查看: 2241|回复: 10
收起左侧

[病毒样本] 14PCS

[复制链接]
自由
发表于 2008-3-23 22:22:08 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
testhawk
发表于 2008-3-23 22:25:15 | 显示全部楼层
14
14.rar » RAR » qq.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 2.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 7sa.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
14.rar » RAR » 19.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
14.rar » RAR » 29.exe - probably unknown NewHeur_PE virus
14.rar » RAR » 3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 8.exe - a variant of Win32/PSW.QQPass.NCZ trojan
14.rar » RAR » 21.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » hh.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
14.rar » RAR » 12.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 6.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 18.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 22.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
14.rar » RAR » 33.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
Exia 该用户已被删除
发表于 2008-3-23 22:25:33 | 显示全部楼层

14

Starting the file scan:

Begin scan in 'E:\AVIRA\14.rar'
E:\AVIRA\14.rar
  [0] Archive type: RAR
  --> qq.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 2.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 7sa.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 19.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 29.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 3.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 8.exe
      [DETECTION] Contains detection pattern of the dropper DR/Delphi.Gen
  --> 21.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> hh.exe
      [DETECTION] Is the Trojan horse TR/VB.cjq
  --> 12.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.uyh
  --> 6.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 18.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 22.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
  --> 33.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.597
      [WARNING]   The file was ignored!


End of the scan: 2008年3月23日  22:27
Used time: 00:33 min

The scan has been done completely.

      0 Scanning directories
     15 Files were scanned
     11 viruses and/or unwanted programs were found
      3 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
挪威的冬天
发表于 2008-3-23 22:26:59 | 显示全部楼层

信息        2008-03-23  22:26:51        您此次查毒清除了12个病毒                       
信息        2008-03-23  22:26:51        您此次查毒共查出12个病毒以及危险代码                       
信息        2008-03-23  22:26:51        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件29个                       
信息        2008-03-23  22:26:51        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-03-23  22:26:51        D:\Desktop\14.rar\33.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:51        D:\Desktop\14.rar\22.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:51        D:\Desktop\14.rar\18.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\6.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\12.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\hh.exe        Win32.Troj.OnlineGameT.lf.94208        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\8.exe        Win32.PSWTroj.QQPass.106616        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\3.exe        Win32.Troj.OnlineGamesT.ee.94208        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\19.exe        Win32.Troj.OnlineGameT.lf.94208        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\7sa.exe        Win32.Troj.OnlineGameT.lf.94208        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\2.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功       
病毒        2008-03-23  22:26:50        D:\Desktop\14.rar\qq.exe        Win32.Troj.OnlineGamesT.e.94315        清除成功
ilyf44
发表于 2008-3-23 22:37:01 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aerbeisi
发表于 2008-3-24 00:27:42 | 显示全部楼层
---------------------------------------------------------------------

[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->qq.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->2.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->7sa.exe->(embedded)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->19.exe->(embedded)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->3.exe->(UPack)
[Found security risk]         <W32/AutoRun.D.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->8.exe->(UPX)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->21.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->hh.exe->(embedded)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->12.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->6.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->18.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->22.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\14.rar->33.exe
[Contains infected objects]        C:\14.rar
[Quarantined]        C:\14.rar->33.exe

---------------------------------------------------------------------
Scan ended:        2008-3-24, 00:27:02
Duration:        00:00:10

Scan result:

Scanned files:                 1
Infected objects:         13
Disinfected objects:         0
Quarantined files:         1
---------------------------------------------------------------------
无尽藏海
发表于 2008-3-24 13:06:04 | 显示全部楼层

14

E:\VIRUS\14.rar>>qq.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>2.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>7sa.exe        Heuri.Suspicious.ERNM        启发式扫描        还未处理
E:\VIRUS\14.rar>>19.exe        Heuri.Suspicious.ERNM        启发式扫描        还未处理
E:\VIRUS\14.rar>>29.exe        W32.Generic.worm.jhho        病毒        还未处理
E:\VIRUS\14.rar>>3.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>8.exe        TrojanPSW.QQPass.zfd.vmcc        木马        还未处理
E:\VIRUS\14.rar>>21.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>hh.exe        TrojanPSW.GameOL.mpc.larn        木马        还未处理
E:\VIRUS\14.rar>>12.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>6.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>18.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>22.exe        W32.Viking.k        病毒        还未处理
E:\VIRUS\14.rar>>33.exe        W32.Viking.k        病毒        还未处理
Palkia
发表于 2008-3-24 13:10:02 | 显示全部楼层

1

在 C:\Documents and Settings\Administrator\桌面\14.rar->33.exe 中发现 Trojan/PSW.OnLineGames.yhx 病毒, 已删除
sam.to
发表于 2008-3-24 16:57:12 | 显示全部楼层
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wen        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/qq.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.weh        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/2.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wdh        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/7sa.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.weg        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/19.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wej        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/29.exe//FSG
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wek        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/3.exe//UPack//PE_Patch
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wel        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/8.exe//UPX
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wei        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/21.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wem        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/hh.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.uyi        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/12.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.vwr        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/6.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.wef        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/18.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.vpr        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/22.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.uyw        檔案: C:\Documents and Settings\kato9096\桌面\14.rar/33.exe//UPack

14
Joker
发表于 2008-3-24 16:59:34 | 显示全部楼层
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wen        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/qq.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.weh        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/2.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wdh        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/7sa.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.weg        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/19.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wej        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/29.exe//FSG
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wek        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/3.exe//UPack//PE_Patch
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wel        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/8.exe//UPX
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wei        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/21.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wem        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/hh.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.uyi        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/12.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.vwr        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/6.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.wef        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/18.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.vpr        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/22.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.uyw        File: C:\Documents and Settings\Administrator\×&Agrave;&Atilde;&aelig;\14.rar/33.exe//UPack
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-6 01:31 , Processed in 0.134274 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表