查看: 2585|回复: 10
收起左侧

[病毒样本] 四个样本~~~~

[复制链接]
tonger2003
发表于 2007-4-14 16:32:27 | 显示全部楼层 |阅读模式
0000000000000

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
soul20010
发表于 2007-4-14 16:34:12 | 显示全部楼层
BitDefender Antivirus Plus v10
g3.rar=>g3.exe        Suspect: BehavesLike:Trojan.StartPage
g0ld.rar=>g0ld.com        Infected: Trojan.Downloader.Delf.PS
The EQs
发表于 2007-4-14 16:35:19 | 显示全部楼层
Scan performed at: 2007-4-14 16:35:32
Scanning Log
NOD32 version 2187 (20070413) NT
Command line: C:\Documents and Settings\EQ2\桌面\ss.rar C:\Documents and Settings\EQ2\桌面\f2.rar C:\Documents and Settings\EQ2\桌面\g0ld.rar C:\Documents and Settings\EQ2\桌面\g3.rar
Operating memory - is OK

Date: 14.4.2007  Time: 16:35:36
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\ss.rar; C:\Documents and Settings\EQ2\桌面\f2.rar; C:\Documents and Settings\EQ2\桌面\g0ld.rar; C:\Documents and Settings\EQ2\桌面\g3.rar
C:\Documents and Settings\EQ2\桌面\ss.rar ?RAR ?ss.dll - Win32/Small.MW trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\f2.rar ?RAR ?f2.exe - probably a variant of Win32/TrojanDownloader.Agent.BBB trojan
C:\Documents and Settings\EQ2\桌面\g0ld.rar ?RAR ?g0ld.com - a variant of Win32/Delf.AG worm
C:\Documents and Settings\EQ2\桌面\g3.rar ?RAR ?g3.exe - a variant of Win32/Rootkit.Agent.NAU trojan
Number of scanned files: 8
Number of threats found: 4
Number of files cleaned: 4
Time of completion: 16:35:37 Total scanning time: 1 sec (00:00:01)
scottxzt
发表于 2007-4-14 16:38:01 | 显示全部楼层
f2,g3,二文件红伞没查出.

[ 本帖最后由 scottxzt 于 2007-4-14 16:40 编辑 ]
红心王子
发表于 2007-4-14 16:40:06 | 显示全部楼层
AntiVir PersonalEdition Classic
Report file date: 2007年4月14日  16:35

Scanning for 738317 virus strains and unwanted programs.

Licensed to:      Avira AntiVir PersonalEdition Classic
Serial number:    0000149996-ADJIE-0001
Platform:         Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Username:         swq
Computer name:    SWQ-5BF4F52C320

Version information:
BUILD.DAT    : 217           12749 Bytes   2006-12-5 17:00:00
AVSCAN.EXE   : 7.0.3.5      208936 Bytes   2007-4-13 06:03:20
AVSCAN.DLL   : 7.0.3.1       35880 Bytes   2006-12-5 09:00:24
LUKE.DLL     : 7.0.3.2      143400 Bytes  2006-10-31 09:07:48
LUKERES.DLL  : 7.0.2.0        9256 Bytes   2006-12-5 09:00:24
ANTIVIR0.VDF : 6.35.0.1    7371264 Bytes   2006-5-31 08:30:08
ANTIVIR1.VDF : 6.37.1.151  4303360 Bytes   2007-2-23 06:03:22
ANTIVIR2.VDF : 6.38.0.214   729600 Bytes   2007-4-12 08:28:26
ANTIVIR3.VDF : 6.38.0.219    22016 Bytes   2007-4-13 08:11:06
AVEWIN32.DLL : 7.3.1.52    2404864 Bytes   2007-4-14 08:11:06
AVPREF.DLL   : 7.0.2.0       23592 Bytes   2006-11-3 03:53:46
AVREP.DLL    : 6.38.0.210  1232936 Bytes   2007-4-13 06:03:22
AVRPBASE.DLL : 7.0.0.0     2162728 Bytes   2006-3-30 01:43:32
AVPACK32.DLL : 7.3.0.8      360488 Bytes   2007-4-13 06:03:22
AVREG.DLL    : 7.0.1.2       30760 Bytes   2007-4-13 06:03:20
NETNT.DLL    : No Information!
RCIMAGE.DLL  : 7.0.1.3     2097192 Bytes   2006-11-8 05:26:28
RCTEXT.DLL   : 7.0.12.1      77864 Bytes   2006-12-5 09:00:22

Configuration settings for the scan:
Jobname..........................: ShlExt
Configuration file...............: C:\DOCUME~1\swq\LOCALS~1\Temp\1825589a.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: off
Scan registry....................: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Expanded search settings.........: 0x00000032

Start of the scan: 2007年4月14日  16:35

Start scanning boot sectors:
Boot sector 'C:\'
      [NOTE]      No virus was found!

Starting the file scan:

Begin scan in 'C:\Documents and Settings\swq\桌面\f2.rar'
Begin scan in 'C:\Documents and Settings\swq\桌面\g0ld.rar'
C:\Documents and Settings\swq\桌面\g0ld.rar
  [0] Archive type: RAR
  --> g0ld.com
      [DETECTION] Contains signature of the construction kit KIT/Delf.AG.2.A
      [INFO]      The file was deleted!
Begin scan in 'C:\Documents and Settings\swq\桌面\g3.rar'


End of the scan: 2007年4月14日  16:36
Used time: 00:44 min

The scan has been done completely.

      0 Scanning directories
      6 Files were scanned
      1 viruses and/or unwanted programs were found
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      5 Files not concerned
      3 Archives were scanned
      0 Warnings
      0 Notes

最后一个被江民的监控拦截了,直接清除了病毒

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
bridgewr
发表于 2007-4-14 16:40:42 | 显示全部楼层
除了一个dll,还有运行后就释放了一个sys在系统目录下,主程序退出,没有其他的动作。另外2个杀

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
harry_chang2003
头像被屏蔽
发表于 2007-4-14 18:46:24 | 显示全部楼层
PCC 2007殺兩隻
欠妳緈諨
发表于 2007-4-14 20:14:38 | 显示全部楼层
f2,g3,avast!也过
promised
发表于 2007-4-14 20:38:54 | 显示全部楼层
g3 beta蜘蛛挂了
caocao
发表于 2007-4-14 20:43:53 | 显示全部楼层
KIS只报一个
已删除: 木马程序 Backdoor.Win32.Small.mw        文件: D:\Downloads\ss.rar\ss.dll
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 13:57 , Processed in 0.137506 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表