查看: 3821|回复: 10
收起左侧

[病毒样本] 【5+5+5】

[复制链接]
schumi小粉
发表于 2009-6-7 13:31:12 | 显示全部楼层 |阅读模式
C:\Documents and Settings\Administrator\桌面\新建文件夹\P3\DRIVER\DRIVER.exe - Win32/Adware.Agent.NKI 应用程序
C:\Documents and Settings\Administrator\桌面\新建文件夹\P3\Setup\Setup.exe - Win32/TrojanClicker.VB.COJ 特洛伊木马
C:\Documents and Settings\Administrator\桌面\新建文件夹\P1\Autorun[1].inf\Autorun.inf.exe - Win32/Adware.Agent.NKI 应用程序
C:\Documents and Settings\Administrator\桌面\新建文件夹\P1\bad\bad\bad.exe - 未查明的 NewHeur_PE 病毒
C:\Documents and Settings\Administrator\桌面\新建文件夹\P1\media[1]\media[1].htm - 可能是 JS/TrojanDownloader.Agent 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\2\2 > NSIS > jah35521.exe - Win32/Kryptik.BT 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\bd\bd.exe > RAR > setup1.exe - Win32/VB.OAF 特洛伊木马
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\bd\bd.exe > RAR > setup2.exe - Win32/VB.OAE 特洛伊木马
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\bd\bd.exe > RAR > setup.exe - Win32/TrojanDownloader.VB.NWS 特洛伊木马
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\kille\KillE.exe - Win32/Agent.PID 特洛伊木马
C:\Documents and Settings\Administrator\桌面\新建文件夹\P2\Setup2\Setup.exe - Win32/TrojanClicker.VB.COJ 特洛伊木马

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2009-6-7 13:35:39 | 显示全部楼层
7/6/2009 13:36:24        Detected: Worm.Win32.AutoRun.stz        C:\Documents and Settings\kato\桌面\P2.rar/P2\2\2/stream/data0001               
7/6/2009 13:36:24        Processing error: Worm.Win32.AutoRun.stz        C:\Documents and Settings\kato\桌面\P2.rar/P2\2\2/stream               
7/6/2009 13:36:25        Detected: Trojan-Downloader.Win32.Agent.bpza        C:\Documents and Settings\kato\桌面\P2.rar/P2\bd\bd.exe/setup.exe/PE_Patch.UPX/UPX               
7/6/2009 13:36:25        Detected: Trojan.Win32.Agent2.hbn        C:\Documents and Settings\kato\桌面\P2.rar/P2\kille\KillE.exe               
7/6/2009 13:36:25        Detected: Trojan.Win32.Agent.brcv        C:\Documents and Settings\kato\桌面\P2.rar/P2\Setup2\Setup.exe/winhost.exe               
7/6/2009 13:36:27        Detected: not-a-virus:AdWare.Win32.Agent.hyz        C:\Documents and Settings\kato\桌面\P3.rar/P3\DRIVER\DRIVER.exe               
7/6/2009 13:36:48        Detected: Trojan.Win32.Agent.brcv        C:\Documents and Settings\kato\桌面\P3.rar/P3\Setup\Setup.exe/winhost.exe               
7/6/2009 13:36:57        Detected: not-a-virus:AdWare.Win32.Agent.hyz        C:\Documents and Settings\kato\桌面\P1.rar/P1\Autorun[1].inf\Autorun.inf.exe               
7/6/2009 13:37:05        Detected: Trojan-Downloader.Win32.Agent.aubs        C:\Documents and Settings\kato\桌面\P1.rar/P1\bad\bad\bad.exe               
7/6/2009 13:37:05        Detected: Trojan-Downloader.JS.Agent.cyp        C:\Documents and Settings\kato\桌面\P1.rar/P1\media[1]\media[1].htm               


to kl

[ 本帖最后由 sam.to 于 2009-6-7 13:37 编辑 ]

评分

参与人数 1人气 +1 收起 理由
schumi小粉 + 1 又看见可爱的可达鸭了~~

查看全部评分

hahacomcn
发表于 2009-6-7 14:54:31 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\F31\桌面\P1.rar'
C:\Documents and Settings\F31\桌面\P1.rar
  [0] Archive type: RAR
    [NOTE]      A backup was created as '4a596442.qua'  ( QUARANTINE )
    [WARNING]   The file was ignored!
    --> P1\Autorun[1].inf\Autorun.inf.exe
      [DETECTION] Contains recognition pattern of the ADSPY/Agent.hyz adware or spyware
    --> P1\bad\bad\bad.exe
      [DETECTION] Is the TR/Dldr.Sket.A Trojan
    --> P1\media[1]\media[1].htm
      [DETECTION] Contains recognition pattern of the HTML/Shellcode.Gen HTML script virus
Begin scan in 'C:\Documents and Settings\F31\桌面\P2.rar'
C:\Documents and Settings\F31\桌面\P2.rar
  [0] Archive type: RAR
    [NOTE]      A backup was created as '4a596443.qua'  ( QUARANTINE )
    [WARNING]   The file was ignored!
    --> P2\kille\KillE.exe
      [DETECTION] Is the TR/Drop.Cingo.B Trojan
    --> P2\Setup2\Setup.exe
      [DETECTION] Contains recognition pattern of the DR/Agent.xbc dropper
    --> P2\2\2
      [1] Archive type: NSIS
      [DETECTION] Contains recognition pattern of the DR/AutoRun.stz dropper
      --> ProgramFilesDir/jah35521.exe
        [DETECTION] Contains recognition pattern of the WORM/Autorun.stz worm
    --> P2\bd\bd.exe
      [1] Archive type: RAR SFX (self extracting)
      [DETECTION] Contains recognition pattern of the DR/Dldr.Agent.bpza dropper
      --> setup.exe
        [DETECTION] Is the TR/Dldr.Agent.bpza Trojan
Begin scan in 'C:\Documents and Settings\F31\桌面\P3.rar'
C:\Documents and Settings\F31\桌面\P3.rar
  [0] Archive type: RAR
    [NOTE]      A backup was created as '4a596444.qua'  ( QUARANTINE )
    [WARNING]   The file was ignored!
    --> P3\DRIVER\DRIVER.exe
      [DETECTION] Contains recognition pattern of the ADSPY/Agent.hyz adware or spyware
    --> P3\LT-RUNNER\LT-RUNNER.EXE
      [DETECTION] Contains recognition pattern of the SPR/FireWallPass program
    --> P3\PnpWmkDrv\PnpWmkDrv.sys
      [DETECTION] Contains recognition pattern of the RKIT/Agent.GZ root kit
    --> P3\Setup\Setup.exe
      [DETECTION] Contains recognition pattern of the DR/Agent.xbc dropper


End of the scan: 2009年6月7日  14:54
Used time: 00:00 Minute(s)

The scan has been done completely.

      0 Scanned directories
     27 Files were scanned
     13 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
sam.to
发表于 2009-6-7 16:25:27 | 显示全部楼层
Hello,


110(2).dll,
C.exe,
LT-RUNNER.EXE,
PnpWmkDrv.sys,
wuauclt.exe

No malicious code were found in these files.

110.dll

This file is corrupted.
黑衣~魂
发表于 2009-6-7 19:56:18 | 显示全部楼层
DR.WEB
2\data002;C:\Documents and Settings\all\桌面\P2\P2\2\2;Trojan.Clb.23;;
2;C:\Documents and Settings\all\桌面\P2\P2\2;Archive contains infected objects;Deleted.;
bad.exe;C:\Documents and Settings\all\桌面\P1\P1\bad\bad;Modification of Win32.HLLM.Generic.349;Deleted.;
2.exe;C:\Documents and Settings\all\桌面;BackDoor.Beizhu.2655;Deleted.;
kingmuro
头像被屏蔽
发表于 2009-6-7 20:23:18 | 显示全部楼层

KAV6.0 6月7日

已删除:广告程序 not-a-virus:AdWare.Win32.Agent.hyz        文件:D:\My Documents\桌面\test\P1.rar/P1\Autorun[1].inf\Autorun.inf.exe
已删除:木马程序 Trojan-Downloader.Win32.Agent.aubs        文件:D:\My Documents\桌面\test\P1.rar/P1\bad\bad\bad.exe
已删除:木马程序 Trojan-Downloader.JS.Agent.cyp        文件:D:\My Documents\桌面\test\P1.rar/P1\media[1]\media[1].htm
已删除:病毒 Worm.Win32.AutoRun.stz        文件:D:\My Documents\桌面\test\P2.rar/P2\2\2//stream//data0001
已删除:木马程序 Trojan-Downloader.Win32.Agent.bpza        文件:D:\My Documents\桌面\test\P2.rar/P2\bd\bd.exe/setup.exe//PE_Patch.UPX//UPX
已删除:木马程序 Trojan.Win32.Agent2.hbn        文件:D:\My Documents\桌面\test\P2.rar/P2\kille\KillE.exe
已删除:木马程序 Trojan.Win32.Agent.brcv        文件:D:\My Documents\桌面\test\P2.rar/P2\Setup2\Setup.exe//winhost.exe
已删除:广告程序 not-a-virus:AdWare.Win32.Agent.hyz        文件:D:\My Documents\桌面\test\P3.rar/P3\DRIVER\DRIVER.exe
已删除:木马程序 Trojan.Win32.Agent.brcv        文件:D:\My Documents\桌面\test\P3.rar/P3\Setup\Setup.exe//winhost.exe
已删除:木马程序 Trojan.Win32.Agent.brcv        文件:D:\My Documents\桌面\test\P3.rar/P3\Setup\Setup.exe
kingmuro
头像被屏蔽
发表于 2009-6-7 20:27:37 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kingmuro
头像被屏蔽
发表于 2009-6-7 20:28:41 | 显示全部楼层
蜘蛛2个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
悠柚
发表于 2009-6-7 20:45:30 | 显示全部楼层
D:\TDDownload\P1.rar/110.dll         已检测: Trojan-Spy.XUW!IK
D:\TDDownload\P1.rar/Autorun.inf.exe         已检测: Riskware.AdWare.Win32.Agent!IK
D:\TDDownload\P1.rar/bad.exe         已检测: Trojan-Dropper.Agent!IK
D:\TDDownload\P1.rar/media[1].htm         已检测: Trojan-Downloader.JS.Agent!IK
D:\TDDownload\P2.rar/jah35521.exe         已检测: Worm.Win32.AutoRun!IK
D:\TDDownload\P2.rar/bd.exe         已检测: Trojan-Dropper.Agent!IK
D:\TDDownload\P2.rar/KillE.exe         已检测: Trojan-Dropper.Cingo!IK
D:\TDDownload\P2.rar/Setup.exe         已检测: Trojan-Downloader.Win32.Small!IK
D:\TDDownload\P3.rar/C.exe         已检测: Trojan-Dropper.Win32.Delf!IK
D:\TDDownload\P3.rar/DRIVER.exe         已检测: Riskware.AdWare.Win32.Agent!IK
D:\TDDownload\P3.rar/LT-RUNNER.EXE         已检测: Virus.Win32.Spyware!IK
D:\TDDownload\P3.rar/PnpWmkDrv.sys         已检测: Virus.Win32.AdWare!IK
D:\TDDownload\P3.rar/Setup.exe         已检测: Trojan-Downloader.Win32.Small!IK
BING126
头像被屏蔽
发表于 2009-6-7 21:19:13 | 显示全部楼层
McAfee 报了11个。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-18 04:20 , Processed in 0.144593 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表