12
返回列表 发新帖
楼主: jimmyleo
收起左侧

[病毒样本] 40 pcs

[复制链接]
kkgh
发表于 2008-4-26 10:04:20 | 显示全部楼层
[扫描路径] C:\Documents and Settings\zh\桌面\b31ae0126d550a8143a61d93919e2fdf.dll
C:\Documents and Settings\zh\桌面\b31ae0126d550a8143a61d93919e2fdf.dll 已被病毒感染 :  Trojan.PWS.Gameff

[扫描路径] C:\Documents and Settings\zh\桌面\b919a9f3b2a18ef83a6dcaa4ac3afc09.exe
>C:\Documents and Settings\zh\桌面\b919a9f3b2a18ef83a6dcaa4ac3afc09.exe 已被病毒感染 :  Win32.HLLP.Tesekl.1

[扫描路径] C:\Documents and Settings\zh\桌面\c3301fd4e51de2f118c860e09ca63b40.dll
C:\Documents and Settings\zh\桌面\c3301fd4e51de2f118c860e09ca63b40.dll 已被病毒感染 :  Trojan.Hitpop

[扫描路径] C:\Documents and Settings\zh\桌面\cb403df183200ba6a265b120bf6162dc.exe
C:\Documents and Settings\zh\桌面\cb403df183200ba6a265b120bf6162dc.exe 已被病毒感染 :  BackDoor.Nunaks

[扫描路径] C:\Documents and Settings\zh\桌面\cc736a086631bea124fd445acf11bf49.exe
>C:\Documents and Settings\zh\桌面\cc736a086631bea124fd445acf11bf49.exe 已被病毒感染 :  Trojan.PWS.Gameff

[扫描路径] C:\Documents and Settings\zh\桌面\d4334c5ae7c99c9b388bf2cb4168515d.exe
>C:\Documents and Settings\zh\桌面\d4334c5ae7c99c9b388bf2cb4168515d.exe 已被病毒感染 :  Trojan.PWS.Gamania.origin

[扫描路径] C:\Documents and Settings\zh\桌面\e341297c244a88147c7d0a75085fa391.exe
C:\Documents and Settings\zh\桌面\e341297c244a88147c7d0a75085fa391.exe 已被病毒感染 :  Trojan.DownLoader.52438

[扫描路径] C:\Documents and Settings\zh\桌面\e41a556929c9874165c3b5f95b3cd1b0.exe
>C:\Documents and Settings\zh\桌面\e41a556929c9874165c3b5f95b3cd1b0.exe 已被病毒感染 :  Trojan.Hitpop

[扫描路径] C:\Documents and Settings\zh\桌面\e41a556929c9874165c3b5f95b3cd1b0.scr
>C:\Documents and Settings\zh\桌面\e41a556929c9874165c3b5f95b3cd1b0.scr 已被病毒感染 :  Trojan.Hitpop

[扫描路径] C:\Documents and Settings\zh\桌面\eca91cb10b82f3aa8439fb2a49add97b.exe
>C:\Documents and Settings\zh\桌面\eca91cb10b82f3aa8439fb2a49add97b.exe - 确定

[扫描路径] C:\Documents and Settings\zh\桌面\ede98e6840cf1f3c40ef10fc3aaac210.sys
C:\Documents and Settings\zh\桌面\ede98e6840cf1f3c40ef10fc3aaac210.sys 已被病毒感染 :  Trojan.NtRootKit.779

[扫描路径] C:\Documents and Settings\zh\桌面\f9da402f6af8379113e248288e3bce39.exe
>C:\Documents and Settings\zh\桌面\f9da402f6af8379113e248288e3bce39.exe\t1.exe 已被病毒感染 :  Trojan.Inject.796
>>C:\Documents and Settings\zh\桌面\f9da402f6af8379113e248288e3bce39.exe\f1.exe 已被病毒感染 :  Trojan.PWS.Gameff
C:\Documents and Settings\zh\桌面\f9da402f6af8379113e248288e3bce39.exe - 发现压缩文件中有被感染的对象

[扫描路径] C:\Documents and Settings\zh\桌面\fb0246250058bea8023b293a47dcd93f.exe
>C:\Documents and Settings\zh\桌面\fb0246250058bea8023b293a47dcd93f.exe 已被病毒感染 :  Trojan.PWS.Gamania.9315

[扫描路径] C:\Documents and Settings\zh\桌面\0730a6d7e4d99ed7cf87fd5cd995e5bd.exe
>C:\Documents and Settings\zh\桌面\0730a6d7e4d99ed7cf87fd5cd995e5bd.exe 可能已被感染了 :  DLOADER.Trojan

[扫描路径] C:\Documents and Settings\zh\桌面\09168f10abc1c6239b9d308dda6bf80f.exe
>C:\Documents and Settings\zh\桌面\09168f10abc1c6239b9d308dda6bf80f.exe 已被病毒感染 :  Trojan.PWS.Gamania.6556

[扫描路径] C:\Documents and Settings\zh\桌面\15e932aeb1a9e426b1389d23c9b0dda9.exe
C:\Documents and Settings\zh\桌面\15e932aeb1a9e426b1389d23c9b0dda9.exe 已被病毒感染 :  Trojan.Inject.796

[扫描路径] C:\Documents and Settings\zh\桌面\17a6424a777022289c6b86d784f58c4f.exe
C:\Documents and Settings\zh\桌面\17a6424a777022289c6b86d784f58c4f.exe 已被病毒感染 :  Trojan.PWS.Gamania.5748

[扫描路径] C:\Documents and Settings\zh\桌面\1b1f7ef245f9986ac03bc710116ca1cd.exe
C:\Documents and Settings\zh\桌面\1b1f7ef245f9986ac03bc710116ca1cd.exe 已被病毒感染 :  Trojan.PWS.Reggin

[扫描路径] C:\Documents and Settings\zh\桌面\1b4f171f83452c571f90b45a6858528a.exe
C:\Documents and Settings\zh\桌面\1b4f171f83452c571f90b45a6858528a.exe 已被病毒感染 :  BackDoor.BlackHole.2109

[扫描路径] C:\Documents and Settings\zh\桌面\2cbc944592b93ed4e537d998a97eaa0e.exe
C:\Documents and Settings\zh\桌面\2cbc944592b93ed4e537d998a97eaa0e.exe 已被病毒感染 :  Win32.HLLP.Lac

[扫描路径] C:\Documents and Settings\zh\桌面\3e69316e114faff3409ec84d8dc63f50.exe
>C:\Documents and Settings\zh\桌面\3e69316e114faff3409ec84d8dc63f50.exe 已被病毒感染 :  Trojan.PWS.Gamania.6556

[扫描路径] C:\Documents and Settings\zh\桌面\4078bed239e0661466c6a67706649c9b.Exe
>>C:\Documents and Settings\zh\桌面\4078bed239e0661466c6a67706649c9b.Exe 已被病毒感染 :  Trojan.PWS.Lineage.origin

[扫描路径] C:\Documents and Settings\zh\桌面\559e1b052ee01710c6fae9889f9e743c.exe
>C:\Documents and Settings\zh\桌面\559e1b052ee01710c6fae9889f9e743c.exe\t1.exe 已被病毒感染 :  Trojan.Inject.796
>>C:\Documents and Settings\zh\桌面\559e1b052ee01710c6fae9889f9e743c.exe\f1.exe 已被病毒感染 :  Trojan.PWS.Gameff
C:\Documents and Settings\zh\桌面\559e1b052ee01710c6fae9889f9e743c.exe - 发现压缩文件中有被感染的对象

[扫描路径] C:\Documents and Settings\zh\桌面\57f866d1c9d93ffc15f90bc6a35ccb6c.exe
>C:\Documents and Settings\zh\桌面\57f866d1c9d93ffc15f90bc6a35ccb6c.exe 已被病毒感染 :  Trojan.MulDrop.14554

[扫描路径] C:\Documents and Settings\zh\桌面\5ed4e0c635a9e611825e875f9794e416.dll
C:\Documents and Settings\zh\桌面\5ed4e0c635a9e611825e875f9794e416.dll 已被病毒感染 :  Trojan.PWS.Maran

[扫描路径] C:\Documents and Settings\zh\桌面\64ade001daf5d5a601b144e967741449.dll
C:\Documents and Settings\zh\桌面\64ade001daf5d5a601b144e967741449.dll 已被病毒感染 :  Trojan.PWS.Gamania.6403

[扫描路径] C:\Documents and Settings\zh\桌面\650b769c23f31cd65ace870e879d481f.exe
C:\Documents and Settings\zh\桌面\650b769c23f31cd65ace870e879d481f.exe - 确定

[扫描路径] C:\Documents and Settings\zh\桌面\669c8613a839d1ce5443e4cad3f92130.dll
C:\Documents and Settings\zh\桌面\669c8613a839d1ce5443e4cad3f92130.dll 已被病毒感染 :  Trojan.PWS.Gamania.origin

[扫描路径] C:\Documents and Settings\zh\桌面\693a12287c361eb2710cf7d201b597a7.sys
C:\Documents and Settings\zh\桌面\693a12287c361eb2710cf7d201b597a7.sys - 确定

[扫描路径] C:\Documents and Settings\zh\桌面\6ac01b79fad46ee82f584a5b0ac432f7.dll
C:\Documents and Settings\zh\桌面\6ac01b79fad46ee82f584a5b0ac432f7.dll 已被病毒感染 :  Trojan.PWS.Gamania.6004

[扫描路径] C:\Documents and Settings\zh\桌面\7fcac1d180df2683c17a67897e4a489a.com
>C:\Documents and Settings\zh\桌面\7fcac1d180df2683c17a67897e4a489a.com 已被病毒感染 :  Trojan.DownLoader.26576

[扫描路径] C:\Documents and Settings\zh\桌面\83e88bfd0641ba78453d6f8ff2898b9e.exe
>C:\Documents and Settings\zh\桌面\83e88bfd0641ba78453d6f8ff2898b9e.exe 已被病毒感染 :  Trojan.PWS.Gameff

[扫描路径] C:\Documents and Settings\zh\桌面\855b25b38fad20c13adf9a26378fa36e.exe
>C:\Documents and Settings\zh\桌面\855b25b38fad20c13adf9a26378fa36e.exe 已被病毒感染 :  Trojan.PWS.Maran

[扫描路径] C:\Documents and Settings\zh\桌面\8f6e844cb56e0cc8da5bcf43dacda129.exe
C:\Documents and Settings\zh\桌面\8f6e844cb56e0cc8da5bcf43dacda129.exe 已被病毒感染 :  Trojan.PWS.Reggin

[扫描路径] C:\Documents and Settings\zh\桌面\9300fe60a34b0d232857fd41dadb8c51.exe
C:\Documents and Settings\zh\桌面\9300fe60a34b0d232857fd41dadb8c51.exe - 确定

[扫描路径] C:\Documents and Settings\zh\桌面\96ee125038dc1f16b349b0a67f38b377.exe
C:\Documents and Settings\zh\桌面\96ee125038dc1f16b349b0a67f38b377.exe 已被病毒感染 :  Trojan.PWS.Reggin

[扫描路径] C:\Documents and Settings\zh\桌面\984fb2a5b2f11e584141cafe9c6caabe.dll
C:\Documents and Settings\zh\桌面\984fb2a5b2f11e584141cafe9c6caabe.dll 已被病毒感染 :  Trojan.Hitpop

[扫描路径] C:\Documents and Settings\zh\桌面\99fa3c27158a8584d16bc93005c144ac.exe
C:\Documents and Settings\zh\桌面\99fa3c27158a8584d16bc93005c144ac.exe 已被病毒感染 :  Trojan.Packed.431

[扫描路径] C:\Documents and Settings\zh\桌面\a4c8da2814d43b87d9b27fb42095970c.exe
C:\Documents and Settings\zh\桌面\a4c8da2814d43b87d9b27fb42095970c.exe 已被病毒感染 :  Trojan.Inject.796

[扫描路径] C:\Documents and Settings\zh\桌面\ade256218faad15e65034d529d1c5571.exe
>C:\Documents and Settings\zh\桌面\ade256218faad15e65034d529d1c5571.exe 已被病毒感染 :  Trojan.MulDrop.14980

-----------------------------------------------------------------------------
扫描统计
-----------------------------------------------------------------------------
已扫描对象: 44
发现受感染对象: 37
发现受变种感染对象: 0
发现可疑对象: 1

瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: RootKit.Win32.Dreamsocks.a
病毒: Packer.Win32.Upack.a     
病毒: Trojan.PSW.Win32.GameOL.mtb
病毒: Trojan.DL.Win32.Delf.yzs
病毒: Trojan.PSW.Win32.GameOL.mtb
病毒: Trojan.Win32.Undef.eho   
病毒: Trojan.Win32.Agent.zzs   
病毒: Trojan.PSW.Win32.Agent.vqp
病毒: Trojan.Clicker.Win32.PopHot.fx
病毒: Dropper.OnlineGames.bd   
病毒: Trojan.DL.Win32.Small.tsm
病毒: RootKit.Win32.Mnless.kq  
病毒: Worm.Mail.Win32.Zhelatin.wsx
病毒: Trojan.Win32.Undef.ada   
病毒: Trojan.PSW.Win32.Agent.vho
病毒: Trojan.Win32.Edog.af     
病毒: Trojan.PSW.Ran.a         
病毒: Trojan.DL.Win32.Banload.txc
病毒: Trojan.PSW.Win32.GameOnline.asp
病毒: Trojan.PSW.RoOnline.a   
病毒: Trojan.PSW.WoWar.GEN     
病毒: Backdoor.Win32.BlackHole.az
病毒: Trojan.Win32.Undef.blq   

用户来源:互联网

软件版本:20.41.42

32个
shtjw
发表于 2008-4-26 15:41:58 | 显示全部楼层
装了3个免费的家伙:avast! 、AVG和Avira AntiVir
两包合并后共40个文件,单独扫分别是34、34和36。共有2个文件都不报,提取后上传扫。

VirSCAN.org Scanned Report :
Scanned time   : 2008/04/26 15:29:35 (CST)
Scanner results: 25%的杀软(9/36)报告发现病毒
File Name      : 3 Engines.rar
File Size      : 37862 byte
File Type      : RAR archive data, v1d, os
MD5            : 5dffcdf4af679bae47389f317695a106
SHA1           : 7ff5041f9308a14e3b495d40865fb2e5fba4b5fc
Online report  : http://virscan.org/report/30d6ccfd5b2be2549484a936b4f663f8.html
Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      3.5.0.16        2008.04.24        2008-04-24  5.06   -
安博士V3       2008.04.26.00   2008.04.26        2008-04-26  2.46   -
AntiVir        7.8.0.10        7.0.3.216         2008-04-25  16.82  -
Arcavir        1.0.4           200804251911      2008-04-25  12.10  -
AVAST          1.0.8           080425-1          2008-04-25  19.04  -
AVG            7.5.51.442      269.23.5/1398     2008-04-25  13.53  -
BitDefender    7.60825.1183769 7.18662           2008-04-26  22.12  -
CA (VET)       9.0.0.143       31.3.5736         2008-04-26  12.48  Win32/Lorofring!generic trojan.
ClamAV         0.93            6863              2008-04-21  0.08   -
Comodo         2.11            2.0.0.507         2008-04-26  1.50   -
CP Secure      1.1.0.715       2008.04.26        2008-04-26  32.15  -
Dr.WEB         4.44.0.9170     2008.04.26        2008-04-26  28.80  Trojan.PWS.Gamania.origin
ewido          4.0.0.2         2008.04.25        2008-04-25  3.95   -
F-PROT         4.4.1.52        20080425          2008-04-25  9.75   Possible W32/Heuristic-166!Eldorado (not disinfectable)
F-SECURE       5.51.6100       2008.04.26.01     2008-04-26  28.77  Trojan-PSW.Win32.Nilage.cil [AVP]
飞塔           2.81-3.11       9.16              2008-04-26  6.70   -
ViRobot        20080425        2008.04.25        2008-04-25  3.62   -
IKARUS         T3.1.01.26      2008.04.26.70659  2008-04-26  16.24  -
江民杀毒       10.00.650       2008.04.26        2008-04-26  3.30   -
卡巴斯基       5.5.10          2008.04.26        2008-04-26  50.61  -
金山毒霸       2007.6.20.249   2008.4.26         2008-04-26  2.94   Win32.Troj.OnlineGeames.ab.114688
迈克菲         5.2.00          5282              2008-04-25  13.69  PWS-OnlineGames.e
Microsoft      1.3408          2008.04.24        2008-04-24  8.66   PWS:Win32/Lineage.WI.dr
MKS_VIR        2.01            2008.04.25        2008-04-25  16.96  -
NORMAN         5.91.10         5.90              2008-04-22  43.48  -
熊猫卫士       9.04.03.0001    2008.04.25        2008-04-25  6.97   Suspicious file
趋势           8.500-1001      5.240.22          2008-04-25  0.06   -
Prevx          V2              20080426          2008-04-26  7.14   -
QuickHeal      9.00            2008.04.26        2008-04-26  3.83   -
瑞星           20.0            20.41.50.00       2008-04-26  3.04   -
SOPHOS         2.72.0          4.28              2008-04-26  29.99  Troj/Cabat-Gen
赛门铁克       1.3.0.24        20080425.002      2008-04-25  0.44   -
nProtect       2008-04-26.00   1435444           2008-04-26  14.81  -
The Hacker     6.2.92          v00293            2008-04-25  2.28   -
VBA32          3.12.6.5        20080425.2354     2008-04-25  11.09  -
VirusBuster    4.3.19:9        9.126.4/11.0      2008-04-25  7.35   -

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
无尽藏海
发表于 2008-4-26 16:18:59 | 显示全部楼层

ik

26:04:2008 16:18:20 SEARCHTASK "USER_DEFINED" started...
scan item: E:\VIRUS\Unknown
Directory scanned(filestreams): E:\VIRUS\Unknown
File scanned: E:\VIRUS\Unknown\0730a6d7e4d99ed7cf87fd5cd995e5bd.exe - SIGNATURE FOUND "Trojan-Clicker.Win32.Small.BG"
File scanned: E:\VIRUS\Unknown\09168f10abc1c6239b9d308dda6bf80f.exe - SIGNATURE FOUND "Trojan-PWS.Win32.OnLineGames.lyx"
File scanned: E:\VIRUS\Unknown\15e932aeb1a9e426b1389d23c9b0dda9.exe - SIGNATURE FOUND "Trojan.Inject.GB"
File scanned: E:\VIRUS\Unknown\17a6424a777022289c6b86d784f58c4f.exe - SIGNATURE FOUND "Trojan-PWS.Win32.Maran.ff"
File scanned: E:\VIRUS\Unknown\1b1f7ef245f9986ac03bc710116ca1cd.exe
File scanned: E:\VIRUS\Unknown\1b4f171f83452c571f90b45a6858528a.exe - SIGNATURE FOUND "Virus.Win32.NSAnti.ABB"
File scanned: E:\VIRUS\Unknown\2cbc944592b93ed4e537d998a97eaa0e.exe - SIGNATURE FOUND "Trojan-PWS.Win32.Gamec.aa"
File scanned: E:\VIRUS\Unknown\3e69316e114faff3409ec84d8dc63f50.exe - SIGNATURE FOUND "Trojan-PWS.Win32.OnLineGames.lyx"
File scanned: E:\VIRUS\Unknown\4078bed239e0661466c6a67706649c9b.Exe - SIGNATURE FOUND "Trojan-Downloader.6165"
File scanned: E:\VIRUS\Unknown\559e1b052ee01710c6fae9889f9e743c.exe - SIGNATURE FOUND "Backdoor.Win32.Hupigon.eez"
File scanned: E:\VIRUS\Unknown\57f866d1c9d93ffc15f90bc6a35ccb6c.exe - SIGNATURE FOUND "Virus.Worm.Win32.Downloader.ik"
File scanned: E:\VIRUS\Unknown\5ed4e0c635a9e611825e875f9794e416.dll - SIGNATURE FOUND "Generic.PWS.Maran"
File scanned: E:\VIRUS\Unknown\64ade001daf5d5a601b144e967741449.dll - SIGNATURE FOUND "Trojan-Spy.Win32.Agent.ash"
File scanned: E:\VIRUS\Unknown\650b769c23f31cd65ace870e879d481f.exe - SIGNATURE FOUND "Trojan.Win32.Inject.hh"
File scanned: E:\VIRUS\Unknown\669c8613a839d1ce5443e4cad3f92130.dll
File scanned: E:\VIRUS\Unknown\693a12287c361eb2710cf7d201b597a7.sys - SIGNATURE FOUND "Trojan-PWS.Win32.OnLineGames.wkt"
File scanned: E:\VIRUS\Unknown\6ac01b79fad46ee82f584a5b0ac432f7.dll - SIGNATURE FOUND "Trojan-PWS.Win32.Lmir.bpb"
File scanned: E:\VIRUS\Unknown\7fcac1d180df2683c17a67897e4a489a.com - SIGNATURE FOUND "Trojan-Downloader.Win32.Banload.kl"
File scanned: E:\VIRUS\Unknown\83e88bfd0641ba78453d6f8ff2898b9e.exe - SIGNATURE FOUND "Trojan-Downloader.Win32.Zlob.and"
File scanned: E:\VIRUS\Unknown\855b25b38fad20c13adf9a26378fa36e.exe - SIGNATURE FOUND "Trojan-Spy.Win32.Agent.hz"
File scanned: E:\VIRUS\Unknown\8f6e844cb56e0cc8da5bcf43dacda129.exe - SIGNATURE FOUND "Trojan.Win32.Inject.qk"
File scanned: E:\VIRUS\Unknown\9300fe60a34b0d232857fd41dadb8c51.exe
File scanned: E:\VIRUS\Unknown\96ee125038dc1f16b349b0a67f38b377.exe - SIGNATURE FOUND "Trojan-PWS.Win32.Magania.bre"
File scanned: E:\VIRUS\Unknown\984fb2a5b2f11e584141cafe9c6caabe.dll - SIGNATURE FOUND "Trojan.Hitpop.J"
File scanned: E:\VIRUS\Unknown\99fa3c27158a8584d16bc93005c144ac.exe - SIGNATURE FOUND "Email-Worm.Win32.Zhelatin.xv"
File scanned: E:\VIRUS\Unknown\a4c8da2814d43b87d9b27fb42095970c.exe - SIGNATURE FOUND "Trojan.Inject.GB"
File scanned: E:\VIRUS\Unknown\ade256218faad15e65034d529d1c5571.exe - SIGNATURE FOUND "Virus.Win32.Downloader.AOV"
File scanned: E:\VIRUS\Unknown\b31ae0126d550a8143a61d93919e2fdf.dll - SIGNATURE FOUND "Trojan-PWS.Win32.OnLineGames.wna"
File scanned: E:\VIRUS\Unknown\b919a9f3b2a18ef83a6dcaa4ac3afc09.exe - SIGNATURE FOUND "BehavesLikeWin32.ExplorerHijack"
File scanned: E:\VIRUS\Unknown\c3301fd4e51de2f118c860e09ca63b40.dll - SIGNATURE FOUND "Trojan-Spy.Win32.Agent.pn"
File scanned: E:\VIRUS\Unknown\cb403df183200ba6a265b120bf6162dc.exe - SIGNATURE FOUND "Trojan-Downloader.Agent.ZBU"
File scanned: E:\VIRUS\Unknown\cc736a086631bea124fd445acf11bf49.exe - SIGNATURE FOUND "Trojan-Downloader.Win32.Zlob.and"
File scanned: E:\VIRUS\Unknown\d4334c5ae7c99c9b388bf2cb4168515d.exe
File scanned: E:\VIRUS\Unknown\e341297c244a88147c7d0a75085fa391.exe - SIGNATURE FOUND "Trojan-Downloader.52438"
File scanned: E:\VIRUS\Unknown\e41a556929c9874165c3b5f95b3cd1b0.exe - SIGNATURE FOUND "Trojan-PWS.Win32.Agent.AN"
File scanned: E:\VIRUS\Unknown\e41a556929c9874165c3b5f95b3cd1b0.scr - SIGNATURE FOUND "Trojan-PWS.Win32.Agent.AN"
File scanned: E:\VIRUS\Unknown\eca91cb10b82f3aa8439fb2a49add97b.exe - SIGNATURE FOUND "Trojan-Downloader.Agent.YFZ"
File scanned: E:\VIRUS\Unknown\ede98e6840cf1f3c40ef10fc3aaac210.sys - SIGNATURE FOUND "Trojan-Downloader.Win32.Agent.dbt"
File scanned: E:\VIRUS\Unknown\f9da402f6af8379113e248288e3bce39.exe - SIGNATURE FOUND "Backdoor.Win32.Hupigon.eez"
File scanned: E:\VIRUS\Unknown\fb0246250058bea8023b293a47dcd93f.exe - SIGNATURE FOUND "Trojan-Downloader.Win32.Delf.TU"
26:04:2008 16:18:21 SEARCHTASK "USER_DEFINED" FINISHED...
----------------------------------------------------
Directories scanned: 1
Files scanned: 40
Virus found: 36
----------------------------------------------------
sun88990
发表于 2008-4-26 16:30:50 | 显示全部楼层
McAfee只抓到32之威脅
Palkia
发表于 2008-4-26 18:23:49 | 显示全部楼层

42

C:\Documents and Settings\Administrator\桌面\Unknown\0730a6d7e4d99ed7cf87fd5cd995e5bd.exe        TrojanDownloader.Small.uhd.oobu        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\09168f10abc1c6239b9d308dda6bf80f.exe        TrojanPSW.OnLineGames.lyx.yjgk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\15e932aeb1a9e426b1389d23c9b0dda9.exe        Trojan.Undef.eho.vgpq        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\17a6424a777022289c6b86d784f58c4f.exe        TrojanPSW.Maran.ff.edgu        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\1b1f7ef245f9986ac03bc710116ca1cd.exe        Trojan.Undef.blq.lrkn        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\1b4f171f83452c571f90b45a6858528a.exe        Backdoor.BlackHole.az.csee        后门        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\2cbc944592b93ed4e537d998a97eaa0e.exe        TrojanPSW.Delf.aih.ljjj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\3e69316e114faff3409ec84d8dc63f50.exe        TrojanPSW.Agent.vqp.olfx        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\4078bed239e0661466c6a67706649c9b.Exe        Trojan.Delphi.Gen.puwo        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\559e1b052ee01710c6fae9889f9e743c.exe>>emb-0.cab>>f1.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\559e1b052ee01710c6fae9889f9e743c.exe>>emb-0.cab>>t1.exe        Trojan.Inject.amb.ibro        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\57f866d1c9d93ffc15f90bc6a35ccb6c.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\5ed4e0c635a9e611825e875f9794e416.dll        TrojanPSW.Maran.ff.klcg.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\64ade001daf5d5a601b144e967741449.dll        TrojanSpy.Agent.ash.yqhs.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\650b769c23f31cd65ace870e879d481f.exe        Trojan.Inject.hh.pxki        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\669c8613a839d1ce5443e4cad3f92130.dll        PWSteal.OnlineGames.e.ykki.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\693a12287c361eb2710cf7d201b597a7.sys        TrojanPSW.OnLineGames.wkt.dkqs        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\6ac01b79fad46ee82f584a5b0ac432f7.dll        PWSteal.Lemir.bpb.ptjw.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\7fcac1d180df2683c17a67897e4a489a.com        TrojanDownloader.Banload.hdl.lhkc        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\83e88bfd0641ba78453d6f8ff2898b9e.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\855b25b38fad20c13adf9a26378fa36e.exe        W32.Viking.k        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\8f6e844cb56e0cc8da5bcf43dacda129.exe        Trojan.Inject.qk.vetc        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\9300fe60a34b0d232857fd41dadb8c51.exe        Trojan.Agent.zzs.kvxj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\96ee125038dc1f16b349b0a67f38b377.exe        TrojanPSW.Magania.bre.sxdp        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\984fb2a5b2f11e584141cafe9c6caabe.dll        TrojanSpy.Pophot.zr.ogxm.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\99fa3c27158a8584d16bc93005c144ac.exe        W32.Zhelatin.xv.bstm        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\a4c8da2814d43b87d9b27fb42095970c.exe        Trojan.Inject.ajw.gvxn        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\ade256218faad15e65034d529d1c5571.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\b31ae0126d550a8143a61d93919e2fdf.dll        TrojanPSW.OnLineGames.wna.elpo.dll        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\b919a9f3b2a18ef83a6dcaa4ac3afc09.exe        TrojanDownloader.Delf.ggz.gtbz        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\c3301fd4e51de2f118c860e09ca63b40.dll        W32.Hitapop.hlow.dll        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\cb403df183200ba6a265b120bf6162dc.exe        TrojanDownloader.Agent.mng.noxv        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\cc736a086631bea124fd445acf11bf49.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\d4334c5ae7c99c9b388bf2cb4168515d.exe        PWSteal.OnlineGames.e.dr.btjr        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\e341297c244a88147c7d0a75085fa391.exe        TrojanDownloader.Tiny.vg.dqse        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\e41a556929c9874165c3b5f95b3cd1b0.exe        TrojanSpy.Pophot.cu.tkyq        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\e41a556929c9874165c3b5f95b3cd1b0.scr        TrojanSpy.Pophot.cu.tkyq        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\eca91cb10b82f3aa8439fb2a49add97b.exe        Backdoor.Agent.fzy.wyxa        后门        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\ede98e6840cf1f3c40ef10fc3aaac210.sys        TrojanDownloader.Agent.dbt.nuda        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\f9da402f6af8379113e248288e3bce39.exe>>emb-0.cab>>f1.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\f9da402f6af8379113e248288e3bce39.exe>>emb-0.cab>>t1.exe        Trojan.Inject.alz.pomj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\Unknown\fb0246250058bea8023b293a47dcd93f.exe        TrojanPSW.OnLineGames.zkj.kckt        木马        还未处理
wangjay1980
发表于 2008-4-26 19:20:17 | 显示全部楼层
Hello,

15e932aeb1a9e426b1389d23c9b0dda9.exe_ - Trojan.Win32.Inject.bdm,
1b1f7ef245f9986ac03bc710116ca1cd.exe_ - Trojan.Win32.Inject.bdl,
208.exe_ - Trojan-Dropper.Win32.Small.blf,
211.exe_ - Trojan-Dropper.Win32.Small.blg,
4078bed239e0661466c6a67706649c9b.exe_ - Trojan-PSW.Win32.Delf.bij,
d4334c5ae7c99c9b388bf2cb4168515d.exe_ - Trojan-PSW.Win32.Nilage.cim,
Launcher.206.exe_ - Trojan.Win32.Agent.kve,
zloi.exe_ - Trojan-Dropper.Win32.Small.blh

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

669c8613a839d1ce5443e4cad3f92130.dll - Trojan-PSW.Win32.Nilage.cil,
9300fe60a34b0d232857fd41dadb8c51.exe_ - Trojan.Win32.Inject.bdj

These files are already detected. Please update your antivirus bases.

Please quote all when answering.

--
Best regards, Evgeny Aseev
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

> Attachment: Unknown.zip
allinwonderi
发表于 2008-4-26 20:27:50 | 显示全部楼层

回复 6楼 挪威的冬天 的帖子

那个是Win32版的命令行,虽然写着DX MS好多杀软都开始摒弃DOS的命令行了
allinwonderi
发表于 2008-4-26 20:28:14 | 显示全部楼层
[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:fb0246250058bea8023b293a47dcd93f.exe<UPX>:fb0246250058bea8023b293a47dcd93f.exe<DLLRES>:DLL10.exe <- Trojan.Psw.Onlinegames.Zjw : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:f9da402f6af8379113e248288e3bce39.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe <- Variant:Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:f9da402f6af8379113e248288e3bce39.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Wna : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:f9da402f6af8379113e248288e3bce39.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:ede98e6840cf1f3c40ef10fc3aaac210.sys <- Downloader.Agent.Dbt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:eca91cb10b82f3aa8439fb2a49add97b.exe <- Trojan.Agent.Fzy : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:e341297c244a88147c7d0a75085fa391.exe <- Downloader.Tiny.Apg : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:e41a556929c9874165c3b5f95b3cd1b0.scr <- Trojan.Spy.Pophot.zp : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:e41a556929c9874165c3b5f95b3cd1b0.exe <- Trojan.Spy.Pophot.zp : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:cc736a086631bea124fd445acf11bf49.exe<UPack>:cc736a086631bea124fd445acf11bf49.exe <- Variant:Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:cc736a086631bea124fd445acf11bf49.exe<UPack>:cc736a086631bea124fd445acf11bf49.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Wna : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:cc736a086631bea124fd445acf11bf49.exe<UPack>:cc736a086631bea124fd445acf11bf49.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:cb403df183200ba6a265b120bf6162dc.exe <- Downloader.Agent.Mng : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:b919a9f3b2a18ef83a6dcaa4ac3afc09.exe<UPX>:b919a9f3b2a18ef83a6dcaa4ac3afc09.exe <- W32.Dr.Agent.Bsv : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:b31ae0126d550a8143a61d93919e2fdf.dll <- Trojan.Psw.Onlinegames.Wna : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:ade256218faad15e65034d529d1c5571.exe<UPack>:ade256218faad15e65034d529d1c5571.exe <- Variant:Trojan.Agent.Fb : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:9300fe60a34b0d232857fd41dadb8c51.exe <- Trojan.Inject.Hh : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:09168f10abc1c6239b9d308dda6bf80f.exe<UPack>:09168f10abc1c6239b9d308dda6bf80f.exe <- Trojan.Psw.Onlinegames.Fcj : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:09168f10abc1c6239b9d308dda6bf80f.exe<UPack>:09168f10abc1c6239b9d308dda6bf80f.exe<DLLRES>:MM0.exe <- Trojan.Psw.Onlinegames.Fcj : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:855b25b38fad20c13adf9a26378fa36e.exe<UPack>:855b25b38fad20c13adf9a26378fa36e.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:855b25b38fad20c13adf9a26378fa36e.exe<UPack>:855b25b38fad20c13adf9a26378fa36e.exe<DLLRES>:IPFILTER0.exe <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:855b25b38fad20c13adf9a26378fa36e.exe<UPack>:855b25b38fad20c13adf9a26378fa36e.exe<DLLRES>:WINXPNP1.exe <- Trojan.Psw.Maran.Dy : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:0730a6d7e4d99ed7cf87fd5cd995e5bd.exe<PECompact2>:0730a6d7e4d99ed7cf87fd5cd995e5bd.exe <- Downloader.Small.Uhd : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:693a12287c361eb2710cf7d201b597a7.sys <- Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:650b769c23f31cd65ace870e879d481f.exe <- Trojan.Inject.Hh : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:559e1b052ee01710c6fae9889f9e743c.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe <- Variant:Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:559e1b052ee01710c6fae9889f9e743c.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Wna : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:559e1b052ee01710c6fae9889f9e743c.exe<DLLRES>:CABINET0.cab<CAB>:f1.exe<UPack>:f1.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:96ee125038dc1f16b349b0a67f38b377.exe <- Trojan.Psw.Magania.Bre : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:83e88bfd0641ba78453d6f8ff2898b9e.exe<UPack>:83e88bfd0641ba78453d6f8ff2898b9e.exe <- Variant:Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:83e88bfd0641ba78453d6f8ff2898b9e.exe<UPack>:83e88bfd0641ba78453d6f8ff2898b9e.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Wna : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:83e88bfd0641ba78453d6f8ff2898b9e.exe<UPack>:83e88bfd0641ba78453d6f8ff2898b9e.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Wkt : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:64ade001daf5d5a601b144e967741449.dll <- Trojan.Psw.Onlinegames.Fcj : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:57f866d1c9d93ffc15f90bc6a35ccb6c.exe<UPack>:57f866d1c9d93ffc15f90bc6a35ccb6c.exe <- Variant:Trojan.Agent.Fb : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part1.rar<RAR>:17a6424a777022289c6b86d784f58c4f.exe <- Trojan.Psw.Maran.Dy : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:7fcac1d180df2683c17a67897e4a489a.com<YODA>:7fcac1d180df2683c17a67897e4a489a.com <- Downloader.Banload.Hdl : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:6ac01b79fad46ee82f584a5b0ac432f7.dll <- Trojan.Psw.Lmir.Bpb : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:5ed4e0c635a9e611825e875f9794e416.dll <- Trojan.Psw.Maran.Ff : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:3e69316e114faff3409ec84d8dc63f50.exe<UPack>:3e69316e114faff3409ec84d8dc63f50.exe <- Trojan.Psw.Onlinegames.Fcj : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:3e69316e114faff3409ec84d8dc63f50.exe<UPack>:3e69316e114faff3409ec84d8dc63f50.exe<DLLRES>:MM0.exe <- Trojan.Psw.Onlinegames.Fcj : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:2cbc944592b93ed4e537d998a97eaa0e.exe<UPX>:2cbc944592b93ed4e537d998a97eaa0e.exe<DLLRES>:MM0.exe <- Trojan.Psw.Lmir.Bpb : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:1b4f171f83452c571f90b45a6858528a.exe <- Trojan.Psw.Onlinegames.Byl : No action
C:\Documents and Settings\All Users\Documents\Test\Unknown.part2.rar<RAR>:1b1f7ef245f9986ac03bc710116ca1cd.exe <- Trojan.Inject.Qk : No action



Scanned objects : 78

Infected objects : 43
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 12:35 , Processed in 0.096856 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表