查看: 2582|回复: 16
收起左侧

[病毒样本] 09

[复制链接]
qianwenxiang
发表于 2008-4-1 21:52:52 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
残缺的唯美
发表于 2008-4-1 21:55:14 | 显示全部楼层
Trojan Horse
病毒 ID: 25464
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[test.exe] 位于[d:\users\administrator\desktop\cpack.rar] - 已感染


Trojan.Zlob
病毒 ID: 4254
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[pageticket2000.exe] 位于[d:\users\administrator\desktop\cpack.rar] - 已感染


Infostealer
病毒 ID: 24770
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[r2o.exe] 位于[d:\users\administrator\desktop\cpack.rar] - 已感染


Infostealer
病毒 ID: 24770
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[ro.exe] 位于[d:\users\administrator\desktop\cpack.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[rse.exe] 位于[d:\users\administrator\desktop\cpack.rar] - 已感染
Exia 该用户已被删除
发表于 2008-4-1 21:55:40 | 显示全部楼层

9

Starting the file scan:

Begin scan in 'E:\cpack.rar'
E:\cpack.rar
  [0] Archive type: RAR
  --> test.exe
      [DETECTION] Is the Trojan horse TR/Inject.HH
  --> myself.exe
      [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
  --> ogame.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.45056
  --> pageticket2000.exe
      [DETECTION] Is the Trojan horse TR/DNSChanger.iik
  --> r2o.exe
      [DETECTION] Is the Trojan horse TR/PSW.Maran.AU
  --> ro.exe
      [DETECTION] Is the Trojan horse TR/PSW.Maran.AU
  --> rse.exe
      [DETECTION] Is the Trojan horse TR/Copiet.B.1
  --> serial.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
  --> sytem.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rra
      [INFO]      The file was deleted!


End of the scan: 2008年4月1日  21:57
Used time: 00:27 min

The scan has been done completely.

      0 Scanning directories
     10 Files were scanned
      9 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
挪威的冬天
发表于 2008-4-1 21:56:42 | 显示全部楼层
信息        2008-04-01  21:56:35        您此次查毒清除了9个病毒                       
信息        2008-04-01  21:56:35        您此次查毒共查出9个病毒以及危险代码                       
信息        2008-04-01  21:56:35        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件14个                       
信息        2008-04-01  21:56:35        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\sytem.exe        Win32.PSWTroj.GameOnline.82944        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\serial.exe        Win32.Troj.Virtumonde.tn.9302        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\rse.exe        Win32.Troj.Delf.ai.114728        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\ro.exe        Win32.Troj.Delf.dk.46493        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\r2o.exe        Win32.Troj.Maran.ff.46505        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\pageticket2000.exe        Win32.Troj.Delf.cy.197248        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\ogame.exe        Win32.Troj.DwonLoaderT.xy.133203        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\myself.exe        Win32.Troj.SpyT.nh.925696        清除成功       
病毒        2008-04-01  21:56:35        D:\Desktop\cpack.rar\test.exe        Win32.Troj.Inject.hh.34816        清除成功
平淡
发表于 2008-4-1 22:11:23 | 显示全部楼层

9ge

C:\Documents and Settings\Administrator\桌面\cpack.rar>>myself.exe        Heuri.Suspicious.ERNM        启发式扫描        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>ogame.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>pageticket2000.exe        Trojan.DNSChanger.ik.mdpo.arc        木马        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>r2o.exe        W32.Viking.k        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>ro.exe        W32.Viking.k        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>rse.exe        TrojanPSW.Delf.aih.ljjj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>serial.exe        TrojanDownloader.Small.tnt.iyoj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>sytem.exe        Packed.UPX.a        带壳程序        还未处理
C:\Documents and Settings\Administrator\桌面\cpack.rar>>test.exe        Trojan.Inject.hh.pxki        木马        还未处理
allinwonderi
发表于 2008-4-1 22:12:56 | 显示全部楼层
[Found Trojan]         <W32/Trojan2.JDU (exact, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\cpack.rar->test.exe
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\cpack.rar->myself.exe
[Found security risk]         <W32/Malware!d64c (exact, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\cpack.rar->pageticket2000.exe
[Found virus]         <W32/Downloader.gen10 (not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\cpack.rar->rse.exe
[Found password stealer]         <W32/Pws.ACJF (exact, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\cpack.rar->sytem.exe->(UPX)

---------------------------------------------------------------------
Scan ended:        2008-4-1, 22:12:53
Duration:        0:00:13

Scan result:

Scanned files:                 6
Infected objects:         5
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------
allinwonderi
发表于 2008-4-1 22:13:56 | 显示全部楼层
[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:test.exe <- Trojan.Inject.Hh : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:myself.exe <- Trojan.Spy.Pophot.Abr : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:ogame.exe <- Worm.Downloader.Hf : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:ogame.exe<UPack>:ogame.exe <- Heur.RoundKick : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:pageticket2000.exe<NSIS>:00.exe<RAR>:01.exe <- Trojan.Packed.Polycrypt.B42 : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:r2o.exe<UPack>:r2o.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:r2o.exe<UPack>:r2o.exe<DLLRES>:IPFILTER0.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:r2o.exe<UPack>:r2o.exe<DLLRES>:WINXPNP1.exe <- Trojan.Psw.Maran.Dy : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:ro.exe<UPack>:ro.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:ro.exe<UPack>:ro.exe<DLLRES>:IPFILTER0.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:ro.exe<UPack>:ro.exe<DLLRES>:WINXPNP1.exe <- Trojan.Psw.Maran.Dy : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:rse.exe<UPX>:rse.exe<DLLRES>:MM0.exe <- Trojan.Psw.Lmir.Bpb : No action
C:\Documents and Settings\All Users\Documents\Test\cpack.rar<RAR>:serial.exe <- Trojan.Downloader.Small.Tnt : No action



Scanned objects : 31

Infected objects : 13
爱过昙花
发表于 2008-4-1 22:42:44 | 显示全部楼层
统计信息
已扫描:
文件: 10
未扫描: 0
结果:
病毒: 9
间谍软件: 0
可疑对象: 0
危险软件: 0
操作:
已杀毒: 0
已重命名: 0
删除: 0
已隔离: 0
失败: 0
引导区:
已扫描: 0
受感染: 0
可疑对象: 0
已杀毒: 0


--------------------------------------------------------------------------------

选项
病毒定义版本:
病毒: 2008-04-01_06
间谍软件: 2008-04-01_06
扫描引擎:
F-Secure Orion: 1.02.38, 2008-04-01
F-Secure Libra: 2.04.04, 2008-03-31
F-Secure AVP: 7.00.171, 2008-04-01
F-Secure Draco: 1.00.35, 2008-02-13
无尽藏海
发表于 2008-4-1 22:43:09 | 显示全部楼层

8

E:\VIRUS\cpack\myself.exe - Win32/Spy.Delf.NHF 特洛伊木马 的变种
E:\VIRUS\cpack\ogame.exe - Win32/Jalous 蠕虫 的变种
E:\VIRUS\cpack\pageticket2000.exe > NSIS > 00.exe > RAR > 01.exe - Win32/TrojanDownloader.Zlob 特洛伊木马 的变种
E:\VIRUS\cpack\r2o.exe - Win32/PSW.Maran.FF 特洛伊木马
E:\VIRUS\cpack\ro.exe - Win32/PSW.Maran 特洛伊木马 的变种
E:\VIRUS\cpack\rse.exe - Win32/PSW.OnLineGames.FCJ 特洛伊木马 的变种
E:\VIRUS\cpack\serial.exe - Win32/TrojanDownloader.Small.IAW 特洛伊木马
E:\VIRUS\cpack\test.exe - 可能是 Win32/Inject 特洛伊木马 的变种
aerbeisi
发表于 2008-4-1 22:54:35 | 显示全部楼层

8

[Found Trojan]         <W32/Trojan2.JDU (exact)>        C:\test\CPACK\test.exe
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\test\CPACK\myself.exe->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\test\CPACK\ogame.exe->(UPack)
[Found security risk]         <W32/Malware!d64c (exact)>        C:\test\CPACK\pageticket2000.exe
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\test\CPACK\r2o.exe->(UPack)
[Found possible security risk]         <W32/Heuristic-162!Eldorado (damaged, not disinfectable)>        C:\test\CPACK\ro.exe->(UPack)
[Found virus]         <W32/Downloader.gen10>        C:\test\CPACK\rse.exe
[Found password stealer]         <W32/Pws.ACJF (exact)>        C:\test\CPACK\sytem.exe->(UPX)
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 09:21 , Processed in 0.132194 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表