查看: 3381|回复: 21
收起左侧

[病毒样本] 23个【MD5略】

[复制链接]
wangjay1980
发表于 2007-10-1 14:29:30 | 显示全部楼层 |阅读模式
如题

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
残缺的唯美
发表于 2007-10-1 14:31:32 | 显示全部楼层
nod32  14
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » wxpSetup204.txt » RAR » jshelp.exe - a variant of Win32/Adware.MoKeAD application
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » wxpSetup204.txt » RAR » jsshow.dll - a variant of Win32/Adware.MoKeAD application
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » wxpSetup204.txt - a variant of Win32/Adware.MoKeAD application
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » 2(1)(2).exe - probably a variant of Win32/PSW.OnLineGames.YA trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » 4(1).exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » 12(1)(1).exe - probably a variant of Win32/AutoRun.Q worm
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » 12(2).exe - probably a variant of Win32/AutoRun.Q worm
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » 18(1).exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » mh(1).exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » mh.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » mminstall.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » moon.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » moyu.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » qiji.exe - probably unknown NewHeur_PE virus
D:\Documents and Settings\EKINCHENG\桌面\23.zip » RAR » qq.exe - probably a variant of Win32/AutoRun.Q worm
D:\Documents and Settings\EKINCHENG\桌面\23.zip - multiple threats - deleted - quarantined
mofunzone
发表于 2007-10-1 14:32:33 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\23.zip'
C:\Users\morgan\Documents\
  23.zip
    [0] Archive type: RAR
    --> tempL.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> wxpSetup204.txt
        [1] Archive type: RAR SFX (self extracting)
        --> jshelp.exe
            [DETECTION] Is the Trojan horse TR/Drop.Webhelp
            [WARNING]   Infected files in archives cannot be repaired!
        --> jsshow.dll
    --> 2(1)(2).exe
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 03ms.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGa.dmj
        [WARNING]   Infected files in archives cannot be repaired!
    --> 4(1).exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 6.exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 7(1)(2).exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 7(2)(1).exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 11(1)(1).exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.dtc
        [WARNING]   Infected files in archives cannot be repaired!
    --> 11(1).exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.dtc
        [WARNING]   Infected files in archives cannot be repaired!
    --> 11wd.exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 12(1)(1).exe
        [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 12(2).exe
        [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 18(1).exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> mh(1).exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> mh.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> mminstall.exe
    --> moon.exe
        [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> moyu.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> ms.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> qiji.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> qq.exe
        [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> tempI.exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年9月30日  23:31
Used time: 00:05 min

The scan has been done completely.

      0 Scanning directories
     26 Files were scanned
     14 viruses and/or unwanted programs were found
      8 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     12 Files not concerned
      2 Archives were scanned
     23 Warnings
      0 Notes
promised
发表于 2007-10-1 14:33:52 | 显示全部楼层
C:\ABC\23\03ms.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\11(1)(1).exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\11(1).exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\11wd.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\12(1)(1).exe - 特征码 'Virus.Win32.AutoRun.bs' 被发现
C:\ABC\23\12(2).exe - 特征码 'Virus.Win32.AutoRun.bs' 被发现
C:\ABC\23\18(1).exe - 特征码 'Trojan-Spy.Win32.Bancos.ha' 被发现
C:\ABC\23\2(1)(2).exe
C:\ABC\23\4(1).exe - 特征码 'Trojan-Spy.Win32.Bancos.ha' 被发现
C:\ABC\23\6.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\7(1)(2).exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\7(2)(1).exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\mh(1).exe - 特征码 'Trojan-Spy.Win32.Bancos.ha' 被发现
C:\ABC\23\mh.exe - 特征码 'Trojan-Spy.Win32.Bancos.ha' 被发现
C:\ABC\23\mminstall.exe
C:\ABC\23\moon.exe - 特征码 'Trojan-PWS.Win32.Agent.BU' 被发现
C:\ABC\23\moyu.exe - 特征码 'Trojan-Spy.Win32.Bancos.ha' 被发现
C:\ABC\23\ms.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\qiji.exe - 特征码 'Trojan-Dropper.Win32.Agent.ane' 被发现
C:\ABC\23\qq.exe - 特征码 'Virus.Win32.AutoRun.bs' 被发现
C:\ABC\23\tempI.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\tempL.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\23\wxpSetup204.txt:\jshelp.exe - 特征码 'not-a-virus:AdWare.Win32.Agent.bs' 被发现
C:\ABC\23\wxpSetup204.txt:\jsshow.dll - 特征码 'not-a-virus:AdWare.Win32.Agent.bs' 被发现
C:\ABC\23\wxpSetup204.txt

        25 文件被扫描
          (1 压缩档 2 文件)
        22 特征码被侦测
        0 可疑代码段被发现
        耗时: 0:04.218
solcroft
发表于 2007-10-1 14:38:56 | 显示全部楼层
谁来猜猜看瑞星扫描杀了几个
wangjay1980
 楼主| 发表于 2007-10-1 14:41:46 | 显示全部楼层
我猜我猜我猜猜猜
wangjay1980
 楼主| 发表于 2007-10-1 14:42:05 | 显示全部楼层
5个
solcroft
发表于 2007-10-1 14:45:23 | 显示全部楼层

回复 7楼 wangjay1980 的帖子

错了,和真正数量差5个 [:27:]
Nerazzurri
发表于 2007-10-1 14:47:15 | 显示全部楼层
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyi        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/tempL.exe//PE_Patch//UPack
deleted: Trojan program Trojan.Win32.Agent.btp        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/wxpSetup204.txt//data.rar/jshelp.exe
deleted: Trojan program Trojan.Win32.Agent.btp        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/wxpSetup204.txt//data.rar/jsshow.dll
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dxx        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/2(1)(2).exe
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyb        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/03ms.exe
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dxu        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/4(1).exe//UPack
deleted: Trojan program Trojan-PSW.Win32.Lmir.bmz        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/6.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.Lmir.bmz        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/7(1)(2).exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.Lmir.bmz        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/7(2)(1).exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dxw        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/11(1)(1).exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dxw        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/11(1).exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyc        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/11wd.exe
deleted: Trojan program Trojan-PSW.Win32.QQPass.afw        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/12(1)(1).exe//UPX
deleted: Trojan program Trojan-PSW.Win32.QQPass.afw        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/12(2).exe//UPX
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dxu        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/18(1).exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyd        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/mh(1).exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyd        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/mh.exe//UPack
deleted: Trojan program Trojan-Downloader.Win32.Hmir.aw        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/mminstall.exe
deleted: Trojan program Backdoor.Win32.Agent.bxm        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/moon.exe
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dye        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/moyu.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyf        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/ms.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.dyg        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/qiji.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.QQGame.ai        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/qq.exe//UPX
deleted: Trojan program Trojan-PSW.Win32.Lmir.bmz        File: F:\Documents and Settings\Crusade\×ÀÃæ\23.zip/tempI.exe//PE_Patch//UPack
promised
发表于 2007-10-1 14:49:04 | 显示全部楼层
mminstall.exe加了upx
卡巴分析师带upx入库
估计发烧了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 01:53 , Processed in 0.125801 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表