楼主: qqq000@qq.com
收起左侧

[病毒样本] 未知07.rar(49个)

[复制链接]
uhthn2002
发表于 2007-7-7 22:09:53 | 显示全部楼层

C:\Documents and Settings\uhthn\Desktop\07\097f7b_mosou.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\1E65B1_nwizzhuxians.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\255bcf_lymangr.dll : infected Trojan-PSW.Win32.OnLineGames.nn
C:\Documents and Settings\uhthn\Desktop\07\2f1974_nwizqjsj.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\380de5_nwiztlbb.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\54f56d_msdeg32.dll : is suspected of Trojan-PSW.Game.32 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\07\855644_syscheck2.exe : is suspected of Malware.Delf.13
C:\Documents and Settings\uhthn\Desktop\07\9fc509_mcce.exe : infected Email-Worm.Win32.VB.da
C:\Documents and Settings\uhthn\Desktop\07\a04f24_packet.dll : is suspected of Trojan-PSW.Game.30 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\07\a4b2bb_msdeg32.dll : is suspected of Trojan-PSW.Game.32 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\07\A59F68_nwizzhuxians.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\ab0d22_8eb70e70.dll : is suspected of Trojan-PSW.Game.63 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\07\b54562_cmdbcs.dll : infected MalwareScope.Trojan-PSW.Game.1
C:\Documents and Settings\uhthn\Desktop\07\ca2b86_wanpacket.dll : is suspected of Trojan-PSW.Game.30 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\07\cba8e3_nwiztlbb.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\dd7f06_upxdnd.dll : infected MalwareScope.Trojan-PSW.Game.12
C:\Documents and Settings\uhthn\Desktop\07\eb17a6_nwiztlbb.dll : is suspected of Downloader.Small.160
C:\Documents and Settings\uhthn\Desktop\07\ec38c2_daso0.dll : infected MalwareScope.Trojan-PSW.Game.10
C:\Documents and Settings\uhthn\Desktop\07\efefa5_b86dcf87.dll : is suspected of Trojan-PSW.Game.63 (paranoid heuristics)


Directories       : 0       Files in archives:      Files on disks:
Archives:                   - total       : 1       - total       : 49   
- scanned         : 1       -  scanned    : 1       - scanned     : 49   
- contain viruses : 0       -  infected   : 0       - infected    : 5     
- deleted         : 0       -  suspicious : 0       - suspicious  : 14
zane_xzz
发表于 2007-7-7 22:15:53 | 显示全部楼层
好多都见过,都有人发过,都是以前的
hj5abc
发表于 2007-7-7 22:56:30 | 显示全部楼层

回复 #29 wangjay1980 的帖子

应该说"捷克斯洛伐克人". alwil和eset的都是懒汉.估计现在都在放假了.sat了今天
hj5abc
发表于 2007-7-7 22:57:57 | 显示全部楼层

回复 #30 wangjay1980 的帖子

jay版在水贴子了.[:27:]
蓝色牛仔裤
发表于 2007-7-7 23:05:18 | 显示全部楼层

回复 #34 hj5abc 的帖子

老是对着样本哆无聊,有空版聊一下放松一下也不错~
蓝色牛仔裤
发表于 2007-7-7 23:21:12 | 显示全部楼层

蜘蛛才4个。。。大丰收!!
woai_jolin
发表于 2007-7-7 23:32:28 | 显示全部楼层
dr web也不杀dll吧
rasis
发表于 2007-7-8 08:29:41 | 显示全部楼层
未知07.rar
  [0] Archive type: RAR
  --> δ֪07\01eaba_boolan95.exe
      [DETECTION] Is the Trojan horse TR/Obfuscated.FD.4
  --> δ֪07\097f7b_mosou.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QW.215
  --> δ֪07\104196_asr.exe
      [DETECTION] Contains signature of the dropper DR/Autoit.AF.1
  --> δ֪07\1E65B1_nwizzhuxians.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> δ֪07\255bcf_lymangr.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NN.269
  --> δ֪07\2f1974_nwizqjsj.dll
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.bjp.174
  --> δ֪07\341041_rav00ae.dat
      [DETECTION] Is the Trojan horse TR/Agent.6774
  --> δ֪07\380de5_nwiztlbb.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.XG.33
  --> δ֪07\4f3ab5_rav008c.dat
      [DETECTION] Is the Trojan horse TR/Dldr.Small.dtd.1
  --> δ֪07\54f56d_msdeg32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NN.294
  --> δ֪07\8AFC0A_autolive(1).sys
      [DETECTION] Contains signature of the rootkit RKIT/Agent.GJ.1
  --> δ֪07\8fe6c5_autolive.dll
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/NewWeb.C.4
  --> δ֪07\9c3729_autoruns.exe
      [DETECTION] Is the Trojan horse TR/Pakes.A.1497
  --> δ֪07\9fc509_mcce.exe
      [DETECTION] Contains signature of the worm WORM/VB.DA.13
  --> δ֪07\a4b2bb_msdeg32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NN.295
  --> δ֪07\A59F68_nwizzhuxians.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> δ֪07\ab0d22_8eb70e70.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> δ֪07\b54562_cmdbcs.dll
      [DETECTION] Is the Trojan horse TR/PSW.Agent.20480
  --> δ֪07\C20178_¸´¼þ070701ok.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Asprotect). Please verify the origin of the file
  --> δ֪07\cba8e3_nwiztlbb.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.XG.34
  --> δ֪07\d7aad9_remotedbg.dll
      [DETECTION] Is the Trojan horse TR/Agent.22016.B
  --> δ֪07\dd7f06_upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.Agent.20480
  --> δ֪07\e0f5bc_kasclfpc.sys
      [DETECTION] Contains signature of the Ad- or Spyware ADSPY/BDSearch.CT
  --> δ֪07\eb17a6_nwiztlbb.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.XG.32
  --> δ֪07\ec38c2_daso0.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> δ֪07\efefa5_b86dcf87.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> δ֪07\f3bbd1_remotedbg.dll
      [DETECTION] Is the Trojan horse TR/Agent.22016.B
      [WARNING]   The file was ignored!


End of the scan: 2007年7月8日  08:27
Used time: 00:15 min

The scan has been done completely.

      0 Scanning directories
     50 Files were scanned
     27 viruses and/or unwanted programs were found
      2 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     21 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
      0 Hidden objects were found
wangjay1980
发表于 2007-7-8 08:52:39 | 显示全部楼层
Hello,

0F65B8.exe_, 173ae3_xlvod_setuphelper.dll, 213822_iviregmgr.exe_, 2bc5c7_virus04.exe_, 396a55_webthunder_setuphelper.dll, 3d5dda_aaaamon.dll, 4acdfa_1.exe.zip, 6cf000_mmvem.exe_, 815907_tecsetup.exe_, 855644_syscheck2.exe_, 8d7cb9_fygaddins.exe_, 9c3729_autoruns.exe_, a04f24_packet.dll, ac09c2_6to4svc.dll, c9a685_e.exe_, ca2b86_wanpacket.dll, cc207b_wpcap.dll, d63dd2_dtdr3260.dll, dc6275_install.exe_, e0f5bc_kasclfpc.sys, e2a711_536enc.dll, e4fa0c_dsqltools.exe_

No malicious code were found in these files.

104196_asr.exe_ - Trojan.Win32.Autoit.af,
341041_rav00ae.dat - Trojan-PSW.Win32.OnLineGames.es,
4f3ab5_rav008c.dat - Trojan-Downloader.Win32.Small.dtd,
b54562_cmdbcs.dll - Trojan-PSW.Win32.OnLineGames.wp

These files are already detected. Please update your antivirus bases.

1E65B1_nwizzhuxians.dll - Trojan-PSW.Win32.Nilage.bjp,
ab0d22_8eb70e70.dll, efefa5_b86dcf87.dll - Backdoor.Win32.Agent.ahj,
dd7f06_upxdnd.dll - Trojan-PSW.Win32.OnLineGames.wz,
fe5723_msapi.dll - Trojan.Win32.Agent.anj

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

C20178070701ok.exe_

This file is corrupted.

Please quote all when answering.

--
Best regards, Vladimir Lebedev
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: ??07.zip
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 19:36 , Processed in 0.098043 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表