123
返回列表 发新帖
楼主: promised
收起左侧

[病毒样本] 木马群38个

[复制链接]
qigang
发表于 2007-11-17 17:27:28 | 显示全部楼层

67/36

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.PSW.Win32.GameOnline.agr
病毒: Trojan.PSW.Win32.SO2Game.d
病毒: Trojan.PSW.Win32.WoWar.aez
病毒: RootKit.Win32.Paice.a   
病毒: Trojan.Win32.Agent.vmq   
病毒: Trojan.DL.Win32.Agent.yrh
病毒: Trojan.PSW.Win32.GameOnline.aen
病毒: Trojan.PSW.Win32.GameOnline.adh
病毒: Trojan.PSW.Win32.GameOnline.agj
病毒: Trojan.PSW.Win32.DJOnline.as
病毒: Trojan.PSW.Win32.GameOnline.adp
病毒: Trojan.PSW.Win32.Woool.c
病毒: Trojan.PSW.Win32.WoWar.uz
病毒: Worm.Win32.PaBug.dq      
病毒: Trojan.PSW.Win32.SunOnline.fy
病毒: Trojan.PSW.Win32.GameOnline.aha
病毒: Trojan.PSW.Win32.GameOnline.ahj
病毒: Trojan.PSW.Win32.SO2Online.n
病毒: Worm.Win32.PaBug.dn      
病毒: Trojan.PSW.Win32.Woool.c
病毒: Trojan.PSW.Win32.GameOnline.afu
病毒: Trojan.PSW.Win32.GameOnline.aeq
病毒: Trojan.PSW.Win32.GameOnline.afs
病毒: Trojan.PSW.Win32.GameOnline.add
病毒: Trojan.PSW.Win32.GameOnline.aem
病毒: Trojan.PSW.Win32.WoWar.aez
病毒: Trojan.PSW.Win32.GameOnline.aeo
病毒: Trojan.PSW.Win32.GameOnline.adc
病毒: Trojan.PSW.Win32.GameOnline.aha

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.18.51
uhthn2002
发表于 2007-11-17 21:13:53 | 显示全部楼层
Uhthn Anti-Spyware V3 Alpha
Version - 3.0.0
Standard Database - 906
Paranoia Database - 48810
Heuristics Analysis - Excessive
Scan in - C:\Documents and Settings\Uhthn\Desktop\New Folder (2)

C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\asview32.dll - Suspected MaliciousScope:GENERIC.MALWARE.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\24.exe - OK
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\21.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\19.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\15.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\13.exe - Suspected MaliciousScope:WIN32.GENERIC.MALWARE.8
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\10.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\8.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\7.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\5.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\4.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\2.exe - Suspected TROJAN-PSW.ONLINEGAMES.2
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\joubjptyej.dll - Suspected MaliciousScope:GENERIC.MALWARE.3
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\Buik01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\AVPSrv.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\pcihdd.sys - Infected GENERIC.MALWARE.623.1A70 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\23.exe - Infected TROJAN-DOWNLOADER.AGENT.5 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\20.exe - Infected TROJAN-PSW.ONLINEGAMES.97 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\18.exe - Infected TROJAN-PSW.ONLINEGAMES.48 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\17.exe - Infected TROJAN-PSW.ONLINEGAMES.48 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\14.exe - Infected WIN32.TROJAN-PSW.ONLINEGAMES.G - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\12.exe - Infected WIN32.TROJAN-PSW.QQPASS.A - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\11.exe - Infected TROJAN-PSW.ONLINEGAMES.48 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\9.exe - Infected TROJAN-PSW.ONLINEGAMES.48 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\6.exe - Infected TROJAN-PSW.GAME.9 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\Wn_Sys8x.Sys - Infected WIN32.TROJAN-PSW.QQPASS.A - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\608769WL.DLL - Infected WIN32.TROJAN-PSW.ONLINEGAMES.G - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\Vml.exe - Infected MaliciousScope:TROJAN-DOWNLOADER.AGENT.3 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\SVCCtrl01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\SQLLink01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\SafeCtrl01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\ProcSvr01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\npptools.dll - KNOWN CLEAN
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\LotusHlp.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\KVBatch01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\DVBBack01.dll - Infected TROJAN-PSW.ONLINEGAMES.43 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\DbgHlp32.dll - Infected TROJAN-PSW.ONLINEGAMES.12 - Deleted
C:\Documents and Settings\Uhthn\Desktop\New Folder (2)\cmdbcs.dll - Infected TROJAN-PSW.ONLINEGAMES.12 - Deleted

38 Files scanned
24 Infected files found
12 Suspected files found
0 Files disinfected
24 Files deleted
woai_jolin
发表于 2007-11-17 21:21:18 | 显示全部楼层
手动杀毒(按时间降序排列)
信息        2007-11-17 21:21:11        您此次查毒删除了27个文件                       
信息        2007-11-17 21:21:11        您此次查毒共查出29个病毒以及危险代码                       
信息        2007-11-17 21:21:11        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件62个                       
信息        2007-11-17 21:21:11        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
风险程序        2007-11-17 21:21:11        G:\V\样本.rar\Vml.exe        Win32.HackTool.Agent.b.13531        跳过,未处理       
风险程序        2007-11-17 21:21:11        G:\V\样本.rar\24.exe\BindFile\Vml.exe        Win32.HackTool.Agent.b.13531        跳过,未处理       
病毒        2007-11-17 21:21:06        G:\V\样本.rar\DbgHlp32.dll        Win32.PSWTroj.OnLineGames.24064        删除成功       
病毒        2007-11-17 21:21:06        G:\V\样本.rar\DVBBack01.dll        Win32.Troj.OnlineGames.dv.26624        删除成功       
病毒        2007-11-17 21:21:06        G:\V\样本.rar\joubjptyej.dll        Win32.PSWTroj.WowT.my.17831        删除成功       
病毒        2007-11-17 21:21:06        G:\V\样本.rar\KVBatch01.dll        Win32.Troj.OnlineGames.xy.23040        删除成功       
病毒        2007-11-17 21:21:06        G:\V\样本.rar\LotusHlp.dll        Win32.PSWTroj.OnLineGames.19456        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\ProcSvr01.dll        Win32.Troj.OnlineGames.nf.27136        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\SafeCtrl01.dll        Win32.Troj.OnlineGamesT.yf.26624        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\SQLLink01.dll        Win32.Troj.OnlineGames.nf.26624        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\SVCCtrl01.dll        Win32.Troj.OnlineGamesT.yf.26624        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\608769WL.DLL        Win32.Troj.OnlineGamesT.xy.44337        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\Wn_Sys8x.Sys        Win32.PSWTroj.QQPass.48244        删除成功       
病毒        2007-11-17 21:21:05        G:\V\样本.rar\6.exe        Win32.Troj.OnLineGamesT.gr.2637        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\9.exe        Win32.Troj.OnlineGamesT.eo.14796        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\10.exe        Win32.Troj.OnLineGamesT.gr.2637        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\11.exe        Win32.Troj.OnlineGamesT.eo.14796        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\12.exe        Win32.PSWTroj.OnLineGames.110705        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\13.exe        Win32.PSWTroj.Lmir.38614        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\14.exe        Win32.Troj.OnlineGamesT.zy.123185        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\15.exe        Win32.Troj.OnLineGamesT.gr.2637        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\17.exe        Win32.Troj.OnlineGamesT.eo.14796        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\18.exe        Win32.Troj.OnlineGamesT.eo.14796        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\20.exe        Win32.Troj.OnLineGamesT.gr.2637        删除成功       
病毒        2007-11-17 21:21:04        G:\V\样本.rar\23.exe        Win32.TrojDownloader.Agent.61440        删除成功       
病毒        2007-11-17 21:21:03        G:\V\样本.rar\pcihdd.sys        Win32.Troj.Agent.dz.6768        删除成功       
病毒        2007-11-17 21:21:03        G:\V\样本.rar\asview32.dll        Win32.PSWTroj.OnLineGames.108032        删除成功       
病毒        2007-11-17 21:21:03        G:\V\样本.rar\AVPSrv.dll        Win32.Troj.OnlineGames.hn.25088        删除成功       
病毒        2007-11-17 21:21:03        G:\V\样本.rar\Buik01.dll        Win32.Troj.OnlineGamesT.yf.26624        删除成功       
信息        2007-11-17 21:20:45        金山毒霸主程序启动查毒过程,查毒方式:命令行查毒                       
信息        2007-11-17 21:20:44        金山毒霸主程序 启动                       
信息        2007-11-17 21:14:08        金山毒霸主程序 退出
有点失落
发表于 2007-11-17 23:05:28 | 显示全部楼层
Start of the scan: 2007年11月17日  22:57

Starting the file scan:

Begin scan in 'F:\BD样本\样本.rar'
F:\BD样本\样本.rar
  [0] Archive type: RAR
  --> Buik01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> AVPSrv.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> asview32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.hnt
  --> pcihdd.sys
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.blm.3
  --> 24.exe
      [DETECTION] Contains detection pattern of the dropper DR/Agent.318861
      [1] Archive type: RAR SFX (self extracting)
      --> Vml.exe
          [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 23.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.blm.3
  --> 21.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 20.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 19.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 18.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> 17.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> 15.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.hqq
  --> 14.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 13.exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/PSW.QQpass.als
  --> 11.exe
      [DETECTION] Is the Trojan horse TR/CrashSystem.C
  --> 10.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 9.exe
      [DETECTION] Is the Trojan horse TR/CrashSystem.C
  --> 8.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 7.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.hxi
  --> 4.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/PSW.Nilage.bty.7
  --> Wn_Sys8x.Sys
      [DETECTION] Is the Trojan horse TR/PSW.QQpass.als
  --> 608769WL.DLL
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> Vml.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> SVCCtrl01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> SQLLink01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> ProcSvr01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> LotusHlp.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> KVBatch01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> joubjptyej.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.hnt
  --> DVBBack01.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> DbgHlp32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.hqq
  --> cmdbcs.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      A backup was created as '476d6888.qua'  ( QUARANTINE )


End of the scan: 2007年11月17日  22:57
Used time: 00:13 min

The scan has been done completely.

      0 Scanning directories
     47 Files were scanned
     24 viruses and/or unwanted programs were found
     13 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     23 Files not concerned
      2 Archives were scanned
      0 Warnings
      0 Notes
ballakay
发表于 2007-11-18 00:29:00 | 显示全部楼层
Scanning Report
18 November 2007 00:27:38 - 00:27:39
Computer name: PUMA-PC
Scanning type: Scan target
Target: C:\Users\Administrator\Desktop\Ñù±¾.rar


--------------------------------------------------------------------------------

Result: 32 malware found
Trojan-PSW.Win32.OnLineGames.hye (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\Buik01.dll
Trojan-PSW.Win32.OnLineGames.hhn (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\AVPSrv.dll
Trojan-PSW.Win32.OnLineGames.hnt (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\asview32.dll
C:\Users\Administrator\Desktop\Ñù±¾.rar\joubjptyej.dll
Trojan-Downloader.Win32.Agent.blm (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\pcihdd.sys
C:\Users\Administrator\Desktop\Ñù±¾.rar\23.exe
Trojan.BAT.Agent.be (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\24.exe
Trojan-PSW.Win32.Nilage.bty (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\21.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\19.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\8.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\7.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\2.exe
Trojan-PSW.Win32.OnLineGames.hrb (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\20.exe
Trojan-PSW.Win32.OnLineGames.hqh (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\18.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\17.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\11.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\9.exe
Trojan-PSW.Win32.OnLineGames.hre (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\15.exe
Trojan-PSW.Win32.OnLineGames.hfr (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\14.exe
Trojan-PSW.Win32.Lmir.bov (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\13.exe
Trojan-PSW.Win32.QQPass.als (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\12.exe
C:\Users\Administrator\Desktop\Ñù±¾.rar\Wn_Sys8x.Sys
Trojan-PSW.Win32.OnLineGames.hho (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\6.exe
Trojan-PSW.Win32.OnLineGames.hxi (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\5.exe
Trojan-PSW.Win32.OnLineGames.hys (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\SVCCtrl01.dll
Trojan-PSW.Win32.OnLineGames.hyr (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\SQLLink01.dll
Trojan-PSW.Win32.OnLineGames.hyk (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\SafeCtrl01.dll
Trojan-PSW.Win32.OnLineGames.hyi (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\ProcSvr01.dll
Trojan-PSW.Win32.OnLineGames.hqt (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\LotusHlp.dll
Trojan-PSW.Win32.Nilage.bue (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\KVBatch01.dll
Trojan-PSW.Win32.OnLineGames.hyf (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\DVBBack01.dll
Trojan-PSW.Win32.OnLineGames.hqq (virus)
C:\Users\Administrator\Desktop\Ñù±¾.rar\DbgHlp32.dll



--------------------------------------------------------------------------------

Riskware found
NetTool.Win32.Agent.b (riskware)
C:\Users\Administrator\Desktop\Ñù±¾.rar\Vml.exe


--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 39
Not scanned: 0
Result:
Viruses: 32
Spyware: 0
Suspicious items: 0
Riskware: 1
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0


--------------------------------------------------------------------------------

Options
Definitions version:
Viruses: 2007-11-17_02
Spyware: 2007-11-16_06
Scanning Engines:
F-Secure AVP: 7.00.171, 2007-11-16
F-Secure Libra: 2.04.01, 2007-11-17
F-Secure Orion: 1.02.37, 2007-11-17
F-Secure Draco: 1.00.35, 2007-10-30
Scanning options:
Scan all files
Scan inside archives
Actions:
Viruses: Delete infected files
Spyware: Delete infected files
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-21 05:17 , Processed in 0.088213 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表