查看: 4018|回复: 20
收起左侧

[病毒样本] 16pcs

[复制链接]
自由
发表于 2007-12-30 18:52:50 | 显示全部楼层 |阅读模式
+

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
无尽藏海
发表于 2007-12-30 18:57:22 | 显示全部楼层
第一个飘……

Begin scan in 'D:\Downloads\样本\15.rar'
D:\Downloads\样本\15.rar
  [0] Archive type: RAR
  --> 14.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
  --> 1.EXE
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> 4.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
  --> 6.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> 10.exe
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> 15.exe
      [DETECTION] Is the Trojan horse TR/FWDisable.25015
  --> 2.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
  --> 5.exe
      [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
  --> 11.exe
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> 16.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 8.exe
      [DETECTION] Is the Trojan horse TR/Agent.16184
  --> 9.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen

16 Files were scanned
     12 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
qigang
发表于 2007-12-30 18:58:48 | 显示全部楼层

31/9

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.PSW.Win32.GamesOnline.db
病毒: Packer.Win32.VmpPacker.a
病毒: Trojan.PSW.Win32.SunGame.h
病毒: Trojan.PSW.Win32.GameOL.gpe
病毒: Malicious Code           
病毒: Trojan.PSW.Win32.GameOL.gmv
病毒: Trojan.Win32.Undef.asp   
病毒: Trojan.PSW.Win32.QQSG.br

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.24.60
a369258147
头像被屏蔽
发表于 2007-12-30 19:04:59 | 显示全部楼层
Trojan/PSW.OnLineGames.hnz“网游窃贼”变种hnz运行后,在后台秘密监视用户键盘操作,当用户登陆网络游戏页面时,窃取玩家游戏帐号和密码,并发送到黑客指定邮箱里。
无尽藏海
发表于 2007-12-30 19:07:17 | 显示全部楼层
蜘蛛

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
will
发表于 2007-12-30 19:14:56 | 显示全部楼层

avast! 11

Win32:AutoRun-IC                               1.EXE
Win32:OnLineGames-BKU [Trj]            3.exe  
Win32:OnLineGames-SR [Trj]              4.exe
Win32:Agent-LSI [Trj]                            5.exe  
Win32:AutoRun-IC                                10.exe        
Win32:AutoRun-IC                                11.exe        
Win32:OnLineGames-BKU [Trj]             12.exe
Win32:Baidubar-B [Trj]                          13.exe(这个就是1.rar里面的)
Win32:OnLineGames-SR [Trj]               14.exe
Win32:OnLineGames-BOA [Trj]            15.exe        
Win32:OnLineGames-BGD [Trj]            16.exe
电影结束了
发表于 2007-12-30 19:23:43 | 显示全部楼层
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 14.exe - a variant of Win32/PSW.Agent.NEC trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 1.EXE - a variant of Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 4.exe - a variant of Win32/PSW.Agent.NEC trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 6.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 10.exe - a variant of Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 15.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 2.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 5.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 11.exe - a variant of Win32/TrojanDownloader.Flux trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 16.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 3.exe - a variant of Win32/PSW.OnLineGames.JOJ trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 8.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\wangcheng\桌面\15.rar » RAR » 12.exe - a variant of Win32/PSW.OnLineGames.JOJ trojan
yangpizhi
发表于 2007-12-30 19:39:12 | 显示全部楼层
第一个F-Prot挂。。。
-----------------------------SCAN REPORT-----------------------------
F-PROT Antivirus for Windows

Antivirus Scanning Engine version number: 4.4.2
Virus signature file from: 2007-12-30, 0:17

Scan name: [Custom Scan]
Path to scan: C:\样本 yangpizhi\15.rar

Normal scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2007-12-30, 19:38:49
---------------------------------------------------------------------

[Found possible security risk]         <W32/Heuristic-114!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\15.rar->14.exe->(embedded)->(UPack)
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\样本 yangpizhi\15.rar->1.EXE->(UPack)
[Found possible security risk]         <W32/Heuristic-114!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\15.rar->4.exe->(embedded)->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->6.exe->(Klone.AF)
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\样本 yangpizhi\15.rar->10.exe->(UPack)
[Found security risk]         <W32/OnlineGames.A.gen!GSA (not disinfectable, generic)>        C:\样本 yangpizhi\15.rar->15.exe->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->2.exe->(FSG)
[Clean]        C:\样本 yangpizhi\15.rar->5.exe->(embedded)
[Clean]        C:\样本 yangpizhi\15.rar->5.exe->(embedded)
[Found possible virus]         <W32/SecRisk-ProcessPatcher-Sml-based!Maximus (not disinfectable)>        C:\样本 yangpizhi\15.rar->5.exe->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->7.exe
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\样本 yangpizhi\15.rar->11.exe->(UPack)
[Found security risk]         <W32/OnlineGames.A.gen!GSA (not disinfectable, generic)>        C:\样本 yangpizhi\15.rar->16.exe->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->3.exe->(embedded)->(embedded)
[Clean]        C:\样本 yangpizhi\15.rar->3.exe->(embedded)->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->3.exe->(UPack)
[Found virus]         <W32/InfoStealer!Generic (not disinfectable)>        C:\样本 yangpizhi\15.rar->8.exe->(embedded)
[Clean]        C:\样本 yangpizhi\15.rar->9.exe->(PecBundle)->(PECompact)
[Clean]        C:\样本 yangpizhi\15.rar->12.exe->(embedded)->(embedded)
[Clean]        C:\样本 yangpizhi\15.rar->12.exe->(embedded)->(UPack)
[Clean]        C:\样本 yangpizhi\15.rar->12.exe->(UPack)
[Contains infected objects]        C:\样本 yangpizhi\15.rar
[Quarantined]        C:\样本 yangpizhi\15.rar->12.exe->(embedded)->(embedded)

---------------------------------------------------------------------
Scan ended:        2007-12-30, 19:39:01
Duration:        0:00:12

Scan result:

Scanned files:                 1
Infected objects:         9
Disinfected objects:         0
Quarantined files:         1
---------------------------------------------------------------------
自由
 楼主| 发表于 2007-12-30 20:00:13 | 显示全部楼层
用卡巴的扫一下,我下午4点的病毒库,一个都不认识
懒得上报发这里,自有高人上报。用卡巴的扫一下,告诉结果就可以。
Palkia
发表于 2007-12-30 20:19:24 | 显示全部楼层
木马名称:未知后门程序

程序:
C:\WINDOWS\SYSTEM32\ZPFOYGLQWZZDC.DLL
是木马程序!
已成功阻止其运行,是否要删除此文件?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 01:43 , Processed in 0.131372 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表