楼主: promised
收起左侧

[病毒样本] 某帖挖的55个

[复制链接]
tonylee
头像被屏蔽
发表于 2008-1-7 13:38:30 | 显示全部楼层
VirusBuster Engine: 4.3.23:9 (2007-02-16), VDB: 9.118.18/11.0 (2008-01-07)

d:\Test\1.exe: mutant Trojan.DR.OnlineGames.Gen.20 (NOT killable) skipped.
d:\Test\10.exe: suspicious  (NOT killable) skipped.
d:\Test\11.exe: suspicious  (NOT killable) skipped.
d:\Test\12.exe: suspicious  (NOT killable) skipped.
d:\Test\13.exe: suspicious  (NOT killable) skipped.
d:\Test\14.exe: suspicious  (NOT killable) skipped.
d:\Test\15.exe: suspicious  (NOT killable) skipped.
d:\Test\16.exe: suspicious  (NOT killable) skipped.
d:\Test\17.exe: suspicious  (NOT killable) skipped.
d:\Test\18.exe: suspicious  (NOT killable) skipped.
d:\Test\19.exe: suspicious  (NOT killable) skipped.
d:\Test\2.exe: suspicious  (NOT killable) skipped.
d:\Test\20.exe: suspicious  (NOT killable) skipped.
d:\Test\21.exe: suspicious  (NOT killable) skipped.
d:\Test\22.exe: suspicious  (NOT killable) skipped.
d:\Test\23.exe: suspicious  (NOT killable) skipped.
d:\Test\24.exe: suspicious  (NOT killable) skipped.
d:\Test\25.exe: suspicious  (NOT killable) skipped.
d:\Test\26.exe: suspicious  (NOT killable) skipped.
d:\Test\3.exe: suspicious  (NOT killable) skipped.
d:\Test\4.exe: suspicious  (NOT killable) skipped.
d:\Test\5.exe: suspicious  (NOT killable) skipped.
d:\Test\6.exe: suspicious  (NOT killable) skipped.
d:\Test\608769L.exe: mutant Trojan.OnlineGames.Gen.64 (NOT killable) skipped.
d:\Test\608769MM.DLL: trojan Trojan.PWS.OnLineGames.COD (killable,deletable) skipped.
d:\Test\608769WL.DLL: mutant Trojan.OnlineGames.Gen.64 (NOT killable) skipped.
d:\Test\7.exe: suspicious  (NOT killable) skipped.
d:\Test\9.exe: suspicious  (NOT killable) skipped.
d:\Test\AVPSrv.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\avwghmn.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\avwlimn.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\avzxmmn.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\cmdbcs.dll: mutant Trojan.OnlineGames.Gen.43 (NOT killable) skipped.
d:\Test\DbgHlp32.dll: mutant Trojan.OnlineGames.Gen.43 (NOT killable) skipped.
d:\Test\gjfhayc.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\gjtmayc.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\jsqxayc.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\kafykzy.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\kapjgzy.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\Kvsc3.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\LotusHlp.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\LYLOADER.EXE: suspicious  (NOT killable) skipped.
d:\Test\LYMANGR.DLL: suspicious  (NOT killable) skipped.
d:\Test\MSDEG32.DLL: suspicious  (NOT killable) skipped.
d:\Test\MsPrint32D.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\NAVMon32.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\NVDispDrv.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\PTSShell.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\rsjzapm.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\sidjhzy.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.
d:\Test\SSLDyn.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\upxdnd.dll: mutant Trojan.OnlineGames.Gen.63 (NOT killable) skipped.
d:\Test\wsmseax.exe: suspicious  (NOT killable) skipped.
d:\Test\wsmsezx.dll: mutant Trojan.OnlineGames.Gen.45 (NOT killable) skipped.

1 target was processed  in 0:00:05 (hour:min:secs).

Summary of completed scans
---------------------------------
files (total)       |       55

Summary of malware pieces found
---------------------------------
mutant              |       25
suspicious          |       28
trojan              |        1

Summary of actions taken on alert
---------------------------------
skipped             |       54
天涯明月
发表于 2008-1-7 22:44:44 | 显示全部楼层

NOD32

扫描进行于:2008-1-7 22:36:26
扫描日志
NOD32版本 2768 (20080106) NT
命令行: C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar

日期: 7.1.2008  时间:22:36:27
已开启反隐藏功能.
已扫描的磁盘,文件夹及文件:C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>rsjzapm.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>sidjhzy.dll - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>SSLDyn.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>upxdnd.dll - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>wsmseax.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>wsmsezx.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>1.exe - Win32/PSW.Agent.NGY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>2.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>3.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>4.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>5.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>6.exe - Win32/PSW.WOW.WU trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>7.exe - Win32/PSW.WOW.WU trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>9.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>10.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>11.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>12.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>13.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>14.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>15.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>16.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>17.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>18.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>19.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>20.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>21.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>22.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>23.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>24.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>25.exe - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>26.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>608769L.exe - Win32/PSW.WOW.WU trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>608769MM.DLL - Win32/PSW.Legendmir.NFF trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>608769WL.DLL - Win32/PSW.Legendmir.NFN trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>AVPSrv.dll - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>avwghmn.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>avwlimn.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>avzxmmn.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>cmdbcs.dll - Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>DbgHlp32.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>gjfhayc.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>gjtmayc.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>jsqxayc.dll - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>kafykzy.dll - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>kapjgzy.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>Kvsc3.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>LotusHlp.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>LYLOADER.EXE - Win32/PSW.Agent.NEC trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>LYMANGR.DLL - Win32/PSW.OnLineGames.DTR trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>MSDEG32.DLL - Win32/PSW.OnLineGames.DVV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>MsIMMs32.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>MsPrint32D.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>NAVMon32.dll - Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>NVDispDrv.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\Administrator\My Documents\新建文件夹\样本.rar >>RAR >>PTSShell.dll - Win32/PSW.OnLineGames.HCV trojan
已扫描的文件数目:55
已发现的病毒数目:55
完成时间: 22:36:29 总扫描时间:2 秒 (00:00:02)
nosferatu
头像被屏蔽
发表于 2008-1-8 03:31:18 | 显示全部楼层
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:        3:30:59 2008-1-8

+ Scan result:       



C:\Documents and Settings\Administrator\桌面\样本.rar/7.exe -> Downloader.Delf.axx : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/6.exe -> Trojan.Lmir.boy : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/22.exe -> Trojan.OnLineGames.dwe : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/15.exe -> Trojan.OnLineGames.eza : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/17.exe -> Trojan.OnLineGames.eza : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/608769L.exe -> Trojan.OnLineGames.hfr : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/608769WL.DLL -> Trojan.OnLineGames.hlt : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/12.exe -> Trojan.OnLineGames.kqd : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/5.exe -> Trojan.OnLineGames.kry : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/2.exe -> Trojan.OnLineGames.lgp : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/19.exe -> Trojan.OnLineGames.loy : No action taken.
C:\Documents and Settings\Administrator\桌面\样本.rar/wsmseax.exe -> Trojan.OnLineGames.loy : No action taken.


::Report end
弄月
发表于 2008-1-8 11:55:12 | 显示全部楼层
毒霸54个哦
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-2 20:27 , Processed in 0.090571 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表