查看: 2956|回复: 7
收起左侧

[病毒样本] 不幸中了baidu

[复制链接]
arlthea
发表于 2007-3-29 10:59:58 | 显示全部楼层 |阅读模式
今天早上也不知道怎么搞的,就上了百度还有新浪,竟然中毒了
用蜘蛛一查,发现还中了不少,windows文件夹下面俨然躺着"bar.exe"(再次鄙视一下baidu)
还有在IE文件夹下面有几个好像是盗QQ的,都发上来了,大家看下袄。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jlennon
头像被屏蔽
发表于 2007-3-29 11:12:25 | 显示全部楼层
扫描报告
2007年3月29日 11:12:11 - 11:12:14
计算机名称: 0553A719C5644CE
扫描类型: 扫描目标
目标: C:\Documents and Settings\Administrator\桌面\bar.rar


--------------------------------------------------------------------------------

结果: 发现 1 恶意软件
Trojan-PSW.Win32.QQPass.sg (病毒)
C:\Documents and Settings\Administrator\桌面\bar.rar\isignup.sys




--------------------------------------------------------------------------------

统计信息
已扫描:
文件: 7
尚未扫描: 0
结果:
病毒: 1
间谍软件: 0
可疑项目: 0
危险软件: 0
操作:
已杀毒: 0
已重命名: 0
已删除邮件: 0
已隔离: 0
失败: 0
启动扇区:
已扫描: 0
已感染: 0
可疑项目: 0
已杀毒: 0


--------------------------------------------------------------------------------

选项
定义版本:
病毒: 2007-03-29_02
间谍软件: 2007-03-29_01
扫描引擎:
F-Secure AVP: 7.00.171, 2007-03-29
F-Secure Libra: 2.04.01, 2007-03-24
F-Secure Orion: 1.02.37, 2007-03-29
F-Secure Draco: 1.00.35, 2007-03-26
扫描选项:
扫描所有文件
扫描内部存档
操作:
病毒: 扫描后询问
间谍软件: 扫描后询问

--------------------------------------------------------------------------------

版权 © 1998-2007 产品支持 | 发送病毒样本到 F-Secure
jlennon
头像被屏蔽
发表于 2007-3-29 11:15:36 | 显示全部楼层
Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2007-3-25
Start time: 2007-3-29 11:16
Engine(s): KAV engine (AVK 17.3527), BD-Engine (BD 17.2421)
Heuristic: On
Archives: On
System areas: On
Check system areas...
Check selected directories and files...
Object: (NSIS o) bzip2_solid_nsis0001
In archive: C:\Documents and Settings\Administrator\桌面\bar\bar.exe
Status: Virus detected
Virus: Adware.Baidubar.P (BD-Engine)
Object: (NSIS o) bzip2_solid_nsis0003
In archive: C:\Documents and Settings\Administrator\桌面\bar\bar.exe
Status: Virus detected
Virus: Adware.Baidubar.J (BD-Engine)
Object: bar.exe
Path: C:\Documents and Settings\Administrator\桌面\bar
Status: Virus could not be removed
Virus: Adware.Baidubar.P, Adware.Baidubar.J (BD-Engine)
Object: isignup.dll
Path: C:\Documents and Settings\Administrator\桌面\bar
Status: Virus could not be removed
Virus: Generic.Malware.SFBdld.0DD76DAB (BD-Engine)
Analysis complete: 2007-3-29 11:16
    6 files checked
    2 infected files detected
    0 suspected files detected

[ 本帖最后由 jlennon 于 2007-3-29 11:17 编辑 ]
mofunzone
发表于 2007-3-29 11:22:39 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\bar.rar'
C:\Documents and Settings\morgan\My Documents\
  bar.rar
    [0] Archive type: RAR
    --> bar.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Baidu.N
        [WARNING]   Infected files in archives cannot be repaired!
    --> updaterrun.exe
        [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Toolbar.Baidu.B
        [WARNING]   Infected files in archives cannot be repaired!
    --> isignup.dll
        [DETECTION] Contains signature of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> isignup.exe
    --> isignup.sys
        [DETECTION] Is the Trojan horse TR/PSW.51485
        [WARNING]   Infected files in archives cannot be repaired!
    --> isignup.bak
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
gggh
发表于 2007-3-29 12:29:30 | 显示全部楼层
kis 杀了...
The EQs
发表于 2007-3-29 13:20:52 | 显示全部楼层
Scan performed at: 2007-3-29 13:20:44
Scanning Log
NOD32 version 2152 (20070328) NT
Command line: C:\Documents and Settings\EQ2\桌面\bar.rar
Operating memory - is OK

Date: 29.3.2007  Time: 13:20:48
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\bar.rar
C:\Documents and Settings\EQ2\桌面\bar.rar ?RAR ?bar.exe ?NSIS ?superutilbar.dll - Win32/Adware.Toolbar.Baidu application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\bar.rar ?RAR ?updaterrun.exe - a variant of Win32/Adware.Toolbar.Baidu application
C:\Documents and Settings\EQ2\桌面\bar.rar ?RAR ?isignup.dll - probably a variant of Win32/PSW.QQShou trojan
C:\Documents and Settings\EQ2\桌面\bar.rar ?RAR ?isignup.sys - probably a variant of Win32/PSW.QQShou trojan
C:\Documents and Settings\EQ2\桌面\bar.rar ?RAR ?isignup.bak - probably a variant of Win32/PSW.QQShou trojan
Number of scanned files: 7
Number of threats found: 5
Number of files cleaned: 1
Time of completion: 13:20:50 Total scanning time: 2 sec (00:00:02)
XinDOS
发表于 2007-3-29 20:46:12 | 显示全部楼层
卡巴搞定

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
95518
发表于 2007-3-29 21:08:38 | 显示全部楼层
avast不让下载
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-18 10:29 , Processed in 0.125286 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表