查看: 2372|回复: 10
收起左侧

[病毒样本] 四样本~~

 关闭 [复制链接]
tonger2003
发表于 2007-3-24 14:36:16 | 显示全部楼层 |阅读模式
四样本~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-3-24 14:39:29 | 显示全部楼层
Scan performed at: 2007-3-24 14:39:38
Scanning Log
NOD32 version 2141 (20070324) NT
Command line: C:\Documents and Settings\EQ2\桌面\~tmp.rar C:\Documents and Settings\EQ2\桌面\miyu03.rar C:\Documents and Settings\EQ2\桌面\nk520.rar C:\Documents and Settings\EQ2\桌面\xxxx.rar
Operating memory - is OK

Date: 24.3.2007  Time: 14:39:42
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\~tmp.rar; C:\Documents and Settings\EQ2\桌面\miyu03.rar; C:\Documents and Settings\EQ2\桌面\nk520.rar; C:\Documents and Settings\EQ2\桌面\xxxx.rar
C:\Documents and Settings\EQ2\桌面\~tmp.rar ?RAR ?~tmp.exe - Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\miyu03.rar ?RAR ?miyu03.exe - a variant of Win32/Agent.NAU worm
Number of scanned files: 8
Number of threats found: 2
Number of files cleaned: 2
Time of completion: 14:39:45 Total scanning time: 3 sec (00:00:03)
蓝色牛仔裤
发表于 2007-3-24 14:39:32 | 显示全部楼层
Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2007-3-22
Start time: 2007-3-24 14:38
Engine(s): KAV engine (AVK 17.3463), BD-Engine (BD 17.5838)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: ~tmp.exe
        In archive: D:\掃描\~tmp.rar
        Status: Virus detected
        Virus: GenPack:Win32.Worm.Viking.IZ (BD-Engine)
Object: ~tmp.rar
        Path: D:\掃描
        Status: Virus detected
        Virus: GenPack:Win32.Worm.Viking.IZ (BD-Engine)
Object: xxxx.exe
        In archive: D:\掃描\xxxx.rar
        Status: Suspected virus
        Virus: Trojan.Downloader.Gen (BD-Engine)
Object: xxxx.rar
        Path: D:\掃描
        Status: Suspected virus
        Virus: Trojan.Downloader.Gen (BD-Engine)
Analysis complete: 2007-3-24 14:38
    4 files checked
    1 infected files detected
    1 suspected files detected
mofunzone
发表于 2007-3-24 14:40:32 | 显示全部楼层
漏掉了一个。。

Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\xxxx.rar'
C:\Documents and Settings\morgan\My Documents\
  xxxx.rar
    [0] Archive type: RAR
    --> xxxx.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\morgan\My Documents\~tmp.rar'
C:\Documents and Settings\morgan\My Documents\
  ~tmp.rar
    [0] Archive type: RAR
    --> ~tmp.exe
        [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\morgan\My Documents\miyu03.rar'
C:\Documents and Settings\morgan\My Documents\
  miyu03.rar
    [0] Archive type: RAR
    --> miyu03.exe
        [DETECTION] Is the Trojan horse TR/Drop.Agent.atw.4
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\morgan\My Documents\nk520.rar'
C:\Documents and Settings\morgan\My Documents\
  nk520.rar
    [0] Archive type: RAR
    --> nk520.exe
mofunzone
发表于 2007-3-24 14:41:06 | 显示全部楼层
nk520里面的东西
<html>
<head>
<title>卡巴斯基反病毒 7.0 测试版</title>
</head>
<body>
<h1>卡巴斯基反病毒 7.0 测试版</h1>
<p>The requested URL <u>http://jipin.818qq.cn/nk/nk520.exe</u> is forbidden</p>
</body>
</html>
shmily512099
发表于 2007-3-24 14:42:02 | 显示全部楼层
微点报警了。。。。。。

为什么那个XXXX占CPU呢  有点怪。。。。难道是系统有问题拉!!!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2007-3-24 14:43:15 | 显示全部楼层
真正的nk520

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-3-24 14:45:39 | 显示全部楼层
Scan performed at: 2007-3-24 14:45:55
Scanning Log
NOD32 version 2141 (20070324) NT
Command line: C:\Documents and Settings\EQ2\桌面\nk520.rar
Operating memory - is OK

Date: 24.3.2007  Time: 14:45:59
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\nk520.rar
C:\Documents and Settings\EQ2\桌面\nk520.rar ?RAR ?nk520.exe - probably a variant of Win32/Agent.NEO trojan
Number of scanned files: 2
Number of threats found: 1
Number of files cleaned: 1
Time of completion: 14:46:00 Total scanning time: 1 sec (00:00:01)
蓝色牛仔裤
发表于 2007-3-24 14:46:10 | 显示全部楼层
Object: nk520.exe
        In archive: D:\掃描\nk520.rar
        Status: Virus detected
        Virus: Backdoor.Win32.Agent.ahj (KAV engine), Backdoor.Hupigon.YBJ (BD-Engine)
马力
发表于 2007-3-24 16:56:08 | 显示全部楼层
驱逐舰一个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 02:16 , Processed in 0.130202 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表