查看: 2504|回复: 10
收起左侧

今天装连连看时发现的!!

[复制链接]
dyw1021
头像被屏蔽
发表于 2007-6-29 17:01:56 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-6-29 17:06:41 | 显示全部楼层
Scan performed at: 2007-6-29 17:06:21
Scanning Log
NOD32 version 2363 (20070629) NT
Command line: C:\Documents and Settings\EQ2\桌面\SkypeClient.rar C:\Documents and Settings\EQ2\桌面\bind_50424.rar C:\Documents and Settings\EQ2\桌面\fenggj.rar C:\Documents and Settings\EQ2\桌面\fengrx.rar C:\Documents and Settings\EQ2\桌面\fengsh.rar C:\Documents and Settings\EQ2\桌面\fengwl.rar
Operating memory - is OK

Date: 29.6.2007  Time: 17:06:26
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\SkypeClient.rar; C:\Documents and Settings\EQ2\桌面\bind_50424.rar; C:\Documents and Settings\EQ2\桌面\fenggj.rar; C:\Documents and Settings\EQ2\桌面\fengrx.rar; C:\Documents and Settings\EQ2\桌面\fengsh.rar; C:\Documents and Settings\EQ2\桌面\fengwl.rar
C:\Documents and Settings\EQ2\桌面\fenggj.rar ?RAR ?fenggj.exe - Win32/PSW.OnLineGames.NBN trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\fengrx.rar ?RAR ?fengrx.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\fengsh.rar ?RAR ?fengsh.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\fengwl.rar ?RAR ?fengwl.exe - probably unknown NewHeur_PE virus [7]
Number of scanned files: 12
Number of threats found: 4
Number of files cleaned: 4
Time of completion: 17:06:27 Total scanning time: 1 sec (00:00:01)

Notes:
[7] File is probably infected with an unknown virus.
mofunzone
发表于 2007-6-29 17:06:44 | 显示全部楼层
楼主的连连看版本不错
全灭了

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\SkypeClient'
C:\Documents and Settings\Administrator\My Documents\SkypeClient\
  bind_50424.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
  fenggj.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.26297
      [WARNING]   The file was ignored!
  fengrx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.24466
      [WARNING]   The file was ignored!
  fengsh.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.22660
      [WARNING]   The file was ignored!
  fengwl.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.25261
      [WARNING]   The file was ignored!
  SkypeClient.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!


End of the scan: 2007年6月29日  02:06
Used time: 00:08 min

The scan has been done completely.

      1 Scanning directories
      6 Files were scanned
      6 viruses and/or unwanted programs were found
      2 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -2 Files not concerned
      0 Archives were scanned
      6 Warnings
      0 Notes
      0 Hidden objects were found
wangjay1980
发表于 2007-6-29 17:07:02 | 显示全部楼层
deleted: Trojan program Trojan-PSW.Win32.Lmir.yw        File: C:\Documents and Settings\Owner\×ÀÃæ\fenggj.rar/fenggj.exe//UPack//VIDEO.DLL
deleted: Trojan program Trojan-Spy.Win32.Delf.vo        File: C:\Documents and Settings\Owner\×ÀÃæ\fengsh.rar/fengsh.exe//UPack
kumagaya
发表于 2007-6-29 17:07:15 | 显示全部楼层
Start of the scan: 2007年6月29日  17:04

Starting the file scan:

Begin scan in 'D:\virus\bind_50424.rar'
D:\virus\bind_50424.rar
  [0] Archive type: RAR
  --> bind_50424.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
Start of the scan: 2007年6月29日  17:04

Starting the file scan:

Begin scan in 'D:\virus\fenggj.rar'
D:\virus\fenggj.rar
  [0] Archive type: RAR
  --> fenggj.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.26297
      [WARNING]   The file was ignored!

Start of the scan: 2007年6月29日  17:05

Starting the file scan:

Begin scan in 'D:\virus\fengrx.rar'
D:\virus\fengrx.rar
  [0] Archive type: RAR
  --> fengrx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.24466
      [WARNING]   The file was ignored!
Start of the scan: 2007年6月29日  17:05

Starting the file scan:

Begin scan in 'D:\virus\fengsh.rar'
D:\virus\fengsh.rar
  [0] Archive type: RAR
  --> fengsh.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.22660
      [WARNING]   The file was ignored!
Start of the scan: 2007年6月29日  17:06

Starting the file scan:

Begin scan in 'D:\virus\fengwl.rar'
D:\virus\fengwl.rar
  [0] Archive type: RAR
  --> fengwl.exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.25261
      [WARNING]   The file was ignored!
Start of the scan: 2007年6月29日  17:06

Starting the file scan:

Begin scan in 'D:\virus\SkypeClient.rar'
D:\virus\SkypeClient.rar
  [0] Archive type: RAR
  --> SkypeClient.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!
taihuxian
发表于 2007-6-29 17:59:21 | 显示全部楼层
Virus: Win32:Qqhelper-BB [Trj]

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Win32:Delf-EQW [Trj]

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Trojan-Spy.Win32.Delf.vo

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Win32:Delf-EQV [Trj]

Virus found while downloading Web content.

Address: bbs.kafan.cn

Virus: Win32:Delf-EQV [Trj]

Virus found while downloading Web content.

Address: bbs.kafan.cn
Whkroran
发表于 2007-6-29 18:47:28 | 显示全部楼层
detected: Trojan program Trojan-PSW.Win32.Lmir.yw        URL: http://bbs.kafan.cn/attachment.p ... e//UPack//VIDEO.DLL
detected: Trojan program Trojan-Spy.Win32.Delf.vo        URL: http://bbs.kafan.cn/attachment.php?aid=94560//fengsh.exe//UPack


今天卡巴更新速度慢些。上报了好多毒。。看来他们又在急忙地研究卡7新版本,,看来很可能将又出新版本了 ( 本人觉得)因为是,每次要出新版本的时候就这样。
风雪
发表于 2007-6-29 19:18:36 | 显示全部楼层
费尔三个木马一个启发。
傻猪猪米走鸡
发表于 2007-6-29 23:05:44 | 显示全部楼层
余下2个我上报nod了
wangjay1980
发表于 2007-6-30 09:23:04 | 显示全部楼层
Hello,

bind_50424.exe_ - Trojan-Downloader.Win32.QQHelper.vx,
fengrx.exe_, fengwl.exe_ - Trojan-Spy.Win32.Delf.uh

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

setup2000.exe_, SkypeClient.exe_

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Erakhtin Kirill
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/



> Attachment: SkypeClient.zip
> Attachment: bind_50424.zip
> Attachment: fengrx.zip
> Attachment: fengwl.zip
> Attachment: setup2000.zip
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-7 22:15 , Processed in 0.130313 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表