12
返回列表 发新帖
楼主: sam.to
收起左侧

[病毒样本] 毒??

[复制链接]
allinwonderi
发表于 2008-4-23 21:28:32 | 显示全部楼层

回复 4楼 qianwenxiang 的帖子

[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__3E3AA.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__43E70.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__49A87.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__4C3AF.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__65972.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__8AC29.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__8FEC5.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__9376D.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__9DF48.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__A212D.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__AA032.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__CCB5B.exe->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__D6485.exe->(UPack)
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__E6666.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\dd.rar->2008-4-23__EA638.exe->(UPack)

---------------------------------------------------------------------
Scan ended:        2008-4-23, 21:28:05
Duration:        0:00:27

Scan result:

Scanned files:                 6
Infected objects:         15
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------
曲中求
发表于 2008-4-23 22:06:08 | 显示全部楼层

回复 4楼 qianwenxiang 的帖子

NOD 32全灭

E:\病毒\dd.rar > RAR > 2008-4-23__ECE2C.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__17419.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__1887B.exe - Win32/PSW.OnLineGames.NOE 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__263C4.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__26709.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__2DA4D.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__3E3AA.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__43E70.exe - Win32/PSW.OnLineGames.YZT 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__49A87.exe - Win32/PSW.OnLineGames.YZT 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__4C3AF.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__65972.exe - Win32/PSW.OnLineGames.ZJK 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__798DE.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__8AC29.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__8FEC5.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__9376D.exe - Win32/PSW.OnLineGames.ZJK 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__9DF48.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__A212D.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__AA032.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__C9B3C.exe - Win32/PSW.OnLineGames.NML 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__CCB5B.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
E:\病毒\dd.rar > RAR > 2008-4-23__D6485.exe - Win32/PSW.OnLineGames.YZT 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__E6666.exe - Win32/PSW.WOW.WU 特洛伊木马
E:\病毒\dd.rar > RAR > 2008-4-23__EA638.exe - Win32/PSW.OnLineGames.MUG 特洛伊木马 的变种
sun88990
发表于 2008-4-23 22:09:19 | 显示全部楼层
McAfee:
PWS-OnlineGames.r
挪威的冬天
发表于 2008-4-23 22:23:38 | 显示全部楼层
信息        2008-04-23  22:21:17        您此次查毒清除了21个病毒                       
信息        2008-04-23  22:21:17        您此次查毒共查出21个病毒以及危险代码                       
信息        2008-04-23  22:21:17        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件34个                       
信息        2008-04-23  22:21:17        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__EA638.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__E6666.exe        Win32.Troj.LmirT.by.9900        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__D6485.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__CCB5B.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__C9B3C.exe        Win32.Troj.OnlineGameT.wi.106496        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__AA032.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__A212D.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__9DF48.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__8FEC5.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__8AC29.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__798DE.exe        Win32.Troj.OnlineGameT.wi.106496        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__65972.exe        Win32.Troj.OnlineGameT.ss.106496        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__4C3AF.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__49A87.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__43E70.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__3E3AA.exe        Win32.Hack.UpackT.a.15981        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__26709.exe        Win32.Troj.OnlineGameT.wi.106496        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__263C4.exe        Win32.Troj.OnlineGamesT.zy.32923        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__1887B.exe        Win32.Troj.OnLineGames.mx.77824        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__17419.exe        Win32.Troj.OnlineGamesT.zy.32923        清除成功       
病毒        2008-04-23  22:21:17        D:\Desktop\dd.rar\2008-4-23__ECE2C.exe        Win32.Troj.OnlineGameT.wi.106496        清除成功
mofunzone
发表于 2008-4-23 23:03:43 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\dd'
C:\Documents and Settings\Administrator\My Documents\dd\
  2008-4-23__17419.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abmx
              [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__1887B.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  2008-4-23__263C4.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abmx.12
              [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__26709.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  2008-4-23__2DA4D.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  2008-4-23__3E3AA.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: RSRC
          --> Object
          --> Object
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  2008-4-23__43E70.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.Online.ddn.2
              [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__49A87.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.Online.ddn.2
              [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__4C3AF.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aajr
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__65972.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.zjk
            [WARNING]   Infected files in archives cannot be repaired!
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
  2008-4-23__798DE.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  2008-4-23__8AC29.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aayo
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__8FEC5.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aayo
                [WARNING]   Infected files in archives cannot be repaired!
            --> Object
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  2008-4-23__9376D.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abis
            [WARNING]   Infected files in archives cannot be repaired!
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
  2008-4-23__9DF48.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aayo
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__A212D.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
              [4] Archive type: Runtime Packed
              --> Object
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
  2008-4-23__AA032.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aayo
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__C9B3C.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  2008-4-23__CCB5B.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aajr
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__D6485.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.Online.ddn.2
              [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__E6666.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
  2008-4-23__EA638.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [2] Archive type: Runtime Packed
          --> Object
            [3] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aayo
                [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  2008-4-23__ECE2C.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!


End of the scan: 2008年4月23日  08:03
Used time: 00:06 min

The scan has been done completely.

      1 Scanning directories
     23 Files were scanned
     26 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     23 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -3 Files not concerned
      0 Archives were scanned
     14 Warnings
     23 Notes
sam.to
 楼主| 发表于 2008-4-24 11:50:49 | 显示全部楼层
Hello.
New malicious software was found in the attached file.
Its detection will be included in the next update. Thank you for your help.
-----------------
Regards, Vladimir Lebedev
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com

已偵測: 特洛伊木馬程式 Trojan-PSW.Win32.OnLineGames.abuw        檔案: C:\Documents and Settings\kato9096\桌面\240680\複製 -dd\2008-4-23__A212D.exe2//PE_Patch//UPack
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-6 00:45 , Processed in 0.099383 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表