查看: 3479|回复: 10
收起左侧

[病毒样本] 老毒

[复制链接]
The EQs
发表于 2007-3-7 22:23:27 | 显示全部楼层 |阅读模式
1010101

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
小邪邪
发表于 2007-3-7 22:24:44 | 显示全部楼层
又是好几个,敢情是闯进毒窝了? 闪。。
The EQs
 楼主| 发表于 2007-3-7 22:24:56 | 显示全部楼层
Scan performed at: 2007-3-7 22:24:16
Scanning Log
NOD32 version 2100 (20070307) NT
Command line: C:\Documents and Settings\EQ2\桌面\DDIV.rar C:\Documents and Settings\EQ2\桌面\divv.rar C:\Documents and Settings\EQ2\桌面\aaaaa.rar C:\Documents and Settings\EQ2\桌面\Kunbang.rar
Operating memory - is OK

Date: 7.3.2007  Time: 22:24:24
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\DDIV.rar; C:\Documents and Settings\EQ2\桌面\divv.rar; C:\Documents and Settings\EQ2\桌面\aaaaa.rar; C:\Documents and Settings\EQ2\桌面\Kunbang.rar
C:\Documents and Settings\EQ2\桌面\DDIV.rar ?RAR ?DDIV.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\divv.rar ?RAR ?divv.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\aaaaa.rar ?RAR ?aaaaa.exe - Win32/TrojanDownloader.VB.APY trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\Kunbang.rar ?RAR ?Kunbang.exe - Incorrect file checksum (CRC), the file is probably password protected.
Number of scanned files: 7
Number of threats found: 3
Number of files cleaned: 3
Time of completion: 22:24:25 Total scanning time: 1 sec (00:00:01)

Notes:
[7] File is probably infected with an unknown virus.
mofunzone
发表于 2007-3-8 00:04:37 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\Kunbang'
C:\Documents and Settings\Administrator\My Documents\Kunbang\
  Kunbang.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.NSIS.Agent.X
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\aaaaa.rar'
C:\Documents and Settings\Administrator\My Documents\
  aaaaa.rar
    [0] Archive type: RAR
    --> aaaaa.exe
        [DETECTION] Is the Trojan horse TR/Agent.5164
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\DDIV.rar'
C:\Documents and Settings\Administrator\My Documents\
  DDIV.rar
    [0] Archive type: RAR
    --> DDIV.exe
        [DETECTION] Is the Trojan horse TR/PSW.Nilage.aui.1
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\My Documents\divv.rar'
C:\Documents and Settings\Administrator\My Documents\
  divv.rar
    [0] Archive type: RAR
    --> divv.exe
        [DETECTION] Is the Trojan horse TR/PSW.Nilage.aui.2
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年3月7日  08:04
Used time: 00:07 min

The scan has been done completely.

      1 Scanning directories
      7 Files were scanned
      4 viruses and/or unwanted programs were found
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      3 Archives were scanned
      7 Warnings
      0 Notes
jlennon
头像被屏蔽
发表于 2007-3-8 08:09:56 | 显示全部楼层
Virus check with AntiVirusKit
Version 17.0.6282
Virus signatures of 3/6/2007
Start time: 3/8/2007 08:09
Engine(s): Engine A (AVK 17.3103), Engine B (BD 17.2113)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: aaaaa.exe
        In archive: C:\Documents and Settings\Administrator\桌面\aaaaa.rar
        Status: Virus detected
        Virus: Trojan-Downloader.Win32.VB.apy (Engine A), GenPack:Generic.Malware.SBdld!.B9D27C05 (Engine B)
Object: aaaaa.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan-Downloader.Win32.VB.apy (Engine A), GenPack:Generic.Malware.SBdld!.B9D27C05 (Engine B)
Object: DDIV.exe
        In archive: C:\Documents and Settings\Administrator\桌面\DDIV.rar
        Status: Virus detected
        Virus: Trojan.Win32.Agent.abs (Engine A), BehavesLike:Trojan.ShellStartup (Engine B)
Object: DDIV.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan.Win32.Agent.abs (Engine A), BehavesLike:Trojan.ShellStartup (Engine B)
Object: divv.exe
        In archive: C:\Documents and Settings\Administrator\桌面\divv.rar
        Status: Virus detected
        Virus: Trojan.Win32.Agent.abs (Engine A), BehavesLike:Trojan.ShellStartup (Engine B)
Object: divv.rar
        Path: C:\Documents and Settings\Administrator\桌面
        Status: Move file into quarantine
        Virus: Trojan.Win32.Agent.abs (Engine A), BehavesLike:Trojan.ShellStartup (Engine B)
Analysis complete: 3/8/2007 08:09
    4 files checked
    3 infected files detected
    0 suspected files detected
soul20010
发表于 2007-3-8 09:08:30 | 显示全部楼层
FS7.0
Result: 3 malware found
Trojan-Downloader.Win32.VB.apy (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\aaaaa.rar\aaaaa.exe
Trojan.Win32.Agent.abs (virus)
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\DDIV.rar\DDIV.exe
C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\divv.rar\divv.exe
hsjj2005
发表于 2007-3-8 09:53:13 | 显示全部楼层
微点
木马名称:Trojan-Downloader.Win32.Small.eqd

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEX4\AAAAA.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

木马名称:Trojan.Win32.Agent.aqe

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEX5\DDIV.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

恶意程序名称:BadJoke.Win32.Reboot.a

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TWIEX6\DIVV.EXE
是恶意程序!
已成功阻止其运行,是否要删除此文件?

最后一个压缩包加密了未测。
hsjj2005
发表于 2007-3-8 09:54:07 | 显示全部楼层
费尔

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
龙井茶
发表于 2007-3-8 10:38:34 | 显示全部楼层
照这样下去,我们论坛的样本区将会受到各大杀软厂商的光顾.
zls156
发表于 2007-3-8 12:33:43 | 显示全部楼层
第一个和第四个.驱逐舰都查不出来.郁闷
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-10 15:19 , Processed in 0.140808 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表