查看: 6765|回复: 19
收起左侧

[病毒样本] vip产物16个

[复制链接]
promised
发表于 2007-8-24 18:02:43 | 显示全部楼层 |阅读模式
[MD5: 43DB27 E3619A B4A8A9 6A4445 99FF7B 5EE3E9 4F5CF9 FC3006 5887C0 FDD421 D0809D C371B8 DA9ACC BB1F7C A68B41 45430D]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-8-24 18:06:05 | 显示全部楼层
Scan performed at: 2007-8-24 18:05:34
Scanning Log
NOD32 version 2481 (20070823) NT
Command line: C:\Documents and Settings\Don johnson\桌面\样本1.rar
Operating memory - is OK

Date: 24.8.2007  Time: 18:05:45
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\Don johnson\桌面\样本1.rar
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?fy.exe - Win32/Delf.NFD trojan - was a part of the deleted object
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?jh.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?mh.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?mir.exe - a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?my.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?qj.exe - probably a variant of Win32/PSW.OnLineGames.NEN trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?qqhx.exe - a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?qst.exe - a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?tl.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?wd.exe - a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?wl.exe - probably a variant of Win32/PSW.OnLineGames.NEN trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?wow.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?zt.exe - a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?zx.exe - a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?cs.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\样本1.rar ?RAR ?dh.exe - a variant of Win32/PSW.OnLineGames.NEN trojan
Number of scanned files: 17
Number of threats found: 16
Number of files cleaned: 1
Time of completion: 18:05:49 Total scanning time: 4 sec (00:00:04)

Notes:
[7] File is probably infected with an unknown virus.
saga3721
发表于 2007-8-24 18:09:20 | 显示全部楼层
小红伞正好响了16声
沸沸
发表于 2007-8-24 18:14:23 | 显示全部楼层


启发了2分半,就这一个文件

[ 本帖最后由 沸沸 于 2007-8-24 18:15 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
458506
发表于 2007-8-24 18:14:49 | 显示全部楼层
NOD32都16个了。。我这个就不用扫了
沸沸
发表于 2007-8-24 18:20:20 | 显示全部楼层


首先,卡7 才报了5个文件
其次,如下文件启发了N久!





报告完毕


[ 本帖最后由 沸沸 于 2007-8-24 18:29 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Guanguancan
发表于 2007-8-24 18:21:33 | 显示全部楼层
还有一些在下载过程中被AVG杀了!汗~~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Guanguancan
发表于 2007-8-24 18:24:23 | 显示全部楼层
还有7个AVG PASS,上报AVG去
碧水寒潭
发表于 2007-8-24 19:19:16 | 显示全部楼层
Start of the scan: 2007年8月24日  19:18

Starting the file scan:

Begin scan in 'H:\AV-TEST'
H:\AV-TEST\样本1.rar
  [0] Archive type: RAR
  --> fy.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> jh.exe
      [DETECTION] Is the Trojan horse TR/Agent.11508
  --> mh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> mir.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineG.MI.1
  --> my.exe
      [DETECTION] Is the Trojan horse TR/Agent.12978.1
  --> qj.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> qqhx.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.CK.2
  --> qst.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> tl.exe
      [DETECTION] Is the Trojan horse TR/Agent.11187
  --> wd.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.CK.2
  --> wl.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.UV.125
  --> wow.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
  --> zt.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.CK.2
  --> zx.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.CK.2
  --> cs.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> dh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was deleted!


End of the scan: 2007年8月24日  19:18
Used time: 00:17 min

The scan has been done completely.

      1 Scanning directories
     17 Files were scanned
     16 viruses and/or unwanted programs were found
      4 classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -3 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
      0 Hidden objects were found
微点卫士
发表于 2007-8-24 20:12:01 | 显示全部楼层
微点:
木马名称:Trojan-PSW.Win32.OnLineGames.iyw

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\QQHX.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.OnLineGames.iyx

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\ZT.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.OnLineGames.iyv

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\ZX.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\JH.EXE
1) C:\DFD1995781.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\JH.EXE
1) C:\DFD1995781.BAT
是否删除可疑程序?
这个东西卡了半天

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\MH.EXE
1) C:\DFD2121562.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\MH.EXE
1) C:\DFD2121562.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\MIR.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\INTERNET EXPLORER\RAVCQMON.EXE
2) C:\PROGRAM FILES\INTERNET EXPLORER\RAVCQMON.DAT
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\MY.EXE
1) C:\DFD2143812.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\MY.EXE
1) C:\DFD2143812.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\QJ.EXE
1) C:\DFD2156875.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\QJ.EXE
1) C:\DFD2156875.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\QST.EXE

E:\AUTORUN.INF
自启动运行!
并生成以下文件:
1) E:\AUTORUN.EXE
2) E:\AUTORUN.INF
以及可由此INF文件引导自启的文件:
E:\AUTORUN.EXE
E:\AUTORUN.EXE

是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\TL.EXE
1) C:\DFD2181546.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\TL.EXE
1) C:\DFD2181546.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\WD.EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\NETMEETING\RAVWDMON.EXE
2) C:\PROGRAM FILES\NETMEETING\RAVWDMON.DAT
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\WL.EXE
1) C:\DFD2203859.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\WL.EXE
1) C:\DFD2203859.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\WOW.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\WINOW.EXE
2) C:\WINDOWS.0\WINOW.DLL
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\CS.EXE
1) C:\DFD2225640.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\CS.EXE
1) C:\DFD2225640.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\DH.EXE
1) C:\DFD2237156.BAT
是可疑程序!
试图删除文件!
是否阻止该进程继续运行?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\DH.EXE
1) C:\DFD2237156.BAT
是否删除可疑程序?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\FY.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\SYSTEM32\PACKET.DLL
2) C:\WINDOWS.0\SYSTEM32\WANPACKET.DLL
3) C:\WINDOWS.0\SYSTEM32\WPCAP.DLL
4) C:\WINDOWS.0\SYSTEM32\DRIVERS\SVCHOST.EXE
是否删除木马程序及其衍生物?

全杀
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-3-1 15:12 , Processed in 0.079286 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表