查看: 2825|回复: 17
收起左侧

[病毒样本] 一吨

[复制链接]
专家
发表于 2007-9-13 14:05:31 | 显示全部楼层 |阅读模式
30来个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2007-9-13 14:11:45 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\070913'
C:\Documents and Settings\Administrator\My Documents\070913\
  11.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [INFO]      The file was deleted!
  1630[1].exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [INFO]      The file was deleted!
  1630[1].txt
  1631.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [INFO]      The file was deleted!
  1631[1].exe
      [DETECTION] Is the Trojan horse TR/Drop.Agen.26778.A
      [INFO]      The file was deleted!
  1631[1].txt
  1632[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.8794
      [INFO]      The file was deleted!
  1632[1].txt
  1633.exe
      [DETECTION] Is the Trojan horse TR/PSW.QQShou.LD
      [INFO]      The file was deleted!
  1633[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.QQShou.LD
      [INFO]      The file was deleted!
  1633[1].txt
  1634.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '471bd4ce.qua'!
  1634[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '46bbfb0f.qua'!
  1634[1].txt
  1635[1].txt
  1636[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.bjj.1
      [INFO]      The file was deleted!
  1636[1].txt
  1637[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineG.MI.1
      [INFO]      The file was deleted!
  1637[1].txt
  1638[1].exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.afu
      [INFO]      The file was deleted!
  1638[1].txt
  1639[1].exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [INFO]      The file was deleted!
  1639[1].txt
  163a[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '471bd4d0.qua'!
  163a[1].txt
  163b[1].exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.agk
      [INFO]      The file was deleted!
  163b[1].txt
  163c[1].exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zlob.cix.1
      [INFO]      The file was deleted!
  163c[1].txt
  163d[1].exe
      [DETECTION] Is the Trojan horse TR/Agent.12229
      [INFO]      The file was deleted!
  163d[1].txt
  163e[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.Agent.20480
      [INFO]      The file was deleted!
  163e[1].txt
  163f[1].exe
      [DETECTION] Is the Trojan horse TR/Spy.Delf.abi.3
      [INFO]      The file was deleted!
  163f[1].txt
  163g.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aaw
      [INFO]      The file was deleted!
  163g[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aaw
      [INFO]      The file was deleted!
  163g[1].txt
  163h[1].exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Agent.alh.38 Backdoor server programs
      [INFO]      The file was deleted!
  163h[1].txt
  163i[1].exe
      [DETECTION] Is the Trojan horse TR/Agent.12288.D
      [INFO]      The file was deleted!
  163i[1].txt
  163j[1].exe
      [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
      [INFO]      The file was deleted!
  163j[1].txt
  163k.exe
      [DETECTION] Contains detection pattern of the worm WORM/Viking.DLL.2
      [INFO]      The file was deleted!
  16Sy.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aaw
      [INFO]      The file was deleted!
  1[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.abt
      [INFO]      The file was deleted!
  1[1]2.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Small.GOC.1
      [INFO]      The file was deleted!
  2.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  20ff2c4c19a31224[1].exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [INFO]      The file was deleted!
  3.exe
      [DETECTION] Is the Trojan horse TR/Hijack.Explor.4100
      [INFO]      The file was deleted!
  3[1].exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
  3[2].exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  7CFB95B0.EXE
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [INFO]      The file was deleted!
  9BA1E96A.DLL
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Exaal.45056 Backdoor server programs
      [INFO]      The file was deleted!
  ~Temp6482.tmp
      [DETECTION] Is the Trojan horse TR/Autorun.BK
      [INFO]      The file was deleted!
  ~tmp1644.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp2065.exe
      [DETECTION] Contains detection pattern of the worm WORM/QQPass.A
      [INFO]      The file was deleted!
  ~tmp4557.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp6263.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp65.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp6557.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp764.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~tmp7800.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.aax.1
      [INFO]      The file was deleted!
  ~up.log


End of the scan: 2007年9月12日  23:11
Used time: 00:05 min

The scan has been done completely.

      1 Scanning directories
     65 Files were scanned
     41 viruses and/or unwanted programs were found
      3 Files were classified as suspicious:
     41 files were deleted
      0 files were repaired
      3 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     24 Files not concerned
      0 Archives were scanned
      0 Warnings
      0 Notes
mofunzone
发表于 2007-9-13 14:13:16 | 显示全部楼层
剩下了21个txt文件。。
sololp 该用户已被删除
发表于 2007-9-13 14:14:00 | 显示全部楼层
小红伞误报多了点 楼主说30多个
mofunzone
发表于 2007-9-13 14:16:06 | 显示全部楼层

回复 4楼 sololp 的帖子

只能说你用的杀软不报的多
sololp 该用户已被删除
发表于 2007-9-13 14:16:08 | 显示全部楼层
drweb 27个
绅博周幸
发表于 2007-9-13 14:18:21 | 显示全部楼层
Ikarus 43
wangjay1980
发表于 2007-9-13 14:22:09 | 显示全部楼层
42
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp65.exe//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp764.exe//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp1644.exe//UPX
detected: virus Worm.Win32.QQPass.a        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp2065.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp4557.exe//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp6263.exe//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp6557.exe//UPX
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\~tmp7800.exe//UPX
detected: Trojan program Trojan-Downloader.Win32.Agent.dex        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1[1]2.exe//UPack
detected: Trojan program Trojan-PSW.Win32.Delf.abt        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1[1].exe//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.adn        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\2.exe//ASPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.cov        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\3.exe//PE_Patch//UPack
detected: virus Heur.Downloader (modification)        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\3[1].exe
detected: Trojan program Trojan-PSW.Win32.Delf.aax        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\3[2].exe//UPX
detected: Trojan program Backdoor.Win32.Agent.beu        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\7CFB95B0.EXE//ASPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.aci        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\11.exe//PE_Patch
detected: Trojan program Trojan-PSW.Win32.Delf.aaw        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\16Sy.exe//UPack
detected: Trojan program Backdoor.Win32.Agent.beu        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\20ff2c4c19a31224[1].exe//ASPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.cqb        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163a[1].exe//PE_Patch//UPack
detected: Trojan program Trojan-Spy.Win32.Delf.agk        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163b[1].exe//UPack
detected: Trojan program Trojan-Dropper.Win32.Killav.e        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163c[1].exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Spy.Win32.Delf.bab        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163d[1].exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.wp        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163e[1].exe
detected: Trojan program Trojan-Spy.Win32.Delf.abi        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163f[1].exe
detected: Trojan program Trojan-PSW.Win32.Delf.aaw        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163g.exe//UPack
detected: Trojan program Trojan-PSW.Win32.Delf.aaw        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163g[1].exe//UPack
detected: Trojan program Backdoor.Win32.Agent.alh        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163h[1].exe//UPack
detected: Trojan program Trojan-Downloader.Win32.Agent.cac        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163i[1].exe
detected: Trojan program Trojan-Downloader.Win32.Small.czl        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163j[1].exe//UPack//#//PE-Crypt.XorPE
detected: virus Worm.Win32.Viking.mc        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\163k.exe//PE_Patch
detected: Trojan program Trojan-PSW.Win32.OnLineGames.cny        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1630[1].exe
detected: Trojan program Trojan-PSW.Win32.WOW.uw        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1631.exe//UPack
detected: Trojan program Trojan-PSW.Win32.WOW.uw        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1631[1].exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bgc        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1632[1].exe
detected: Trojan program Trojan-PSW.Win32.QQShou.le        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1633.exe//UPX
detected: Trojan program Trojan-PSW.Win32.QQShou.le        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1633[1].exe//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.cnf        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1634.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.cnf        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1634[1].exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.bgr        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1636[1].exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.aia        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1637[1].exe
detected: Trojan program Trojan-Spy.Win32.Delf.afu        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1638[1].exe//UPack
detected: virus Heur.Invader (modification)        File: E:\Ñù±¾\н¨Îļþ¼Ð (3)\1639[1].exe//PE_Patch.UPX
专家
 楼主| 发表于 2007-9-13 14:28:56 | 显示全部楼层
我只是肉眼估算个数的,没按指头数
螳螂打石子
发表于 2007-9-13 15:49:10 | 显示全部楼层
30个一吨?42个,一吨半?
红伞扫完剩下20个txt文件和一个log文件
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-9-21 09:05 , Processed in 0.131642 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表