12
返回列表 发新帖
楼主: promised
收起左侧

[病毒样本] 16个一包

[复制链接]
一派胡言
发表于 2007-7-6 14:55:34 | 显示全部楼层
北京江民新科技术有限公司

        扫描引擎 10.00.600
        病毒库日期 2007-07-06
        更新日期 2007-07-06

扫描目标 C:\Documents and Settings\Administrator\桌面\virus\

开始时间 2007-07-06 14:54:56

在 C:\Documents and Settings\Administrator\桌面\virus\alqq.exe 中发现 Trojan/PSW.GamePass.cqd 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\1.exe 中发现 TrojanDownloader.Agent.kcb 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\fSIck\fSIck.exe 中发现 Worm/Agent.d 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\Game.dll 中发现 Trojan/PSW.QQPass.crk 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\sinawin.exe 中发现 Worm/Agent.d 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\sinacoun.exe 中发现 TrojanDownloader.TpxVip.e 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\Temp\csrss.exe 中发现 TrojanProxy.Agent.gm 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\Temp\new_web.exe 中发现 TrojanDownloader.Delf.ja 病毒, 已删除
在 C:\Documents and Settings\Administrator\桌面\virus\Temp\tdsetup.exe 中发现 Trojan/Agent.apg 病毒, 已删除
正常结束。

扫描结果:
                 文件数 :634                                 病毒体 :9         
                   删除 :9                                     解毒 :0         
    扫描速度(千字节/秒) :14583                             扫描时间 :00:00:12
    扫描文件速度(个/秒) :52
The EQs
发表于 2007-7-6 15:11:02 | 显示全部楼层
Scan performed at: 2007-7-6 15:10:40
Scanning Log
NOD32 version 2381 (20070706) NT
Command line: C:\Documents and Settings\EQ2\桌面\1
Operating memory - is OK

Date: 6.7.2007  Time: 15:10:47
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\1\
C:\Documents and Settings\EQ2\桌面\1\virus\1.exe - Win32/TrojanDownloader.Adload.NBC trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\virus\alqq.exe - probably a variant of Win32/PSW.QQShou trojan
C:\Documents and Settings\EQ2\桌面\1\virus\sinacoun.exe - Win32/TrojanDownloader.VB.NIM trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\virus\sinawin.exe - Win32/Agent.T worm - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\virus\wd2_051117_NAV067_mini.exe ?NSIS ?aaa - Win32/Adware.AllSum application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\virus\wd2_051117_NAV067_mini.exe ?NSIS ?aaa - Win32/Adware.AllSum application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\virus\wd2_051117_NAV067_mini.exe ?NSIS ?aaa - Win32/Adware.AllSum application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\virus\fSIck\fSIck.exe - Win32/Agent.T worm - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\virus\Temp\ad1760.exe ?NSIS ?cpush.dll - Win32/Adware.BHO.AV application - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\1\virus\Temp\bind_50103.exe - a variant of Win32/TrojanDownloader.QQHelper trojan
C:\Documents and Settings\EQ2\桌面\1\virus\Temp\sinavip1006.exe - Win32/TrojanDownloader.VB.NIM trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\1\virus\Temp\tdsetup.exe - Win32/Adware.Zhongsou application - quarantined - unable to clean - deleted
Number of scanned files: 24
Number of threats found: 12
Number of files cleaned: 10
Time of completion: 15:10:52 Total scanning time: 5 sec (00:00:05)
XinDOS
发表于 2007-7-6 15:28:22 | 显示全部楼层
卡巴搞定
woai_jolin
发表于 2007-7-6 19:11:59 | 显示全部楼层
原帖由 EQ2 于 2007-7-6 15:11 发表
Scan performed at: 2007-7-6 15:10:40
Scanning Log
NOD32 version 2381 (20070706) NT
Command line: C:\Documents and Settings\EQ2\桌面\1
Operating memory - is OK

Date: 6.7.2007  Time: 15:10:4 ...

看来今天下午一更新nod就又能多杀2个lo
风雪
发表于 2007-7-6 19:44:27 | 显示全部楼层
setup168启发,剩下全部报。
tracydk
发表于 2007-7-6 19:54:40 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\virus.part2.rar'
F:\病毒样本\virus.part2.rar
  [0] Archive type: RAR
  --> virus\Temp\sinavip1006.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\virus.part1.rar'
F:\病毒样本\virus.part1.rar
  [0] Archive type: RAR
  --> virus\1.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.aku.16
  --> virus\alqq.exe
      [DETECTION] Is the Trojan horse TR/PSW.QQPass.UP.17
  --> virus\fSIck\fSIck.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\Game.dll
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> virus\sinacoun.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.arj.1
  --> virus\sinawin.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> virus\Temp\bind_50103.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.AX.2
  --> virus\Temp\csrss.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.bfb
      [INFO]      The file was deleted!
wangjay1980
发表于 2007-7-7 00:12:28 | 显示全部楼层
new_web.exek - Trojan-Downloader.Win32.Dadobra.bm,
sinavip1006.exek - Trojan-Dropper.Win32.VB.qb

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.


setup168.exek

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Vladimir Krylov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-11 01:18 , Processed in 0.131000 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表