楼主: 绅博周幸
收起左侧

[病毒样本] 一个马,PASS不少杀软

[复制链接]
斯干
发表于 2008-2-23 11:06:54 | 显示全部楼层
江民过了……
zwl2828
发表于 2008-2-23 11:29:46 | 显示全部楼层

Avira AntiVir

Contains suspicious code HEUR/Crypted
mofunzone
发表于 2008-2-23 11:51:16 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\list'
C:\Documents and Settings\Administrator\My Documents\list\
  1.exe
    [0] Archive type: Runtime Packed
    --> Object
  10.exe
    [0] Archive type: OVL
    --> Object
    --> Object
      [INFO]      The file was deleted!
  11.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rjh.5
                [WARNING]   Infected files in archives cannot be repaired!
            --> Object
            --> Object
      [INFO]      The file was deleted!
  12.exe
    [0] Archive type: Runtime Packed
    --> Object
      [INFO]      The file was deleted!
  13.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12181
      [INFO]      The file was deleted!
  14.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.11920
      [INFO]      The file was deleted!
  15.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rmg.4
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
  16.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12389
      [INFO]      The file was deleted!
  17.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.qiv
                [WARNING]   Infected files in archives cannot be repaired!
            --> Object
      [INFO]      The file was deleted!
  18.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
      [INFO]      The file was deleted!
  19.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rjh
                [WARNING]   Infected files in archives cannot be repaired!
            --> Object
            --> Object
      [INFO]      The file was deleted!
  2.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
      [INFO]      The file was deleted!
  20.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
      [INFO]      The file was deleted!
  21.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rhj.3
                [WARNING]   Infected files in archives cannot be repaired!
            --> Object
      [INFO]      The file was deleted!
  22.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.yub
      [INFO]      The file was deleted!
  23.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
      [INFO]      The file was deleted!
  24.exe
    [0] Archive type: Runtime Packed
    --> Object
      [INFO]      The file was deleted!
  25.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12312
      [INFO]      The file was deleted!
  26.exe
      [DETECTION] Is the Trojan horse TR/PSW.QQpass.avg
      [INFO]      The file was deleted!
  27.exe
    [0] Archive type: Runtime Packed
    --> Object
      [INFO]      The file was deleted!
  3.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
            --> Object
      [INFO]      The file was deleted!
  4.exe
    [0] Archive type: Runtime Packed
    --> Object
      [INFO]      The file was deleted!
  5.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
      [INFO]      The file was deleted!
  6.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
      [INFO]      The file was deleted!
  7.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
            --> Object
      [INFO]      The file was deleted!
  8.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12082
      [INFO]      The file was deleted!
  9.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.Wow.acd
              [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
  down.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Dldr.Delf.epw.1
            [WARNING]   Infected files in archives cannot be repaired!
      [INFO]      The file was deleted!
  listtt.exe
    [0] Archive type: Runtime Packed
    --> Object
      [INFO]      The file was deleted!


End of the scan: 2008年2月22日  19:50
Used time: 00:06 min

The scan has been done completely.

      1 Scanning directories
     29 Files were scanned
     29 viruses and/or unwanted programs were found
      6 Files were classified as suspicious:
     28 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
     26 Archives were scanned
      7 Warnings
      0 Notes
leonfg
发表于 2008-2-23 12:31:06 | 显示全部楼层
ESET 1+29 全
C:\Documents and Settings\GUNDAM\桌面\GU.rar » RAR » GU.exe - probably a variant of Win32/TrojanDownloader.Dadobra.FX trojan

C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 1.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 10.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 11.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 12.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 13.exe - Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 14.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 15.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 16.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 17.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 18.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 19.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 2.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 20.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 21.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 22.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 23.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 24.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 25.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 26.exe - Win32/PSW.QQPass.AVG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 27.exe - Win32/Agent.NOS trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 3.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 4.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 5.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 6.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 7.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 8.exe - Win32/PSW.OnLineGames.PBQ trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » 9.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » down.exe - Win32/TrojanDownloader.Delf.EPW trojan
C:\Documents and Settings\GUNDAM\桌面\list.rar » RAR » listtt.exe - Win32/TrojanDownloader.Agent.NVM trojan
xiaoxmj
发表于 2008-2-23 12:52:52 | 显示全部楼层
信息        2008-02-23  12:52:43        您此次查毒共查出27个病毒以及危险代码                       
信息        2008-02-23  12:52:43        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件61个                       
信息        2008-02-23  12:52:43        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\listtt.exe        Win32.Troj.Downloader.ex.23552        跳过,未处理       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\down.exe        Win32.TrojDownloader.Delf.43008        跳过,未处理       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\9.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\8.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\7.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:43        C:\Documents and Settings\Administrator\桌面\list.rar\6.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\5.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\4.exe        Win32.Troj.OnlineGamesT.oy.61440        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\3.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\26.exe        Win32.PSWTroj.QQPass.108696        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\25.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\24.exe        Win32.Troj.OnlineGamesT.oy.61440        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\23.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\22.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\21.exe        Win32.Troj.OnlineGameT.am.107664        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\20.exe        Win32.Troj.OnlineGamesT.e.94315        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\2.exe        Win32.Troj.OnlineGamesT.e.94315        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\19.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\18.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\17.exe        Win32.Troj.OnlineGamesT.nr.37008        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\16.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\15.exe        Win32.Troj.OnlineGamesT.ty.98304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\14.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\13.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\12.exe        Win32.Troj.OnlineGamesT.oy.61440        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\11.exe        Win32.Troj.GamesHackT.gu.94304        跳过,未处理       
病毒        2008-02-23  12:52:42        C:\Documents and Settings\Administrator\桌面\list.rar\10.exe        Win32.Troj.OnlineGamesT.af.57344        跳过,未处理       
信息        2008-02-23  12:52:31        金山毒霸主程序启动查毒过程,查毒方式:命令行查毒                       
信息        2008-02-23  12:52:30        金山毒霸主程序 启动                       
信息        2008-02-23  12:48:16        金山毒霸主程序 退出                       
信息        2008-02-23  12:48:13        金山毒霸主程序 启动                       
信息        2008-02-23  12:48:11        金山毒霸主程序 退出
xiaoxmj
发表于 2008-2-23 12:53:40 | 显示全部楼层
费尔全杀
wangjay1980
发表于 2008-2-23 13:32:23 | 显示全部楼层
23
detected: Trojan program Trojan-PSW.Win32.Agent.zf        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/1.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/11.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rmb        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/13.exe//PE_Patch//UPack//data0000.bin//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rog        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/14.exe//PE_Patch//UPack//data0000.bin//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rmg        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/15.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.qiv        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/17.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/18.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/19.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rmj        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/2.exe//UPack
detected: Trojan program Trojan.Win32.Vaklik.ku        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/20.exe//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rbf        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/21.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rpd        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/22.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/23.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.roo        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/25.exe//PE_Patch//UPack//data0000.bin//UPack
detected: Trojan program Trojan-PSW.Win32.QQPass.avg        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/26.exe//UPX
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/3.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/5.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/6.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/7.exe//PE_Patch//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.roh        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/8.exe//PE_Patch//UPack//data0000.bin//UPack
detected: Trojan program Trojan-PSW.Win32.OnLineGames.rhu        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/9.exe//PE_Patch//UPack
detected: Trojan program Trojan-Downloader.Win32.Delf.epw        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/down.exe//PE_Patch//UPack
detected: Trojan program Trojan-Dropper.Win32.Agent.env        File: C:\Documents and Settings\Owner\×ÀÃæ\list.rar/listtt.exe//PE_Patch//UPack

TO KL


Hello,

10.exe - Trojan-PSW.Win32.OnLineGames.rqs,
12.exe, 24.exe - Trojan.Win32.Agent.fvb,
16.exe - Trojan-PSW.Win32.OnLineGames.rqr,
27.exe - Trojan.Win32.Agent.fvg,
4.exe - Trojan.Win32.Agent.fvc,
GU.exe - Trojan-Downloader.Win32.Small.int

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Vyacheslav Zakorzhevsky
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: GU.rar
> Attachment: list.rar

[ 本帖最后由 wangjay1980 于 2008-2-23 19:38 编辑 ]
啊弥陀佛
发表于 2008-2-23 13:53:19 | 显示全部楼层
木马名称:Trojan-PSW.Win32.OLGames.lyb
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\17.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

木马名称:Trojan-PSW.Win32.OLGames.lyg
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\21.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

木马名称:Trojan-Downloader.Win32.Delf.iyd
程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\DOWN.EXE
是木马程序!
已成功阻止其运行,是否要删除此文件?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\1.EXE
木马程序生成以下文件:
1) C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\TMP48.TMP
2) C:\WINDOWS\SYSTEM32\MSOSMHFP00.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\2.EXE
木马程序生成以下文件:
1) C:\WINDOWS\WSOCKDRV32.EXE
2) C:\WINDOWS\SYSTEM32\WSOCKDRV32.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\3.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\CUHAD.DLL
2) C:\WINDOWS\SYSTEM32\MSEPION.SYS
3) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\4.EXE
病毒程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\HHRDXD.DLL
是否删除木马程序及其衍生物?


程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\5.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\OQNAUHC.DLL
2) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\6.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\IJOUGIEMNAW.DLL
2) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\7.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\GNOLNAIT.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\8.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\IGBWD1031.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\9.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\EOHSOM.DLL
2) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\10.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\HACHAC1036.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\11.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\BAUHGNEM.DLL
2) C:\WINDOWS\SYSTEM32\MSEPION.SYS
3) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\13.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\CBB-CBB-1028.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\14.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\NNNNNN1028.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\15.EXE
木马程序生成以下文件:
1) C:\WINDOWS\UPXDND.EXE
2) C:\WINDOWS\SYSTEM32\UPXDND.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\16.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\BAABAA1028.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\18.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\JEMNAW.DLL
2) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\19.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\XJXR.DLL
2) C:\WINDOWS\SYSTEM32\MSEPION.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\20.EXE
木马程序生成以下文件:
1) C:\WINDOWS\DBGHLP32.EXE
2) C:\WINDOWS\SYSTEM32\DBGHLP32.DLL
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\22.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\JADJAD1038.EXE
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\23.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\QLIHZOUHGNFE.DLL
2) C:\WINDOWS\SYSTEM32\DRIVERS\MSYECP.SYS
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\24.EXE
病毒程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\SGREFG.DLL
是否删除木马程序及其衍生物?


程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\25.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\SABSAB1011.EXE
是否删除木马程序及其衍生物?


程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\27.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\73684.DAT
是否删除木马程序及其衍生物?

程序:
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\LIST\LISTTT.EXE
木马程序生成以下文件:
1) C:\WINDOWS\SYSTEM32\EXPLORER.EXE
是否删除木马程序及其衍生物?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
挪威的冬天
发表于 2008-2-23 13:54:21 | 显示全部楼层
金山毒霸 MISS
dkdobe
发表于 2008-2-23 14:08:08 | 显示全部楼层
ACCESS DENIED
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://bbs.kafan.cn/attachment.php?aid=206379

The folowing error was encountered:

The requested object is INFECTED. The following viruses Heur.Downloader were found

Please contact your service provider if you feel this is incorrect.



--------------------------------------------------------------------------------

Generated Sat Feb 23 14:07:54 2008 by Kaspersky Internet Security 7.0
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-13 09:54 , Processed in 0.081955 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表