查看: 3569|回复: 13
收起左侧

[病毒样本] 猪猪乐园搞到的10只

[复制链接]
promised
发表于 2007-12-31 16:34:51 | 显示全部楼层 |阅读模式
C:\ABC\1\10.rar:\update.exe - 特征码 'Trojan-Spy.Win32.Delf.rx' 被发现
C:\ABC\1\10.rar:\sms8s.exe - 特征码 'Trojan-Spy.Win32.Delf.PD' 被发现
C:\ABC\1\10.rar:\sms6s.exe - 特征码 'Trojan-Spy.Win32.Delf.uv' 被发现
C:\ABC\1\10.rar:\sms3s.exe - 特征码 'Trojan-Spy.Win32.Delf.uv' 被发现
C:\ABC\1\10.rar:\sms0s.exe - 特征码 'Trojan.Delf.NEB' 被发现
C:\ABC\1\10.rar:\WinSy_8z.Sys - 特征码 'Trojan-PWS.Win32.Nilage.bga' 被发现
C:\ABC\1\10.rar:\gdqqsgi32.dll - 特征码 'Trojan-PWS.Win32.Small.br' 被发现
C:\ABC\1\10.rar:\gddji32.dll - 特征码 'Trojan-PWS.Win32.Small.br' 被发现
C:\ABC\1\10.rar:\rarjetl.exe - 特征码 'Trojan-Spy.Win32.Delf.uv' 被发现
C:\ABC\1\10.rar:\rarjepi.dll - 特征码 'Virus.Win32.OnLineGames.BGD' 被发现

[ 本帖最后由 promised 于 2007-12-31 16:49 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
醉一生爱妍
发表于 2007-12-31 16:37:11 | 显示全部楼层
10个江民K9个!!!!
库洛洛
发表于 2007-12-31 16:37:22 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\10.rar'
E:\10.rar
  [0] Archive type: RAR
  --> sms8s.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> sms6s.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> sms3s.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.lpr
  --> sms0s.exe
      [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
  --> WinSy_8z.Sys
      [DETECTION] Contains suspicious code HEUR/Malware
  --> gdqqsgi32.dll
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> gddji32.dll
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> rarjetl.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.lpr
  --> rarjepi.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.lpr
      [WARNING]   The file was ignored!


End of the scan: 2007年12月31日  16:38
Used time: 00:15 min

The scan has been done completely.

      0 Scanning directories
     11 Files were scanned
      8 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
wangjay1980
发表于 2007-12-31 16:38:58 | 显示全部楼层
detected: Trojan program Trojan-Downloader.Win32.Dirat.au        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/update.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.mpj        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/sms8s.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.kwh        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/sms6s.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.lrc        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/sms3s.exe//UPack
detected: Trojan program Trojan-Dropper.Win32.Microjoin.gc        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/sms0s.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.mpj        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/gdqqsgi32.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.lmw        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/gddji32.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.lrc        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/rarjetl.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.lpr        File: C:\Documents and Settings\Owner\×ÀÃæ\10.rar/rarjepi.dll
yangpizhi
发表于 2007-12-31 16:44:33 | 显示全部楼层
FP漏一个
-----------------------------SCAN REPORT-----------------------------
F-PROT Antivirus for Windows

Antivirus Scanning Engine version number: 4.4.2
Virus signature file from: 2007-12-31, 5:54

Scan name: 12.31
Path to scan: C:\样本 yangpizhi\12.31\|

Thorough scan
Also scan: Inside subfolders, Compressed files, Streams

Scan started: 2007-12-31, 16:43:57
---------------------------------------------------------------------

[Clean]        Boot sector on drive F:
[Clean]        Boot sector on drive E:
[Clean]        Boot sector on drive D:
[Clean]        Boot sector on drive C:
[Clean]        Master Boot Record on disk 0
[Clean]        C:\样本 yangpizhi\12.31\10.rar->update.exe
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->sms8s.exe->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->sms6s.exe->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->sms3s.exe->(UPack)
[Clean]        C:\样本 yangpizhi\12.31\10.rar->sms0s.exe->(UPX)
[Found possible virus]         <W32/Document-disguised-based!Maximus (not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->sms0s.exe
[Found virus]         <W32/InfoStealer!Generic (not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->WinSy_8z.Sys
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->gdqqsgi32.dll->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->gddji32.dll->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\样本 yangpizhi\12.31\10.rar->rarjetl.exe->(UPack)
[Found password stealer]         <W32/OnlineGames.A.gen!Eldorado (not disinfectable, generic)>        C:\样本 yangpizhi\12.31\10.rar->rarjepi.dll
[Contains infected objects]        C:\样本 yangpizhi\12.31\10.rar
[Quarantined]        C:\样本 yangpizhi\12.31\10.rar->rarjepi.dll

---------------------------------------------------------------------
Scan ended:        2007-12-31, 16:44:02
Duration:        0:00:04

Scan result:

Scanned files:                 6
Infected objects:         9
Disinfected objects:         0
Quarantined files:         1
---------------------------------------------------------------------
testhawk
发表于 2007-12-31 16:47:19 | 显示全部楼层
nod32 9
10.rar » RAR » sms8s.exe - a variant of Win32/PSW.OnLineGames.JOJ trojan
10.rar » RAR » sms6s.exe - Win32/PSW.OnLineGames.KWH trojan
10.rar » RAR » sms3s.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
10.rar » RAR » sms0s.exe - probably a variant of Win32/AutoRun.Q worm
10.rar » RAR » WinSy_8z.Sys - probably a variant of Win32/AutoRun.Q worm
10.rar » RAR » gdqqsgi32.dll - a variant of Win32/PSW.OnLineGames.JOJ trojan
10.rar » RAR » gddji32.dll - probably a variant of Win32/PSW.OnLineGames.NHF trojan
10.rar » RAR » rarjetl.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
10.rar » RAR » rarjepi.dll - a variant of Win32/PSW.OnLineGames.FDY trojan
will
发表于 2007-12-31 16:55:34 | 显示全部楼层

avast! 10

Win32:Delf-HBE [Trj]                                     update.exe  
Win32:OnLineGames-BKU [Trj]                  sms8s.exe
Win32:OnLineGames-BBH [Trj]                  sms6s.exe
Win32:OnLineGames-BGD [Trj]                  sms3s.exe
Win32:Delf-FZG [Trj]                                       sms0s.exe
Win32:Delf-FZG [Trj]                                      WinSy_8z.Sys  
Win32:OnLineGames-BKU [Trj]                  gdqqsgi32.dll
Win32:OnLineGames-BBH [Trj]                  gddji32.dll
Win32:OnLineGames-BGD [Trj]                  rarjetl.exe
Win32:OnLineGames-BGD [Trj]                  rarjepi.dll
kkgh
发表于 2007-12-31 16:59:55 | 显示全部楼层
AVG Anti-Spyware - 扫描报告
---------------------------------------------------------

+ 创建时间:        17:03:05 2007-12-31

+ 扫描结果:       



C:\Documents and Settings\zh\桌面\10.rar/update.exe -> Downloader.Dirat.au : 未进行操作.
C:\Documents and Settings\zh\桌面\10.rar/sms0s.exe -> Dropper.Microjoin.gc : 未进行操作.
C:\Documents and Settings\zh\桌面\10.rar/sms6s.exe -> Trojan.OnLineGames.kvw : 未进行操作.
C:\Documents and Settings\zh\桌面\10.rar/rarjetl.exe -> Trojan.OnLineGames.lrb : 未进行操作.
C:\Documents and Settings\zh\桌面\10.rar/sms3s.exe -> Trojan.OnLineGames.lrb : 未进行操作.


::报告结束

        瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.DL.Win32.Mnless.jm
病毒: Trojan.PSW.Win32.GameOL.gmv
病毒: Trojan.PSW.Win32.GameOL.ggg
病毒: Trojan.PSW.Win32.GameOL.GEN
病毒: Worm.Win32.PaBug.fi      
病毒: Worm.Win32.PaBug.fi      
病毒: Trojan.PSW.Win32.GameOL.GEN
病毒: Trojan.PSW.Win32.GameOL.GEN

用户来源:互联网

软件版本:20.25
wangjay1980
发表于 2007-12-31 17:36:31 | 显示全部楼层
WinSy_8z.Sys - Trojan-PSW.Win32.QQPass.aqm

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.
jimmyleo
发表于 2007-12-31 17:37:14 | 显示全部楼层
最爱那个猪头标志
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-23 20:58 , Processed in 0.140083 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表