查看: 2355|回复: 9
收起左侧

[病毒样本] 裸奔一天的结果

[复制链接]
qianwenxiang
发表于 2007-5-18 16:51:14 | 显示全部楼层 |阅读模式
光临时文件夹就这么多了 裸奔害死人啊 ...

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
promised
发表于 2007-5-18 16:52:41 | 显示全部楼层
太肥了
观弈书童
发表于 2007-5-18 17:01:23 | 显示全部楼层
很多都不是毒,有必要发这么一大包上来吗
tonger2003
发表于 2007-5-18 17:04:06 | 显示全部楼层
卡7未开启发扫描的结果

已删除: 木马程序 Trojan-Downloader.Win32.Delf.bgt        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\[ASPack].exe//ASPack
已删除: 病毒 Virus.Win32.Delf.aq        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\[NsPack].exe
已删除: 木马程序 Trojan-Downloader.Win32.Banload.anp        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\1263.exe//PE_Patch.PECompact//PecBundle//PECompact
已删除: 木马程序 Trojan.Win32.VB.axk        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\2121.exe//PE_Patch//UPack
已删除: 广告软件 not-a-virus:AdWare.Win32.Boran.w        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\ad_1430.exe//data0002
已删除: 木马程序 Trojan-Downloader.Win32.Cryptic.hg        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\bind_50006.exe//PE_Patch.UPX//UPX//PE_Patch//data0002
已删除: 木马程序 Trojan-Downloader.Win32.Agent.bcd        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\cf02.exe//PE_Patch.UPX//UPX//stream//data0001//PE_Patch.UPX//UPX
已删除: 木马程序 Trojan-Downloader.Win32.Agent.bcc        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\cf02.exe//PE_Patch.UPX//UPX//stream//data0003
已删除: 木马程序 Trojan.Win32.Agent.afb        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\cf02.exe//PE_Patch.UPX//UPX//stream//data0004
已删除: 广告软件 not-a-virus:AdWare.Win32.Cinmus.j        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\dodolook043.exe//data0003//data0004
已删除: 广告软件 not-a-virus:AdWare.Win32.WSearch.a        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\mUninstall.exe
已删除: 木马程序 Trojan.Win32.VB.azs        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\myTroj.exe//FSG
已删除: 病毒 Worm.Win32.Delf.bd        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\setup2.exe/setup.exe
已删除: 广告软件 not-a-virus:AdWare.Win32.WSearch.j        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\setup.exe//PE_Patch.PECompact//PecBundle//PECompact
已删除: 广告软件 not-a-virus:AdWare.Win32.Dm.g        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\tool.exe/tool.exe
已删除: 木马程序 Trojan.Win32.Zapchast.ct        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\wang3.exe//data0002
已删除: 木马程序 Trojan.Win32.Zapchast.ct        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\wang3.exe//data0003
已删除: 木马程序 Trojan-Dropper.Win32.VB.od        文件: C:\Documents and Settings\Administrator\桌面\~dtu[1]\yqu[1].exe
坐在墙头
发表于 2007-5-18 18:15:04 | 显示全部楼层
楼主裸奔上不健康网站啦吧?
我裸奔半年都没遇见你这么多
欠妳緈諨
发表于 2007-5-18 18:21:53 | 显示全部楼层
太肥了,咽不下!
jlennon
头像被屏蔽
发表于 2007-5-18 18:27:42 | 显示全部楼层
-----------------------------SCAN REPORT-----------------------------
F-PROT Antivirus for Windows

Antivirus Scanning Engine version number: 4.3.3
Virus signature file from: 2007-5-17, 2:20

Scan name: [Custom Scan]
Path to scan: C:\Documents and Settings\Administrator\桌面\~dtu[1].part07.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part06.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part08.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part09.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part01.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part02.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part04.rar|C:\Documents and Settings\Administrator\桌面\~dtu[1].part05.rar

Normal scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2007-5-18, 18:27:06
---------------------------------------------------------------------

[Unscannable]        <File is damaged>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part08.rar->setup2.exe
[Found adware]         <W32/Adware.EHO (exact, not disinfectable)>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part08.rar->tool.exe->tool.exe
[Contains infected objects]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part08.rar
[Quarantined]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part08.rar->W95INF32.DLL
[Found possible virus]         <W32/Threat-IKNP-based!Maximus (not disinfectable)>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar->[NsPack].exe
[Found downloader]         <W32/Downloader.CFVA (exact, not disinfectable)>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar->1263.exe
[Found possible virus]         <W32/Threat-SysVenFakU-based!Maximus (not disinfectable)>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar->2121.exe
[Contains infected objects]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar
[Quarantined]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part03.rar->ad_1430.exe
[Found downloader]         <W32/Downloader.BBGW (exact, not disinfectable)>        C:\Documents and Settings\Administrator\桌面\~dtu[1].part04.rar->cf02.exe->(UPX)
[Contains infected objects]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part04.rar
[Quarantined]        C:\Documents and Settings\Administrator\桌面\~dtu[1].part04.rar->cf02.exe->(UPX)

---------------------------------------------------------------------
Scan ended:        2007-5-18, 18:27:15
Duration:        0:00:09

Scan result:

Scanned files:                 9
Infected objects:         5
Disinfected objects:         0
Quarantined files:         3
---------------------------------------------------------------------
pcvirus
发表于 2007-5-18 19:55:05 | 显示全部楼层
楼主,你上的都是什么网啊,现在的virus有那么多么
mofunzone
发表于 2007-5-19 12:37:10 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\~dtu'
C:\Documents and Settings\morgan\My Documents\~dtu\
  1263.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
  2001.exe
      [DETECTION] Is the Trojan horse TR/Drop.BHO.12854
      [INFO]      The file was deleted!
  2121.exe
      [DETECTION] Is the Trojan horse TR/VB.SJ.721
      [INFO]      The file was deleted!
  ADVPACK.DLL
  ad_1430.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Boran.XSS
      [INFO]      The file was deleted!
  agent.ini
  BaiduBar.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/ToolBar.B.B.1
      [INFO]      The file was deleted!
  bind_50006.exe
  cf02.exe
  cnnic.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Cdnup.A.1
      [INFO]      The file was deleted!
  coopen_setup_51239.exe
  dach1des00.dll
  db.pdb
  dodolook043.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/Drop.Cinmus.P
      [INFO]      The file was deleted!
  eAPI.fne
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '469e7f17.qua'!
  eBayISAPI[1].dll
    [0] Archive type: GZ
    --> eBayISAPI[1]
  gert0.dll
  iext.fnr
  install.inf
  main.pdb
  mUninstall.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/WSearch.2
      [INFO]      The file was deleted!
  myTroj.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46a27f50.qua'!
  npf.sys
  Packet.dll
  PacketSniffer.exe
  REGBACK.EXE
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46957f1c.qua'!
  regsvr32.exe
  Sc.exe
  setup.exe
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/WSearch.O
      [INFO]      The file was deleted!
  setup2.exe
    [0] Archive type: CAB (Microsoft)
    --> setup.exe
        [DETECTION] Contains code of the Windows virus W32/Delf.aq.1
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      The file was deleted!
  shell.fne
  sleep.exe
  System.dll
  tool.exe
      [DETECTION] Contains signature of the dropper DR/Agent.asa.2
      [INFO]      The file was deleted!
  Uninstall.exe
  unp168007273.tmp
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/ToolBar.B.B.1
      [INFO]      The file was deleted!
  W95INF16.DLL
  W95INF32.DLL
  wang3.exe
  WanPacket.dll
  wpcap.dll
  xplib.fne
  yqu[1].exe
      [DETECTION] Is the Trojan horse TR/Agent.53196.B
      [INFO]      The file was deleted!
  [ASPack].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
  [NsPack].exe
      [DETECTION] Contains signature of the Windows virus W32/Delf.aq.1
      [INFO]      The file was deleted!
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\0\
  Juggle Mouse.exe
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\1\
  Help.htm
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\2\
  Theme Builder.exe
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\3\
  background.gif
  jfaq.htm
  juggle.gif
  left.htm
  main.htm
  part1.htm
  part10.htm
  part2.htm
  part3.htm
  part4.htm
  part5.htm
  part6.htm
  part7.htm
  part8.htm
  part9.htm
  screen1.gif
  screen2.gif
  screen3.gif
  smallarrow.gif
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\4\
  Blue.thm
  pic.gif
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\5\
  Fruit.thm
  part1.gif
  part2.gif
  part3.gif
  part4.gif
  part5.gif
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\6\
  COMCTL32.OCX
C:\Documents and Settings\morgan\My Documents\~dtu\data\{F6FDA4F3-06B2-4C0E-A0AC-8EDF97164A5D}\7\
  MAGE.DLL
C:\Documents and Settings\morgan\My Documents\~dtu\lng\
  Enu.lng
C:\Documents and Settings\morgan\My Documents\~dtu\plugins\0\
  StdUI.dll
C:\Documents and Settings\morgan\My Documents\~dtu\plugins\0\lng\
  Enu.lng
C:\Documents and Settings\morgan\My Documents\~dtu\presetup\
  App.ins
  Gins.bmp
  Gins.ini
  License.rtf
  Readme.rtf


End of the scan: 2007年5月18日  21:36
Used time: 00:16 min

The scan has been done completely.

     16 Scanning directories
     87 Files were scanned
     18 viruses and/or unwanted programs were found
      3 classified as suspicious:
     15 files were deleted
      0 files were repaired
      3 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     66 Files not concerned
      2 Archives were scanned
      1 Warnings
      0 Notes
      0 Hidden objects were found
jeremy600832
发表于 2007-5-19 12:45:46 | 显示全部楼层
瑞星共10个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 22:20 , Processed in 0.132331 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表