楼主: 电影结束了
收起左侧

[病毒样本] virus

[复制链接]
jimmyleo
发表于 2008-1-28 11:16:09 | 显示全部楼层
原帖由 llgiggs 于 2008-1-28 11:11 发表
楼主给的网站:

第一个:打不开

第二个:2.png

第三个:3.png   4.png

那个..是batch down来着.. 用(*)下载..



ps:被未结束抢先了..本来想今天发的..
冷冷
发表于 2008-1-28 11:17:52 | 显示全部楼层
-------------------------------------------------------------------------------

I:\virus\test/1.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/10.exe: PUA.Packed.UPack FOUND
I:\virus\test/11.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/12.exe: PUA.Packed.UPack FOUND
I:\virus\test/13.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/14.exe: PUA.Packed.UPack FOUND
I:\virus\test/15.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/16.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/17.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/18.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/19.exe: PUA.Packed.UPack FOUND
I:\virus\test/2.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/20.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/21.exe: Trojan.QQPass-493 FOUND
I:\virus\test/22.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/23.exe: PUA.Packed.UPack-2 FOUND
I:\virus\test/24.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/26.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/4.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/5.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/6.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/7.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/8.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/9.exe: PUA.Packed.UPack-3 FOUND
I:\virus\test/a11.exe: PUA.Packed.UPack-2 FOUND
I:\virus\test/avzxomn.dll: Trojan.Spy-20428 FOUND
I:\virus\test/avzxost.exe: PUA.Packed.UPack FOUND
I:\virus\test/DbgHlp32.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/gjcsdyc.dll: Trojan.Spy-16287 FOUND
I:\virus\test/gjcsdzc.exe: PUA.Packed.UPack FOUND
I:\virus\test/gnolnait.dll: PUA.Packed.UPack FOUND
I:\virus\test/gqvvvvvi.dll: PUA.Packed.UPack FOUND
I:\virus\test/hjxr.dll: PUA.Packed.UPack FOUND
I:\virus\test/hqyjvemzyzj.dll: PUA.Packed.UPack FOUND
I:\virus\test/iemnaw.dll: PUA.Packed.UPack FOUND
I:\virus\test/IGB_DJOL_1023.dll: PUA.Packed.UPack FOUND
I:\virus\test/IGB_DJOL_1023.exe: PUA.Packed.UPack-2 FOUND
I:\virus\test/ijiq.dll: PUA.Packed.UPack FOUND
I:\virus\test/iqnauhc.dll: PUA.Packed.UPack FOUND
I:\virus\test/jgnnohkof.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/k.exe: PUA.Packed.UPack-2 FOUND
I:\virus\test/lnaixnauhqq.dll: PUA.Packed.UPack FOUND
I:\virus\test/LotusHlp.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/msepion.sys: Trojan.Mono-9 FOUND
I:\virus\test/msfjcmb32.dll: PUA.Packed.UPack FOUND
I:\virus\test/mstfhncn32.dll: PUA.Packed.UPack FOUND
I:\virus\test/nahzij.dll: PUA.Packed.UPack FOUND
I:\virus\test/niluw.dll: PUA.Packed.UPack FOUND
I:\virus\test/nuygnef.dll: PUA.Packed.UPack FOUND
I:\virus\test/NVDispDRV.EXE: PUA.Packed.UPack-1 FOUND
I:\virus\test/oadnew.dll: PUA.Packed.UPack FOUND
I:\virus\test/PTSShell.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/qvvipwmq.exe: PUA.Packed.UPack-1 FOUND
I:\virus\test/scvhost.exe: PUA.Packed.UPack-2 FOUND
I:\virus\test/tmp2A6.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2A7.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2AA.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2AD.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2AE.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2B0.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2B6.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2BA.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2BD.tmp: PUA.Packed.UPack FOUND
I:\virus\test/tmp2C0.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2C3.tmp: PUA.Packed.UPack FOUND
I:\virus\test/tmp2C5.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2C9.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2CA.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2CB.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2CC.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2CF.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2D0.tmp: Trojan.QQPass-493 FOUND
I:\virus\test/tmp2D1.tmp: PUA.Packed.UPack-1 FOUND
I:\virus\test/tmp2D4.tmp: PUA.Packed.UPack-2 FOUND
I:\virus\test/tmp2D5.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2D7.tmp: PUA.Packed.UPack-3 FOUND
I:\virus\test/tmp2D9.tmp: PUA.Packed.UPack-2 FOUND
I:\virus\test/tmp2DB.tmp: PUA.Packed.UPack-2 FOUND
I:\virus\test/uohsom.dll: PUA.Packed.UPack FOUND
I:\virus\test/utgnehz.dll: PUA.Packed.UPack FOUND
I:\virus\test/wenwjsafj.dll: PUA.Packed.UPack FOUND
I:\virus\test/WinForm.exE: PUA.Packed.UPack-1 FOUND
I:\virus\test/Wn_Sys8x.Sys: Trojan.QQPass-493 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 198032
Engine version: 0.92
Scanned directories: 1
Scanned files: 111
Infected files: 83

Data scanned: 3.09 MB
Time: 8.921 sec (0 m 8 s)

I:\virus\test\1.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\10.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\11.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\12.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\13.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\14.exe - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\15.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\16.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\17.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\18.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\19.exe - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\2.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\20.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\21.exe - Signature 'Trojan-Proxy.Win32.Delf.AN' found
I:\virus\test\22.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\23.exe - Suspect code-parts found (Level: 25)
I:\virus\test\24.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\26.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\4.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\5.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\6.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\7.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\8.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\9.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\a11.exe - Signature 'Backdoor.Win32.Delf.cwq' found
I:\virus\test\avzxoin.dll
I:\virus\test\avzxomn.dll - Signature 'Virus.Win32.OnLineGames.BGD' found
I:\virus\test\avzxost.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\DbgHlp32.dll - Signature 'Virus.Win32.OnLineGames.BHW' found
I:\virus\test\DbgHlp32.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\gjcsdss.dll
I:\virus\test\gjcsdyc.dll - Signature 'Virus.Win32.OnLineGames.BGD' found
I:\virus\test\gjcsdzc.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\gnolnait.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\gqvvvvvi.dll - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\test\hjxr.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\hqyjvemzyzj.dll - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\iemnaw.dll - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\IGB_DJOL_1023.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\IGB_DJOL_1023.exe - Suspect code-parts found (Level: 25)
I:\virus\test\ijiq.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\iqnauhc.dll - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\jgnnohkof.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\jgnnohkof.exe.hiv
I:\virus\test\k.exe - Signature 'Trojan-Downloader.Win32.VB.chb' found
I:\virus\test\lnaixnauhqq.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\LotusHlp.dll - Signature 'Virus.Win32.OnLineGames.BHW' found
I:\virus\test\LotusHlp.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\msepion.sys - Signature 'Trojan.Win32.Agent.anj' found
I:\virus\test\msfjcmb32.dll - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\mstfhncn32.dll - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\nahzij.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\niluw.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\nuygnef.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\NVDispDrv.dll - Signature 'Virus.Win32.OnLineGames.BHW' found
I:\virus\test\NVDispDRV.EXE - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\oadnew.dll - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\pop.sys
I:\virus\test\PTSShell.dll - Signature 'Trojan-PWS.Win32.OnLineGames.ozu' found
I:\virus\test\PTSShell.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\puid.sys - Signature 'Trojan-Downloader.Win32.Agent.hif' found
I:\virus\test\qvvipwmq.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\scvhost.exe - Signature 'Backdoor.Win32.Delf.cwq' found
I:\virus\test\tmp2A3.tmp - Suspect code-parts found (Level: 5)
I:\virus\test\tmp2A4.tmp - Suspect code-parts found (Level: 5)
I:\virus\test\tmp2A6.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2A7.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2A8.tmp
I:\virus\test\tmp2AA.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2AC.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.pmi' found
I:\virus\test\tmp2AD.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2AE.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2B0.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2B2.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.pmi' found
I:\virus\test\tmp2B5.tmp
I:\virus\test\tmp2B6.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2B9.tmp
I:\virus\test\tmp2BA.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2BD.tmp - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\tmp2BE.tmp
I:\virus\test\tmp2C0.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2C2.tmp
I:\virus\test\tmp2C3.tmp - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\test\tmp2C5.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2C8.tmp
I:\virus\test\tmp2C9.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2CA.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2CB.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2CC.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2CF.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2D0.tmp - Signature 'Trojan-Proxy.Win32.Delf.AN' found
I:\virus\test\tmp2D1.tmp - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\tmp2D3.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.phh' found
I:\virus\test\tmp2D4.tmp - Suspect code-parts found (Level: 25)
I:\virus\test\tmp2D5.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2D6.tmp
I:\virus\test\tmp2D7.tmp - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\test\tmp2D9.tmp - Signature 'Backdoor.Win32.Delf.cwq' found
I:\virus\test\tmp2DB.tmp - Signature 'Trojan-Downloader.Win32.VB.chb' found
I:\virus\test\tmp2DD.tmp - Signature 'Trojan-PWS.Win32.OnLineGames.pmi' found
I:\virus\test\tmp2DF.tmp
I:\virus\test\tmp2E3.tmp
I:\virus\test\tmp2E5.tmp
I:\virus\test\uohsom.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\utgnehz.dll - Signature 'Trojan-PWS.Win32.Small.br' found
I:\virus\test\verclsid.exe
I:\virus\test\wenwjsafj.dll - Signature 'Trojan-PWS.Win32.Agent.jp' found
I:\virus\test\WinForm.dll - Signature 'Virus.Win32.OnLineGames.BHW' found
I:\virus\test\WinForm.exE - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\test\Wn_Sys8x.Sys - Signature 'Trojan-Proxy.Win32.Delf.AN' found
I:\virus\test\~esace
111 Files scanned
   (0 Archives with 0 files)
90 Signatures found
5 Suspect code-parts found

Used time: 0:04.687

[ 本帖最后由 冷_冷 于 2008-1-28 11:32 编辑 ]
jimmyleo
发表于 2008-1-28 11:23:15 | 显示全部楼层
clamav很无趣

对dwing的upack意见这么大...
mofunzone
发表于 2008-1-28 11:26:23 | 显示全部楼层
3.exe和25.exe失效,剩下一共24个文件,antivir全灭
Starting the file scan:
Begin scan in 'C:\TDDOWNLOAD\26.exe'
C:\TDDOWNLOAD\
  26.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\1.exe'
C:\TDDOWNLOAD\
  1.exe
      [DETECTION] Is the Trojan horse TR/Vaklik.GH
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\2.exe'
C:\TDDOWNLOAD\
  2.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.3
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\4.exe'
C:\TDDOWNLOAD\
  4.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.poc
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\5.exe'
C:\TDDOWNLOAD\
  5.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.2
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\6.exe'
C:\TDDOWNLOAD\
  6.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\7.exe'
C:\TDDOWNLOAD\
  7.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\8.exe'
C:\TDDOWNLOAD\
  8.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\9.exe'
C:\TDDOWNLOAD\
  9.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\10.exe'
C:\TDDOWNLOAD\
  10.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLinGame.lus
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\11.exe'
C:\TDDOWNLOAD\
  11.exe
      [DETECTION] Is the Trojan horse TR/PSW.Wow.acd
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\12.exe'
C:\TDDOWNLOAD\
  12.exe
      [DETECTION] Is the Trojan horse TR/WuDisable.B
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\13.exe'
C:\TDDOWNLOAD\
  13.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\14.exe'
C:\TDDOWNLOAD\
  14.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\15.exe'
C:\TDDOWNLOAD\
  15.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ozu.3
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\16.exe'
C:\TDDOWNLOAD\
  16.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\17.exe'
C:\TDDOWNLOAD\
  17.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.1
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\18.exe'
C:\TDDOWNLOAD\
  18.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\19.exe'
C:\TDDOWNLOAD\
  19.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\20.exe'
C:\TDDOWNLOAD\
  20.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.PMG.2
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\21.exe'
C:\TDDOWNLOAD\
  21.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\22.exe'
C:\TDDOWNLOAD\
  22.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\23.exe'
C:\TDDOWNLOAD\
  23.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12138
      [INFO]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\24.exe'
C:\TDDOWNLOAD\
  24.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [INFO]      The file was deleted!

End of the scan: 1990年1月1日  19:25
Used time: 00:07 min
The scan has been done completely.
      0 Scanning directories
     24 Files were scanned
     24 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     24 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
      0 Notes

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
冷冷
发表于 2008-1-28 11:27:56 | 显示全部楼层

回复 13楼 jimmyleo 的帖子

哪个?
ClamAV 都报壳 也不好
zwl2828
发表于 2008-1-28 11:27:59 | 显示全部楼层

Avira AntiVir

Access to the data has been denied!
Warning: A virus or unwanted program has been found in the HTTP Data.

Requested URL:  bbs.kafan.cn/attachment.php?aid=191558
Information:  Is the Trojan horse TR/Dropper.Gen
wangjay1980
发表于 2008-1-28 11:31:07 | 显示全部楼层
95
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ngd        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C3.tmp//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pjj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C5.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C8.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ozu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C9.tmp//UPack
detected: Trojan program Trojan.Win32.Vaklik.gq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2CA.tmp//UPack//PE_Patch
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2CB.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2CC.tmp//PE_Patch//UPack
detected: Trojan program Trojan.Win32.Vaklik.gg        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2CF.tmp//UPack
detected: virus Heur.Trojan.Generic        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D1.tmp//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.phh        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D3.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pov        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D4.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D5.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D7.tmp//PE_Patch//UPack
detected: Trojan program Backdoor.Win32.Delf.cwq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2D9.tmp//PE_Patch//UPack
detected: Trojan program Trojan-Downloader.Win32.VB.cii        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2DB.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2DD.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2DF.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2E3.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2E5.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppn        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\uohsom.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\utgnehz.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\wenwjsafj.dll//UPack//PE_Patch.MaskPE
detected: Trojan program Trojan.Win32.Vaklik.gh        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\WinForm.dll
detected: Trojan program Trojan.Win32.Vaklik.gl        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\WinForm.exE//UPack
detected: Trojan program Trojan.Win32.Vaklik.gl        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\1.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\2.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poc        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\4.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\5.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\6.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\7.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\8.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\9.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.odx        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\10.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\11.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ngd        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\12.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pjj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\13.exe//PE_Patch//UPack
detected: virus Heur.Invader (modification)        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\14.exe//PE_Patch.UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ozu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\15.exe//UPack
detected: Trojan program Trojan.Win32.Vaklik.gq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\16.exe//UPack//PE_Patch
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\17.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\18.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poh        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\19.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan.Win32.Vaklik.gg        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\20.exe//UPack
detected: virus Heur.Trojan.Generic        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\22.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pov        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\23.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\24.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\26.exe//PE_Patch//UPack
detected: Trojan program Backdoor.Win32.Delf.cwq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\a11.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.oiu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\avzxomn.dll
detected: Trojan program Trojan-PSW.Win32.OnLineGames.odx        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\avzxost.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmg        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\DbgHlp32.dll
detected: Trojan program Trojan.Win32.Vaklik.gg        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\DbgHlp32.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.nge        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\gjcsdyc.dll
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ngd        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\gjcsdzc.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pps        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\gnolnait.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pob        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\gqvvvvvi.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppr        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\hjxr.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\iemnaw.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmh        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\IGB_DJOL_1023.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pov        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\IGB_DJOL_1023.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\ijiq.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\iqnauhc.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poc        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\jgnnohkof.exe//UPack
detected: Trojan program Trojan-Downloader.Win32.VB.cii        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\k.exe
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pph        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\lnaixnauhqq.dll//UPack
detected: virus Heur.Trojan.Generic        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\LotusHlp.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poh        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\msfjcmb32.dll//PE_Patch.UPX//UPX
detected: virus Heur.Invader (modification)        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\mstfhncn32.dll//PE_Patch.UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pqr        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\nahzij.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\niluw.dll//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pqk        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\nuygnef.dll//UPack
detected: Trojan program Trojan.Win32.Vaklik.gq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\NVDispDRV.EXE//UPack//PE_Patch
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pon        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\oadnew.dll
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ppu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\pop.sys
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ozu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\PTSShell.dll
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ozu        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\PTSShell.exe//UPack
detected: Trojan program Trojan-Downloader.Win32.Agent.hua        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\puid.sys
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poc        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\qvvipwmq.exe//UPack
detected: Trojan program Backdoor.Win32.Delf.cwq        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\scvhost.exe//PE_Patch//UPack
detected: Trojan program Trojan.Win32.Vaklik.gl        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2A6.tmp//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2A7.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poc        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2AA.tmp//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2AC.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2AD.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2AE.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2B0.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2B2.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2B5.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2B6.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2B9.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2BA.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.odx        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2BD.tmp//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2BE.tmp
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C0.tmp//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pmi        File: C:\Documents and Settings\Owner\×ÀÃæ\н¨Îļþ¼Ð\tmp2C2.tmp
wangjay1980
发表于 2008-1-28 11:32:12 | 显示全部楼层
24
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/26.exe//PE_Patch//UPack
detected: Trojan program Trojan.Win32.Vaklik.gl        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/1.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/2.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poc        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/4.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/5.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/6.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poj        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/7.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/8.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/9.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.odx        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/10.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/11.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ngd        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/12.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pjj        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/13.exe//PE_Patch//UPack
detected: virus Heur.Invader (modification)        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/14.exe//PE_Patch.UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.ozu        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/15.exe//UPack
detected: Trojan program Trojan.Win32.Vaklik.gq        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/16.exe//UPack//PE_Patch
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/17.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/18.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.poh        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/19.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan.Win32.Vaklik.gg        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/20.exe//UPack
detected: virus Heur.Trojan.Generic        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/22.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pov        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/23.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pbp        File: C:\Documents and Settings\Owner\×ÀÃæ\TDDOWNLOAD.rar/24.exe//PE_Patch//UPack
leonfg
发表于 2008-1-28 11:55:29 | 显示全部楼层
ESET 84
C:\Documents and Settings\GUNDAM\桌面\virus\1.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\10.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\11.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\12.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\13.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\14.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\15.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\16.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\17.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\18.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\19.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\2.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\20.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\21.exe - probably a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\GUNDAM\桌面\virus\22.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\24.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\26.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\4.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\GUNDAM\桌面\virus\5.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\6.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\7.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\8.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\9.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\a11.exe - Win32/NetTool.Agent.NAA application
C:\Documents and Settings\GUNDAM\桌面\virus\avzxomn.dll - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\avzxost.exe - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\DbgHlp32.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\DbgHlp32.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\gjcsdyc.dll - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\gjcsdzc.exe - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\gnolnait.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\hjxr.dll - probably a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\hqyjvemzyzj.dll - probably a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\iemnaw.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\ijiq.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\iqnauhc.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\jgnnohkof.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\GUNDAM\桌面\virus\lnaixnauhqq.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\LotusHlp.dll - a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\LotusHlp.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\msepion.sys - a variant of Win32/PSW.OnLineGames.NFC trojan
C:\Documents and Settings\GUNDAM\桌面\virus\msfjcmb32.dll - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\mstfhncn32.dll - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\nahzij.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\niluw.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\nuygnef.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\NVDispDrv.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\NVDispDRV.EXE - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\oadnew.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\PTSShell.dll - a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\PTSShell.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\puid.sys - a variant of Win32/TrojanDownloader.Small.HLV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\qvvipwmq.exe - probably unknown NewHeur_PE virus
C:\Documents and Settings\GUNDAM\桌面\virus\scvhost.exe - Win32/NetTool.Agent.NAA application
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2A3.tmp - probably a variant of Win32/TrojanDownloader.Small.NZK trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2A4.tmp - probably a variant of Win32/TrojanDownloader.Small.NZK trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2A6.tmp - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2A7.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2AA.tmp - probably unknown NewHeur_PE virus
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2AD.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2AE.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2B0.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2B6.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2BA.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2BD.tmp - Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2C0.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2C3.tmp - a variant of Win32/PSW.OnLineGames.FDY trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2C5.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2C9.tmp - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2CA.tmp - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2CB.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2CC.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2CF.tmp - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2D0.tmp - probably a variant of Win32/AutoRun.Q worm
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2D1.tmp - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2D5.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2D7.tmp - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\virus\tmp2D9.tmp - Win32/NetTool.Agent.NAA application
C:\Documents and Settings\GUNDAM\桌面\virus\uohsom.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\utgnehz.dll - a variant of Win32/PSW.OnLineGames.NLH trojan
C:\Documents and Settings\GUNDAM\桌面\virus\wenwjsafj.dll - probably a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\WinForm.dll - probably a variant of Win32/PSW.OnLineGames.HCV trojan
C:\Documents and Settings\GUNDAM\桌面\virus\WinForm.exE - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\virus\Wn_Sys8x.Sys - probably a variant of Win32/AutoRun.Q worm
wangjay1980
发表于 2008-1-28 12:08:35 | 显示全部楼层
Hello,

14.exe, 14.exe, mstfhncn32.dll - Trojan-PSW.Win32.OnLineGames.prf,
21.exe, 21.exe, tmp2D0.tmp - Trojan-PSW.Win32.QQPass.asz,
22.exe, 22.exe, LotusHlp.exe, tmp2D1.tmp - Trojan-PSW.Win32.OnLineGames.prg,
hqyjvemzyzj.dll - Trojan-PSW.Win32.WOW.ajy,
LotusHlp.dll - Trojan-PSW.Win32.OnLineGames.prh,
msepion.sys - Trojan-PSW.Win32.OnLineGames.pri,
NVDispDrv.dll - Trojan-PSW.Win32.OnLineGames.prj,
tmp2A3.tmp, tmp2A4.tmp - Trojan-Downloader.Win32.Small.hzf,
Wn_Sys8x.Sys - Trojan-PSW.Win32.QQPass.ata

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

avzxoin.dll, gjcsdss.dll, jgnnohkof.exe.hiv, tmp2A8.tmp, tmp2D6.tmp, verclsid.exe, ~esace

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Denis Maslennikov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: TDDOWNLOAD.rar
> Attachment: windows.zip
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-26 00:44 , Processed in 0.108874 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表