楼主: will
收起左侧

[病毒样本] 再来25只~盗号的~

[复制链接]
zwl2828
发表于 2008-1-12 07:16:44 | 显示全部楼层
原帖由 卡巴007 于 2008-1-11 19:23 发表
昨天上报卡巴漏掉的两个文件,今天卡巴回复认为这两个文件不是病毒!

C:\Users\Wesley\Downloads\virus.rar
  [0] Archive type: RAR
  --> Backup\zcombho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Zcom.32768
  --> Backup\zkbaidubho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/BaiduBa.40960
zwl2828
发表于 2008-1-12 07:17:30 | 显示全部楼层

Avira AntiVir

25个

C:\Users\Wesley\Downloads\Backup.rar
  [0] Archive type: RAR
  --> Backup\1707e7b.dll
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> Backup\lymangr.dll
      [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
  --> Backup\msexec.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.25088
  --> Backup\919331mm.dll
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> Backup\919331wl.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> Backup\avpsrv.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDV.1
  --> Backup\cmdbcs.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvw.1
  --> Backup\dbghlp32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDS.1
  --> Backup\kvsc3.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndw
  --> Backup\lotushlp.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndq
  --> Backup\mppds.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvt
  --> Backup\msimms32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mwi.4
  --> Backup\msprint32d.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndu
  --> Backup\ptsshell.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muj.2
  --> Backup\shaproc.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndm
  --> Backup\upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muy.5
  --> Backup\winsvr32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mzj
  --> Backup\wsockdrv32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndr.2
  --> Backup\zcombho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Zcom.32768
  --> Backup\zkbaidubho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/BaiduBa.40960
  --> Backup\792405c6.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
  --> Backup\axuzazn.sys
      [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.20560
  --> Backup\ietool.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IETool.IS
  --> Backup\iebho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IESearch.AZZ
  --> Backup\Auto.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
ye221017
发表于 2008-1-13 11:15:03 | 显示全部楼层
费尔报了25个 是不是你们抢先上报了5555
zwl2828
发表于 2008-1-13 11:29:07 | 显示全部楼层

Avira AntiVir

C:\Users\Wesley\Downloads\Backup.rar
  [0] Archive type: RAR
  --> Backup\1707e7b.dll
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> Backup\lymangr.dll
      [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
  --> Backup\msexec.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.25088
  --> Backup\919331mm.dll
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> Backup\919331wl.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> Backup\avpsrv.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDV.1
  --> Backup\cmdbcs.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvw.1
  --> Backup\dbghlp32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDS.1
  --> Backup\kvsc3.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndw
  --> Backup\lotushlp.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndq
  --> Backup\mppds.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvt
  --> Backup\msimms32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mwi.4
  --> Backup\msprint32d.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndu
  --> Backup\ptsshell.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muj.2
  --> Backup\shaproc.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndm
  --> Backup\upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muy.5
  --> Backup\winsvr32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mzj
  --> Backup\wsockdrv32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndr.2
  --> Backup\zcombho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Zcom.32768
  --> Backup\zkbaidubho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/BaiduBa.40960
  --> Backup\792405c6.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
  --> Backup\axuzazn.sys
      [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.20560
  --> Backup\ietool.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IETool.IS
  --> Backup\iebho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IESearch.AZZ
  --> Backup\Auto.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
loveyuwei
发表于 2008-1-13 12:31:54 | 显示全部楼层
下载解压就隔离了13个,另外12个扫描检测到2个。。

MCAFEE。。 ,郁闷``

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
卡巴007 该用户已被删除
发表于 2008-1-13 15:24:06 | 显示全部楼层
卡巴的工程师不认为那两个文件是病毒啊!
残缺的唯美
发表于 2008-1-13 16:03:43 | 显示全部楼层
Result: 23 malware found
Worm.Win32.AutoRun.bnc (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\1707e7b.dll
G:\Users\Administrator\Desktop\Backup.rar\Backup\792405c6.exe
G:\Users\Administrator\Desktop\Backup.rar\Backup\Auto.exe
Trojan-PSW.Win32.OnLineGames.mzk (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\lymangr.dll
Trojan-Downloader.Win32.Agent.hdl (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\msexec.dll
Trojan-PSW.Win32.OnLineGames.mdd (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\919331mm.dll
Trojan-PSW.Win32.OnLineGames.iay (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\919331wl.dll
Trojan-PSW.Win32.OnLineGames.ndv (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\avpsrv.dll
Trojan-PSW.Win32.OnLineGames.mvw (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\cmdbcs.dll
Trojan-PSW.Win32.OnLineGames.nds (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\dbghlp32.dll
Trojan-PSW.Win32.OnLineGames.ndw (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\kvsc3.dll
Trojan-PSW.Win32.OnLineGames.ndq (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\lotushlp.dll
Trojan-PSW.Win32.OnLineGames.mvt (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\mppds.dll
Trojan-PSW.Win32.OnLineGames.mwi (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\msimms32.dll
Trojan-PSW.Win32.OnLineGames.ndu (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\msprint32d.dll
Trojan-PSW.Win32.OnLineGames.muj (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\ptsshell.dll
Trojan-PSW.Win32.OnLineGames.ndm (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\shaproc.dll
Trojan-PSW.Win32.OnLineGames.muy (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\upxdnd.dll
Trojan-PSW.Win32.OnLineGames.mzj (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\winsvr32.dll
Trojan-PSW.Win32.OnLineGames.ndr (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\wsockdrv32.dll
Trojan.Win32.Small.ye (virus)
G:\Users\Administrator\Desktop\Backup.rar\Backup\axuzazn.sys
AdWare.Win32.BHO.sd (adware)
G:\Users\Administrator\Desktop\Backup.rar\Backup\ietool.dll
AdWare.Win32.BHO.sc (adware)
G:\Users\Administrator\Desktop\Backup.rar\Backup\iebho.dll
gamesrui
发表于 2008-1-13 17:40:31 | 显示全部楼层
Scan ended [The scan has been done completely.].
Number of files: 26
Number of folders: 0
Number of malware: 25
Number of alerts: 0 [:03:] [:03:]
33629544
头像被屏蔽
发表于 2008-1-14 12:27:52 | 显示全部楼层

fs扫出23个

Statistics
Scanned:
Files: 26
Not scanned: 0
Result:
Viruses: 21
Spyware: 2
Suspicious items: 0
Riskware: 0
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0
jick117
发表于 2008-1-14 12:59:08 | 显示全部楼层
检测到病毒: Worm.Win32.AutoRun.bnc (3x), Trojan-PSW.Win32.OnLineGames.mzk, Trojan-Downloader.Win32.Agent.hdl, Trojan-PSW.Win32.OnLineGames.mdd, Trojan-PSW.Win32.OnLineGames.iay, Trojan-PSW.Win32.OnLineGames.ndv, Trojan-PSW.Win32.OnLineGames.mvw, Trojan-PSW.Win32.OnLineGames.nds, Trojan-PSW.Win32.OnLineGames.ndw, Trojan-PSW.Win32.OnLineGames.ndq, Trojan-PSW.Win32.OnLineGames.mvt, Trojan-PSW.Win32.OnLineGames.mwi, Trojan-PSW.Win32.OnLineGames.ndu, Trojan-PSW.Win32.OnLineGames.muj, Trojan-PSW.Win32.OnLineGames.ndm, Trojan-PSW.Win32.OnLineGames.muy, Trojan-PSW.Win32.OnLineGames.mzj, Trojan-PSW.Win32.OnLineGames.ndr, Trojan.Win32.Small.ye, not-a-virus:AdWare.Win32.BHO.sd, not-a-virus:AdWare.Win32.BHO.sc
文件: E8739A5Bd01
目录: C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\2tecr2l3.default\Cache
进程: FIREFOX.EXE
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-13 04:57 , Processed in 0.089467 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表