12
返回列表 发新帖
楼主: jehovah_king
收起左侧

[病毒样本] 一个病毒送的

[复制链接]
Graybird
发表于 2008-1-26 15:08:12 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\新建文件夹.rar'
E:\新建文件夹.rar
  [0] Archive type: RAR
  --> н¨Îļþ¼Ð\1[1].exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> н¨Îļþ¼Ð\tmp70.tmp
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ode.2
  --> н¨Îļþ¼Ð\tmp71.tmp
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ode.2
  --> н¨Îļþ¼Ð\tmp73.tmp
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> н¨Îļþ¼Ð\WinForm.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> н¨Îļþ¼Ð\WinForm.exE
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [WARNING]   The file was ignored!


End of the scan: 2008年1月26日  15:09
Used time: 00:10 min

The scan has been done completely.

      0 Scanning directories
      9 Files were scanned
      5 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
啊弥陀佛
发表于 2008-1-26 15:15:48 | 显示全部楼层
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\样本\1.EXE
木马程序生成以下文件:
1) C:\WINDOWS\WINFORM.EXE
2) C:\WINDOWS\SYSTEM32\WINFORM.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\样本\6.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\IEMNAW.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\样本\19.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\VCKTFLTFJ.DLL
2) C:\WINDOWS\SYSTEM32\MSFJCMB32.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\样本\20.EXE
木马程序生成以下文件:
1) C:\WINDOWS\DBGHLP32.EXE
2) C:\WINDOWS\SYSTEM32\DBGHLP32.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\样本\21.EXE
并生成以下文件:
1) E:\AUTORUN.EXE
2) E:\AUTORUN.INF
3) E:\AUTORUN.EXE
是否删除木马程序及其衍生物?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2008-1-26 15:52:41 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\新建文件夹.rar'
C:\Documents and Settings\Administrator\My Documents\
  新建文件夹.rar
    [0] Archive type: RAR
发表帖子      --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\1[1].exe
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Contains suspicious code HEUR/Malware
              [WARNING]   Infected files in archives cannot be repaired!
[完成后可按 C    --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\down[1].txt
trl+Ente    --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\tmp70.tmp
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ode.2
        [WARNING]   Infected files in archives cannot be repaired!
r 发布]      --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\tmp71.tmp
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ode.2
        [WARNING]   Infected files in archives cannot be repaired!
预览帖子  恢复      --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\tmp73.tmp
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Contains suspicious code HEUR/Malware
              [WARNING]   Infected files in archives cannot be repaired!
数据  清空    --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\WinForm.dll
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
内容       --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\WinForm.exE
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Contains suspicious code HEUR/Malware
              [WARNING]   Infected files in archives cannot be repaired!
默认表情    --> ￐ᅡᄑ뙈ᅣᄐ?ᄐ￐\~wupcai
      [WARNING]   The file was ignored!
  新建文件夹.rar:Zone.Identifier


End of the scan: 2008年1月25日  23:52
Used time: 00:04 min

The scan has been done completely.

      0 Scanning directories
     10 Files were scanned
      2 viruses and/or unwanted programs were found
      4 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      8 Files not concerned
      4 Archives were scanned
      7 Warnings
      0 Notes
leonfg
发表于 2008-1-26 18:18:20 | 显示全部楼层
原帖由 鱼是一只我 于 2008-1-26 14:47 发表
楼主的里边江民不能杀的,打包上传,密码:virus

ESET  7
C:\Documents and Settings\GUNDAM\桌面\样本\1.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\样本\11.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\样本\19.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\样本\20.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\样本\21.exe - probably a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\GUNDAM\桌面\样本\3.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\样本\6.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
sam.to
发表于 2008-1-26 20:33:59 | 显示全部楼层
替楼主的#1打包

已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gl        檔案: C:\Documents and Settings\kato9096\桌面\6\1.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.odx        檔案: C:\Documents and Settings\kato9096\桌面\6\10.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\11.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ngd        檔案: C:\Documents and Settings\kato9096\桌面\6\12.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pjj        檔案: C:\Documents and Settings\kato9096\桌面\6\13.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\15.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gq        檔案: C:\Documents and Settings\kato9096\桌面\6\16.exe//UPack//PE_Patch
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\17.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\18.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poh        檔案: C:\Documents and Settings\kato9096\桌面\6\19.exe//PE_Patch.UPX//UPX
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poj        檔案: C:\Documents and Settings\kato9096\桌面\6\2.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gg        檔案: C:\Documents and Settings\kato9096\桌面\6\20.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.QQPass.ast        檔案: C:\Documents and Settings\kato9096\桌面\6\21.exe//UPX
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pol        檔案: C:\Documents and Settings\kato9096\桌面\6\22.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pmh        檔案: C:\Documents and Settings\kato9096\桌面\6\23.exe//PE_Patch//UPack//data0000.bin//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poj        檔案: C:\Documents and Settings\kato9096\桌面\6\3.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poc        檔案: C:\Documents and Settings\kato9096\桌面\6\4.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\5.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poj        檔案: C:\Documents and Settings\kato9096\桌面\6\6.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.poj        檔案: C:\Documents and Settings\kato9096\桌面\6\7.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\8.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pbp        檔案: C:\Documents and Settings\kato9096\桌面\6\9.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Backdoor.Win32.Delf.cwq        檔案: C:\Documents and Settings\kato9096\桌面\6\a11.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-Downloader.Win32.VB.cii        檔案: C:\Documents and Settings\kato9096\桌面\6\k.exe


24

4个不报,上报

[ 本帖最后由 kato9096 于 2008-1-26 20:35 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2008-1-26 20:36:59 | 显示全部楼层
原帖由 jehovah_king 于 2008-1-26 13:45 发表
附件(不是对2楼的回复)
而是一楼没发的


已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gl        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\1[1].exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pik        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\tmp70.tmp
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.pik        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\tmp71.tmp
已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gl        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\tmp73.tmp//UPack
已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gh        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\WinForm.dll
已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gl        檔案: C:\Documents and Settings\kato9096\桌面\6\陔膘恅璃標.rar/陔膘恅璃標\WinForm.exE//UPack
冷冷
发表于 2008-1-26 20:38:46 | 显示全部楼层

I:\virus\test\新建文件夹\1[1].exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\新建文件夹\down[1].txt
I:\virus\test\新建文件夹\tmp70.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.ode' found
I:\virus\test\新建文件夹\tmp71.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.ode' found
I:\virus\test\新建文件夹\tmp73.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\新建文件夹\WinForm.dll - Signature 'Virus.Win32.OnLineGames.BHW' found
I:\virus\test\新建文件夹\WinForm.exE - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\新建文件夹\~wupcai
8 Files scanned
   (0 Archives with 0 files)
6 Signatures found
0 Suspect code-parts found
Used time: 0:00.046
-------------------------------------------------------------------------------

I:\virus\test/新建文件夹/1[1].exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/新建文件夹/tmp73.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/新建文件夹/WinForm.exE: PUA.Packed.UPack-1 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 197940
Engine version: 0.92
Scanned directories: 2
Scanned files: 8
Infected files: 3

Data scanned: 0.09 MB
Time: 6.437 sec (0 m 6 s)
sam.to
发表于 2008-1-26 20:59:05 | 显示全部楼层
原帖由 kato9096 于 2008-1-26 20:33 发表
替楼主的#1打包

已刪除: 特洛伊木馬程式 Trojan.Win32.Vaklik.gl        檔案: C:\Documents and Settings\kato9096\桌面\6\1.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.odx        檔案: C:\Documents ...

Hello,

14.exek, 24.exek, 25.exek

No malicious code were found in these files.

26.exek

This file contains a warning "The requested URL is infected with virus".
It means that you've tried to download infected file
or site you've visited tried to download infected file secretly.

Please quote all when answering.

--
Best regards, Vladimir Krylov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
ballakay
发表于 2008-1-26 21:02:47 | 显示全部楼层
Scanning Report
26 January 2008 21:02:10 - 21:02:13
Computer name: PUMA-PC
Scanning type: Scan target
Target: C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar


--------------------------------------------------------------------------------

Result: 6 malware found
Trojan.Win32.Vaklik.gl (virus)
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\1[1].exe
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\tmp73.tmp
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\WinForm.exE
Trojan-PSW.Win32.OnLineGames.pik (virus)
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\tmp70.tmp
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\tmp71.tmp
Trojan.Win32.Vaklik.gh (virus)
C:\Users\Administrator\Desktop\н¨Îļþ¼Ð.rar\н¨Îļþ¼Ð\WinForm.dll




--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 9
Not scanned: 0
Result:
Viruses: 6
Spyware: 0
Suspicious items: 0
Riskware: 0
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Quarantined: 0
Failed: 0
Boot Sectors:
Scanned: 0
Infected: 0
Suspicious items: 0
Disinfected: 0
woai_jolin
发表于 2008-1-26 21:04:01 | 显示全部楼层
Scan Log
Version of virus signature database: 2824 (20080126)
Date: 2008-1-26  Time: 21:04:07
Scanned disks, folders and files: G:\v\新建文件夹.rar
G:\v\新建文件夹.rar » RAR » 新建文件夹\1[1].exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\down[1].txt - is OK
G:\v\新建文件夹.rar » RAR » 新建文件夹\tmp70.tmp - Win32/TrojanDownloader.Small.NZL trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\tmp71.tmp - Win32/TrojanDownloader.Small.NZL trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\tmp73.tmp - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\WinForm.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\WinForm.exE - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\新建文件夹.rar » RAR » 新建文件夹\~wupcai - is OK
Number of scanned objects: 9
Number of threats found: 6
Time of completion: 21:04:08  Total scanning time: 1 sec (00:00:01)
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 18:51 , Processed in 0.098344 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表