查看: 3785|回复: 22
收起左侧

[病毒样本] 5baf93,下载者和它下载的13个病毒!

[复制链接]
欠妳緈諨
发表于 2007-9-21 13:21:13 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
绅博周幸
发表于 2007-9-21 13:22:18 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\player.rar'
D:\player.rar
  [0] Archive type: RAR
  --> player.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO]      The file was deleted!
绅博周幸
发表于 2007-9-21 13:23:31 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\13¸ö.rar'
D:\13¸ö.rar
  [0] Archive type: RAR
  --> 103009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.dcu
  --> 103010.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.czk
  --> 103011.exe
      [DETECTION] Is the Trojan horse TR/Agent.11995
  --> 103012.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 103013.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
  --> 103001.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 103002.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.cya
  --> 103003.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 103004.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 103005.exe
      [DETECTION] Contains detection pattern of the dropper DR/Cinmus.RJ
  --> 103006.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 103007.exe
      [DETECTION] Is the Trojan horse TR/PSW.Delf.bap
  --> 103008.exe
      [DETECTION] Is the Trojan horse TR/Agent.12719
      [WARNING]   The file was ignored!


End of the scan: 2007年9月20日  22:06
Used time: 00:09 min

The scan has been done completely.

      0 Scanning directories
     14 Files were scanned
     10 viruses and/or unwanted programs were found
      3 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
风野胤
发表于 2007-9-21 13:23:32 | 显示全部楼层
重复的
幸福
最近怎么老发重复的

ps 某去找一下
说不定是更新的

[ 本帖最后由 风野胤 于 2007-9-21 13:25 编辑 ]
残缺的唯美
发表于 2007-9-21 13:24:09 | 显示全部楼层
D:\Documents and Settings\EKINCHENG\桌面\player.rar - probably a variant of Win32/TrojanDownloader.Delf.NSA trojan - deleted - quarantined
D:\Documents and Settings\EKINCHENG\桌面\player.rar » RAR » player.exe - probably a variant of Win32/TrojanDownloader.Delf.NSA trojan

D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103013.exe - probably a variant of Win32/AutoRun.Q worm
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103012.exe » FSG v2.0 - internal error
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103011.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103010.exe - a variant of Win32/PSW.OnLineGames.NEN trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103009.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103004.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103003.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103002.exe - probably a variant of Win32/PSW.OnLineGames.NEN trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103001.exe - a variant of Win32/PSW.Agent.NEC trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103008.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103007.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103006.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar » RAR » 103005.exe - probably a variant of Win32/PSW.OnLineGames.YA trojan
D:\Documents and Settings\EKINCHENG\桌面\13个.rar - multiple threats - deleted - quarantined
生成物有1个错误
欠妳緈諨
 楼主| 发表于 2007-9-21 13:28:26 | 显示全部楼层

回复 4楼 风野胤 的帖子

下载者那个名字好像见过的,不过下载的毒好像没人发过
风野胤
发表于 2007-9-21 13:32:15 | 显示全部楼层
原帖由 欠你幸福 于 2007-9-21 13:28 发表
下载者那个名字好像见过的,不过下载的毒好像没人发过

是你自己发的
OTL
刚测了MD5
一样的
http://bbs.kafan.cn/viewthread.php?tid=132967&extra=page%3D2
kkgh
发表于 2007-9-21 13:37:02 | 显示全部楼层
微点全部干掉
红心王子
发表于 2007-9-21 13:46:17 | 显示全部楼层
2007-9-21        13:45:48        1190353548        Administrator        3356        Sign of "Win32:Delf-FOQ [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\player.rar\player.exe" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:Delf-FVM [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103009.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103010.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103011.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:Delf-CSK [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103012.exe" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:Autorun-BS [Wrm]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103013.exe\[UPX]\[Embedded#05ef8]" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:OnLineGames-ST [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103001.exe\[Embedded#0c80]\[Upack]\[Embedded#5158]\[Upack]" file.  
2007-9-21        13:45:53        1190353553        Administrator        3356        Sign of "Win32:OnLineGames-SR [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103001.exe" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103002.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103003.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Delf-FVM [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103004.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BBZ [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103005.exe\[Embedded#1c60]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BBZ [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103005.exe" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103006.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103007.exe\[Upack]\[Embedded#MUSIC]" file.  
2007-9-21        13:45:54        1190353554        Administrator        3356        Sign of "Win32:Onlinegames-BCC [Trj]" has been found in "C:\Documents and Settings\Administrator\桌面\13个.rar\103008.exe\[Upack]\[Embedded#MUSIC]" file.
zszzd
发表于 2007-9-21 15:53:27 | 显示全部楼层
晕死,KILL7.1 报了两只。。。。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-1-14 18:18 , Processed in 0.096562 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表