楼主: 欠妳緈諨
收起左侧

[病毒样本] 16d64f,下载者及下载的20个毒!

[复制链接]
IllusionWing
发表于 2007-9-8 20:44:34 | 显示全部楼层
UGuard Log (Digital Fox - gankeyu@126.com)
UGuarduu.exe = 3.6.2
HC0.rlb = 2.7.0
HC2.rlb = 2.3.8
FN0.rlb = 2.3.0
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (1).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (2).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (3).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (5).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (6).exe 检测到 Trojan.Generic
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (7).exe 检测到 Trojan.Generic
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (8).exe 检测到 Win32.Unknown.b.1
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (9).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (10).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (11).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (12).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (13).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (14).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (15).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (16).exe 检测到 Generic.Upack -> Dwing
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (17).exe 检测到 Trojan.Generic
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (18).exe 检测到 Trojan.Delf.uv
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (19).exe 检测到 Backdoor.Generic
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (20).exe 检测到 Win32.Unknown.b.1
[扫描] [Level 2] 在 C:\Documents and Settings\new\桌面\VS\20ge\ss (21).exe 检测到 Win32.AutorunU
任务 扫描 完成。共耗费的时间:0-00-00 00:00:00:0296,共扫描的文件数量:21,共扫描到的威胁数量:20,威胁率:0.95238095
wangjay1980
发表于 2007-9-8 21:12:17 | 显示全部楼层
detected: Trojan program Trojan-Proxy.Win32.Small.du        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/20.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bms        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/1.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.blb        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/2.exe
detected: Trojan program Trojan-Spy.Win32.Delf.agk        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/3.exe//UPack
detected: Trojan program Trojan-Spy.Win32.Delf.ago        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/5.exe//UPack
detected: Trojan program Trojan-Downloader.Win32.Agent.csr        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/6.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bgr        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/7.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aav        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/8.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.Delf.aaw        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/9.exe//UPack
detected: Trojan program Trojan-Spy.Win32.Delf.ach        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/10.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.blx        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/11.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.box        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/12.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bmj        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/13.exe//UPack
detected: Trojan program Trojan-PSW.Win32.Agent.pl        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/14.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bou        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/15.exe//UPack
detected: Trojan program Trojan-Dropper.Win32.Agent.aqq        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/16.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bwr        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/17.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Spy.Win32.Delf.abi        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/18.exe
detected: Trojan program Trojan-Downloader.Win32.Small.czl        File: C:\Documents and Settings\Owner\×ÀÃæ\20ge.rar/19.exe//NSPack
detected: Trojan program Trojan-Downloader.Win32.Injecter.f        File: C:\Documents and Settings\Owner\×ÀÃæ\momo.rar/momo.exe
20
uhthn2002
发表于 2007-9-8 22:46:36 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Paranoia Database - 3938
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\uhthn\Desktop\New Folder (2)

C:\Documents and Settings\uhthn\Desktop\New Folder (2)\momo.exe - Suspicious of Win32.Trojan-Downloader.Zlob.1
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\20.exe - Infected with PDB-2996 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\1.exe - Infected with PDB-129 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\2.exe - Infected with PDB-890 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\3.exe - Infected with PDB-1499 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\4.exe - Suspicious of Trojan-PSW.Game.2
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\5.exe - Infected with PDB-888 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\6.exe - Infected with PDB-2791 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\7.exe - Infected with PDB-3903 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\8.exe - Suspicious of Trojan-PSW.OnLineGames.2
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\9.exe - Suspicious of Trojan-PSW.Game.3
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\10.exe - Infected with PDB-154 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\11.exe - Infected with PDB-293 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\12.exe - Infected with PDB-569 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\13.exe - Infected with PDB-1670 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\14.exe - Infected with PDB-2965 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\15.exe - Infected with PDB-29 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\16.exe - Infected with PDB-206 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\17.exe - Infected with PDB-1510 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\18.exe - Infected with PDB-2037 Malware program - Deleted
C:\Documents and Settings\uhthn\Desktop\New Folder (2)\19.exe - Infected with MalwareSpy.PDB-2958 Malware program - Deleted

21 Files scanned
17 Infected files found
4 Suspicious files found
0 Files cured
17 Files deleted
qianwenxiang
发表于 2007-9-8 22:47:16 | 显示全部楼层
发现卡饭好多人都有自己的杀毒软件...我也来冒个泡

VirusEliminator 扫描开始@2007-9-8 22:44:02@NewUser@Demand
SCAN STATUS:AN31-B
C:\Test\0908\20ge\1.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\1.exe大小15360 特征STLYXVYULTZKK
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\10.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\10.exe大小12407 特征RKQNPSPVLLWLR
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\11.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\11.exe大小12790 特征NLYLTOUOLMLOS
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\12.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\12.exe大小28431 特征SKQVZKNPNLVKV
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\13.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\13.exe大小12560 特征OKUZRYZQLLYQW
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\14.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\14.exe大小12065 特征UNWRPUOOZZVP
事件发生时间:2007-9-8 22:44:03
事件发生操作者:NewUser
C:\Test\0908\20ge\15.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\15.exe大小11800 特征MKUZZNKUZWRM
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\16.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\16.exe大小166397 特征YXSWTVVLLUQWRV
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\17.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\17.exe大小18432 特征LXSLUZQLYVMW
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\18.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\18.exe大小12382 特征UWLLOTTZLLVXY
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\19.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\19.exe大小26924 特征VYTXQTWLMUYPU
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\2.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\2.exe大小12903 特征ORZWZORQLMNTX
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\20.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\20.exe大小19100 特征VRSZKUKMLZWXQ
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\3.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\3.exe大小12441 特征VQLPZRXWLLXON
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\4.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\4.exe大小26397 特征OTOVSYWUMUQTL
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\5.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\5.exe大小12171 特征RSTOWMONLKKWR
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\6.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\6.exe大小17920 特征OVTNZXNKLYNRU
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\7.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\7.exe大小18432 特征NSQUWRXLYVMW
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\8.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\8.exe大小36273 特征RVPYVNMXOYMZP
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
C:\Test\0908\20ge\9.exe发现病毒Possible A Trojan
C:\Test\0908\20ge\9.exe大小23611 特征ZVTMTSNKMPZLN
事件发生时间:2007-9-8 22:44:04
事件发生操作者:NewUser
平淡
发表于 2007-9-8 22:48:57 | 显示全部楼层

回复 14楼 qianwenxiang 的帖子

又多出来一个  Eliminator
qianwenxiang
发表于 2007-9-8 22:52:07 | 显示全部楼层
原帖由 平淡 于 2007-9-8 22:48 发表
又多出来一个  Eliminator


它曾经把我系统文件删掉一大半 刚刚avast崩溃了 就顺便玩了下这个
沸沸
发表于 2007-9-9 13:21:16 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.Proxy.Win32.Small.du
病毒: Dropper.Win32.XYOnline.j
病毒: Trojan.PSW.Win32.RocOnline.cx
病毒: Trojan.PSW.Win32.OnlineGames.yii
病毒: Trojan.PSW.Win32.OnlineGames.yet
病毒: Trojan.PSW.Win32.OnlineGames.ybl
病毒: Trojan.PSW.Win32.OnlineGames.yem
病毒: Trojan.PSW.Win32.YBOnline.ak
病毒: Trojan.PSW.Win32.OnlineGames.yiq
病毒: Trojan.PSW.Win32.ZeroOnline.am
病毒: Trojan.PSW.Win32.NPSword.a
病毒: Trojan.PSW.Win32.QQHX.tps
病毒: Dropper.Win32.Agent.och  
病毒: Trojan.PSW.Win32.OnlineGames.yim
病毒: Trojan.PSW.Win32.OnlineGames.yba
病毒: Trojan.PSW.Win32.LMir.lyd

用户来源:互联网

软件版本:20.08.52

瑞星14个
woai_jolin
发表于 2007-9-9 13:25:34 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.DL.Win32.Autorun.ios

MAC地址:00:18:F3:7D:11:AD

用户来源:局域网

软件版本:19.39.60
woai_jolin
发表于 2007-9-9 13:25:55 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.Proxy.Win32.Small.du
病毒: Dropper.Win32.XYOnline.j
病毒: Trojan.PSW.Win32.RocOnline.cx
病毒: Trojan.PSW.Win32.OnlineGames.yii
病毒: Trojan.PSW.Win32.AskTao.cd
病毒: Trojan.PSW.Win32.OnlineGames.yet
病毒: Trojan.PSW.Win32.OnlineGames.ybl
病毒: Trojan.PSW.Win32.LMir.yev
病毒: Trojan.PSW.Win32.WoWar.wo
病毒: Trojan.PSW.Win32.OnlineGames.yem
病毒: Trojan.PSW.Win32.YBOnline.ak
病毒: Trojan.PSW.Win32.OnlineGames.yiq
病毒: Trojan.PSW.Win32.ZeroOnline.am
病毒: Trojan.PSW.Win32.NPSword.a
病毒: Trojan.PSW.Win32.QQHX.tps
病毒: Dropper.Win32.Agent.och  
病毒: Trojan.PSW.Win32.OnlineGames.yim
病毒: Trojan.PSW.Win32.OnlineGames.yba
病毒: Trojan.PSW.Win32.LMir.lyd

MAC地址:00:18:F3:7D:11:AD

用户来源:局域网

软件版本:19.39.60
2007zxf1
发表于 2007-9-9 13:45:59 | 显示全部楼层
红伞比瑞星多6个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-22 14:43 , Processed in 0.091397 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表