12
返回列表 发新帖
楼主: zh94518
收起左侧

[病毒样本] 过卡巴的鸽子

[复制链接]
wangjay1980
发表于 2007-5-27 14:28:35 | 显示全部楼层
detected: Trojan program Backdoor.Win32.Hupigon.wi        URL: http://bbs.kafan.cn/attachment.php?aid=76651//G_07.exe
真幽默
caocao
发表于 2007-5-27 14:32:39 | 显示全部楼层
原帖由 红心王子 于 2007-5-27 13:19 发表
探测到: 木马程序 Backdoor.Win32.Hupigon.wi        文件: C:\Documents and Settings\Administrator\桌面\G_07.rar/G_07.exe
并没有过啊
卡巴7报了

是啊,不能过卡巴7
剑指七星
发表于 2007-5-27 15:00:31 | 显示全部楼层
卡6报
已检测到: 木马程序 Backdoor.Win32.Hupigon.wi        URL: http:/bbs.kafan.cn/attachment.php?aid=76651/G_07.exe
firelife
发表于 2007-5-27 17:47:09 | 显示全部楼层
被熊猫抓到,HOHO,,
沸沸
发表于 2007-5-27 18:34:53 | 显示全部楼层
小红伞居然没报诶
3480071
发表于 2007-5-27 18:46:25 | 显示全部楼层
惨了,NOD没反应,风云防火墙也连屁都不放一个,这个鸽子怎么跟B2轰炸机似的没影了,贴出报告,高手看下。


  1. 2007-05-27,18:32:20

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  18.     <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [(Verified)"ESET, spol. s r.o."]
  19.     <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
  20.     <FY_FireWall><C:\Program Files\FengYun\FYFireWall.exe>  [[url]www.218.cc[/url]]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  22.     <mspspabsp><C:\WINDOWS\system32\mspspabsp.exe>  []
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  25.     <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
  26.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]

  27. ==================================
  28. 启动文件夹
  29. N/A

  30. ==================================
  31. 服务
  32. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Disabled]
  33.   <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
  34. [Human Interface Device Access / HidServ][Stopped/Disabled]
  35.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  36. [NOD32 Kernel Service / NOD32krn][Running/Auto Start]
  37.   <"C:\Program Files\Eset\nod32krn.exe"><Eset>
  38. [Shadow System Service / ShadowSystemService][Stopped/Manual Start]
  39.   <C:\WINDOWS\system32\shadow\ShadowService.exe><N/A>
  40. [SRS Labs License Service / SRS Labs License Service][Stopped/Disabled]
  41.   <"C:\Program Files\Common Files\SRS Labs Shared\Service\srslabslicenseservice.exe"><N/A>
  42. [Sysbak hotkey Server / Sysbak_hotkey_Server][Stopped/Manual Start]
  43.   <><N/A>

  44. ==================================
  45. 驱动程序
  46. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  47.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  48. [AliIde / AliIde][Stopped/Boot Start]
  49.   <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
  50. [AMON / AMON][Running/Auto Start]
  51.   <\SystemRoot\system32\drivers\amon.sys><Eset>
  52. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  53.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  54. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  55.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  56. [CmdIde / CmdIde][Running/Boot Start]
  57.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  58. [FYTdifltDrv / FYTdifltDrv][Running/System Start]
  59.   <\??\C:\Program Files\FengYun\FYTdiDrv.sys><N/A>
  60. [ialm / ialm][Running/Manual Start]
  61.   <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
  62. [MegaIDE / MegaIDE][Running/Boot Start]
  63.   <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
  64. [nod32drv / nod32drv][Running/System Start]
  65.   <\SystemRoot\system32\drivers\nod32drv.sys><N/A>
  66. [npkcrypt / npkcrypt][Running/Auto Start]
  67.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  68. [nv / nv][Stopped/Manual Start]
  69.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  70. [PauseDrv / PauseDrv][Stopped/Manual Start]
  71.   <\??\C:\WINDOWS\system32\Drivers\PauseDrv.sys><N/A>
  72. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  73.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  74. [PxHelp20 / PxHelp20][Running/Boot Start]
  75.   <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
  76. [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
  77.   <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
  78. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  79.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  80. [Secdrv / Secdrv][Stopped/Manual Start]
  81.   <system32\DRIVERS\secdrv.sys><N/A>
  82. [SRS Labs Audio Sandbox (WDM) / SRS_SSCFilter][Running/Manual Start]
  83.   <system32\drivers\srs_sscfilter.sys><>
  84. [ViaIde / ViaIde][Running/Boot Start]
  85.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>

  86. ==================================
  87. 浏览器加载项
  88. [Web Browser Applet Control]
  89.   {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\Msjava.dll, Microsoft Corporation>
  90. [PeerDraw 类]
  91.   {10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation>
  92. [Windows Genuine Advantage Validation Tool]
  93.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft Corporation>
  94. [Windows Media Player]
  95.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  96. [HTML Document]
  97.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
  98. [Microsoft Office Control]
  99.   {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~2\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
  100. [HHCtrl Object]
  101.   {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
  102. [Shell Name Space]
  103.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
  104. [WUWebControl Class]
  105.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  106. [Windows Media Player]
  107.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  108. [360SafeLive]
  109.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <F:\360safe\live.dll, 360safe.COM>
  110. [Microsoft Web 浏览器]
  111.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  112. [Microsoft Scriptlet Component]
  113.   {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
  114. [SearchAssistantOC]
  115.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  116. [Microsoft DirectAnimation Control]
  117.   {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} <C:\WINDOWS\system32\danim.dll, Microsoft Corporation>
  118. [RDS.DataSpace]
  119.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  120. [AUDIO__MID Moniker Class]
  121.   {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  122. [AUDIO__MP3 Moniker Class]
  123.   {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  124. [AUDIO__WAV Moniker Class]
  125.   {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  126. [AUDIO__X_MS_WMA Moniker Class]
  127.   {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  128. [VIDEO__X_MS_ASF Moniker Class]
  129.   {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  130. [VIDEO__X_MS_WMV Moniker Class]
  131.   {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  132. [&使用迅雷下载]
  133.   <F:\软件\软件1\Thunder\Program\geturl.htm, N/A>
  134. [&使用迅雷下载全部链接]
  135.   <F:\软件\软件1\Thunder\Program\getallurl.htm, N/A>

  136. ==================================
  137. 正在运行的进程
  138. [PID: 424][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  139. [PID: 476][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  140. [PID: 1740][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  141.     [C:\WINDOWS\system32\msuadosat.dll]  [Microsoft Corporation, 6.0.2900.2802]
  142.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  143.     [C:\Program Files\Unlocker\UnlockerCOM.dll]  [N/A, ]
  144.     [C:\Program Files\Eset\nodshex.dll]  [N/A, ]
  145.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  146.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 32 ]
  147.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  148.     [C:\WINDOWS\system32\shadow\pDeskTop.dll]  [N/A, ]
  149.     [C:\WINDOWS\system32\faxshell.dll]  [Microsoft Corporation, 5.00.2134.1]
  150.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll]  [Anti-Malware Development a.s., 7, 5, 0, 49]
  151. [PID: 1824][C:\Program Files\Eset\nod32kui.exe]  [Eset , 2, 70, 32 ]
  152.     [C:\Program Files\Eset\nod32rui.dll]  [N/A, ]
  153.     [C:\Program Files\Eset\pu_amon.dll]  [Eset , 2, 70, 32 ]
  154.     [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 70, 32 ]
  155.     [C:\Program Files\Eset\pu_dmon.dll]  [Eset , 2, 70, 32 ]
  156.     [C:\Program Files\Eset\pr_dmon.dll]  [N/A, ]
  157.     [C:\Program Files\Eset\pu_emon.dll]  [Eset , 2, 70, 32 ]
  158.     [C:\Program Files\Eset\pr_emon.dll]  [N/A, ]
  159.     [C:\Program Files\Eset\pu_imon.dll]  [Eset , 2, 70, 32 ]
  160.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  161.     [C:\Program Files\Eset\pu_nod32.dll]  [Eset , 2, 70, 32 ]
  162.     [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 70, 32 ]
  163.     [C:\Program Files\Eset\pu_upd.dll]  [Eset , 2, 70, 32 ]
  164.     [C:\Program Files\Eset\pr_upd.dll]  [N/A, ]
  165.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  166. [PID: 1840][C:\Program Files\FengYun\FYFireWall.exe]  [[url]www.218.cc[/url], 1.2.5.1755]
  167.     [C:\Program Files\FengYun\arpinfo.dll]  [N/A, ]
  168.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  169. [PID: 1856][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  170.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  171. [PID: 284][C:\WINDOWS\system32\shadow\ShadowTip.exe]  [PowerShadow, 1, 0, 0, 1]
  172.     [C:\WINDOWS\system32\shadow\pDeskTop.dll]  [N/A, ]
  173.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  174. [PID: 228][F:\软件\软件2\安全\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  175.     [C:\Program Files\FengYun\fymon.dll]  [[url]www.218.cc[/url], 1.2.3.75]
  176.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 32 ]
  177.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]

  178. ==================================
  179. 文件关联
  180. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  181. .EXE  OK. ["%1" %*]
  182. .COM  OK. ["%1" %*]
  183. .PIF  OK. ["%1" %*]
  184. .REG  OK. [regedit.exe "%1"]
  185. .BAT  OK. ["%1" %*]
  186. .SCR  OK. ["%1" /S]
  187. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  188. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  189. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  190. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  191. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  192. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  193. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  194. ==================================
  195. Winsock 提供者
  196. NOD32 protected [MSAFD Tcpip [TCP/IP]]
  197.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  198. NOD32 protected [MSAFD Tcpip [UDP/IP]]
  199.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  200. NOD32 protected [MSAFD Tcpip [RAW/IP]]
  201.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  202. NOD32 protected [RSVP UDP Service Provider]
  203.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  204. NOD32 protected [RSVP TCP Service Provider]
  205.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  206. NOD32
  207.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)

  208. ==================================
  209. Autorun.inf
  210. N/A

  211. ==================================
  212. HOSTS 文件
  213. 127.0.0.1       localhost
  214. 127.0.0.1 localhost
  215. 127.0.0.1 localhost

  216. ==================================
  217. API HOOK
  218. N/A

  219. ==================================
  220. 隐藏进程
  221. N/A

  222. ==================================


复制代码
鼻耳盖子
发表于 2007-5-28 16:46:24 | 显示全部楼层

微点报已知

木马名称:Backdoor.Win32.Huigezi.stg
程序:
I:\TEST\070527\16\G_07\G_07.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
Heavyrain1st
发表于 2007-5-28 16:54:02 | 显示全部楼层
卡巴6.0
已删除: 木马程序 Backdoor.Win32.Hupigon.wi        文件: C:\Documents and Settings\桌面\G_07.rar/G_07.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 16:12 , Processed in 0.100295 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表