查看: 4164|回复: 15
收起左侧

[病毒样本] 18

[复制链接]
dearhaoji
发表于 2009-6-20 15:24:18 | 显示全部楼层 |阅读模式
.................................................mm.exe生成、、

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hj5abc
发表于 2009-6-20 15:35:06 | 显示全部楼层
avira left 3 ..
clamwin ..


Scan Started Sat Jun 20 15:32:19 2009
-------------------------------------------------------------------------------


G:\xxx\2_0.exe: Trojan.Dropper-1805 FOUND
G:\xxx\sys3E.tmp: Trojan.Dropper-1805 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 575069
Engine version: 0.95.2
Scanned directories: 1
Scanned files: 18
Infected files: 2

Data scanned: 3.07 MB
Data read: 1.59 MB (ratio 1.93:1)
Time: 14.047 sec (0 m 14 s)
--------------------------------------
Completed
--------------------------------------
kingmuro
头像被屏蔽
发表于 2009-6-20 16:01:30 | 显示全部楼层

KAV6.0

已检测:广告程序 not-a-virus:AdWare.Win32.AdMedia.ed        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\2_0.exe
已检测:广告程序 not-a-virus:AdWare.Win32.BHO.hmc        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\7_0.exe//stream//data0001
已检测:木马程序 Trojan.Win32.BHO.sfi        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\customsat.dll
已检测:木马程序 Exploit.Win32.IMG-WMF.fk        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\explorer.exe//PE_Patch//UPack//PE-Crypt.Morf
已检测:广告程序 not-a-virus:AdWare.Win32.Cinmus.auxo        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\google.dll
已检测:木马程序 Trojan.Win32.AntiAV.bim        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\MSGSCR.TLB
已检测:木马程序 Trojan.Win32.AntiAV.bim        文件:D:\My Documents\桌面\test\X.rar/新建文件夹 (2)\msmsgs.dll
已检测:木马程序 Trojan-Dropper.Win32.Agent.aome        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\19_0.exe//FSG
已检测:木马程序 Trojan-GameThief.Win32.OnLineGames.vcqj        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\88_0.exe//NSPack//PE-Crypt.Morf
已检测:广告程序 not-a-virus:AdWare.Win32.AdMedia.ed        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\sys3E.tmp
已检测:广告程序 not-a-virus:AdWare.Win32.BHO.hmc        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\sys3F.tmp//stream//data0001
已检测:木马程序 Trojan-GameThief.Win32.OnLineGames.vcqj        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\sys45.tmp//NSPack//PE-Crypt.Morf
已检测:广告程序 not-a-virus:AdWare.Win32.BHO.hmc        文件:D:\My Documents\桌面\test\Y.rar/新建文件夹\sys3F.tmp
kingmuro
头像被屏蔽
发表于 2009-6-20 16:04:42 | 显示全部楼层
2_0.exe/data003\data003;D:\My Documents\桌面\test\X\新建文件夹 (2)\2_0.exe/data003;Trojan.Popwin.1160;;
data003;D:\My Documents\桌面\test\X\新建文件夹 (2);Archive contains infected objects;;
2_0.exe;D:\My Documents\桌面\test\X\新建文件夹 (2);Archive contains infected objects;;
360box.exe;D:\My Documents\桌面\test\X\新建文件夹 (2);Trojan.Sniff;;
7_0.exe\data002;D:\My Documents\桌面\test\X\新建文件夹 (2)\7_0.exe;Trojan.SoftPush.1;;
7_0.exe;D:\My Documents\桌面\test\X\新建文件夹 (2);Archive contains infected objects;;
explorer.exe;D:\My Documents\桌面\test\X\新建文件夹 (2);Trojan.Siggen.564;;
google.dll;D:\My Documents\桌面\test\X\新建文件夹 (2);Trojan.Popwin.1160;;
11_0.exe;D:\My Documents\桌面\test\X\新建文件夹;Trojan.Siggen.564;;
19_0.exe;D:\My Documents\桌面\test\X\新建文件夹;Trojan.Inject.5729;;
88_0.exe;D:\My Documents\桌面\test\X\新建文件夹;Trojan.Sniff.101;;
sys3E.tmp/data003\data003;D:\My Documents\桌面\test\X\新建文件夹\sys3E.tmp/data003;Trojan.Popwin.1160;;
data003;D:\My Documents\桌面\test\X\新建文件夹;Archive contains infected objects;;
sys3E.tmp;D:\My Documents\桌面\test\X\新建文件夹;Archive contains infected objects;;
sys3F.tmp\data002;D:\My Documents\桌面\test\X\新建文件夹\sys3F.tmp;Trojan.SoftPush.1;;
sys3F.tmp;D:\My Documents\桌面\test\X\新建文件夹;Archive contains infected objects;;
sys45.tmp;D:\My Documents\桌面\test\X\新建文件夹;Trojan.Sniff.101;;
大蜘蛛     17个
kingmuro
头像被屏蔽
发表于 2009-6-20 16:06:22 | 显示全部楼层
kv2008

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2009-6-20 16:10:04 | 显示全部楼层
miss 4, to kl
残缺的唯美
发表于 2009-6-20 16:15:54 | 显示全部楼层
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\sys3E.tmp Adware.Generic.53220 Delete Failed (file was in an archive)
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\11_0.exe DeepScan:Generic.Malware.dldspTkg.25D51E1F Disinfect Failed (file was in an archive)
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\sys48.tmp Dropped:Application.BHO.Zhongsou.A Disinfect Failed
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\sys3F.tmp Dropped:Application.Generic.51726 Disinfect Failed
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\88_0.exe GenPack:Trojan.Dropper.SZV Disinfect Failed (file was in an archive)
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\sys45.tmp GenPack:Trojan.Dropper.SZV Disinfect Failed
C:\Users\ekincheng\Desktop\Y.rar=]新建文件夹\19_0.exe Trojan.Generic.1857079 Delete Failed (file was in an archive)

C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\2_0.exe Adware.Generic.53220 Delete Failed (file was in an archive)
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\google.dll DeepScan:Generic.Adw.Cinmus.2.62D62188 Disinfect Failed
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\9_0.exe Dropped:Application.BHO.Zhongsou.A Disinfect Failed
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\7_0.exe Dropped:Application.Generic.51726 Disinfect Failed
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\dll3C.tmp Generic.Malware.SP!Pk!Tkg.9CBCEFDF Disinfect Failed
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\360box.exe Trojan.Agent.AHKC Delete Failed (file was in an archive)
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\explorer.exe Trojan.Crypt.GQ Disinfect Failed


Objects that were not scanned:Object Name Reason Final Status
C:\Users\ekincheng\Desktop\X.rar=]新建文件夹 (2)\SA.PIF=]照片 .exe Password-protected Not scanned
悠柚
发表于 2009-6-20 16:56:05 | 显示全部楼层
mpav 15ge
3个to
残缺的唯美
发表于 2009-6-20 21:29:51 | 显示全部楼层
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\11_0.exe - probably a variant of Win32/Genetik trojan
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\88_0.exe - a variant of Win32/TrojanDropper.Delf.NIN trojan
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\sys3E.tmp » NSIS » 235.exe » NSIS » 龏? - Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\sys3F.tmp » NSIS » cpush.dll - a variant of Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\sys3F.tmp » NSIS » Uninst.exe - Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\sys45.tmp - a variant of Win32/TrojanDropper.Delf.NIN trojan
C:\Users\ekincheng\Desktop\Y.rar » RAR » 新建文件夹\sys48.tmp » NSIS » IETimber.dll - Win32/Adware.Zhongsou application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\2_0.exe » NSIS » 235.exe » NSIS » 龏? - Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\360box.exe - Win32/NetTool.Agent.B potentially unsafe application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\7_0.exe » NSIS » cpush.dll - a variant of Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\7_0.exe » NSIS » Uninst.exe - Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\9_0.exe » NSIS » IETimber.dll - Win32/Adware.Zhongsou application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\customsat.dll - Win32/BHO.SFI trojan
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\dll3C.tmp - probably a variant of Win32/AutoRun.Agent.IE worm
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\explorer.exe - Win32/Exploit.MS08-067.A trojan
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\google.dll - Win32/Adware.Cinmus application
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\MSGSCR.TLB - Win32/BHO.SFI trojan
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\msmsgs.dll - Win32/BHO.SFI trojan
C:\Users\ekincheng\Desktop\X.rar » RAR » 新建文件夹 (2)\SA.PIF » RAR » 照片                                                                                                                                                                .exe - Incorrect file checksum (CRC); the file is probably password protected.
luxiao200888
发表于 2009-6-20 21:34:38 | 显示全部楼层

回复 2楼 hj5abc 的帖子

clamwin....

慢慢体会
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-18 06:13 , Processed in 0.129028 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表