查看: 3815|回复: 23
收起左侧

[病毒样本] 10只

[复制链接]
promised
发表于 2007-11-9 22:00:05 | 显示全部楼层 |阅读模式
C:\ABC\样本.rar:\OnlO0r.bak - 特征码 'Virus.Win32.AutoRun.u' 被发现
C:\ABC\样本.rar:\OnlO0r.dll - 特征码 'Virus.Win32.AutoRun.u' 被发现
C:\ABC\样本.rar:\scvhost.exe - 特征码 'Backdoor.Win32.Delf.awy' 被发现
C:\ABC\样本.rar:\svchost.exe - 特征码 'Virus.Win32.QQRob.AS' 被发现
C:\ABC\样本.rar:\pcihdd.sys - 特征码 'Trojan-Downloader.Win32.Agent.blm' 被发现
C:\ABC\样本.rar:\fkqxejpuyf.dll - 特征码 'Trojan-PWS.Win32.Agent.jp' 被发现
C:\ABC\样本.rar:\mswmp32.dll - 特征码 'Trojan-PWS.Win32.Delf.ix' 被发现
C:\ABC\样本.rar:\S1682.exe - 特征码 'Trojan-Downloader.Win32.Zlob.and' 被发现
C:\ABC\样本.rar:\win5.exe - 特征码 'Trojan-PWS.Win32.OnLineGames.wp' 被发现
C:\ABC\样本.rar:\win7.exe - 特征码 'Trojan-Downloader.Win32.Agent.blm' 被发现
C:\ABC\样本.rar
11 文件被扫描
   (1 压缩档 10 文件)
10 特征码被侦测
0 可疑代码段被发现
耗时: 0:00.234

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
微点卫士
发表于 2007-11-9 22:01:56 | 显示全部楼层
木马名称:Backdoor.Win32.ARP.c

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\SCVHOST.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Dropper.Win32.Delf.ctm

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\SVCHOST.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Downloader.Win32.Agent.jzd

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\PCIHDD.SYS
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.WOW.bjs

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\MSWMP32.DLL
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-PSW.Win32.OnLineGames.tom

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\WIN5.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?
木马名称:Trojan-Downloader.Win32.Agent.lkp

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.DDB55590E8074DB\桌面\WIN7.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

S1682.exe
Nerazzurri
发表于 2007-11-9 22:02:26 | 显示全部楼层

9个 上报

deleted: Trojan program Trojan-PSW.Win32.Delf.aha        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/OnlO0r.bak//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-PSW.Win32.Delf.aha        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/OnlO0r.dll
deleted: Trojan program Backdoor.Win32.Delf.awy        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/scvhost.exe
deleted: Trojan program Trojan-Dropper.Win32.Delf.ais        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/svchost.exe//FSG//PEPatch
deleted: Trojan program Trojan-Downloader.Win32.Agent.blm        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/pcihdd.sys
deleted: Trojan program Trojan-PSW.Win32.WOW.adm        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/fkqxejpuyf.dll//UPack//PE_Patch.MaskPE
deleted: Trojan program Trojan-PSW.Win32.WOW.adm        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/mswmp32.dll//FSG
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.fyn        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/win5.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.blm        File: C:\Users\Jack Jones\Desktop\Ñù±¾.rar/win7.exe
gwg829
头像被屏蔽
发表于 2007-11-9 22:03:54 | 显示全部楼层
LZ今晚放毒无数  跟不上了
qigang
发表于 2007-11-9 22:04:12 | 显示全部楼层

17/9

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.PSW.Win32.GameOnline.yp
病毒: Trojan.PSW.Win32.GameOnline.yr
病毒: Backdoor.Win32.Agent.yff
病毒: Trojan.Win32.Agent.zte   
病毒: RootKit.Win32.Paice.a   
病毒: Trojan.PSW.Win32.WoWar.aea
病毒: Trojan.PSW.Win32.WoWar.aea
病毒: Trojan.PSW.Win32.GameOnline.px
病毒: Trojan.DL.Win32.Agent.yrh

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.17.42
sbbdms
发表于 2007-11-9 22:13:32 | 显示全部楼层
江民杀7
nosferatu
头像被屏蔽
发表于 2007-11-9 22:23:28 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\样本.rar'
C:\Documents and Settings\Administrator\桌面\样本.rar
  [0] Archive type: RAR
  --> OnlO0r.bak
      [DETECTION] Is the Trojan horse TR/Autorun.BK
  --> OnlO0r.dll
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> scvhost.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> svchost.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> pcihdd.sys
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.blm.3
  --> fkqxejpuyf.dll
      [DETECTION] Is the Trojan horse TR/PSW.Wow.adm
  --> mswmp32.dll
      [DETECTION] Is the Trojan horse TR/PSW.Wow.adm
  --> S1682.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> win5.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> win7.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.blm.3
      [INFO]      The file was deleted!


End of the scan: 星期五 2007年11月9日  22:23
Used time: 00:07 min

The scan has been done completely.

      0 Scanning directories
     12 Files were scanned
      8 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
IllusionWing
发表于 2007-11-9 22:25:26 | 显示全部楼层
9个

UGuard Log (Digital Fox - gankeyu@126.com)
UGuarduu.exe = 4.5.0
HC0.rlb = 3.0.0
HC2.rlb = 2.4.0
FN0.rlb = 2.3.1
扫描选项:扫描档案, 扩展, 忽略非活动, 忽略大文件, nFile, BAT模拟, 捆绑检测, 变形壳, 启发,
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\fkqxejpuyf.dll 检测到 Packed.Generic.UPack
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\mswmp32.dll 检测到 Packed.Generic.Modified
[扫描] [nFile Detect 2] 在 F:\Users\Administrator\Desktop\VDB\OnlO0r.bak 检测到 Generic.nFile
[扫描] [nFile Detect 2] 在 F:\Users\Administrator\Desktop\VDB\OnlO0r.dll 检测到 Generic.nFile
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\S1682.exe 检测到 Packed.Generic.Modified
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\scvhost.exe 检测到 Packed.Generic.Modified
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\svchost.exe 检测到 Packed.Generic.Modified
[扫描] [捆绑检测] 在 F:\Users\Administrator\Desktop\VDB\win5.exe//UPX 检测到 Generic.Binder
[扫描] [变形壳检测] 在 F:\Users\Administrator\Desktop\VDB\win7.exe 检测到 Packed.Unknown.c6e7
检测到了 9 个未知的恶意程序,请上报。
任务 扫描 完成。共耗费的时间:0-00-00 00:00:00:0125,共扫描的文件数量:11,共扫描到的威胁数量:9,威胁率:81.82%,扫描速率: 88 文件/秒,扫描速度: 3308.46 千字节/秒,共扫描了 413.56 千字节。
dericyeoh
发表于 2007-11-9 22:27:44 | 显示全部楼层
deleted: Trojan program Trojan-PSW.Win32.Delf.aha        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/OnlO0r.bak//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-PSW.Win32.Delf.aha        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/OnlO0r.dll
deleted: Trojan program Backdoor.Win32.Delf.awy        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/scvhost.exe
deleted: Trojan program Trojan-Dropper.Win32.Delf.ais        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/svchost.exe//FSG//PEPatch
deleted: Trojan program Trojan-Downloader.Win32.Agent.blm        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/pcihdd.sys
deleted: Trojan program Trojan-PSW.Win32.WOW.adm        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/fkqxejpuyf.dll//UPack//PE_Patch.MaskPE
deleted: Trojan program Trojan-PSW.Win32.WOW.adm        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/mswmp32.dll//FSG
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.fyn        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/win5.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.blm        File: C:\Documents and Settings\Deric Yeoh\×ÀÃæ\Ñù±¾.rar/win7.exe
yitp
发表于 2007-11-9 22:31:17 | 显示全部楼层
Result: 7 malware found
Backdoor.Win32.Delf.awy (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\scvhost.exe
Trojan-Dropper.Win32.Delf.ais (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\svchost.exe
Trojan-Downloader.Win32.Agent.blm (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\pcihdd.sys
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\win7.exe
Trojan-PSW.Win32.WOW.adm (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\fkqxejpuyf.dll
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\mswmp32.dll
Trojan-PSW.Win32.OnLineGames.fyn (virus)
C:\Documents and Settings\Administrator\×ÀÃæ\Ñù±¾.rar\win5.exe




--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 11
Not scanned: 0
Result:
Viruses: 7
Spyware: 0
Suspicious items: 0
Riskware: 0
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0


--------------------------------------------------------------------------------

Options
Definitions version:
Viruses: 2007-11-09_02
Spyware: 2007-11-09_01
Scanning Engines:
F-Secure AVP: 7.00.171, 2007-11-09
F-Secure Libra: 2.04.01, 2007-11-06
F-Secure Orion: 1.02.37, 2007-11-09
F-Secure Draco: 1.00.35, 2007-10-30
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 16:48 , Processed in 0.134282 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表