查看: 3702|回复: 17
收起左侧

[病毒样本] 新病毒bao

[复制链接]
chabosh
发表于 2008-5-2 21:15:00 | 显示全部楼层 |阅读模式
新病毒bao

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ykz1991
发表于 2008-5-2 21:18:18 | 显示全部楼层


全部Packed

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
红心王子
发表于 2008-5-2 21:20:36 | 显示全部楼层
时间        处理结果        木马名称        木马进程名        木马文件创建者
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.lby        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\TICISMS.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.mry        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\TCIOCP64.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.mrw        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\DBHLP32.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.msa        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\JYLVVIBI.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.mvu        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\FMSJHIF.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.msc        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\FMSIOCPS.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.mou        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\FMSBBQI.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
2008-05-02 21:20:13        处理成功        Trojan-PSW.Win32.OL-Game.lfm        C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\VIR\BINGDU\DIONPIS.EXE        C:\PROGRAM FILES\WINRAR\WINRAR.EXE
qigang
发表于 2008-5-2 21:29:56 | 显示全部楼层

54/0

rising20.42.40未杀!
hj5abc
发表于 2008-5-2 21:32:16 | 显示全部楼层
vb的引擎太牛了.

2008-5-2 21:27:53    SYSTEM    1080    Sign of "Win32:OnLineGames-DNU [Trj]" has been found in "F:\bingdu\bingdu\fmsbbqi.exe\[FSG]" file.  
2008-5-2 21:27:54    SYSTEM    1080    Sign of "Win32:OnLineGames-CDA [Trj]" has been found in "F:\bingdu\bingdu\fmsiocps.exe\[FSG]" file.  
2008-5-2 21:27:54    SYSTEM    1080    Sign of "Win32:OnLineGames-DJX [Trj]" has been found in "F:\bingdu\bingdu\jylvvibi.exe\[FSG]" file.  
2008-5-2 21:27:54    SYSTEM    1080    Sign of "Win32:OnLineGames-DAB [Trj]" has been found in "F:\bingdu\bingdu\yuiabct.exe\[FSG]" file.  
2008-5-2 21:27:54    SYSTEM    1080    Sign of "Win32:Agent-CNF [Trj]" has been found in "F:\bingdu\bingdu\ptshell.exe\[FSG]" file.  
2008-5-2 21:27:55    SYSTEM    1080    Sign of "Win32:VB-GDM [Trj]" has been found in "F:\bingdu\bingdu\SoundMan.exe" file.  
The EQs
发表于 2008-5-2 21:32:46 | 显示全部楼层

17

C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\cinfonmc.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\dbhlp32.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\dionpis.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\explorer.exe - probably a variant of Win32/TrojanDownloader.Agent.NWV trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\fiosectc.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\fmsbbqi.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\fmsiocps.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\fmsjhif.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\issms32.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\jylvvibi.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\mfchlp64.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\ptshell.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\SoundMan.exe - probably unknown NewHeur_PE virus - deleted - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\tciocp64.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\ticisms.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\WINSvr64.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
C:\Documents and Settings\Don Johnson\桌面\bingdu\bingdu\yuiabct.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan - cleaned by deleting - quarantined
醉一生爱妍
发表于 2008-5-2 21:39:09 | 显示全部楼层
卡8.0 MISS 3

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
yk1234
发表于 2008-5-2 21:41:44 | 显示全部楼层
红伞剩3个
mofunzone
发表于 2008-5-3 02:26:01 | 显示全部楼层
剩1个
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\bingdu'
C:\Documents and Settings\Administrator\My Documents\bingdu\bingdu\
  cinfonmc.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  dbhlp32.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  dionpis.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  explorer.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  fiosectc.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  fmsbbqi.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  fmsiocps.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '488e5d15.qua'!
  fmsjhif.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  issms32.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  jylvvibi.exe
    [0] Archive type: Runtime Packed
    --> Object
        [DETECTION] Is the Trojan horse TR/Onlinegames.NVI
      [NOTE]      The file was deleted!
  mfchlp64.exe
      [DETECTION] Is the Trojan horse TR/PSW.16789
      [NOTE]      The file was deleted!
  popo.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  ptshell.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  SoundMan.exe
    [0] Archive type: RSRC
    --> Object
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
  tciocp64.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  ticisms.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: OVL
        --> Object
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
  vqqsdl.exe
  WINSvr64.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!
  yuiabct.exe
    [0] Archive type: Runtime Packed
    --> Object
      [NOTE]      The file was deleted!


End of the scan: 2008年5月2日  11:25
Used time: 00:04 min

The scan has been done completely.

      2 Scanning directories
     19 Files were scanned
     16 viruses and/or unwanted programs were found
      2 Files were classified as suspicious:
     17 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      0 Archives were scanned
      0 Warnings
     18 Notes
mofunzone
发表于 2008-5-3 02:28:46 | 显示全部楼层
25007781          vqqsdl.exe          88 KB          UNDER ANALYSIS
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-21 21:23 , Processed in 0.159955 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表