查看: 4456|回复: 15
收起左侧

[病毒样本] 一大包41个样本

[复制链接]
gzg
发表于 2007-10-9 22:42:43 | 显示全部楼层 |阅读模式
大家一起扫扫看  质量应该还是可以的

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qigang
发表于 2007-10-9 22:44:52 | 显示全部楼层

41/15

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.PSW.Win32.OnlineGames.zop
病毒: Trojan.PSW.Win32.OnlineGames.zeq
病毒: Trojan.PSW.Win32.OnlineGames.zox
病毒: Trojan.Win32.Agent.zip   
病毒: Trojan.PSW.Win32.OnlineGames.zfa
病毒: Trojan.PSW.Win32.SunOnline.dg
病毒: Trojan.PSW.Win32.OnlineGames.zoy
病毒: Trojan.PSW.Win32.OnlineGames.zox
病毒: Trojan.PSW.Win32.OnlineGames.zqd
病毒: Trojan.PSW.Win32.OnlineGames.zoq
病毒: Trojan.PSW.Win32.OnlineGames.zem
病毒: Trojan.PSW.Win32.QQSG.h  
病毒: Trojan.PSW.Win32.OnlineGames.zoh
病毒: Trojan.PSW.Win32.XYOnline.ku

MAC地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:19.44.12
The EQs
发表于 2007-10-9 22:46:35 | 显示全部楼层

nod32扫到31个文件,查杀了20个

C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » svchost.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » AVPSRV.EXE - Win32/PSW.OnLineGames.YA trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » WinRAR_1.ex - probably unknown NewHeur_PE virus
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » MSIMMS32.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » GENPROTECT.EXE - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » 1FAF9AF4.EXE - Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » AVPSRV.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » KVSC3.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » AUTO.EXE - Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » CMDBCS.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » GENPROTECT.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » UPXDND.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » MPPDS.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » MSCCRT.DLL - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » MSPRINT32D.DLL - Win32/PSW.OnLineGames.NFX trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » MSPRINT32D.EXE - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » ZINFORMS.DLL - Win32/PSW.OnLineGames.NFZ trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » LYMANGR.DLL - Win32/PSW.OnLineGames.DTR trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » RARJBTL.EXE - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Don johnson\桌面\一大包.rar » RAR » AVWLBST.EXE - probably a variant of Win32/Genetik trojan
mofunzone
发表于 2007-10-9 23:02:58 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\һ���.rar'
C:\Users\morgan\Documents\
  һ���.rar
    [0] Archive type: RAR
    --> svchost.exe
        [DETECTION] Contains detection pattern of the worm WORM/Downloader.A.4
        [WARNING]   Infected files in archives cannot be repaired!
    --> AVPSRV.EXE
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ejm
        [WARNING]   Infected files in archives cannot be repaired!
    --> WinRAR_1.ex
        [DETECTION] Contains detection pattern of the worm WORM/Downloader.A.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> MSIMMS32.DLL
        [DETECTION] Is the Trojan horse TR/OnLineGames.24064.9
        [WARNING]   Infected files in archives cannot be repaired!
    --> GENPROTECT.EXE
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1FAF9AF4.EXE
        [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> AVPSRV.DLL
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ejm
        [WARNING]   Infected files in archives cannot be repaired!
    --> KVSC3.DLL
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.elw
        [WARNING]   Infected files in archives cannot be repaired!
    --> AUTO.EXE
        [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> CMDBCS.DLL
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ems.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> GENPROTECT.DLL
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ekz
        [WARNING]   Infected files in archives cannot be repaired!
    --> UPXDND.DLL
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.eln
        [WARNING]   Infected files in archives cannot be repaired!
    --> MPPDS.DLL
        [DETECTION] Is the Trojan horse TR/OnLineGames.24576.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> MSCCRT.DLL
        [DETECTION] Is the Trojan horse TR/PSW.26624.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> MSPRINT32D.DLL
        [DETECTION] Is the Trojan horse TR/PSW.Nilage.bql.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> MSPRINT32D.EXE
        [DETECTION] Is the Trojan horse TR/PSW.Nilage.bql.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> ZINFORMS.DLL
    --> LYMANGR.DLL
        [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> RUNASSRV.EXE
        [DETECTION] Is the Trojan horse TR/Zlob.Gen.39
        [WARNING]   Infected files in archives cannot be repaired!
    --> QQSGATL.DLL
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> RARJBTL.EXE
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.eni
        [WARNING]   Infected files in archives cannot be repaired!
    --> SVCHOT.EXE
    --> SYSNET.EXE
    --> SYSTM.EXE
    --> TASKMR.EXE
    --> TT10.EXE
    --> TT12.EXE
    --> TT15.EXE
    --> TMP7.TMP
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> AVWLBST.EXE
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.enb
        [WARNING]   Infected files in archives cannot be repaired!
    --> PLUS.EXE
        [WARNING]   The file was ignored!


End of the scan: 2007年10月9日  08:02
Used time: 00:05 min

The scan has been done completely.

      0 Scanning directories
     32 Files were scanned
     22 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     10 Files not concerned
      1 Archives were scanned
     23 Warnings
      0 Notes
wangjay1980
发表于 2007-10-9 23:04:15 | 显示全部楼层
21
detected: virus Worm.Win32.Downloader.a        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/svchost.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ejm        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/AVPSRV.EXE//PE_Patch.UPX//UPX
detected: virus Worm.Win32.Downloader.a        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/WinRAR_1.ex
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ejz        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/GENPROTECT.EXE//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.Agent.dwp        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/1FAF9AF4.EXE
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ejm        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/AVPSRV.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.elw        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/KVSC3.DLL
detected: Trojan program Trojan-Downloader.Win32.Agent.dwp        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/AUTO.EXE
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ems        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/CMDBCS.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ekz        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/GENPROTECT.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.eln        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/UPXDND.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.enp        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/MPPDS.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ejo        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/MSCCRT.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.eli        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/MSPRINT32D.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.elf        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/MSPRINT32D.EXE//PE_Patch.UPX//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.elu        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/ZINFORMS.DLL
detected: Trojan program Trojan-PSW.Win32.OnLineGames.efg        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/LYMANGR.DLL//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.dyh        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/QQSGATL.DLL//UPack//#
detected: Trojan program Trojan-PSW.Win32.OnLineGames.eni        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/RARJBTL.EXE//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.dyh        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/TMP7.TMP//UPack//#
detected: Trojan program Trojan-PSW.Win32.OnLineGames.enb        File: C:\Documents and Settings\Owner\×ÀÃæ\Ò»´ó°ü.rar/AVWLBST.EXE//UPack
欠妳緈諨
发表于 2007-10-9 23:07:46 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kp2006
头像被屏蔽
发表于 2007-10-9 23:11:05 | 显示全部楼层
江民杀毒软件报告文件

        北京江民新科技术有限公司

        扫描引擎 11.00.702
        病毒库日期 2007-10-09
        更新日期 2007-10-09

扫描目标 D:\Documents and Settings\Administrator\桌面\一大包.rar

开始时间 2007-10-09 23:06:17

在 D:\Documents and Settings\Administrator\桌面\一大包.rar->1FAF9AF4.EXE 中发现 TrojanDownloader.Agent.rmc 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->AUTO.EXE 中发现 TrojanDownloader.Agent.rmc 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->MSCCRT.DLL 中发现 Trojan/PSW.OnLineGames.hsl 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->LYMANGR.DLL 中发现 Trojan/PSW.OnLineGames.hsn 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->RARJBTL.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->SVCHOT.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->SYSNET.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->SYSTM.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->TASKMR.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->TT10.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->TT12.EXE 中发现 Trojan/PSW.OnLineGames.hmt 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->TT15.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->AVWLBST.EXE 中发现 TrojanSpy.Delf.aud 病毒, 已删除
在 D:\Documents and Settings\Administrator\桌面\一大包.rar->PLUS.EXE 中发现 Trojan/PSW.OnLineGames.hnz 病毒, 已删除
正常结束。

扫描结果:
                 文件数 :499                                 病毒体 :14        
                   删除 :14                                    解毒 :0         
    扫描速度(千字节/秒) :1289                              扫描时间 :00:01:48
    扫描文件速度(个/秒) :4
nk16hj
发表于 2007-10-10 00:01:37 | 显示全部楼层
F-secure 扫描发现19个 解压后又拦下了18个
平淡
发表于 2007-10-10 00:07:05 | 显示全部楼层
费尔23个
moonsilver
发表于 2007-10-10 00:22:54 | 显示全部楼层
rs 15个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-19 10:47 , Processed in 0.121397 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表