12
返回列表 发新帖
楼主: kp2006
收起左侧

[病毒样本] 9个

[复制链接]
454651860
发表于 2007-11-6 13:06:28 | 显示全部楼层
那几个网页是挂马的
浏览器后台下载,金山2008清理专家的防挂马全拦了
pmj_sh
发表于 2007-11-6 13:20:00 | 显示全部楼层
Object: A0017233.exe
        Path: C:\Documents and Settings\pMj\桌面\9
        Status: Virus detected
        Virus: Trojan-PSW.Win32.OnLineGames.grr (Engine A)
Object: A0017234.exe
        Path: C:\Documents and Settings\pMj\桌面\9
        Status: Virus detected
        Virus: Trojan.Win32.Agent.cli (Engine A)
Object: A0017249.exe
        Path: C:\Documents and Settings\pMj\桌面\9
        Status: Virus detected
        Virus: Backdoor.Win32.Popwin.aic (Engine A)
Object: xp14[1].htm
        Path: C:\Documents and Settings\pMj\桌面\9
        Status: Virus detected
        Virus: Trojan-Downloader.VBS.Agent.ff (Engine A)
Analysis complete: 11/6/2007 13:20
    9 files checked
    4 infected files detected
    0 suspected files detected
googlehack
发表于 2007-11-6 14:05:53 | 显示全部楼层
貌似是从系统还原区提取的……这么说以前就中病毒了?
caocao
发表于 2007-11-6 16:04:05 | 显示全部楼层

回复 9楼 Redevil 的帖子

卡巴剩余几个可以杀了
Hello,

aa2[1].htm_ - Trojan-Downloader.VBS.Psyme.jy,
aa4[1].htm_ - Trojan-Downloader.JS.Small.hj,
aa6[1].htm_ - Trojan-Downloader.JS.Small.hk,
ee2[1].htm_ - Trojan-Downloader.JS.Small.hl,
winoperl.sys - Rootkit.Win32.Agent.mt

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Namestnikov Yury
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
吃青草的狼
发表于 2007-11-6 17:15:58 | 显示全部楼层
信息        2007-11-06  17:14:37        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2007-11-06  17:14:37        D:\桌面.rar\A0017249.exe        Win32.Hack.Popwin.106535        清除成功       
病毒        2007-11-06  17:14:37        D:\桌面.rar\A0017234.exe        Win32.Troj.Agent.61440        清除成功       
病毒        2007-11-06  17:14:37        D:\桌面.rar\A0017233.exe        Win32.PSWTroj.OnlineGames.os.90112        清除成功       

毒霸2008
傻猪猪米走鸡
发表于 2007-11-6 19:12:11 | 显示全部楼层
D:\firefox下载的文件\桌面.rar » RAR » A0017233.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\firefox下载的文件\桌面.rar » RAR » A0017249.exe - Win32/TrojanDownloader.Flux trojan
xuekaihappy
发表于 2007-11-6 19:19:16 | 显示全部楼层
试试看
haol
发表于 2007-11-6 22:45:02 | 显示全部楼层
trend found 4 threats
uhthn2002
发表于 2007-11-7 00:13:50 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 810
Paranoia Database - 48490
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\Uhthn\Desktop\New Folder (2)

C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\aa6[1].htm - Infected VIRUS.SCRIPT.C93 - Disinfected
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\xp14[1].htm - OK
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\aa2[1].htm - OK
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\ee2[1].htm - OK
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\A0017233.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\A0017234.exe - Infected TROJAN-DOWNLOADER.AGENT.21 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\A0017249.exe - Infected BACKDOOR.AGENT.9 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\winoperl.sys - Suspected TROJAN-DOWNLOADER (HTTP://{REMOVED}/...)
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\aa4[1].htm - OK

9 Files scanned
3 Infected files found
2 Suspected files found
1 Files disinfected
2 Files deleted
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 21:47 , Processed in 0.103219 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表