查看: 4407|回复: 23
收起左侧

[病毒样本] 21个

[复制链接]
qianwenxiang
发表于 2007-12-12 22:16:57 | 显示全部楼层 |阅读模式
某某程序下载的
clamwin
----------- SCAN SUMMARY -----------
Known viruses: 175718
Engine version: 0.91.1
Scanned directories: 0
Scanned files: 20
Skipped non-executable files: 0
Infected files: 0
Data scanned: 0.29 MB
Time: 6.969 sec (0 m 6 s)
--------------------------------------
Completed
--------------------------------------

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
挪威的冬天
发表于 2007-12-12 22:19:54 | 显示全部楼层

信息        2007-12-12  22:18:16        您此次查毒共查出17个病毒以及危险代码                       
信息        2007-12-12  22:18:16        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件33个                       
信息        2007-12-12  22:18:16        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\C0NIME.EXE        Worm.AutoRuns.y.151552        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00023.exe        Win32.PSWTroj.OnLineGames.106496        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00021.exe        Win32.Troj.OnLineGamesT.or.258048        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00020.exe        Win32.Troj.OnLineGamesT.gp.15597        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00019.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00016.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00013.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00012.exe        Win32.Troj.OnLineGamesT.or.258048        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00010.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00009.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00008.exe        Win32.Troj.OnLineGamesT.or.258048        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00006.exe        Win32.Troj.AgentT.fm.14452        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00005.exe        Win32.Troj.OnlineGamesT.fi.86016        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00004.exe        Win32.Troj.OnLineGamesT.gp.15597        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00003.exe        Win32.Troj.OnLineGamesT.gr.2637        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00002.exe        Win32.PSWTroj.OnLineGames.15361        跳过,未处理       
病毒        2007-12-12  22:18:16        C:\Documents and Settings\Norways Winter\桌面\system.rar\00001.exe        Win32.Troj.OnLineGamesT.gr.2637        跳过,未处理
wangjay1980
发表于 2007-12-12 22:24:09 | 显示全部楼层
19
detected: Trojan program Trojan-PSW.Win32.OnLineGames.isb        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00001.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.jps        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00002.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.isb        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00003.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kbj        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00004.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kfv        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00005.exe//UPack
detected: Trojan program Backdoor.Win32.PcClient.ie        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00006.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kag        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00008.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.jpc        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00009.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.jop        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00010.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kmp        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00012.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.iys        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00013.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kkq        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00014.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.knn        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00016.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kfs        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00019.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.jml        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00020.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.khm        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00021.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.jct        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/00023.exe//UPack
detected: virus Virus.Win32.AutoRun.aik        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/C0NIME.EXE//UPack
detected: Trojan program Trojan.Win32.Qhost.aaf        File: C:\Documents and Settings\Owner\×ÀÃæ\system.rar/host.exe//UPack
剑书
头像被屏蔽
发表于 2007-12-12 22:30:07 | 显示全部楼层
Starting the file scan:

Begin scan in 'K:\system.rar'
K:\system.rar
  [0] Archive type: RAR
  --> 00001.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00002.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00003.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00004.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kas
  --> 00005.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.kfv.1
  --> 00006.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jal
  --> 00008.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jfm
  --> 00009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jpc
  --> 00010.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfj
  --> 00012.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00013.exe
      [DETECTION] Is the Trojan horse TR/FWDisable.24932
  --> 00014.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> 00016.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGam.htk
  --> 00019.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kfr
  --> 00020.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfh
  --> 00021.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00023.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
  --> C0NIME.EXE
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> host.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> soundma.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      A backup was created as '47d2f0be.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!


End of the scan: 2007年12月12日  22:29
Used time: 00:03 min

The scan has been done completely.

      0 Scanning directories
     22 Files were scanned
     18 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
zhr5898
发表于 2007-12-12 22:32:16 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\system.rar'
D:\system.rar
  [0] Archive type: RAR
  --> 00001.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00002.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00003.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00004.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kas
  --> 00005.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.kfv.1
  --> 00006.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jal
  --> 00008.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jfm
  --> 00009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jpc
  --> 00010.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfj
  --> 00012.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00013.exe
      [DETECTION] Is the Trojan horse TR/FWDisable.24932
  --> 00014.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> 00016.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGam.htk
  --> 00019.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kfr
  --> 00020.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfh
  --> 00021.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00023.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
  --> C0NIME.EXE
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> host.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> soundma.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was deleted!


End of the scan: 2007年12月12日  22:33
Used time: 00:20 min

The scan has been done completely.

      0 Scanning directories
     21 Files were scanned
     18 viruses and/or unwanted programs were found
      2 Files were classified as suspicious
碧水寒潭
发表于 2007-12-12 22:34:10 | 显示全部楼层
Start of the scan: 2007年12月12日  22:33

Starting the file scan:

Begin scan in 'I:\样本'
I:\样本\system.rar
  [0] Archive type: RAR
  --> 00001.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00002.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00003.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00004.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kas
  --> 00005.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.kfv.1
  --> 00006.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jal
  --> 00008.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jfm
  --> 00009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jpc
  --> 00010.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfj
  --> 00012.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00013.exe
      [DETECTION] Is the Trojan horse TR/FWDisable.24932
  --> 00014.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> 00016.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGam.htk
  --> 00019.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.kfr
  --> 00020.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.jfh
  --> 00021.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00023.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
  --> C0NIME.EXE
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> host.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> soundma.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was deleted!


End of the scan: 2007年12月12日  22:33
Used time: 00:15 min

The scan has been done completely.

      1 Scanning directories
     21 Files were scanned
     18 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
欠妳緈諨
发表于 2007-12-12 22:39:38 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
残缺的唯美
发表于 2007-12-12 23:08:32 | 显示全部楼层
G:\Users\Administrator\Desktop\system.rar » RAR » 00001.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00002.exe - a variant of Win32/PSW.OnLineGames.YA trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00003.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00004.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00006.exe - Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00008.exe - a variant of Win32/PSW.OnLineGames.JOJ trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00009.exe - Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00010.exe - Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00012.exe - a variant of Win32/PSW.OnLineGames.JOJ trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00013.exe - Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00014.exe - probably a variant of Win32/PSW.OnLineGames.NGU trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00016.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00019.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00020.exe - Win32/PSW.OnLineGames.FDY trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00021.exe - probably a variant of Win32/PSW.OnLineGames.NHF trojan
G:\Users\Administrator\Desktop\system.rar » RAR » 00023.exe - a variant of Win32/Agent.NLW trojan
G:\Users\Administrator\Desktop\system.rar » RAR » C0NIME.EXE - probably unknown NewHeur_PE virus
sam.to
发表于 2007-12-12 23:12:20 | 显示全部楼层

回复 3楼 wangjay1980 的帖子

你有把沒有报的上报嗎?
wangjay1980
发表于 2007-12-12 23:22:38 | 显示全部楼层

回复 9楼 kato9096 的帖子

报了,只要是我回帖的都肯定上报了

我看到你回帖的,我就不用上报了

[ 本帖最后由 wangjay1980 于 2007-12-12 23:23 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-22 21:03 , Processed in 0.135122 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表