查看: 4210|回复: 22
收起左侧

[病毒样本] 18个

[复制链接]
qianwenxiang
发表于 2007-8-31 21:17:26 | 显示全部楼层 |阅读模式
[B62700 3FE408 72525C 4A39C1 FC509C E557B0 FAF04A 1D9778 B62700 F4E9DD 572820 4E6B49 C50E73 F5F251 238E63 FCBE74 E264B0]

http://exs.mail.foxmail.com/cgi-bin/downloadfilepart?svrid=1&fid=9a97647e5402f4a7041f32994f709e77894986c8b02ed74d

提取码 4d8b3306

[ 本帖最后由 promised 于 2007-8-31 21:27 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
promised
发表于 2007-8-31 21:26:27 | 显示全部楼层
C:\ABC\083102\virus (1).exe - 特征码 'DroppedBackdoor.Agent.YVK' 被发现
C:\ABC\083102\virus (10).exe - 特征码 'MalwareScope.Backdoor.Hupigon.1' 被发现
C:\ABC\083102\virus (11).exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\083102\virus (12).exe:\hackxi.bat
C:\ABC\083102\virus (12).exe:\hackxi.exe - 特征码 'Backdoor.Win32.GrayBird.oc' 被发现
C:\ABC\083102\virus (12).exe:\hackxi.vbs
C:\ABC\083102\virus (12).exe
C:\ABC\083102\virus (13).exe - 特征码 'Trojan-PWS.Win32.Nilage.lp' 被发现
C:\ABC\083102\virus (14).exe - 特征码 'MalwareScope.Backdoor.Hupigon.1' 被发现
C:\ABC\083102\virus (15).exe - 特征码 'Backdoor.Win32.Hupigon.awl' 被发现
C:\ABC\083102\virus (16).exe - 特征码 'Virus.Win32.AutoRun.f' 被发现
C:\ABC\083102\virus (17).exe - 特征码 'Trojan-Spy.Win32.Delf.PG' 被发现
C:\ABC\083102\virus (18).exe - 特征码 'Backdoor.Win32.GrayBird.oc' 被发现
C:\ABC\083102\virus (2).exe - 特征码 'Generic.PWStealer' 被发现
C:\ABC\083102\virus (3).exe - 特征码 'BehavesLikeWin32.ExplorerHijack' 被发现
C:\ABC\083102\virus (4).exe - 特征码 'Generic.PWStealer' 被发现
C:\ABC\083102\virus (5).exe - 特征码 'Generic.Graybird' 被发现
C:\ABC\083102\virus (6).exe - 特征码 'Backdoor.Win32.Hupigon.awl' 被发现
C:\ABC\083102\virus (7).exe - 特征码 'Trojan-PWS.Win32.Maran.cd' 被发现
C:\ABC\083102\virus (8).exe - 特征码 'Trojan-PWS.Win32.Delf.mc' 被发现
C:\ABC\083102\virus (9).exe - 特征码 'Trojan-PWS.Win32.Delf.mc' 被发现

        23 文件被扫描
          (1 压缩档 3 文件)
        18 特征码被侦测
        0 可疑代码段被发现
        耗时: 0:00.781
bjfhj
发表于 2007-8-31 21:28:02 | 显示全部楼层
已删除: 木马程序 Backdoor.Win32.Hupigon.cir        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (10).exe//SimplePack
已删除: 木马程序 Trojan-Downloader.Win32.Agent.cnm        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (11).exe//PE_Patch//UPack
已删除: 木马程序 Trojan.BAT.TimeReset.c        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (12).exe/hackxi.bat
已删除: 木马程序 Backdoor.Win32.Hupigon.cks        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (12).exe/hackxi.exe//PE_Patch
已删除: 木马程序 Trojan-Downloader.Win32.Small.ege        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (13).exe
已删除: 木马程序 Backdoor.Win32.Hupigon.cir        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (14).exe//SimplePack
已删除: 木马程序 Backdoor.Win32.Hupigon.exc        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (15).exe//PE-Armor//PE_Patch.PECompact//PecBundle//PECompact//PE_Patch.MaskPE
已删除: 木马程序 Trojan-Downloader.Win32.Agent.bpp        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (16).exe
已删除: 木马程序 Trojan-PSW.Win32.Delf.qc        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (17).exe//UPX
已删除: 病毒 Heur.Downloader (变种)        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (2).exe
已删除: 木马程序 Backdoor.Win32.Hupigon.cks        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (18).exe//PE_Patch
已删除: 木马程序 Trojan-PSW.Win32.Nilage.blg        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (3).exe//PE_Patch//NSPack//PE_Patch
已删除: 病毒 Heur.Downloader (变种)        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (4).exe
已删除: 木马程序 Backdoor.Win32.Hupigon.dsx        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (5).exe
已删除: 木马程序 Backdoor.Win32.Hupigon.exc        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (6).exe//PE-Armor//PE_Patch.PECompact//PecBundle//PECompact//PE_Patch.MaskPE
已删除: 木马程序 Backdoor.Win32.Banito.br        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (7).exe//VPacker
探测到: 木马程序 Trojan-PSW.Win32.Delf.wh        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (8).exe//#//PE_Patch.UPX//UPX
已删除: 木马程序 Trojan-PSW.Win32.Delf.wh        文件: C:\Documents and Settings\Administrator\桌面\083102.rar/virus (9).exe//PE_Patch.UPX//UPX
hj5abc
发表于 2007-8-31 21:44:32 | 显示全部楼层
17

2007-8-31 21:40:08 Scanned disks, folders and files: F:\083102[1]
2007-8-31 21:40:08 F:\083102[1]\083102\virus (10).exe - a variant of Win32/Hupigon trojan
2007-8-31 21:40:09 F:\083102[1]\083102\virus (11).exe - probably unknown NewHeur_PE virus [7]
2007-8-31 21:40:09 F:\083102[1]\083102\virus (12).exe » ZIP » hackxi.exe - Win32/Hupigon trojan
2007-8-31 21:40:09 F:\083102[1]\083102\virus (13).exe - Win32/TrojanDownloader.Delf.NQX trojan
2007-8-31 21:40:09 F:\083102[1]\083102\virus (14).exe - a variant of Win32/Hupigon trojan
2007-8-31 21:40:12 F:\083102[1]\083102\virus (15).exe - a variant of Win32/Hupigon trojan
2007-8-31 21:40:12 F:\083102[1]\083102\virus (16).exe - Win32/Delf.NDF worm
2007-8-31 21:40:12 F:\083102[1]\083102\virus (17).exe - Win32/PSW.Delf.NGO trojan
2007-8-31 21:40:12 F:\083102[1]\083102\virus (18).exe - Win32/Hupigon trojan
2007-8-31 21:40:13 F:\083102[1]\083102\virus (2).exe - a variant of Win32/PSW.Delf.NIY trojan
2007-8-31 21:40:13 F:\083102[1]\083102\virus (3).exe - probably a variant of Win32/PSW.Delf.NHI trojan
2007-8-31 21:40:13 F:\083102[1]\083102\virus (4).exe - a variant of Win32/PSW.Delf.NIY trojan
2007-8-31 21:40:13 F:\083102[1]\083102\virus (5).exe - a variant of Win32/Hupigon trojan
2007-8-31 21:40:16 F:\083102[1]\083102\virus (6).exe - a variant of Win32/Hupigon trojan
2007-8-31 21:40:35 F:\083102[1]\083102\virus (7).exe - probably a variant of Win32/Pacex.Gen virus(NewHeur_PE) [7]
2007-8-31 21:40:35 F:\083102[1]\083102\virus (8).exe - probably a variant of Win32/PSW.Delf.NHI trojan
2007-8-31 21:40:35 F:\083102[1]\083102\virus (9).exe - probably a variant of Win32/PSW.Delf.NHI trojan
2007-8-31 21:40:35 Number of scanned files: 20
2007-8-31 21:40:35 Number of threats found: 17
2007-8-31 21:40:35 Time of completion: 21:40:35  Total scanning time: 27 sec (00:00:27)
2007-8-31 21:40:35
2007-8-31 21:40:35 Notes:
2007-8-31 21:40:35 [7] File is probably infected with an unknown virus.

[ 本帖最后由 hj5abc 于 2007-8-31 21:48 编辑 ]
微点卫士
发表于 2007-8-31 21:47:20 | 显示全部楼层
微点:
木马名称:Trojan-Downloader.Win32.Agent.jnf

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (11).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Downloader.Win32.Delf.gfp

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (13).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Backdoor.Win32.Huigezi.whr

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (15).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan.Win32.Delf.bgk

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (16).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.Delf.ewd

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (17).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.Nilage.bqs

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (3).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Backdoor.Win32.Huigezi.whr

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (6).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Backdoor.Win32.Banito.co

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (7).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.Delf.euo

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (9).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (1).EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\SYSTEM32\ZCPGMKDT.DLL
2) C:\WINDOWS.0\SYSTEM32\DRIVERS\ZCPGMKDT.SYS
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (2).EXE
木马程序生成以下文件:
1) C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\SYSTEM6.JUP
2) C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\SYSTEM6.INS
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (4).EXE
是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (5).EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\WWW.DARKST.COM
是否删除木马程序及其衍生物?
木马名称:未知间谍软件

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (5).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (8).EXE

C:\AUTORUN.INF
自启动运行!
并生成以下文件:
1) C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWTEMP.BAK
2) C:\PROGRAM FILES\INTERNET EXPLORER\PLUGINS\NEWTEMP.DLL
3) C:\PEGEFILE.PIF
4) C:\AUTORUN.INF
以及可由此INF文件引导自启的文件:
C:\PEGEFILE.PIF

是否删除木马程序及其衍生物?
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (10).EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\HACKER.COM.CN.EXE
是否删除木马程序及其衍生物?
程序:
C:\WINDOWS.0\TEMP\HACKXI.EXE
木马程序生成以下文件:
1) C:\WINDOWS.0\HACKER.COM.CN.EXE
是否删除木马程序及其衍生物?木马名称:未知间谍软件
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\083102\VIRUS (18).EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:未知间谍软件
程序:
C:\WINDOWS.0\TEMP\HACKXI.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?


14蓝屏了,又是鸽子

[ 本帖最后由 微点卫士 于 2007-8-31 21:48 编辑 ]
风野胤
发表于 2007-8-31 21:48:23 | 显示全部楼层
Win32/Pacex.Gen
感染性病毒?
hj5abc
发表于 2007-8-31 21:51:11 | 显示全部楼层
原帖由 风野胤 于 2007-8-31 21:48 发表
Win32/Pacex.Gen
感染性病毒?

第一次看ess这么报.. 你的nod32是不是这样报的?
tracydk
发表于 2007-8-31 21:52:55 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\083102.part1.rar'
F:\病毒样本\083102.part1.rar
  [0] Archive type: RAR
  --> 083102\virus (1).exe
      [DETECTION] Contains signature of the dropper DR/PcClient.Gen
  --> 083102\virus (10).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> 083102\virus (11).exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
    --> 083102\virus (12).exe
      [1] Archive type: ZIP SFX (self extracting)
      --> hackxi.exe
          [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.GU Backdoor server programs
  --> 083102\virus (13).exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 083102\virus (14).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> 083102\virus (15).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> 083102\virus (16).exe
      [DETECTION] Is the Trojan horse TR/Agent.28829
  --> 083102\virus (17).exe
      [DETECTION] Is the Trojan horse TR/PSW.Steal.25812
  --> 083102\virus (18).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.GU Backdoor server programs
  --> 083102\virus (2).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 083102\virus (3).exe
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.blg
  --> 083102\virus (4).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
Begin scan in 'F:\病毒样本\083102.part2.rar'
F:\病毒样本\083102.part2.rar
  [0] Archive type: RAR
  --> 083102\virus (6).exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> 083102\virus (7).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 083102\virus (8).exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.WH.10
  --> 083102\virus (9).exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.WH.10
      [INFO]      The file was deleted!
uhthn2002
发表于 2007-8-31 21:55:14 | 显示全部楼层
C:\Documents and Settings\uhthn\Desktop\vir\virus (18).exe : infected Trojan-Downloader.Win32.Small.dln
C:\Documents and Settings\uhthn\Desktop\vir\virus (1).exe : is suspected of Malware.Agent.22 (paranoid heuristics)
C:\Documents and Settings\uhthn\Desktop\vir\virus (2).exe : infected MalwareScope.Trojan-PSW.Game.7
C:\Documents and Settings\uhthn\Desktop\vir\virus (3).exe : infected Trojan-PSW.Win32.Nilage.blg
C:\Documents and Settings\uhthn\Desktop\vir\virus (4).exe : infected MalwareScope.Trojan-PSW.Game.7
C:\Documents and Settings\uhthn\Desktop\vir\virus (5).exe : infected BackDoor.Pigeon.610
C:\Documents and Settings\uhthn\Desktop\vir\virus (6).exe : infected Backdoor.Win32.Hupigon.exc
C:\Documents and Settings\uhthn\Desktop\vir\virus (7).exe : infected Trojan-PSW.Win32.OnLineGames.tc
C:\Documents and Settings\uhthn\Desktop\vir\virus (8).exe : is suspected of Embedded.Trojan-PSW.Win32.Delf.wh
C:\Documents and Settings\uhthn\Desktop\vir\virus (9).exe : infected Trojan-PSW.Win32.Delf.wh
C:\Documents and Settings\uhthn\Desktop\vir\virus (10).exe : infected MalwareScope.Backdoor.Hupigon.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (11).exe : is suspected of Win32.Trojan.Downloader (http://...)
C:\Documents and Settings\uhthn\Desktop\vir\virus (12).exe:<ZIP>\hackxi.exe : infected Trojan-Downloader.Win32.Small.dln
C:\Documents and Settings\uhthn\Desktop\vir\virus (13).exe : infected Trojan-Downloader.Win32.Small.ege
C:\Documents and Settings\uhthn\Desktop\vir\virus (14).exe : infected MalwareScope.Backdoor.Hupigon.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (15).exe : infected Backdoor.Win32.Hupigon.exc
C:\Documents and Settings\uhthn\Desktop\vir\virus (16).exe : infected Trojan-Downloader.Win32.Agent.bpp
C:\Documents and Settings\uhthn\Desktop\vir\virus (17).exe : infected MalwareScope.Trojan-PSW.Game.7


Directories       : 0       Files in archives:      Files on disks:
Archives:                   - total       : 3       - total       : 18   
- scanned         : 1       -  scanned    : 3       - scanned     : 18   
- contain viruses : 1       -  infected   : 1       - infected    : 15   
- deleted         : 0       -  suspicious : 0       - suspicious  : 3     


Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Heuristics - OPEN
Scan in - C:\Documents and Settings\uhthn\Desktop\vir

C:\Documents and Settings\uhthn\Desktop\vir\virus (18).exe - Suspicious of Win32.Backdoor.Hupigon.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (1).exe - Suspicious of Trojan-Downloader.Small.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (2).exe - Suspicious of Win32.Trojan-Downloader.Zlob.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (3).exe - Suspicious of MalwareSpy.Win32.Trojan-Downloader.Delf.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (4).exe - Suspicious of Win32.Trojan-Downloader.Zlob.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (5).exe - Suspicious of Win32.Backdoor.Hupigon.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (6).exe - Suspicious of Win32.Trojan-PSW.Game.16
C:\Documents and Settings\uhthn\Desktop\vir\virus (7).exe - Suspicious file
C:\Documents and Settings\uhthn\Desktop\vir\virus (8).exe - Suspicious of Win32.Trojan-PSW.Game.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (9).exe - Suspicious of Win32.Trojan-PSW.Game.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (10).exe - Suspicious of Trojan-Downloader.Small.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (11).exe - Suspicious of Trojan-PSW.OnLineGames.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (12).exe - Suspicious of Win32.Trojan-Dropper.Rime.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (13).exe - Suspicious of MalwareSpy.Trojan-Downloader.Delf.1
C:\Documents and Settings\uhthn\Desktop\vir\virus (14).exe - Suspicious of Trojan-Downloader.Small.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (15).exe - Suspicious of Win32.Trojan-PSW.Game.16
C:\Documents and Settings\uhthn\Desktop\vir\virus (16).exe - Suspicious of Trojan-PSW.Game.2
C:\Documents and Settings\uhthn\Desktop\vir\virus (17).exe - Suspicious of Win32.Trojan-PSW.Game.1

18 Files scanned
0 Infected files found
18 Suspicious files found
0 Files cured
0 Files deleted
yurius
发表于 2007-8-31 23:04:07 | 显示全部楼层
第一次看到这样的报法

C:\virus\083102\virus (7).exe - probably a variant of Win32/Pacex.Gen virus(NewHeur_PE) [7]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-16 01:31 , Processed in 0.149141 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表