查看: 2871|回复: 13
收起左侧

[病毒样本] E-MAIL蠕虫[MD5: B89429 A072F3 8144BA 8990D3 40F8E3 10AB3B]

[复制链接]
dikex
发表于 2007-6-7 12:41:37 | 显示全部楼层 |阅读模式
如题,某E-MAIL蠕虫以及生成的一堆东西

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1原创 +1 收起 理由
lanvin + 1 谢谢支持

查看全部评分

kp2006
头像被屏蔽
发表于 2007-6-7 12:43:50 | 显示全部楼层
卡吧7不报
蓝色牛仔裤
发表于 2007-6-7 12:49:30 | 显示全部楼层
蜘蛛挂了。。。BD殺了3个

Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2007-6-5
Start time: 2007-6-7 12:49
Engine(s): KAV engine (AVK 17.5171), BD-Engine (BD 17.3623)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: dpnepgph.dll
        Path: C:\Documents and Settings\Administrator\桌面\样本
        Status: Virus detected
        Virus: DeepScan:Generic.Stration.6DC8905F (BD-Engine)
Object: fmifsqlu.dll
        Path: C:\Documents and Settings\Administrator\桌面\样本
        Status: Virus detected
        Virus: DeepScan:Generic.Stration.8BFFEA6A (BD-Engine)
Object: vote.pif
        Path: C:\Documents and Settings\Administrator\桌面\样本
        Status: Virus detected
        Virus: DeepScan:Generic.Stration.81D1FAF2 (BD-Engine)
Analysis complete: 2007-6-7 12:49
    6 files checked
    3 infected files detected
    0 suspected files detected
mofunzone
发表于 2007-6-7 13:06:17 | 显示全部楼层
新基因

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\样本'
C:\Documents and Settings\Administrator\My Documents\样本\
  dpnepgph.dll
      [DETECTION] Contains signature of the worm WORM/Stration.Gen
      [INFO]      The file was deleted!
  fmifsqlu.dll
      [DETECTION] Contains signature of the worm WORM/Stration.Gen
      [INFO]      The file was deleted!
  fmifsqlu.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/UPACK). Please verify the origin of the file
      [INFO]      The file was moved to '46d092fb.qua'!
  mmutuman.dll
      [DETECTION] Contains signature of the worm WORM/Stration.Gen
      [INFO]      The file was deleted!
  sensccfg.exe
      [DETECTION] Contains signature of the worm WORM/Stration.Gen
      [INFO]      The file was deleted!
  vote.pif
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO]      The file was deleted!


End of the scan: 2007年6月6日  22:07
Used time: 00:12 min

The scan has been done completely.

      1 Scanning directories
      6 Files were scanned
      6 viruses and/or unwanted programs were found
      0 classified as suspicious:
      5 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
promised
发表于 2007-6-7 13:27:40 | 显示全部楼层
Scan performed at: 2007-6-7 13:28:13
Scanning Log
NOD32 version 2313 (20070606) NT
Command line: C:\ABC\样本[1]
Operating memory - is OK

Date: 7.6.2007  Time: 13:28:22
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\ABC\样本[1]\
C:\ABC\样本[1]\vote.pif - a variant of Win32/Stration.XJ worm
Number of scanned files: 6
Number of threats found: 1
Number of active threats: 1
Time of completion: 13:28:51 Total scanning time: 29 sec (00:00:29)
1688388728
发表于 2007-6-7 13:57:20 | 显示全部楼层
Product BitDefender Antivirus Plus v10
//        Product 10.2
//
//        Created on:        07/06/2007        13:57:06
//
//-----------------------------------------------------------------


Virus Statistics

Scan path        : E:\病毒库\样本
Folders        : 1
Files        :  6
Memory processes scanned        : 0
Archives        : 0
Runtime packers        : 0
Identified viruses        : 3
Infected files        : 3
Memory processes infected        : 0
Suspect files        : 0
Warnings        : 0
Disinfected files        : 0
Deleted files        : 0
Moved files        : 3
I/O errors        : 0
Scan time        : 00:00:26
Scan speed (files/sec)        : 0

Virus definitions        : 825797108
Scan plugins        : 16
Archive plugins        : 41
Unpack plugins        : 6
Mail plugins        : 6
System plugins        : 5

Virus scan options

Detection
[ ] Scan boot sectors
[ ] Memory Processes
[X] Scan archives
[X] Scan runtime packers
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Move to quarantine
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[X] Move to quarantine
[ ] Prompt user

Virus scan options
[X] Enable warnings
[X] Enable heuristics
[X] Show all files in log
[X] Report file: C:\Documents and Settings\Administrator\Application Data\BitDefender\Desktop\Profiles\Logs\contextual\1181195826.log

Spyware scan options

[X] Scan for riskware
[ ] Skip dial and applications from scan
[ ] Registry keys
[ ] Cookies


Summary:

E:\病毒库\样本\dpnepgph.dll        Infected: DeepScan:Generic.Stration.6DC8905F
E:\病毒库\样本\dpnepgph.dll        Disinfection failed
E:\病毒库\样本\dpnepgph.dll        Moved
E:\病毒库\样本\fmifsqlu.dll        Infected: DeepScan:Generic.Stration.8BFFEA6A
E:\病毒库\样本\fmifsqlu.dll        Disinfection failed
E:\病毒库\样本\fmifsqlu.dll        Moved
E:\病毒库\样本\vote.pif        Infected: DeepScan:Generic.Stration.81D1FAF2
E:\病毒库\样本\vote.pif        Disinfection failed
E:\病毒库\样本\vote.pif        Moved
红心王子
发表于 2007-6-7 14:05:31 | 显示全部楼层
费尔两个
上报给卡巴去

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2007-6-7 14:42:51 | 显示全部楼层
ESS

2007/6/7 14:41:28        Scanning Log
2007/6/7 14:41:28        Version of virus signature database: 2314 (20070606)
2007/6/7 14:41:28        Date: 7.6.2007  Time: 14:41:28
2007/6/7 14:41:28        Scanned disks, folders and files: E:\病毒测试\
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar - a variant of Win32/Stration.XJ worm - deleted
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar » RAR » vote.pif - a variant of Win32/Stration.XJ worm
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar » RAR » fmifsqlu.dll - next archive volume not found
2007/6/7 14:41:38        Number of scanned files: 5
2007/6/7 14:41:38        Number of threats found: 1
2007/6/7 14:41:38        Time of completion: 14:41:38  Total scanning time: 10 sec (00:00:10)
woai_jolin
发表于 2007-6-7 14:43:26 | 显示全部楼层
ESS

2007/6/7 14:41:28        Scanning Log
2007/6/7 14:41:28        Version of virus signature database: 2314 (20070606)
2007/6/7 14:41:28        Date: 7.6.2007  Time: 14:41:28
2007/6/7 14:41:28        Scanned disks, folders and files: E:\病毒测试\
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar - a variant of Win32/Stration.XJ worm - deleted
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar » RAR » vote.pif - a variant of Win32/Stration.XJ worm
2007/6/7 14:41:38        E:\病毒测试\样本.part1.rar » RAR » fmifsqlu.dll - next archive volume not found
2007/6/7 14:41:38        Number of scanned files: 5
2007/6/7 14:41:38        Number of threats found: 1
2007/6/7 14:41:38        Time of completion: 14:41:38  Total scanning time: 10 sec (00:00:10)
cookiejack
发表于 2007-6-7 17:33:34 | 显示全部楼层
kaspersky 7.0.119 has announced 2 viruses
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 16:05 , Processed in 0.130887 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表