123
返回列表 发新帖
楼主: lanvin
收起左侧

[病毒样本] 16个 都是新的

[复制链接]
NobleT
发表于 2007-11-4 15:29:01 | 显示全部楼层
Antivirus Scanning Engine version number: 4.4.2
Virus signature file from: 2007-11-4, 5:21

Scan name: [Custom Scan]
Path to scan: F:\|

Normal scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2007-11-4, 15:27:30
---------------------------------------------------------------------

[Clean]        Boot sector on drive F:
[Clean]        Boot sector on drive E:
[Clean]        Boot sector on drive D:
[Clean]        Boot sector on drive G:
[Clean]        Boot sector on drive C:
[Clean]        Master Boot Record on disk 0
[Clean]        F:\RECYCLER\S-1-5-21-746137067-725345543-839522115-1003\desktop.ini
[Clean]        F:\RECYCLER\S-1-5-21-746137067-725345543-839522115-1003\INFO2
[Clean]        F:\wos5_00006.jpg
[Clean]        F:\wos5_00008.jpg
[Clean]        F:\wos5_00010.jpg
[Clean]        F:\wos5_00011.jpg
[Clean]        F:\wos5_00013.jpg
[Clean]        F:\wos5_00017.jpg
[Clean]        F:\wos5_00022.jpg
[Clean]        F:\存档\fdgvd.sav
[Clean]        F:\存档\Hroll\playersave\commondt.sav
[Clean]        F:\存档\Hroll\playersave\playersave
[Clean]        F:\存档\Hroll\playersave2\commondt.sav
[Clean]        F:\存档\Hroll\playersave2\playersave
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-1.exe
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-10.exe->(PEP)
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-11.exe->(SimplePack)
[Found virus]         <W32/Downloader.gen10 (not disinfectable)>        F:\新建文件夹.part1.rar->新建文件夹\name-12.exe->(UPX)->(PE_Patch.MaskPE)
[Found backdoor]         <W32/Hupigon.A.gen!Eldorado (not disinfectable, generic)>        F:\新建文件夹.part1.rar->新建文件夹\name-13.exe
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-14.exe
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-15.exe
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-16.exe->(MEW)
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-2.exe
[Clean]        F:\新建文件夹.part1.rar->新建文件夹\name-3.exe
[Contains infected objects]        F:\新建文件夹.part1.rar
[Quarantined]        F:\新建文件夹.part1.rar->新建文件夹\name-3.exe
[Clean]        F:\新建文件夹.part2.rar->新建文件夹\name-5.exe->(SVKProtector)
[Clean]        F:\新建文件夹.part2.rar->新建文件夹\name-6.exe->(Aspack)->(Aspack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (not disinfectable)>        F:\新建文件夹.part2.rar->新建文件夹\name-7.exe->(NSPack)->(NSPack)->(NSPack)
[Clean]        F:\新建文件夹.part2.rar->新建文件夹\name-8.exe
[Clean]        F:\新建文件夹.part2.rar->新建文件夹\name-9.exe
[Contains infected objects]        F:\新建文件夹.part2.rar
[Quarantined]        F:\新建文件夹.part2.rar->新建文件夹\name-9.exe

---------------------------------------------------------------------
Scan ended:        2007-11-4, 15:27:43
Duration:        0:00:12

Scan result:

Scanned files:                 22
Infected objects:         3
Disinfected objects:         0
Quarantined files:         2
chenyilong58
发表于 2007-11-4 16:36:05 | 显示全部楼层
金山毒霸0个!!!!!!
jijiasd
发表于 2007-11-4 16:48:38 | 显示全部楼层
毒霸信息安全
程序版本:2007.11.1.10
杀毒引擎版本:2007.10.08.01
数据流引擎版本:2007.03.29.18
病毒库版本2007.11.04.15
扫描文件:1
病毒名:安全
查杀:病毒\木马 0

[ 本帖最后由 jijiasd 于 2007-11-4 16:50 编辑 ]
2007zxf1
发表于 2007-11-4 17:12:57 | 显示全部楼层
红伞12.卡巴8
wangjay1980
发表于 2007-11-4 17:20:29 | 显示全部楼层
name-16.exe_, name-2.exe_,

No malicious code were found in these files.
uhthn2002
发表于 2007-11-4 17:36:09 | 显示全部楼层

vba32

C:\Documents and Settings\Uhthn\Desktop\新建\name-1.exe : is suspected of Malware.Agent.22 (paranoid heuristics)
C:\Documents and Settings\Uhthn\Desktop\新建\name-1.exe : backup copy created
C:\Documents and Settings\Uhthn\Desktop\新建\name-10.exe : infected BackDoor.Pigeon.775
C:\Documents and Settings\Uhthn\Desktop\新建\name-11.exe : is suspected of Backdoor.XiaoBird.226 (paranoid heuristics)
C:\Documents and Settings\Uhthn\Desktop\新建\name-11.exe : backup copy created
C:\Documents and Settings\Uhthn\Desktop\新建\name-12.exe : is suspected of Embedded.MalwareScope.Trojan-PSW.Game.7
C:\Documents and Settings\Uhthn\Desktop\新建\name-12.exe : backup copy created
C:\Documents and Settings\Uhthn\Desktop\新建\name-15.exe : infected Win32.HLLW.SpyBot
C:\Documents and Settings\Uhthn\Desktop\新建\name-16.exe : infected Backdoor.Win32.Ciadoor.13
C:\Documents and Settings\Uhthn\Desktop\新建\name-4.exe : infected MalwareScope.Worm.Viking.3
C:\Documents and Settings\Uhthn\Desktop\新建\name-5.exe : is suspected of Backdoor.XiaoBird.226 (paranoid heuristics)
C:\Documents and Settings\Uhthn\Desktop\新建\name-5.exe : backup copy created
C:\Documents and Settings\Uhthn\Desktop\新建\name-7.exe : is suspected of Malware.VB.52
C:\Documents and Settings\Uhthn\Desktop\新建\name-7.exe : backup copy created
C:\Documents and Settings\Uhthn\Desktop\新建\name-8.exe : infected AdWare.Win32.Semt.a


Directories       : 0       Files in archives:      Files on disks:
Archives:                   - total       : 0       - total       : 16   
- scanned         : 0       -  scanned    : 0       - scanned     : 16   
- contain viruses : 0       -  infected   : 0       - infected    : 5     
- deleted         : 0       -  suspicious : 0       - suspicious  : 5
uhthn2002
发表于 2007-11-4 17:37:23 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 803
Paranoia Database - 48490
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\Uhthn\Desktop\新建

C:\Documents and Settings\Uhthn\Desktop\新建\name-1.exe - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\新建\name-10.exe - Infected WIN32.TROJAN-DOWNLOADER.AGENT.3 - Deleted
C:\Documents and Settings\Uhthn\Desktop\新建\name-11.exe - Suspected WIN32.TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\新建\name-12.exe - Suspected MaliciousScope:WIN32.GENERIC.MALWARE.1
C:\Documents and Settings\Uhthn\Desktop\新建\name-13.exe - OK
C:\Documents and Settings\Uhthn\Desktop\新建\name-14.exe - OK
C:\Documents and Settings\Uhthn\Desktop\新建\name-15.exe - OK
C:\Documents and Settings\Uhthn\Desktop\新建\name-16.exe - OK
C:\Documents and Settings\Uhthn\Desktop\新建\name-2.exe - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\新建\name-3.exe - Infected TROJAN.VB.A - Deleted
C:\Documents and Settings\Uhthn\Desktop\新建\name-4.exe - OK
C:\Documents and Settings\Uhthn\Desktop\新建\name-5.exe - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\新建\name-6.exe - Infected BACKDOOR.HUPIGON.10 - Deleted
C:\Documents and Settings\Uhthn\Desktop\新建\name-7.exe - Suspected MaliciousScope:WIN32.GENERIC.MALWARE.12
C:\Documents and Settings\Uhthn\Desktop\新建\name-8.exe - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\新建\name-9.exe - OK

16 Files scanned
3 Infected files found
7 Suspected files found
0 Files disinfected
3 Files deleted
googlehack
发表于 2007-11-6 13:20:08 | 显示全部楼层
质量还不错,有一部分是加壳的,还有一部分没有。
无敌敏敏
发表于 2007-11-6 13:33:15 | 显示全部楼层

红伞14个

Starting the file scan:

Begin scan in 'E:\新建文件夹.part1.rar'
E:\新建文件夹.part1.rar
  [0] Archive type: RAR
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-1.exe
      [DETECTION] Contains detection pattern of the dropper DR/PcClient.Gen
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-10.exe
      [DETECTION] Is the Trojan horse TR/Spy.Agent.IY
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-11.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-12.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-13.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.vih Backdoor server programs
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-14.exe
      [DETECTION] Is the Trojan horse TR/VB.bjb
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-15.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Agent.YWI.1 Backdoor server programs
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-16.exe
      [DETECTION] Contains detection pattern of the worm WORM/Sumom.C.22
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-2.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Pcclient.SYX.89 Backdoor server programs
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-3.exe
      [DETECTION] Contains detection pattern of the SPR/Fake.Syscontrol program
      [INFO]      The file was deleted!
Begin scan in 'E:\新建文件夹.part2.rar'
E:\新建文件夹.part2.rar
  [0] Archive type: RAR
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-5.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.vjh Backdoor server programs
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-6.exe
      [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Asprotect). Please verify the origin of the file
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-7.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> &ETH;&Acirc;&frac12;¨&Icirc;&Auml;&frac14;&thorn;&frac14;&ETH;\name-9.exe
      [DETECTION] Is the Trojan horse TR/Agent.39936.11
      [INFO]      The file was deleted!


End of the scan: 2007年11月6日  13:31
Used time: 00:25 min

The scan has been done completely.

      0 Scanning directories
     17 Files were scanned
     14 viruses and/or unwanted programs were found

[ 本帖最后由 无敌敏敏 于 2007-11-6 13:40 编辑 ]
xuekaihappy
发表于 2007-11-6 19:22:22 | 显示全部楼层
。。。好像没什么反应啊
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 06:39 , Processed in 0.084185 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表