楼主: will
收起左侧

[病毒样本] 再来25只~盗号的~

[复制链接]
zhkchi
发表于 2008-1-14 13:29:37 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\zk\桌面\Backup.rar'
C:\Documents and Settings\zk\桌面\Backup.rar
  [0] Archive type: RAR
  --> Backup\1707e7b.dll
      [DETECTION] Is the Trojan horse TR/Autorun.CA
  --> Backup\lymangr.dll
      [DETECTION] Is the Trojan horse TR/PSW.Online.agb.2
  --> Backup\msexec.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.25088
  --> Backup\919331mm.dll
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> Backup\919331wl.dll
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> Backup\avpsrv.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDV.1
  --> Backup\cmdbcs.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvw.1
  --> Backup\dbghlp32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NDS.1
  --> Backup\kvsc3.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndw
  --> Backup\lotushlp.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndq
  --> Backup\mppds.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mvt
  --> Backup\msimms32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mwi.4
  --> Backup\msprint32d.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndu
  --> Backup\ptsshell.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muj.2
  --> Backup\shaproc.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndm
  --> Backup\upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.muy.5
  --> Backup\winsvr32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.mzj
  --> Backup\wsockdrv32.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ndr.2
  --> Backup\zcombho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/Zcom.32768
  --> Backup\zkbaidubho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/BaiduBa.40960
  --> Backup\792405c6.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
  --> Backup\axuzazn.sys
      [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.20560
  --> Backup\ietool.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IETool.IS
  --> Backup\iebho.dll
      [DETECTION] Contains detection pattern of the Ad- or Spyware ADSPY/IESearch.AZZ
  --> Backup\Auto.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.bnc
      [WARNING]   The file was ignored!


End of the scan: 2008年1月14日  13:27
Used time: 00:13 min

The scan has been done completely.

      0 Scanning directories
     26 Files were scanned
     25 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
gho
发表于 2008-1-14 18:28:10 | 显示全部楼层
2008-1-14        18:25:30        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\1707e7b.dll        W32/Winko.worm.dll (Virus)
2008-1-14        18:25:36        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\lymangr.dll        Generic PWS.j (Trojan)
2008-1-14        18:25:44        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\919331mm.dll        PWS-Lineage (Trojan)
2008-1-14        18:25:44        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\919331wl.dll        PWS-LegMir.dll (Trojan)
2008-1-14        18:25:50        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\cmdbcs.dll        PWS-Mmorpg.gen (Trojan)
2008-1-14        18:25:56        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\kvsc3.dll        PWS-Mmorpg.gen (Trojan)
2008-1-14        18:25:57        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\mppds.dll        PWS-OnlineGames.ad (Trojan)
2008-1-14        18:26:03        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\msimms32.dll        PWS-LegMir.dll (Trojan)
2008-1-14        18:26:03        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\ptsshell.dll        PWS-OnlineGames.ad (Trojan)
2008-1-14        18:26:09        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\shaproc.dll        PWS-Mmorpg.gen (Trojan)
2008-1-14        18:26:20        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\upxdnd.dll        PWS-OnlineGames.v.dll (Trojan)
2008-1-14        18:26:21        Deleted         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\winsvr32.dll        PWS-OnlineGames.ad (Trojan)
2008-1-14        18:26:21        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\792405c6.exe        New Malware.aj (Trojan)
2008-1-14        18:26:27        Moved (Clean failed because the file isn't cleanable)         WHUT-D9193C067E\gho        WinRAR.exe        C:\Documents and Settings\gho\桌面\Backup\Auto.exe        New Malware.aj (Trojan)
2121qq
发表于 2008-1-15 03:07:07 | 显示全部楼层
中了个msexec.dll,真郁闷
悠柚
发表于 2008-1-15 07:10:26 | 显示全部楼层
Access to the data has been denied!
Warning: A virus or unwanted program has been found in the HTTP Data.

Requested URL:         bbs.kafan.cn/attachment.php?aid=180885
Information:         Is the Trojan horse TR/Autorun.CA

Generated by AntiVir WebGuard 7.01.00.13, AVE 7.6.0.46, VDF 7.0.1.236
qcs_93140521
发表于 2008-1-15 09:52:59 | 显示全部楼层
金山报了21个!
jhdcboy
头像被屏蔽
发表于 2008-1-15 12:11:17 | 显示全部楼层
费尔报了26个
Date,Virus Name,Virus Type,User,Filename,Scan Type
2008-1-15 12:09:24,Trojan.VB.crg.mmru.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\zkbaidubho.dll,Manual scan
2008-1-15 12:09:24,Trojan.VB.cqn.asya.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\zcombho.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndr.evad.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\wsockdrv32.dll,Manual scan
2008-1-15 12:09:24,Trojan.Fawryh.ypch.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\winsvr32.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.GameOL.ibd.liqy.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\upxdnd.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndm.xbhi.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\shaproc.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.QQHX.tvd.dxls.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\ptsshell.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndu.npwd.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\msprint32d.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.GameOL.ibp.pvee.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\msimms32.dll,Manual scan
2008-1-15 12:09:24,TrojanDownloader.Agent.hdl.izbc.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\msexec.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.mvt.zrud.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\mppds.dll,Manual scan
2008-1-15 12:09:24,PWSteal.j.dnmy.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\lymangr.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndq.wegn.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\lotushlp.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndw.ixen.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\kvsc3.dll,Manual scan
2008-1-15 12:09:24,Adware.BHO.sd.inoo.dll,广告程序,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\ietool.dll,Manual scan
2008-1-15 12:09:24,Adware.BHO.sc.gqra.dll,广告程序,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\iebho.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.GameOL.lcm.lnkw.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\dbghlp32.dll,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.mvw.mfoa.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\cmdbcs.dll,Manual scan
2008-1-15 12:09:24,Trojan.Small.ye.azmj,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\axuzazn.sys,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.ndv.fypq.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\avpsrv.dll,Manual scan
2008-1-15 12:09:24,Backdoor.DKA.ainr,后门,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\Auto.exe,Manual scan
2008-1-15 12:09:24,TrojanPSW.OnLineGames.iay.tcqr.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\919331wl.dll,Manual scan
2008-1-15 12:09:24,Trojan.Lemir.G.hivv.dll,木马,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\919331mm.dll,Manual scan
2008-1-15 12:09:24,Backdoor.DKA.ainr,后门,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\792405c6.exe,Manual scan
2008-1-15 12:09:24,W32.Winko.worm.dll.rbln.dll,病毒,严俊,C:\Documents and Settings\严俊\桌面\Backup.rar>>Backup\1707e7b.dll,Manual scan
2008-1-15 12:09:24,Adware.BHO.sc.gqra.dll,广告程序,严俊,C:\Documents and Settings\严俊\Local Settings\Temp\TWIEX0\Backup\iebho.dll,Manual scan
2008-1-15 12:09:24,Backdoor.DKA.ainr,后门,严俊,C:\Documents and Settings\严俊\Local Settings\Temp\TWIEX0\Backup\Auto.exe,Manual scan
colordancer
发表于 2008-1-15 14:01:04 | 显示全部楼层
趋势:

InterScan Web Security detected malicious code in your web traffic:

Item: http://www.kafan.cn/bbs/attachment.php?aid=180885
Action: deleted

Infection detail:

-- File: Backup/1707e7b.dll, Enclosure: Backup.rar, malicious code name: TROJ_GENERIC.APC
-- File: Backup/lymangr.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.EAH
-- File: Backup/919331wl.dll, Enclosure: Backup.rar, malicious code name: TSPY_LEGMIR.DAJ
-- File: Backup/avpsrv.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/cmdbcs.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/dbghlp32.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/mppds.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/msimms32.dll, Enclosure: Backup.rar, malicious code name: TROJ_GENERIC.APC
-- File: Backup/ptsshell.dll, Enclosure: Backup.rar, malicious code name: TROJ_GENERIC.APC
-- File: Backup/upxdnd.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/winsvr32.dll, Enclosure: Backup.rar, malicious code name: TSPY_ONLINEG.NSM
-- File: Backup/792405c6.exe, Enclosure: Backup.rar, malicious code name: WORM_AUTORUN.PJ
-- File: Backup/Auto.exe, Enclosure: Backup.rar, malicious code name: WORM_AUTORUN.PJ
alauco
发表于 2008-1-15 18:36:56 | 显示全部楼层
不行啊.不能下载...

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-24 05:45 , Processed in 0.093891 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表