侧

[病毒样本] 2p

[复制链接]
hddu
发表于 2009-5-16 11:31:26 | 显示全部楼层 |阅读模式
2p

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hddu
 楼主| 发表于 2009-5-16 11:33:51 | 显示全部楼层
生成物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Sebastian
发表于 2009-5-16 11:35:34 | 显示全部楼层
D:\kafan\2p\ad.exe
    [DETECTION] Is the TR/Downloader.Gen Trojan
Sebastian
发表于 2009-5-16 11:38:09 | 显示全部楼层

回复 2楼 hddu 的帖子

Starting the file scan:

Begin scan in 'D:\kafan\2pe'
D:\kafan\2pe\s0.exe
    [DETECTION] Is the TR/PSW.LdPinch.jm1 Trojan
    [NOTE]      The file was deleted!
D:\kafan\2pe\s1.exe
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
D:\kafan\2pe\s2.exe
    [DETECTION] Is the TR/Crypt.UPKM.Gen Trojan
    [NOTE]      The file was deleted!
D:\kafan\2pe\s3.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
D:\kafan\2pe\s4.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
        [2] Archive type: CAB (Microsoft)
        --> svchost.exe
          [DETECTION] Is the TR/Dldr.Agent.xsd Trojan
    [NOTE]      The file was deleted!
D:\kafan\2pe\s5.exe
    [DETECTION] Contains recognition pattern of the SPR/AutoIt.Gen program
    [NOTE]      The file was deleted!
D:\kafan\2pe\s6.exe
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!


End of the scan: 2009年5月16日  11:40
Used time: 00:04 Minute(s)

The scan has been done completely.

      1 Scanned directories
     12 Files were scanned
      7 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      7 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      5 Files not concerned
      1 Archives were scanned
      0 Warnings
      7 Notes
schumi小粉
发表于 2009-5-16 11:48:45 | 显示全部楼层
Win32:Microjoin-DE [Trj]
lingbo110120
发表于 2009-5-16 11:51:18 | 显示全部楼层
C:\Users\BOBO\Desktop\2pe\1 - 正常
C:\Users\BOBO\Desktop\2pe\hysetup.exe - 正常
C:\Users\BOBO\Desktop\2pe\s0.exe - 可能是 Win32/TrojanDropper.Agent.NNO 特洛伊木马 的变种 - 扫描完成后再选择处理方式
C:\Users\BOBO\Desktop\2pe\s1.exe - Win32/Agent.PJI 特洛伊木马 - 扫描完成后再选择处理方式
C:\Users\BOBO\Desktop\2pe\s2.exe - Win32/AutoRun.Delf.AK 蠕虫 的变种 - 扫描完成后再选择处理方式
C:\Users\BOBO\Desktop\2pe\s3.exe > FSG v2.0 - 正常
C:\Users\BOBO\Desktop\2pe\s4.exe > UPX v12_m2 > CAB > internet.exe > UPX v12_m2 - 正常
C:\Users\BOBO\Desktop\2pe\s4.exe > UPX v12_m2 > CAB > svchost.exe - Win32/Kryptik.OA.Gen 特洛伊木马
C:\Users\BOBO\Desktop\2pe\s4.exe > CAB > internet.exe > UPX v12_m2 - 正常
C:\Users\BOBO\Desktop\2pe\s4.exe > CAB > svchost.exe - Win32/Kryptik.OA.Gen 特洛伊木马
C:\Users\BOBO\Desktop\2pe\s5.exe > AUTOIT > script.au3 - 正常
C:\Users\BOBO\Desktop\2pe\s5.exe > AUTOIT > file.bin - 正常
C:\Users\BOBO\Desktop\2pe\s6.exe - Win32/Injector.AQ 特洛伊木马 的变种 - 扫描完成后再选择处理方式
C:\Users\BOBO\Desktop\2pe\s7.exe - 正常
布施大行
发表于 2009-5-16 11:59:26 | 显示全部楼层
1楼伞杀之
           [检测]        Is the TR/Downloader.Gen Trojan


2楼伞杀之
          [检测]        Is the TR/PSW.LdPinch.jm1 Trojan
    --> 2pe\s1.exe
      [检测]        Is the TR/Spy.Gen Trojan
    --> 2pe\s2.exe
      [检测]        Is the TR/Crypt.UPKM.Gen Trojan
    --> 2pe\s3.exe
      [检测]        Is the TR/Dropper.Gen Trojan
    --> 2pe\s4.exe
      --> Object
        [2] 压缩文档类型: RSRC
        --> Object
          [3] 压缩文档类型: CAB (Microsoft)
          --> svchost.exe
            [检测]        Is the TR/Dldr.Agent.xsd Trojan
    [注意]        备份创建为 '4a733a48.qua'  ( 隔离 )
    [注意]        此文件已被删除!
SUZAKU
发表于 2009-5-16 13:42:27 | 显示全部楼层
[:26:] 二楼

G DATA 杀出

2pe[1].part1
1个

2pe[1].part2

3个
SUZAKU
发表于 2009-5-16 13:43:37 | 显示全部楼层
1楼杀
1个
feihongtian 该用户已被删除
发表于 2009-5-16 14:47:20 | 显示全部楼层
Result: 1 malware found
Generic.Malware.dld!!.3E1EA864 (virus)
  • C:\Documents and Settings\sk\桌面\virus\16\2p\ad.exe Action: deleted

Result: 4 malware found

MemScan:Trojan.Downloader.JLUS (virus)
  • C:\Documents and Settings\sk\桌面\virus\16\2pe\s0.exe Action: deleted
Generic.Malware.SP!dldspg.29FD65EE (virus)
  • C:\Documents and Settings\sk\桌面\virus\16\2pe\s2.exe Action: deleted
GenPack:Generic.Rincux2.730FD74B (virus)
  • C:\Documents and Settings\sk\桌面\virus\16\2pe\s4.exe Action: deleted
Trojan.Injector.AQ (virus)
  • C:\Documents and Settings\sk\桌面\virus\16\2pe\s6.exe Action: deleted

Scanning Engines:
  • F-Secure Aquarius: 11.00.00, 2009-05-14
  • F-Secure Hydra: 3.08.9080, 2009-05-15
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-12 21:13 , Processed in 0.152703 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表