12
返回列表 发新帖
楼主: kingmuro
收起左侧

[病毒样本] 一些……

[复制链接]
xxl
发表于 2009-7-23 17:41:54 | 显示全部楼层
Kaspersky Lab
拒绝访问
无法返回请求的网页

试图访问的网页:

http://bbs.kafan.cn/attachment.php?aid=
587166&k=592f5434743b52b250851699059d90f
2&t=1248341992

被以下病毒感染:Backdoor.Win32.Agent.aixh



创建日期:
2009-7-23 17:41:05
Kaspersky Lab


2009-7-23 17:40:44        检测到威胁: Trojan-Dropper.Win32.Agent.avww        Internet Explorer                http://bbs.kafan.cn/attachment.p ... 1248341992//b/a/002[1].exe//ASPack                       
2009-7-23 17:40:44        被拒绝: Trojan-Dropper.Win32.Agent.avww        Internet Explorer                http://bbs.kafan.cn/attachment.p ... 1248341992//b/a/002[1].exe//ASPack                       
2009-7-23 17:41:05        检测到威胁: Backdoor.Win32.Agent.aixh        Internet Explorer                http://bbs.kafan.cn/attachment.p ... 92//b/a/RtmgtxC.dll                       
2009-7-23 17:41:05        被拒绝: Backdoor.Win32.Agent.aixh        Internet Explorer                http://bbs.kafan.cn/attachment.p ... 92//b/a/RtmgtxC.dll
cemetery
发表于 2009-7-23 17:46:07 | 显示全部楼层
a2 kill 27
haol
发表于 2009-7-23 18:50:30 | 显示全部楼层
drweb found 31 threats
黑衣~魂
发表于 2009-7-23 19:04:23 | 显示全部楼层
descript.ion-CLEAN

dr.web清空

002.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.31967;Deleted.;
002[1].exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.31967;Deleted.;
002____0.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.31967;Deleted.;
003.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.31967;Deleted.;
003[1].exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.31967;Deleted.;
J001.exe\data001;C:\Documents and Settings\all\桌面\b\b\a\J001.exe;BackDoor.Siggen.138;;
J001.exe\data002;C:\Documents and Settings\all\桌面\b\b\a\J001.exe;Trojan.DownLoad.12520;;
J001.exe;C:\Documents and Settings\all\桌面\b\b\a;Container contains infected objects;Invalid path to file ;
J001.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.origin;Renamed.;
J002.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002[1].exe;C:\Documents and Settings\all\桌面\b\b\a;Probably DLOADER.Trojan;Renamed.;
J002___0.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___1.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___2.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___3.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___4.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___5.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___6.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
J002___7.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.23267;Deleted.;
oasnp.exe;C:\Documents and Settings\all\桌面\b\b\a;Probably DLOADER.Trojan;Deleted.;
RemrtmC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RimvtcC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RjmwtrC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RjmwttC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RlmqtvC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RtmgtxC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RumjtgC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
RwmbtwC.dll;C:\Documents and Settings\all\桌面\b\b\a;BackDoor.Siggen.138;Deleted.;
Scanner[1].dll;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.32750;Deleted.;
scanner[2].dll;C:\Documents and Settings\all\桌面\b\b\a;Trojan.MulDrop.32750;Deleted.;
svchost.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.DownLoad.40392;Deleted.;
svchost0.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.DownLoad.40392;Deleted.;
svchost1.exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.DownLoad.40392;Deleted.;
svchost[2].exe;C:\Documents and Settings\all\桌面\b\b\a;Trojan.DownLoad.40392;Deleted.;

[ 本帖最后由 黑衣~魂 于 2009-7-23 19:05 编辑 ]
sam.to
发表于 2009-7-24 12:32:28 | 显示全部楼层
您好,


descript.ion

以上文件不包含恶意代码。

J001.exe - Backdoor.Win32.Agent.ajdg

以上文件包含恶意代码,下次更新即可查杀。感谢您的上报。

J002.exe,
J002___0.exe,
J002___1.exe,
J002___2.exe,
J002___3.exe,
J002___4.exe,
J002___5.exe,
J002___6.exe,
J002___7.exe - Backdoor.Win32.Agent.ajcg
Scanner[1].dll,
scanner[2].dll - Exploit.Win32.SqlShell.i

以上文件卡巴斯基已经可以查杀,请您更新病毒库。
Lelouch
发表于 2009-7-24 13:20:44 | 显示全部楼层
伊卡璐斯漏三个
descript.ion,Scanner[1].dll,
scanner[2].dll
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-17 19:28 , Processed in 0.099720 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表