查看: 3074|回复: 17
收起左侧

[病毒样本] 一包病毒,过 驱逐舰,卡巴报;不扫MD5了,会晕的

[复制链接]
157131
发表于 2007-7-10 20:42:02 | 显示全部楼层 |阅读模式
体积很小,精致的病毒,卡巴会报, 过了我的 驱逐舰

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-7-10 20:42:47 | 显示全部楼层
Scan performed at: 2007-7-10 20:42:33
Scanning Log
NOD32 version 2389 (20070710) NT
Command line: C:\Documents and Settings\EQ2\桌面\RAV008C.zip
Operating memory - is OK

Date: 10.7.2007  Time: 20:42:38
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\RAV008C.zip
C:\Documents and Settings\EQ2\桌面\RAV008C.zip ?ZIP ?RAV008C.exe - a variant of Win32/PSW.OnLineGames.NCU trojan
C:\Documents and Settings\EQ2\桌面\RAV008C.zip ?ZIP ?LYLOADER.EXE - a variant of Win32/PSW.Agent.NEC trojan
Number of scanned files: 5
Number of threats found: 2
Number of files cleaned: 1
Time of completion: 20:42:39 Total scanning time: 1 sec (00:00:01)
1688388728
发表于 2007-7-10 20:43:33 | 显示全部楼层
病毒: Win32:Onlinegames-ACS [Trj], Win32:OnLineGames-ST [Trj], Win32:OnLineGames-SS [Trj]
文件: RAV008C[1].zip
目录: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ODE3GLQZ
进程: GreenBrowser.exe
wangjay1980
发表于 2007-7-10 20:44:47 | 显示全部楼层
detected: Trojan program Trojan-PSW.Win32.OnLineGames.es        File: C:\Documents and Settings\Owner\×ÀÃæ\RAV008C.zip/RAV008C.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.nn        File: C:\Documents and Settings\Owner\×ÀÃæ\RAV008C.zip/LYLOADER.EXE//PE_Patch//UPack
风雪
发表于 2007-7-10 20:45:52 | 显示全部楼层
费尔三个。
snakebone
头像被屏蔽
发表于 2007-7-10 20:47:54 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\RAV008C.zip'
C:\Documents and Settings\Administrator\桌面\
  RAV008C.zip
    [0] Archive type: ZIP
    --> RAV008C.DAT
        [DETECTION] Is the Trojan horse TR/Agent.4832.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> RAV008C.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGam.QW
        [WARNING]   Infected files in archives cannot be repaired!
    --> LYMANGR.DLL
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> LYLOADER.EXE
        [DETECTION] Is the Trojan horse TR/PSW.Onlinega.L.2
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      A backup was created as '46e98035.qua'  ( QUARANTINE )
        [INFO]      The file was deleted!
tracydk
发表于 2007-7-10 20:59:06 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\RAV008C.zip'
F:\病毒样本\RAV008C.zip
  [0] Archive type: ZIP
  --> RAV008C.DAT
      [DETECTION] Is the Trojan horse TR/Agent.4832.1
  --> RAV008C.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGam.QW
  --> LYMANGR.DLL
      [DETECTION] Contains suspicious code HEUR/Malware
  --> LYLOADER.EXE
      [DETECTION] Is the Trojan horse TR/PSW.Onlinega.L.2
      [INFO]      The file was deleted!
坐在墙头
发表于 2007-7-10 21:01:28 | 显示全部楼层

哇咔咔,费尔的启发

又见费尔的启发

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
taitan001
发表于 2007-7-10 21:03:54 | 显示全部楼层
全启发
F:\RAV008C.zip:<ZIP>\RAV008C.exe : is suspected of Trojan-PSW.Game.3 (paranoid heuristics)
F:\RAV008C.zip:<ZIP>\LYMANGR.DLL : is suspected of Trojan-PSW.Game.38 (paranoid heuristics)
F:\RAV008C.zip:<ZIP>\LYLOADER.EXE : is suspected of Trojan-PSW.Game.32 (paranoid heuristics)
promised
发表于 2007-7-10 21:09:42 | 显示全部楼层
c:\ABC\RAV008C.zip:\RAV008C.DAT - Signature 'Trojan-Dropper.Win32.Agent.ane' found
c:\ABC\RAV008C.zip:\RAV008C.exe - Signature 'Trojan-Downloader.Win32.Zlob.and' found
c:\ABC\RAV008C.zip:\LYMANGR.DLL - Signature 'Trojan-Dropper.Win32.Agent.ane' found
c:\ABC\RAV008C.zip:\LYLOADER.EXE - Signature 'Trojan-Downloader.Win32.Zlob.and' found
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-5 03:40 , Processed in 0.125941 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表