查看: 3833|回复: 23
收起左侧

[病毒样本] Dogdel

[复制链接]
qianwenxiang
发表于 2008-2-2 14:49:52 | 显示全部楼层 |阅读模式
又是这玩意 index.dat记录了它的罪证:
hxxp://g.935425.com/00018.exe
hxxp://e.935425.com/00005.exe
hxxp://f.935425.com/00022.exe
hxxp://e.935425.com/00002.exe
hxxp://qq.935425.com/arp111.exe
hxxp://a.935425.com/00011.exe
hxxp://c.935425.com:999/host.exe
hxxp://f.935425.com/00033.exe
hxxp://c.935425.com:999/soundma.exe
hxxp://c.935425.com:999/wdlm.exe
hxxp://c.935425.com:999/lmmh.exe
hxxp://a.935425.com/00006.exe
hxxp://g.935425.com/00024.exe
hxxp://c.935425.com:999/fbd.exe
hxxp://f.935425.com/00013.exe
hxxp://e.935425.com/00004.exe
hxxp://g.935425.com/jz.exe
hxxp://e.935425.com/00023.exe
hxxp://f.935425.com/00017.exe
hxxp://a.935425.com/00009.exe
hxxp://f.935425.com/00015.exe
hxxp://f.935425.com/00016.exe
hxxp://e.935425.com/00003.exe
hxxp://e.935425.com/00001.exe
hxxp://c.935425.com:999/lmmy.exe
hxxp://qq.935425.com/00025.exe

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
冷冷
发表于 2008-2-2 14:51:53 | 显示全部楼层
皇帝
I:\virus\Dogdel.rar:\00003.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar:\00001.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00025.exe - Signature 'Trojan-Proxy.Win32.Delf.AN' found
I:\virus\Dogdel.rar:\wdfmgr.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar:\host.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\lmmh.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\lmmy.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\soundma.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\wdlm.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\jz.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\Dogdel.rar:\fbd.exe - Signature 'Trojan-Spy.Win32.Banker.ahy' found
I:\virus\Dogdel.rar:\www.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar:\real.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar:\arp111.exe - Signature 'Trojan-Spy.Win32.Banker.ahy' found
I:\virus\Dogdel.rar:\00018.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\Dogdel.rar:\00005.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00022.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar:\00002.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00011.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\00033.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00006.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00024.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00013.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00004.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00023.exe - Signature 'Trojan-Dropper.Win32.Agent.ane' found
I:\virus\Dogdel.rar:\00017.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\Dogdel.rar:\00009.exe - Signature 'Trojan-Spy.Win32.Agent.hz' found
I:\virus\Dogdel.rar:\00015.exe - Signature 'Trojan-Spy.Win32.Delf.PD' found
I:\virus\Dogdel.rar:\00016.exe - Signature 'Trojan-Spy.Win32.Delf.uv' found
I:\virus\Dogdel.rar

        30 Files scanned
          (1 Archiv with 29 files)
        29 Signatures found
        0 Suspect code-parts found
        Used time: 0:00.468
Graybird
发表于 2008-2-2 14:52:03 | 显示全部楼层

29

Starting the file scan:

Begin scan in 'E:\Dogdel.rar'
E:\Dogdel.rar
  [0] Archive type: RAR
  --> 00003.exe
      [DETECTION] Is the Trojan horse TR/WuDisable.B
  --> 00001.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.aav.1
  --> 00025.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.FF.27
  --> wdfmgr.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> host.exe
      [DETECTION] Is the Trojan horse TR/Qhost.aef
  --> lmmh.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> lmmy.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> soundma.exe
      [DETECTION] Is the Trojan horse TR/Drop.Age.51042.B
  --> wdlm.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> jz.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.10
  --> fbd.exe
      [DETECTION] Is the Trojan horse TR/Agent.drk
  --> www.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> real.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> arp111.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> 00018.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prw.11
  --> 00005.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 00022.exe
      [DETECTION] Is the Trojan horse TR/WuDisable.B
  --> 00002.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prj.1
  --> 00011.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.igf
  --> 00033.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00006.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00024.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.266
  --> 00013.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00004.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.267
  --> 00023.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
  --> 00017.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmw.2
  --> 00015.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.olr.1
  --> 00016.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [INFO]      The file was deleted!


End of the scan: 2008年2月2日  14:53
Used time: 00:26 min

The scan has been done completely.

      0 Scanning directories
     30 Files were scanned
     29 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
spaceplane
发表于 2008-2-2 14:53:51 | 显示全部楼层
蜘蛛 26
AVAST 21
mofunzone
发表于 2008-2-2 14:57:20 | 显示全部楼层
29全灭

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\Dogdel.rar'
C:\Documents and Settings\Administrator\My Documents\
  Dogdel.rar
  Dogdel.rar:Zone.Identifier
    [0] Archive type: RAR
    --> 00003.exe
        [DETECTION] Is the Trojan horse TR/WuDisable.B
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00001.exe
        [DETECTION] Is the Trojan horse TR/PSW.Online.aav.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00025.exe
        [DETECTION] Contains detection pattern of the worm WORM/Autorun.FF.27
        [WARNING]   Infected files in archives cannot be repaired!
    --> wdfmgr.exe
        [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
        [WARNING]   Infected files in archives cannot be repaired!
    --> host.exe
        [DETECTION] Is the Trojan horse TR/Qhost.aef
        [WARNING]   Infected files in archives cannot be repaired!
    --> lmmh.exe
        [DETECTION] Is the Trojan horse TR/Hijacker.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> lmmy.exe
        [DETECTION] Is the Trojan horse TR/Hijacker.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> soundma.exe
        [DETECTION] Is the Trojan horse TR/Drop.Age.51042.B
        [WARNING]   Infected files in archives cannot be repaired!
    --> wdlm.exe
        [DETECTION] Is the Trojan horse TR/Hijacker.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> jz.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.10
        [WARNING]   Infected files in archives cannot be repaired!
    --> fbd.exe
        [DETECTION] Is the Trojan horse TR/Agent.drk
        [WARNING]   Infected files in archives cannot be repaired!
    --> www.exe
        [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
        [WARNING]   Infected files in archives cannot be repaired!
    --> real.exe
        [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
        [WARNING]   Infected files in archives cannot be repaired!
    --> arp111.exe
        [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00018.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prw.11
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00005.exe
        [DETECTION] Is the Trojan horse TR/Spy.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00022.exe
        [DETECTION] Is the Trojan horse TR/WuDisable.B
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00002.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prj.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00011.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Agent.igf
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00033.exe
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00006.exe
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00024.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.266
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00013.exe
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00004.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.267
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00023.exe
        [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00017.exe
        [DETECTION] Is the Trojan horse TR/Rootkit.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00009.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmw.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00015.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.olr.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> 00016.exe
        [DETECTION] Is the Trojan horse TR/Dropper.Gen
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      The file was deleted!


End of the scan: 2008年2月1日  22:57
Used time: 00:07 min

The scan has been done completely.

      0 Scanning directories
     31 Files were scanned
     29 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      2 Files not concerned
      1 Archives were scanned
     29 Warnings
      0 Notes
鱼是一只我
发表于 2008-2-2 14:58:03 | 显示全部楼层
卡巴全杀
费尔漏了一个
solcroft
发表于 2008-2-2 14:59:40 | 显示全部楼层
昨天被金山的“恶意行为拦截”耍了一整天
回归nod32

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
IllusionWing
发表于 2008-2-2 15:02:14 | 显示全部楼层
漏了一个

[ 本帖最后由 gankeyu 于 2008-2-2 15:04 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
woai_jolin
发表于 2008-2-2 15:04:49 | 显示全部楼层
Scan Log
Version of virus signature database: 2845 (20080202)
Date: 2008-2-2  Time: 15:04:16
Scanned disks, folders and files: G:\v\Dogdel.rar
G:\v\Dogdel.rar » RAR » 00003.exe - Win32/PSW.OnLineGames.FDY trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00001.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00025.exe - probably a variant of Win32/AutoRun.Q worm - was a part of the deleted object
G:\v\Dogdel.rar » RAR » wdfmgr.exe - a variant of Win32/Anilogo worm - was a part of the deleted object
G:\v\Dogdel.rar » RAR » host.exe - Win32/Qhost.AEF trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » lmmh.exe - Win32/Spy.Delf.NGN trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » lmmy.exe - Win32/PSW.Delf.NKV trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » soundma.exe - Win32/PSW.Delf.NKU trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » wdlm.exe - Win32/TrojanDownloader.Delf.OBF trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » jz.exe - a variant of Win32/PSW.OnLineGames.MUG trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » fbd.exe - probably a variant of Win32/Spy.Agent trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » www.exe - a variant of Win32/Anilogo worm - was a part of the deleted object
G:\v\Dogdel.rar » RAR » real.exe - a variant of Win32/Anilogo worm - was a part of the deleted object
G:\v\Dogdel.rar » RAR » arp111.exe - probably unknown NewHeur_PE virus [7] - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00018.exe - Win32/PSW.OnLineGames.MUG trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00005.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00022.exe - Win32/PSW.OnLineGames.FDY trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00002.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00011.exe - Win32/PSW.OnLineGames.NMN trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00033.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00006.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00024.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00013.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00004.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00023.exe - Win32/PSW.OnLineGames.JTC trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00017.exe - a variant of Win32/PSW.OnLineGames.MUG trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00009.exe - a variant of Win32/PSW.OnLineGames.NLY trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00015.exe - Win32/PSW.OnLineGames.MUG trojan - was a part of the deleted object
G:\v\Dogdel.rar » RAR » 00016.exe - a variant of Win32/PSW.OnLineGames.FDY trojan - was a part of the deleted object
Number of scanned objects: 30
Number of threats found: 29
Time of completion: 15:04:27  Total scanning time: 11 sec (00:00:11)

Notes:
[7] Object is probably infected with an unknown virus.
woai_jolin
发表于 2008-2-2 15:05:29 | 显示全部楼层
Start of the scan: 2008年2月2日  15:05

Starting the file scan:

Begin scan in 'G:\v\Dogdel.rar'
G:\v\Dogdel.rar
  [0] Archive type: RAR
  --> 00003.exe
      [DETECTION] Is the Trojan horse TR/WuDisable.B
  --> 00001.exe
      [DETECTION] Is the Trojan horse TR/PSW.Online.aav.1
  --> 00025.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.FF.27
  --> wdfmgr.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> host.exe
      [DETECTION] Is the Trojan horse TR/Qhost.aef
  --> lmmh.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> lmmy.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> soundma.exe
      [DETECTION] Is the Trojan horse TR/Drop.Age.51042.B
  --> wdlm.exe
      [DETECTION] Is the Trojan horse TR/Hijacker.Gen
  --> jz.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.10
  --> fbd.exe
      [DETECTION] Is the Trojan horse TR/Agent.drk
  --> www.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> real.exe
      [DETECTION] Contains detection pattern of the worm WORM/Cekar.A
  --> arp111.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
  --> 00018.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prw.11
  --> 00005.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 00022.exe
      [DETECTION] Is the Trojan horse TR/WuDisable.B
  --> 00002.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.prj.1
  --> 00011.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.igf
  --> 00033.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00006.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00024.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.266
  --> 00013.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 00004.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.267
  --> 00023.exe
      [DETECTION] Contains detection pattern of the dropper DR/Dldr.Agent.YMX
  --> 00017.exe
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 00009.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmw.2
  --> 00015.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.olr.1
  --> 00016.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [INFO]      The file was deleted!


End of the scan: 2008年2月2日  15:05
Used time: 00:08 min

The scan has been done completely.

      0 Scanning directories
     30 Files were scanned
     29 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-2 03:28 , Processed in 0.134607 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表