查看: 3642|回复: 22
收起左侧

[病毒样本] 51个

[复制链接]
promised
发表于 2007-9-5 19:48:20 | 显示全部楼层 |阅读模式
md5l略

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2007-9-5 19:56:51 | 显示全部楼层

99/36

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.PSW.Win32.Agent.vcd
病毒: Trojan.PSW.Win32.XYOnline.hd
病毒: Trojan.PSW.Win32.NPSword.a
病毒: Trojan.PSW.Win32.RBLand.ar
病毒: Trojan.PSW.Win32.OnlineGames.yda
病毒: Trojan.PSW.Win32.RocOnline.cx
病毒: Trojan.PSW.Win32.WOWar.vn
病毒: Trojan.PSW.Win32.Agent.vcx
病毒: Trojan.PSW.Win32.OnlineGames.ydk
病毒: Trojan.PSW.Win32.OnlineGames.ycn
病毒: Trojan.PSW.Win32.OnlineGames.ygl
病毒: Trojan.PSW.Win32.OnlineGames.yav
病毒: Trojan.PSW.Win32.FYOnline.cu
病毒: Trojan.PSW.Win32.OnlineGames.yaz
病毒: Trojan.PSW.Win32.ZhuXian.av
病毒: Trojan.PSW.Win32.OnlineGames.xzf
病毒: Worm.Win32.Pabug.n      
病毒: Trojan.PSW.Win32.OnlineGames.yfi
病毒: Trojan.PSW.Win32.OnlineGames.yfk
病毒: Trojan.PSW.Win32.ZeroOnline.ak
病毒: Worm.Nimaya.ef           
病毒: Hack.Win32.ArpCheater.d  
病毒: Trojan.PSW.Win32.ZeroOnline.am
病毒: Trojan.Mnless.lpi        
病毒: Trojan.PSW.Win32.YBOnline.ak
病毒: Trojan.PSW.Win32.OnlineGames.yer
病毒: Trojan.PSW.QQPass.tnm   

MAC地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:19.39.22
残缺的唯美
发表于 2007-9-5 19:59:41 | 显示全部楼层
--> 0.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.A
  --> 1(1).exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> 1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 2(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PL
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 3(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.1
  --> 4.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.blb
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 6(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGame.YF
  --> 7(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 7.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bjn.1
  --> 8(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 8.exe
      [DETECTION] Is the Trojan horse TR/Agent.12334
  --> 9(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 9.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.2
  --> 10(1).exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
  --> 10.exe
      [DETECTION] Is the Trojan horse TR/Agent.11212
  --> 11(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 11.exe
      [DETECTION] Is the Trojan horse TR/Agent.11112
  --> 12(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.3
  --> 13(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 13.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
  --> 14(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 14.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.N
  --> 15(1).exe
      [DETECTION] Is the Trojan horse TR/Agent.13082
  --> 15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.8
  --> 16(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ.2
  --> 16.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 17.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 18.exe
      [DETECTION] Is the Trojan horse TR/Agent.ABOY.4
  --> 19(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 19.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Kolmat.B.18 Backdoor server programs
  --> 20(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 20.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.alh.32 Backdoor server programs
  --> cs.exe
      [DETECTION] Is the Trojan horse TR/Agent.12580
  --> dh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> fy.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> jh.exe
      [DETECTION] Is the Trojan horse TR/Agent.12236
  --> mh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> mir.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> my.exe
      [DETECTION] Is the Trojan horse TR/Agent.13496
  --> qj.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> qqhx.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bla
  --> qst.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.Q
  --> tl.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> wd.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.4166
  --> wl.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> zx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ
      [INFO]      A backup was created as '475099f3.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
timhas266
发表于 2007-9-5 20:01:21 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\tim\桌面\virus.zip'
C:\Documents and Settings\tim\桌面\virus.zip
  [0] Archive type: ZIP
  --> 0.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.A
  --> 1(1).exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> 1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 2(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PL
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 3(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.1
  --> 4.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.blb
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 6(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGame.YF
  --> 7(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 7.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bjn.1
  --> 8(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 8.exe
      [DETECTION] Is the Trojan horse TR/Agent.12334
  --> 9(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 9.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.2
  --> 10(1).exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
  --> 10.exe
      [DETECTION] Is the Trojan horse TR/Agent.11212
  --> 11(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 11.exe
      [DETECTION] Is the Trojan horse TR/Agent.11112
  --> 12(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.3
  --> 13(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 13.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
  --> 14(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 14.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.N
  --> 15(1).exe
      [DETECTION] Is the Trojan horse TR/Agent.13082
  --> 15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.8
  --> 16(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ.2
  --> 16.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 17.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 18.exe
      [DETECTION] Is the Trojan horse TR/Agent.ABOY.4
  --> 19(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 19.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Kolmat.B.18 Backdoor server programs
  --> 20(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 20.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.alh.32 Backdoor server programs
  --> cs.exe
      [DETECTION] Is the Trojan horse TR/Agent.12580
  --> dh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> fy.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> jh.exe
      [DETECTION] Is the Trojan horse TR/Agent.12236
  --> mh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> mir.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> my.exe
      [DETECTION] Is the Trojan horse TR/Agent.13496
  --> qj.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> qqhx.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bla
  --> qst.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.Q
  --> tl.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.blx
  --> wd.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.4166
  --> wl.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> zx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ
      [INFO]      A backup was created as '47509ade.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
ssy275
发表于 2007-9-5 20:10:30 | 显示全部楼层
50

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
taki_K
发表于 2007-9-5 20:16:53 | 显示全部楼层
ESS beta2
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 9.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 9(1).exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 8.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 8(1).exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 7.exe - a variant of Win32/PSW.OnLineGames.YA trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 7(1).exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 6.exe - a variant of Win32/PSW.OnLineGames.YA trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 6(1).exe - probably a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 5.exe » FSG v2.0 - internal error
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 4.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 3.exe - a variant of Win32/PSW.OnLineGames.NEN trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 3(1).exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 2.exe - probably a variant of Win32/PSW.OnLineGames.YA trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 2(1).exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 1.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 0.exe - probably a variant of Win32/PSW.Delf.NHI trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 18.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 17.exe - a variant of Win32/PSW.OnLineGames.YA trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 16.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 16(1).exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 15.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 15(1).exe - probably a variant of Win32/PSW.OnLineGames.NEN trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 14.exe - a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 14(1).exe - Win32/Delf.NFD trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 13.exe - a variant of Win32/PSW.Legendmir.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 13(1).exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 12.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 12(1).exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 11.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 11(1).exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 10.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 10(1).exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » wd.exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » tl.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » qst.exe - a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » qqhx.exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » qj.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » my.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » mir.exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » mh.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » jh.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » fy.exe - Win32/Delf.NFD trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » dh.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » cs.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 20.exe - Win32/Agent.NEM trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 20(1).exe - probably a variant of Win32/PSW.OnLineGames.NEP trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 19.exe - Win32/Delf.NGD trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » 19(1).exe - Win32/PSW.Legendmir.NFC trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » zx.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\virus.zip » ZIP » wl.exe - probably a variant of Win32/Genetik trojan
浪滔天
发表于 2007-9-5 20:22:54 | 显示全部楼层
卡巴7.0.0.125 高启发
查出:41  其中启发:8   
剩下的10个中有8个高启发扫描时卡住过不去(卡巴启发的老问题了)

已隔离: 病毒 Heur.Invader (变种)        文件: D:\virus\17.exe//PE_Patch.UPX
已隔离: 病毒 Heur.StartPage (变种)        文件: D:\virus\1(1).exe//PEPatch
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\8(1).exe//PE_Patch//UPack
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\12(1).exe
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\13(1).exe//PE_Patch//UPack
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\wd.exe//PE_Patch//UPack
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\20(1).exe//PE_Patch//UPack
已隔离: 病毒 Heur.Trojan.Generic (变种)        文件: D:\virus\mir.exe//PE_Patch//UPack
已删除: 病毒 Worm.Win32.QQPass.a        文件: D:\virus\0.exe//PE_Patch.UPX//UPX
已删除: 病毒 Worm.Win32.QQPass.n        文件: D:\virus\14.exe//UPX
已删除: 病毒 Worm.Win32.QQPass.q        文件: D:\virus\qst.exe//UPX
已删除: 木马程序 Backdoor.Win32.Agent.alh        文件: D:\virus\20.exe//UPack
已删除: 木马程序 Backdoor.Win32.Delf.awy        文件: D:\virus\fy.exe
已删除: 木马程序 Backdoor.Win32.Delf.awy        文件: D:\virus\14(1).exe
已删除: 木马程序 Backdoor.Win32.Kolmat.b        文件: D:\virus\19.exe//PE_Patch.UPX//UPX
已删除: 木马程序 Trojan-PSW.Win32.Agent.pj        文件: D:\virus\16(1).exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.Agent.pj        文件: D:\virus\zx.exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.Agent.pl        文件: D:\virus\2(1).exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.Agent.po        文件: D:\virus\7(1).exe//UPX
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.akj        文件: D:\virus\13.exe//PE_Patch//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.akj        文件: D:\virus\19(1).exe//ASPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bjn        文件: D:\virus\7.exe//PE_Patch.UPX//UPX
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bkz        文件: D:\virus\2.exe
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bla        文件: D:\virus\qqhx.exe//PE_Patch//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.blb        文件: D:\virus\4.exe
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bln        文件: D:\virus\5.exe//FSG
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.blx        文件: D:\virus\jh.exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.blx        文件: D:\virus\tl.exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bmj        文件: D:\virus\cs.exe//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bmw        文件: D:\virus\18.exe//PE_Patch//UPack
已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bnk        文件: D:\virus\6.exe//PE_Patch.UPX//UPX
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\9.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\8.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\3.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\15.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\12.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\10.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.abi        文件: D:\virus\11.exe
已删除: 木马程序 Trojan-Spy.Win32.Delf.acg        文件: D:\virus\my.exe//UPack
已删除: 木马程序 Trojan-Spy.Win32.Delf.acg        文件: D:\virus\15(1).exe//UPack
已删除: 木马程序 Trojan-Spy.Win32.Delf.acm        文件: D:\virus\10(1).exe//UPack
wangjay1980
发表于 2007-9-5 20:51:43 | 显示全部楼层
启发BUG,就怕这个修改的UPX
tracydk
发表于 2007-9-5 20:57:43 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\病毒样本\virus.zip'
F:\病毒样本\virus.zip
  [0] Archive type: ZIP
  --> 0.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.A
  --> 1(1).exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> 1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 2(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PL
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 3(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.1
  --> 4.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.blb
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 6(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGame.YF
  --> 7(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 7.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bjn.1
  --> 8(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 8.exe
      [DETECTION] Is the Trojan horse TR/Agent.12334
  --> 9(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 9.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.2
  --> 10(1).exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
  --> 10.exe
      [DETECTION] Is the Trojan horse TR/Agent.11212
  --> 11(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 11.exe
      [DETECTION] Is the Trojan horse TR/Agent.11112
  --> 12(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.3
  --> 13(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 13.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
  --> 14(1).exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
  --> 14.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.N
  --> 15(1).exe
      [DETECTION] Is the Trojan horse TR/Agent.13082
  --> 15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.8
  --> 16(1).exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ.2
  --> 16.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 17.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 18.exe
      [DETECTION] Is the Trojan horse TR/Agent.ABOY.4
  --> 19(1).exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
  --> 19.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Kolmat.B.18 Backdoor server programs
  --> 20(1).exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 20.exe
      [DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Agent.alh.32 Backdoor server programs
  --> cs.exe
      [DETECTION] Is the Trojan horse TR/Agent.12580
  --> dh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> fy.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> jh.exe
      [DETECTION] Is the Trojan horse TR/Agent.12236
  --> mh.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> mir.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> my.exe
      [DETECTION] Is the Trojan horse TR/Agent.13496
  --> qj.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> qqhx.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bla
  --> qst.exe
      [DETECTION] Contains signature of the worm WORM/QQPass.Q
  --> tl.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.blx
  --> wd.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.4166
  --> wl.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> zx.exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.PJ
      [INFO]      The file was deleted!
残缺的唯美
发表于 2007-9-5 21:34:13 | 显示全部楼层
symantec19个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-12 00:52 , Processed in 0.130720 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表