查看: 3209|回复: 14
收起左侧

[病毒样本] 某帖一包(更新到三包)

[复制链接]
醉一生爱妍
发表于 2008-4-27 11:16:58 | 显示全部楼层 |阅读模式
http://bbs.kafan.cn/viewthread.php?tid=242000&extra=page%3D1

Hello.
Trojan.Win32.Delf.buk
New malicious software was found in the attached file.
It's detection will be included in the next update. Thank you for your help.
-----------------
Regards, Yury Nesmachny
Virus Analyst, Kaspersky Lab.

Ph.: +7(495) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com


> Attachment: virus1.rar


[ 本帖最后由 garyyan456 于 2008-4-27 12:06 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
红心王子
发表于 2008-4-27 11:19:41 | 显示全部楼层
时间        处理结果        木马名称        木马进程名        木马文件创建者
2008-04-27 11:18:55        处理成功        Trojan.Win32.StartPage.aez        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A25.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:55        处理成功        Trojan-PSW.Win32.OLGames.ibf        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A22.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:55        处理成功        Trojan-PSW.Win32.OnLineGame.lgi        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A21.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:55        处理成功        Trojan-PSW.Win32.OL-Game.hyj        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A19.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:54        处理成功        Trojan-PSW.Win32.OL-Game.jqm        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A16.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:54        处理成功        Trojan-PSW.Win32.OL-Game.hym        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A9.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-04-27 11:18:54        处理成功        Trojan-Downloader.Win32.Zlob.fxh        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\VIRUS\A3.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
Exia 该用户已被删除
发表于 2008-4-27 11:21:45 | 显示全部楼层

全灭

第一包
Starting the file scan:

Begin scan in 'E:\AV\virus'
E:\AV\virus\a1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The file was deleted!
E:\AV\virus\a2.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abie
      [NOTE]      The file was deleted!
E:\AV\virus\a4.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a7.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a8.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.zjk
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a10.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a6.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.Steal.44658
      [NOTE]      The file was deleted!
E:\AV\virus\a9.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.ait.1
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4841f45e.qua'!
E:\AV\virus\a11.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abtp
      [NOTE]      The file was deleted!
E:\AV\virus\a12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a13.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a16.exe
      [DETECTION] Is the Trojan horse TR/Onlinegames.NVI
      [NOTE]      The file was deleted!
E:\AV\virus\a18.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12910
      [NOTE]      The file was deleted!
E:\AV\virus\a17.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a14.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a19.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a21.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rxqe
      [NOTE]      The file was deleted!
E:\AV\virus\a22.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.157
      [NOTE]      The file was deleted!
E:\AV\virus\a20.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
      [NOTE]      The file was deleted!
E:\AV\virus\a23.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a24.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a25.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [NOTE]      The file was deleted!


End of the scan: 2008年4月27日  11:34
Used time: 00:30 min

The scan has been done completely.

      1 Scanning directories
     25 Files were scanned
     25 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
     24 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
     25 Notes

第二包
Starting the file scan:

Begin scan in 'E:\AV\virus'
E:\AV\virus\a1.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The file was deleted!
E:\AV\virus\a2.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abie
      [NOTE]      The file was deleted!
E:\AV\virus\a4.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a7.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a8.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.zjk
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a10.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a6.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.Steal.44658
      [NOTE]      The file was deleted!
E:\AV\virus\a9.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.ait.1
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4841f4dc.qua'!
E:\AV\virus\a11.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abtp
      [NOTE]      The file was deleted!
E:\AV\virus\a12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a13.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delphi.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a16.exe
      [DETECTION] Is the Trojan horse TR/Onlinegames.NVI
      [NOTE]      The file was deleted!
E:\AV\virus\a18.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.12910
      [NOTE]      The file was deleted!
E:\AV\virus\a17.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a14.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a19.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a21.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rxqe
      [NOTE]      The file was deleted!
E:\AV\virus\a22.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.157
      [NOTE]      The file was deleted!
E:\AV\virus\a20.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
      [NOTE]      The file was deleted!
E:\AV\virus\a23.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a24.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\a25.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [NOTE]      The file was deleted!
E:\AV\virus\001.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abtn
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aji
      [NOTE]      The file was deleted!
E:\AV\virus\002.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4845f4da.qua'!
E:\AV\virus\003.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\004.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\005.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.ajb
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4848f4db.qua'!
E:\AV\virus\006.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\007.exe
      [DETECTION] Is the Trojan horse TR/Onlinegames.NVI
      [NOTE]      The file was deleted!
E:\AV\virus\009.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\010.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\008.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!


End of the scan: 2008年4月27日  11:36
Used time: 00:34 min

The scan has been done completely.

      1 Scanning directories
     35 Files were scanned
     35 viruses and/or unwanted programs were found
      4 Files were classified as suspicious:
     32 files were deleted
      0 files were repaired
      3 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
     35 Notes

第三包
Starting the file scan:

Begin scan in 'E:\AV\virus'
E:\AV\virus\soc5.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc4.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc3.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc1.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abtn
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aji
      [NOTE]      The file was deleted!
E:\AV\virus\soc7.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc9.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.ait.1
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4876f599.qua'!
E:\AV\virus\soc6.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abtp
      [NOTE]      The file was deleted!
E:\AV\virus\soc10.exe
      [DETECTION] Is the Trojan horse TR/PSW.16785
      [NOTE]      The file was deleted!
E:\AV\virus\soc13.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc11.exe
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aji
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '4876f59a.qua'!
E:\AV\virus\soc15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc12.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc8.exe
      [DETECTION] Is the Trojan horse TR/Onlinegames.NVI
      [NOTE]      The file was deleted!
E:\AV\virus\soc16.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc2.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abie
      [NOTE]      The file was deleted!
E:\AV\virus\soc19.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc20.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc17.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NVI.53
      [NOTE]      The file was deleted!
E:\AV\virus\soc18.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc21.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
E:\AV\virus\soc14.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!


End of the scan: 2008年4月27日  11:38
Used time: 00:26 min

The scan has been done completely.

      1 Scanning directories
     21 Files were scanned
     22 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
     19 files were deleted
      0 files were repaired
      2 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -1 Files not concerned
      0 Archives were scanned
      0 Warnings
     21 Notes

[ 本帖最后由 Exia 于 2008-4-27 11:39 编辑 ]
yunhan123
发表于 2008-4-27 11:22:51 | 显示全部楼层
清除病毒种类列表:
病毒: Trojan.PSW.Win32.GameOL.nbr
病毒: Trojan.PSW.Win32.GameOL.ndu
病毒: Trojan.PSW.Win32.GameOL.ndz
病毒: Trojan.PSW.Win32.GameOL.nek
病毒: Trojan.PSW.Win32.GameOL.myf
病毒: Trojan.PSW.Win32.XYOnline.acy
病毒: Trojan.PSW.Win32.GameOL.ndy
病毒: Worm.Win32.PaBug.gfg     
病毒: RootKit.Win32.HideFile.g
病毒: Trojan.PSW.Win32.GameOL.ndt
病毒: Trojan.PSW.Win32.GameOL.nei
病毒: Trojan.PSW.Win32.GameOL.nee
病毒: Trojan.PSW.Win32.GamesOnline.fz
病毒: Trojan.PSW.Win32.QQSG.dq
病毒: Trojan.PSW.Win32.GameOnlines.h
病毒: Trojan.PSW.Win32.Shanda.bi
病毒: Trojan.PSW.Win32.GameOL.nej
病毒: Trojan.PSW.Win32.GameOL.neh
病毒: Packer.Win32.Upack.a     
病毒: Trojan.PSW.Win32.GameOL.myk
病毒: Trojan.Mnless.lpi        
病毒: Trojan.PSW.Win32.QQHX.twn
病毒: Trojan.PSW.Win32.GameOL.nff
病毒: Trojan.Win32.StartPage.mcy
杀26个
yunhan123
发表于 2008-4-27 11:23:46 | 显示全部楼层
也只剩下个A1
平淡
发表于 2008-4-27 11:24:25 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a1.exe        Trojan.Cap841915.tgvh        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a10.exe        TrojanSpy.Gen.hrbc        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a11.exe        Trojan.Cap84233.gqry        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a12.exe        TrojanSpy.Gen.nsbl        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a13.exe        PWSteal.Lemir.bpv.gnfb        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a14.exe        TrojanSpy.Gen.recx        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a15.exe        TrojanSpy.Gen.mpik        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a16.exe        TrojanOnlinegames.NVI.csfz        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a17.exe        TrojanPSW.OnLineGames.omq.dqej        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a18.exe        W32.Warezov.p        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a19.exe        TrojanPSW.OnLineGames.ablh.zzbi        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a2.exe        Trojan.Cap841923.wlzv        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a20.exe        Backdoor.Delf.awy.crke        后门        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a21.exe        PWSteal.m.gzcm        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a22.exe        W32.Viking.k        病毒        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a23.exe        TrojanDropper.Gen.gbjj        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a24.exe        Trojan.Ck88866.Gen.ovwd        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a25.exe        Trojan.StartPage.avr.yvey        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a3.exe        TrojanDownloader.Nurech.bd.bmqk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a4.exe        TrojanSpy.Gen.wrmz        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a5.exe        TrojanSpy.Gen.nkax        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a6.exe        Trojan.Delphi.Gen.yjem        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a7.exe        TrojanSpy.Gen.jouq        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a8.exe        TrojanPSW.OnLineGames.wlu.kjdk        木马        还未处理
C:\Documents and Settings\Administrator\桌面\virus.rar>>virus\a9.exe        RootKit.FileHider.d.elxu        木马        还未处理
残缺的唯美
发表于 2008-4-27 11:40:52 | 显示全部楼层
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a2.exe - Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a4.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a5.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a7.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a8.exe - a variant of Win32/PSW.OnLineGames.ZJK trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a3.exe - Win32/PSW.OnLineGames.NOE trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a10.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a6.exe - a variant of Win32/PSW.QQPass.NCZ trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a9.exe - a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a11.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a12.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a13.exe - Win32/PSW.WOW.WU trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a16.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a18.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a17.exe - probably a variant of Win32/PSW.WOW.WU trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a15.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a14.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a19.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a21.exe - Win32/PSW.OnLineGames.MUG trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a22.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a20.exe - Win32/Delf.NFD trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a23.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a24.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\virus.rar » RAR » virus\a25.exe - probably a variant of Win32/StartPage trojan
残缺的唯美
发表于 2008-4-27 11:41:10 | 显示全部楼层
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a2.exe - Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a4.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a5.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a7.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a8.exe - a variant of Win32/PSW.OnLineGames.ZJK trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a3.exe - Win32/PSW.OnLineGames.NOE trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a10.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a6.exe - a variant of Win32/PSW.QQPass.NCZ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a9.exe - a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a11.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a12.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a13.exe - Win32/PSW.WOW.WU trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a16.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a18.exe - a variant of Win32/PSW.OnLineGames.PBQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a17.exe - probably a variant of Win32/PSW.WOW.WU trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a15.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a14.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a19.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a21.exe - Win32/PSW.OnLineGames.MUG trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a22.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a20.exe - Win32/Delf.NFD trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a23.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a24.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\a25.exe - probably a variant of Win32/StartPage trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\001.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\002.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\003.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\004.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\005.exe - a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\006.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\007.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\009.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\010.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\delet.rar » RAR » virus\008.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
残缺的唯美
发表于 2008-4-27 11:41:35 | 显示全部楼层
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc5.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc4.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc1.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc7.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc9.exe - a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc6.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc10.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc13.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc11.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc15.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc12.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc8.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc16.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc2.exe - Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc19.exe - probably a variant of Win32/PSW.OnLineGames.NMQ trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc20.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc17.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc18.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc21.exe - Win32/PSW.OnLineGames.NFL trojan
D:\Documents and Settings\EKINCHENG\桌面\opling.rar » RAR » virus\soc14.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
爱·妖姬
发表于 2008-4-27 14:30:09 | 显示全部楼层
一个Sophos就三包全清,微点都不需要出动
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-15 14:12 , Processed in 0.138371 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表