123
返回列表 发新帖
楼主: Oceanzd
收起左侧

[病毒样本] Temp文件夹发现的~~

[复制链接]
蓝色牛仔裤
发表于 2007-4-18 11:05:04 | 显示全部楼层
beta蜘蛛4个...

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mmmsdsfdx
发表于 2007-5-26 00:03:54 | 显示全部楼层
不知道小红伞怎么样
傻猪猪米走鸡
发表于 2007-5-26 01:04:47 | 显示全部楼层

nod

Scan performed at: 2007-5-26 1:08:43
Scanning Log
NOD32 version 2292 (20070525) NT
Command line: F:\virus\AtiCimUn.rar F:\virus\c0nime.rar F:\virus\byetmr.rar F:\virus\IEXPL0RER(1).rar F:\virus\IEXPL0RER.rar F:\virus\rundl132.rar F:\virus\UPX.rar
C:\Program Files\Eset\nod32.exe - is OK
MBR sector of the 1. physical disk - is OK
Active boot sector of the 1. physical disk - is OK

Date: 26.5.2007  Time: 01:08:45
Anti-Stealth technology is enabled.
Scanned disks, folders and files: F:\virus\AtiCimUn.rar; F:\virus\c0nime.rar; F:\virus\byetmr.rar; F:\virus\IEXPL0RER(1).rar; F:\virus\IEXPL0RER.rar; F:\virus\rundl132.rar; F:\virus\UPX.rar
F:\virus\AtiCimUn.rar ?RAR ?AtiCimUn.exe - probably unknown WIN32 virus [7]
F:\virus\c0nime.rar ?RAR ?c0nime.exe - a variant of Win32/PSW.Agent.NDP trojan
F:\virus\byetmr.rar ?RAR ?byetmr.exe - Win32/Pacex.Gen virus
F:\virus\IEXPL0RER(1).rar ?RAR ?IEXPL0RER(1).VBS - is OK
F:\virus\IEXPL0RER.rar ?RAR ?IEXPL0RER.EXE - probably unknown NewHeur_PE virus [7]
F:\virus\rundl132.rar ?RAR ?rundl132.exe - a variant of Win32/PSW.Agent.NDP trojan
F:\virus\UPX.rar ?RAR ?UPX.EXE - is OK
Number of scanned files: 7
Number of threats found: 5
Time of completion: 01:08:50 Total scanning time: 5 sec (00:00:05)

Notes:
[7] File is probably infected with an unknown virus.
伯夷叔齐
发表于 2007-5-26 02:31:25 | 显示全部楼层
D:\AtiCimUn.rar
  [0] Archive type: RAR
  --> AtiCimUn.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.bkw.28
      [WARNING]   The file was ignored!
Begin scan in 'D:\byetmr.rar'
D:\byetmr.rar
  [0] Archive type: RAR
  --> byetmr.exe
      [DETECTION] Is the Trojan horse TR/PSW.WOW.EC.100
      [WARNING]   The file was ignored!
Begin scan in 'D:\c0nime.rar'
D:\c0nime.rar
  [0] Archive type: RAR
  --> c0nime.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.KW.2
      [WARNING]   The file was ignored!
Begin scan in 'D:\IEXPL0RER.rar'
D:\IEXPL0RER.rar
  [0] Archive type: RAR
  --> IEXPL0RER.EXE
      [DETECTION] Is the Trojan horse TR/Agent.8900
      [WARNING]   The file was ignored!
Begin scan in 'D:\IEXPL0RER(1).rar'
Begin scan in 'D:\rundl132.rar'
D:\rundl132.rar
  [0] Archive type: RAR
  --> rundl132.exe
      [DETECTION] Is the Trojan horse TR/Agent.34708.B
      [WARNING]   The file was ignored!
Begin scan in 'D:\UPX.rar'

End of the scan: 2007年5月26日  02:29
Used time: 00:30 min
The scan has been done completely.
      0 Scanning directories
     21 Files were scanned
      5 viruses and/or unwanted programs were found
      0 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     16 Files not concerned
      7 Archives were scanned
      5 Warnings
      0 Notes
      0 Hidden objects were found
The EQs
发表于 2007-5-26 09:00:20 | 显示全部楼层
Scan performed at: 2007-5-26 8:59:57
Scanning Log
NOD32 version 2292 (20070525) NT
Command line: C:\Documents and Settings\EQ2\桌面\UPX.rar C:\Documents and Settings\EQ2\桌面\AtiCimUn.rar C:\Documents and Settings\EQ2\桌面\c0nime.rar C:\Documents and Settings\EQ2\桌面\byetmr.rar C:\Documents and Settings\EQ2\桌面\IEXPL0RER(1).rar C:\Documents and Settings\EQ2\桌面\IEXPL0RER.rar C:\Documents and Settings\EQ2\桌面\rundl132.rar
Operating memory - is OK

Date: 26.5.2007  Time: 09:00:02
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\UPX.rar; C:\Documents and Settings\EQ2\桌面\AtiCimUn.rar; C:\Documents and Settings\EQ2\桌面\c0nime.rar; C:\Documents and Settings\EQ2\桌面\byetmr.rar; C:\Documents and Settings\EQ2\桌面\IEXPL0RER(1).rar; C:\Documents and Settings\EQ2\桌面\IEXPL0RER.rar; C:\Documents and Settings\EQ2\桌面\rundl132.rar
C:\Documents and Settings\EQ2\桌面\AtiCimUn.rar ?RAR ?AtiCimUn.exe - probably unknown WIN32 virus [7]
C:\Documents and Settings\EQ2\桌面\c0nime.rar ?RAR ?c0nime.exe - a variant of Win32/PSW.Agent.NDP trojan
C:\Documents and Settings\EQ2\桌面\byetmr.rar ?RAR ?byetmr.exe - Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\IEXPL0RER.rar ?RAR ?IEXPL0RER.EXE - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\rundl132.rar ?RAR ?rundl132.exe - a variant of Win32/PSW.Agent.NDP trojan
Number of scanned files: 14
Number of threats found: 5
Number of files cleaned: 5
Time of completion: 09:00:06 Total scanning time: 4 sec (00:00:04)

Notes:
[7] File is probably infected with an unknown virus.
zxy900906
发表于 2007-5-26 09:00:25 | 显示全部楼层
2007-5-26        8:56:56        已删除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\桌面\IEXPL0RER.EXE        W32/Tufik.worm.a (病毒)
2007-5-26        8:56:56        已删除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\Documents and Settings\Administrator\桌面\桌面\IEXPL0RER.EXE        W32/Tufik.worm.a (病毒)
2007-5-26        8:56:57        已删除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\Documents and Settings\Administrator\桌面\桌面\rundl132.exe        PWS-Mmorpg.gen (ED) (特洛伊)
2007-5-26        8:56:57        已清除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\Documents and Settings\Administrator\桌面\桌面\AtiCimUn.exe        W32/Tufik.worm.a!inf (病毒)
2007-5-26        8:56:57        已删除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\桌面\C0NIME.EXE        PWS-LegMir.gen.f (特洛伊)
2007-5-26        8:56:57        已删除         ZXY900906\Administrator        F:\WinRar\WinRAR.exe        C:\Documents and Settings\Administrator\桌面\桌面\c0nime.exe\c0nime.exe        PWS-LegMir.gen.f (特洛伊)

咖啡..
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-2 10:23 , Processed in 0.139632 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表