12
返回列表 发新帖
楼主: qianwenxiang
收起左侧

[病毒样本] 27

[复制链接]
醉一生爱妍
发表于 2008-4-4 22:16:19 | 显示全部楼层
质量不好哟
ALEXBLAIR
发表于 2008-4-4 22:21:28 | 显示全部楼层
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yvy        File: \2008-4-4__10999.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.zaw        File: \2008-4-4__12461.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.ymm        File: \2008-4-4__149D9.exe//UPack//PE_Patch
deleted: Trojan program Trojan-Dropper.Win32.Agent.kji        File: \2008-4-4__1E2CD.exe//UPX
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.ylx        File: \2008-4-4__21563.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yuu        File: \2008-4-4__315DD.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.vlp        File: \2008-4-4__333B8.exe//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yvw        File: \2008-4-4__3C4D3.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yvk        File: \2008-4-4__4BFFD.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.ypf        File: \2008-4-4__63C69.exe//UPack//PE_Patch
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.ywa        File: \2008-4-4__680CC.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yuu        File: \2008-4-4__6CDD.exe//PE_Patch//UPack
deleted: Trojan program Backdoor.Win32.Popwin.awj        File: \2008-4-4__7628.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yvi        File: \2008-4-4__78238.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yzs        File: \2008-4-4__8AF23.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yip        File: \2008-4-4__8F28A.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yuy        File: \2008-4-4__9B6EB.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yip        File: \2008-4-4__BD07E.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.zaw        File: \2008-4-4__D313E.exe//PE_Patch//UPack
deleted: Trojan program Trojan.Win32.Agent.hko        File: \2008-4-4__D33C2.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.zaw        File: \2008-4-4__E9A60.exe//PE_Patch//UPack
deleted: Trojan program Trojan-PSW.Win32.OnLineGames.yux        File: \2008-4-4__F07D.exe//PE_Patch//UPack
tanlimo
发表于 2008-4-4 23:06:41 | 显示全部楼层
ess扫描日志
病毒库版本: 3003 (20080404)
日期: 2008-4-4  时间: 23:09:42
已扫描的磁盘、文件夹和文件: G:\multi.rar
G:\multi.rar > RAR > 2008-4-4__6CDD.exe - 可能是 Win32/PSW.OnLineGames.NMQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__7628.exe - Win32/TrojanDownloader.Flux 特洛伊木马
G:\multi.rar > RAR > 2008-4-4__78238.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__8AF23.exe - Win32/PSW.OnLineGames.NMQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__8F28A.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__994F.exe - 可能是 Win32/PSW.OnLineGames.NMQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__9B6EB.exe - 可能是 Win32/PSW.OnLineGames.NMQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__A64C3.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__B4E0.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__BD07E.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__D313E.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__D33C2.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__E9A60.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__F07D.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 080329.exe - Win32/Spy.Delf.NHF 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__10999.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__12461.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__149D9.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__1E2CD.exe - Win32/PSW.Legendmir.NFR 特洛伊木马
G:\multi.rar > RAR > 2008-4-4__21563.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__315DD.exe - 可能是 Win32/PSW.OnLineGames.NMQ 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__333B8.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__3C4D3.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__4BFFD.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__5F123.exe - Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__63C69.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
G:\multi.rar > RAR > 2008-4-4__680CC.exe - 可能是 Win32/PSW.OnLineGames.NFL 特洛伊木马 的变种
已扫描的对象数: 27
发现的威胁数: 27
完成时间: 23:10:25  总扫描时间: 43 秒 (00:00:43)
sam.to
发表于 2008-4-4 23:20:04 | 显示全部楼层
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yuu        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__6CDD.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Backdoor.Win32.Popwin.awj        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__7628.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yvi        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__78238.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yzs        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__8AF23.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yip        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__8F28A.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yuy        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__9B6EB.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yxn        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__A64C3.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yxl        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__B4E0.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yip        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__BD07E.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.zaw        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__D313E.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan.Win32.Agent.hko        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__D33C2.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.zaw        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__E9A60.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yux        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__F07D.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yvy        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__10999.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.zaw        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__12461.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ymm        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__149D9.exe//UPack//PE_Patch
已刪除: 特洛伊木馬程式 Trojan-Dropper.Win32.Agent.kji        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__1E2CD.exe//UPX
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ylx        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__21563.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yuu        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__315DD.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.vlp        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__333B8.exe//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yvw        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__3C4D3.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.yvk        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__4BFFD.exe//PE_Patch//UPack
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ypf        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__63C69.exe//UPack//PE_Patch
已刪除: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.ywa        檔案: C:\Documents and Settings\kato9096\桌面\229097.rar/2008-4-4__680CC.exe//PE_Patch//UPack


24,上报卡巴
ALEXBLAIR
发表于 2008-4-4 23:29:27 | 显示全部楼层

回复 14楼 kato9096 的帖子


Hello,

080329.exe_ - Trojan-Spy.Win32.Pophot.ana,

2008-4-4__5F123.exe_ - Trojan-PSW.Win32.OnLineGames.zev,

2008-4-4__994F.exe_ - Trojan-PSW.Win32.OnLineGames.zez

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

2008-4-4__A64C3.exe_ - Trojan-PSW.Win32.OnLineGames.yxn,

2008-4-4__B4E0.exe_ - Trojan-PSW.Win32.OnLineGames.yxl

These files are already detected. Please update your antivirus bases.

Please quote all when answering.

--
Best regards, Dmitry Shvetsov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
haol
发表于 2008-4-4 23:40:36 | 显示全部楼层
f-secure found 24 threats
wangjay1980
发表于 2008-4-4 23:43:00 | 显示全部楼层
原帖由 ALEXBLAIR 于 2008-4-4 23:29 发表

Hello,

080329.exe_ - Trojan-Spy.Win32.Pophot.ana,

2008-4-4__5F123.exe_ - Trojan-PSW.Win32.OnLineGames.zev,

2008-4-4__994F.exe_ - Trojan-PSW.Win32.OnLineGames.zez

New malicious sof ...


哈哈,太猥亵了
sam.to
发表于 2008-4-4 23:49:37 | 显示全部楼层
Hello,

080329.exe_ - Trojan-Spy.Win32.Pophot.ana,

2008-4-4__5F123.exe_ - Trojan-PSW.Win32.OnLineGames.zev,

2008-4-4__994F.exe_ - Trojan-PSW.Win32.OnLineGames.zez

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Dmitry Shvetsov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
woai_jolin
发表于 2008-4-5 02:25:34 | 显示全部楼层
Scan Log
Version of virus signature database: 3003 (20080404)
Date: 2008/4/5  Time: 2:25:21
Scanned disks, folders and files: G:\v\multi.rar
G:\v\multi.rar » RAR » 2008-4-4__6CDD.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__7628.exe - Win32/TrojanDownloader.Flux trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__78238.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__8AF23.exe - a variant of Win32/PSW.OnLineGames.NMQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__8F28A.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__994F.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__9B6EB.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__A64C3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__B4E0.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__BD07E.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__D313E.exe - a variant of Win32/PSW.OnLineGames.NML trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__D33C2.exe - a variant of Win32/PSW.OnLineGames.NML trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__E9A60.exe - a variant of Win32/PSW.OnLineGames.NML trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__F07D.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 080329.exe - a variant of Win32/Spy.Delf.NHF trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__10999.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__12461.exe - a variant of Win32/PSW.OnLineGames.NML trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__149D9.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__1E2CD.exe - Win32/PSW.Legendmir.NFR trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__21563.exe - a variant of Win32/PSW.OnLineGames.NML trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__315DD.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__333B8.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__3C4D3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__4BFFD.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__5F123.exe - a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__63C69.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
G:\v\multi.rar » RAR » 2008-4-4__680CC.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - was a part of the deleted object
Number of scanned objects: 28
Number of threats found: 27
Number of cleaned objects: 27
Time of completion: 2:25:32  Total scanning time: 11 sec (00:00:11)
马力
发表于 2008-4-5 10:45:33 | 显示全部楼层
驱逐舰10个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-4 10:12 , Processed in 0.097596 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表