查看: 3287|回复: 19
收起左侧

[病毒样本] 28个 (来自美国和阿拉伯大型毒窟)

[复制链接]
sam.to
发表于 2009-12-21 20:45:05 | 显示全部楼层 |阅读模式
本帖最后由 sam.to 于 2009-12-22 16:41 编辑

129253ddf268f6e519dd1e2d48a6c564  A1551.exe_
51b7efb2c10d9395fae39062c8c83cc7  startup-shutdown-sound.exe_
abc874c86bfa73b8c7a6be78ebeb91cc  wh_19387680.exe_
15b0cbc9f2daa9cdb2e8cf04429e0fed  wh_19400972.exe_
86b1e671781adebf62fd2d58598952bc  wh_19407166.exe_
095cf9c6bb9245cc25fe756602799963  wh_19435336.exe_
6343a94c0c5654c79a5f5b57260d65dc  wh_19437397.exe_
a9af943a1e599f3354e553bc82098c86  wh_19456634.exe_
754c81ae1591f38559bc0d535f67435d  wh_19508360.exe_
3f307bebc82111fef33b6c350a90123d  wh_19520284.exe_
db6ddfa67607f83847a6e02229c58cbd  wh_19526720.exe_
96c58b19971312ce05da62fe4e8553d4  wh_19621790.exe_
089699cd95cce14fb763ca9368d9abf1  wh_19805819.exe_
372e137eb4147df6c376545c5829b7f2  wh_19806974.exe_
f647baf2985f11fc797bbe978f5853f5  wh_19869122.exe_
df329056e08a4fe16a6bfbba11ab46d4  wh_19887972.exe_
5c683645121514b89d56f3703d49c957  wh_20037267.exe_
39f09619d9a98475330268e5fa1e09df  wh_20066317.exe_
2ac1013e12d5cccdb690d54d0f6f0459  wh_20075106.exe_
b0774184f312199883c4334fa21d3100  wh_20160797.exe_
d449973c671846d3def8c063987bc8a1  wh_20191714.exe_
e1f12cc49598a504b912da4570d91022  wh_20216905.exe_
3b112018a95e0973aa0c478f5b9194b9  wh_20267532.exe_
529f3960f8c5c48b99adca00b29bddb0  wh_20268193.exe_
997492498e602a51ea1ddbf1c334ba9e  wh_20324751.exe_
f0952488bdc43c3de775a2654856ddff  wh_20384071.exe_
c0c990ce629c1178a07c107fb21efb0f  wh_20422945.exe_
6d8c83a54d8e99df9e1fee14f61f073c  wh_20431987.exe_


卡巴报大部分(heur)

to kl,ll



Hello,

A1551.exe_ - Trojan.Win32.Refroso.aakx,

wh_19387680.exe_ - Trojan.Win32.Buzus.cuun,

wh_19400972.exe_,
wh_19526720.exe_.proxy.exe_ - Trojan.Win32.Buzus.cuxi,

wh_19407166.exe_.SeRvEr.exe_,
wh_20267532.exe_.SeRvEr.exe_ - Trojan.Win32.Midgare.aioe,

wh_19437397.exe_ - Trojan.Win32.Refroso.aalc,

wh_19456634.exe_ - Trojan-Dropper.MSIL.Agent.ajv,

wh_19508360.exe_ - Trojan-Downloader.Win32.Zudz.bq,

wh_19520284.exe_ - Backdoor.Win32.Poison.bcmd,

wh_19621790.exe_ - Trojan.Win32.Refroso.aali,

wh_19805819.exe_ - Backdoor.Win32.Bifrose.bzqd,

wh_19806974.exe_ - Trojan-Downloader.Win32.VB.tnd,

wh_19869122.exe_ - Trojan.Win32.Refroso.aalj,

wh_19887972.exe_ - Backdoor.Win32.Poison.bcmi,

wh_20037267.exe_ - Trojan.Win32.Refroso.aalk,

wh_20066317.exe_ - Trojan.Win32.Refroso.aala,

wh_20075106.exe_ - Trojan.Win32.Refroso.aall,

wh_20160797.exe_ - Trojan.Win32.Refroso.aalm,

wh_20191714.exe_ - Backdoor.Win32.Bifrose.bzqg,

wh_20267532.exe_.7maya.bat_ - Trojan.BAT.KillAV.nn,

wh_20267532.exe_.deep.bat_ - Trojan-Downloader.BAT.Agent.ci,

wh_20324751.exe_ - Trojan.Win32.Buzus.cuuy,

wh_20384071.exe_.cam.exe_ - Trojan-Dropper.Win32.Stabs.gnk,

wh_20422945.exe_.IMG_0375.exe_ - Trojan.Win32.Agent.demc,

wh_20431987.exe_ - Trojan.Win32.Refroso.aalx

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

startup-shutdown-sound.exe_

No malicious code was found in this file.

wh_19435336.exe_ - Trojan-Downloader.Win32.Pher.xx,

wh_20216905.exe_ - Trojan.Win32.DelfInject.b,

wh_20268193.exe_.Dos.exe_,
wh_20268193.exe_.kabo.exe_ - Backdoor.Win32.IRCBot.jvw

These files are detected at this moment. Please update your antivirus bases.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

--
Best regards,
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ray1106
发表于 2009-12-21 20:48:21 | 显示全部楼层
A2+红伞 剩余2个
kanfaner
头像被屏蔽
发表于 2009-12-21 20:49:40 | 显示全部楼层
本帖最后由 kanfaner 于 2009-12-21 21:10 编辑

互补没漏

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kaibuliaokou
头像被屏蔽
发表于 2009-12-21 21:00:17 | 显示全部楼层
金山毒霸kill 25个···
kingmuro
头像被屏蔽
发表于 2009-12-21 22:15:27 | 显示全部楼层
avast                                 27个
2009-12-21 22:12:57        GXF        2576        Sign of "Win32:Inject-UZ [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\A1551.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Trojan-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19387680.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Buzus-AAQ [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19400972.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Midgare-VB [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19407166.exe_\SeRvEr.exe" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Zbot-LWU [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19437397.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Trojan-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19456634.exe_\[Embedded_I#012f4]\CRYPTE~1.EXE" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Trojan-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19508360.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Buzus-AAQ [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19526720.exe_\proxy.exe" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Malware-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19621790.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Midgare-VB [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19805819.exe_" file.  
2009-12-21 22:13:00        GXF        2576        Sign of "Win32:Spyware-gen [Spy]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19869122.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:PoisonIvy-IU [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_19887972.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Trojan-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20037267.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Refroso-F [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20066317.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Bifrose-EDW [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20075106.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Bifrose-DYN [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20160797.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Midgare-VB [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20191714.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Delf-MTG [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20216905.exe_\rgdgfdhtfjhhgj.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "BV:Agent-AO [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20267532.exe_\deep.bat" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Midgare-VB [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20267532.exe_\SeRvEr.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:IRCBot-DMI [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20268193.exe_\Dos.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:IRCBot-DMI [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20268193.exe_\kabo.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Vitro" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20268193.exe_\?exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Malware-gen" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20324751.exe_" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Crypt-EQS [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20384071.exe_\cam.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:Agent-AFNY [Trj]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20422945.exe_\IMG_0375.exe\2.exe" file.  
2009-12-21 22:13:01        GXF        2576        Sign of "Win32:VB-LXD [Drp]" has been found in "D:\My Documents\桌面\test\4wrsft\4wrsft\wh_20431987.exe_" file.
jianhua_265
发表于 2009-12-21 22:24:11 | 显示全部楼层
毒霸miss  7
中邪
发表于 2009-12-22 00:27:14 | 显示全部楼层
本帖最后由 中邪 于 2009-12-22 00:30 编辑

AVG9.0Free 31个!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
dreams521
发表于 2009-12-22 00:32:55 | 显示全部楼层
回复 1# sam.to

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jason_jiang
发表于 2009-12-22 07:48:50 | 显示全部楼层
drweb missed 5, to
水晶
头像被屏蔽
发表于 2009-12-22 09:10:26 | 显示全部楼层
毒霸10:病毒        2009-12-22  09:09:16        病毒在文件F:\duba\4wrsft\wh_20431987.exe_中        Win32.Hack.Bifrose         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_20191714.exe_中        Win32.Hack.Mnless         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_20160797.exe_中        Win32.Troj.Midgare         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_20075106.exe_中        Worm.DownLoaderT.at         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_20037267.exe_中        Win32.Troj.Refroso         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_19805819.exe_中        Win32.Troj.Poison.c         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_19621790.exe_中        Win32.Troj.IAgent         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_19520284.exe_中        Win32.Troj.Agent.yd         处理成功(操作:删除)       
病毒        2009-12-22  09:09:15        病毒在文件F:\duba\4wrsft\wh_19508360.exe_中        Win32.Troj.Vapsup.d         处理成功(操作:删除)       
病毒        2009-12-22  09:09:14        病毒在文件F:\duba\4wrsft\wh_19400972.exe_中        Win32.Troj.IAgent         处理成功(操作:删除)       
病毒        2009-12-22  09:09:14        病毒在文件F:\duba\4wrsft\wh_19387680.exe_中        Win32.Troj.Injector.JB         处理成功(操作:删除)       
病毒        2009-12-22  09:09:14        病毒在文件F:\duba\4wrsft\A1551.exe_中        Win32.Troj.Refroso         处理成功(操作:删除)       
病毒        2009-12-22  09:08:58        病毒在文件F:\duba\4wrsft\wh_20431987.exe_中        Win32.Hack.Bifrose         处理成功(操作:删除)       
病毒        2009-12-22  09:08:58        病毒在文件F:\duba\4wrsft\wh_20191714.exe_中        Win32.Hack.Mnless         处理成功(操作:删除)       
病毒        2009-12-22  09:08:58        病毒在文件F:\duba\4wrsft\wh_20160797.exe_中        Win32.Troj.Midgare         处理成功(操作:删除)       
病毒        2009-12-22  09:08:58        病毒在文件F:\duba\4wrsft\wh_20075106.exe_中        Worm.DownLoaderT.at         处理成功(操作:删除)       
病毒        2009-12-22  09:08:57        病毒在文件F:\duba\4wrsft\wh_20037267.exe_中        Win32.Troj.Refroso         处理成功(操作:删除)       
病毒        2009-12-22  09:08:57        病毒在文件F:\duba\4wrsft\wh_19805819.exe_中        Win32.Troj.Poison.c         处理成功(操作:删除)       
病毒        2009-12-22  09:08:57        病毒在文件F:\duba\4wrsft\wh_19621790.exe_中        Win32.Troj.IAgent         处理成功(操作:删除)       
病毒        2009-12-22  09:08:57        病毒在文件F:\duba\4wrsft\wh_19520284.exe_中        Win32.Troj.Agent.yd         处理成功(操作:删除)       
病毒        2009-12-22  09:08:57        病毒在文件F:\duba\4wrsft\wh_19508360.exe_中        Win32.Troj.Vapsup.d         处理成功(操作:删除)       
病毒        2009-12-22  09:08:56        病毒在文件F:\duba\4wrsft\wh_19400972.exe_中        Win32.Troj.IAgent         处理成功(操作:删除)       
病毒        2009-12-22  09:08:56        病毒在文件F:\duba\4wrsft\wh_19387680.exe_中        Win32.Troj.Injector.JB         处理成功(操作:删除)       
病毒        2009-12-22  09:08:55        病毒在文件F:\duba\4wrsft\A1551.exe_中        Win32.Troj.Refroso         处理成功(操作:删除)
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 04:24 , Processed in 0.084424 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表