查看: 6658|回复: 36
收起左侧

[病毒样本] 57个,能扫出30个算优秀

 关闭 [复制链接]
eacocn
发表于 2008-5-7 09:27:11 | 显示全部楼层 |阅读模式
(转自精睿安防社区)附带 机器狗病毒,欢迎测试并且研究下
大家将就着用吧..记得用右键哦!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2008-5-7 09:40:42 | 显示全部楼层
33个

Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\17_69527_41568809542c991'
C:\Documents and Settings\morgan\My Documents\17_69527_41568809542c991\
  017AAA04.exe
  078870BE.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.11503
      [NOTE]      The file was deleted!
  079CE54F.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [NOTE]      The file was deleted!
  08F2AF78.exe
  0EBFC50D.exe
  0FEC2F6C.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rmi
      [NOTE]      The file was deleted!
  12F373F7.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.VB.8
      [NOTE]      The file was deleted!
  13306129.exe
  193EBCAE.exe
  1B1A91E6.exe
  1B7F4C90.sys
      [DETECTION] Contains detection pattern of the rootkit RKIT/Ring0.A
      [NOTE]      The file was deleted!
  1FC3F279.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jwb
      [NOTE]      The file was deleted!
  213A6D52.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.RPD.2
      [NOTE]      The file was deleted!
  29DDD92D.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  2C2125BD.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.RPD.2
      [NOTE]      The file was deleted!
  33120719.exe
  41FEC741.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.QYJ
            [WARNING]   Infected files in archives cannot be repaired!
      [NOTE]      The file was deleted!
  42260861.exe
  50084D08.exe
  549654F7.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  55D5CC15.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zlob.RY
      [NOTE]      The file was deleted!
  56D750CE.exe
      [DETECTION] Contains detection pattern of the SPR/Spy.Col program
      [NOTE]      The file was deleted!
  5B6E099D.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.VB.7
      [NOTE]      The file was deleted!
  5E1E7D0D.exe
  68B2C126.exe
  6DF52419.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '486708c0.qua'!
  7452794A.exe
  75C90C34.exe
  81D3A1E0.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.11987
      [NOTE]      The file was deleted!
  88AB2F6C.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  89DD2FE7.exe
  89E7E97A.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '486608b5.qua'!
  8E384A86.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [NOTE]      The file was deleted!
  9A6CC0ED.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  9F0A2413.exe
  A0D13601.exe
  A3F1431E.dll
    [0] Archive type: Runtime Packed
    --> Object
        [DETECTION] Is the Trojan horse TR/PSW.Online.gyo.2
      [NOTE]      The file was deleted!
  A59AFE82.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.cpu
      [NOTE]      The file was deleted!
  A6AEA151.exe
  A81C0866.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.aio
      [NOTE]      The file was deleted!
  B578B381.exe
  BB68F23F.sys
      [DETECTION] Contains detection pattern of the application APPL/Killapp
      [NOTE]      The file was deleted!
  BCCC62E0.exe
  C0B1890A.exe
  C24B51FC.sys
  C47604BD.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [NOTE]      The fund was classified as suspicious.
      [NOTE]      The file was moved to '485808b0.qua'!
  C4BA6B18.exe
  C874FEB0.dll
    [0] Archive type: Runtime Packed
    --> Object
        [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
      [NOTE]      The file was deleted!
  CCD54802.exe
      [DETECTION] Is the Trojan horse TR/Heita
      [NOTE]      The file was deleted!
  D9428229.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zlob.Gen
      [NOTE]      The file was deleted!
  DF859A44.tmp
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.epw.1
      [NOTE]      The file was deleted!
  E2DD595B.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  ECFFF489.dat
    [0] Archive type: Runtime Packed
    --> Object
        [DETECTION] Is the Trojan horse TR/PSW.OnLi.iiu.1.A
      [NOTE]      The file was deleted!
  EED49A78.exe
  F38B1ACC.exe
  F5663BF7.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!
  FD6A38ED.dll
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
        --> Object
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
      [NOTE]      The file was deleted!


End of the scan: 2008年5月6日  18:40
Used time: 00:04 min

The scan has been done completely.

      1 Scanning directories
     57 Files were scanned
     30 viruses and/or unwanted programs were found
      3 Files were classified as suspicious:
     30 files were deleted
      0 files were repaired
      3 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     27 Files not concerned
      0 Archives were scanned
      1 Warnings
     33 Notes
郁冰兰雪
发表于 2008-5-7 09:42:56 | 显示全部楼层
EAV 26个
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 5B6E099D.dll - Win32/PSW.OnLineGames.DTR 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 12F373F7.dll - Win32/PSW.Agent.NEC 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 55D5CC15.exe - Win32/TrojanDownloader.Zlob.ARV 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 29DDD92D.sys - Win32/PSW.OnLineGames.NFC 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 1FC3F279.dll - Win32/PSW.OnLineGames.NHF 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 079CE54F.exe - 可能是 Win32/Obfuscated 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 078870BE.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 41FEC741.exe - Win32/PSW.OnLineGames.NLY 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 0FEC2F6C.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 549654F7.tmp - Win32/PSW.OnLineGames.MYG 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 213A6D52.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 2C2125BD.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > F5663BF7.tmp - Win32/PSW.OnLineGames.MYG 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > FD6A38ED.dll - Win32/PSW.OnLineGames.NLH 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 88AB2F6C.tmp - Win32/PSW.OnLineGames.MYG 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 81D3A1E0.exe - Win32/PSW.OnLineGames.PBQ 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > E2DD595B.tmp - Win32/PSW.OnLineGames.MYG 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > DF859A44.tmp - Win32/TrojanDownloader.Delf.EPW 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > D9428229.exe - Win32/TrojanDownloader.Zlob.ARV 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 8E384A86.exe - Win32/Ceckno 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > ECFFF489.dat - Win32/PSW.OnLineGames.NCU 特洛伊木马 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > A59AFE82.exe - 可能是 Win32/Autorun 蠕虫 的变种
D:\病毒样本\17_69527_41568809542c991.rar > RAR > 9A6CC0ED.sys - Win32/PSW.OnLineGames.NFC 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > A3F1431E.dll - Win32/PSW.OnLineGames.DVV 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > A81C0866.dll - Win32/TrojanDownloader.Agent.IAJ 特洛伊木马
D:\病毒样本\17_69527_41568809542c991.rar > RAR > C874FEB0.dll - Win32/PSW.OnLineGames.NHF 特洛伊木马 的变种
foxkissme
发表于 2008-5-7 09:43:41 | 显示全部楼层
微点干掉了33个。。。小红伞才四个
mofunzone
发表于 2008-5-7 09:44:19 | 显示全部楼层
3732113 7452794A.exe 9.59 KB DAMAGED FILE (UNKNOWN)
3732125 0EBFC50D.exe 6.77 KB DAMAGED FILE (UNKNOWN)
3732108 1B1A91E6.exe 11.25 KB DAMAGED FILE (UNKNOWN)
2693039 5E1E7D0D.exe 6.5 KB DAMAGED FILE (UNKNOWN)
3732124 08F2AF78.exe 9.58 KB DAMAGED FILE (UNKNOWN)
3732116 9F0A2413.exe 9.58 KB DAMAGED FILE (UNKNOWN)
3732123 017AAA04.exe 10.99 KB DAMAGED FILE (UNKNOWN)
3732112 68B2C126.exe 6.73 KB DAMAGED FILE (UNKNOWN)
3732114 75C90C34.exe 8.18 KB DAMAGED FILE (UNKNOWN)
3732115 89DD2FE7.exe 8 KB DAMAGED FILE (UNKNOWN)
3732107 193EBCAE.exe 8.18 KB DAMAGED FILE (UNKNOWN)
3732111 50084D08.exe 8.18 KB DAMAGED FILE (UNKNOWN)
mofunzone
发表于 2008-5-7 09:44:37 | 显示全部楼层
3732122 F38B1ACC.exe 9.16 KB DAMAGED FILE (UNKNOWN)
3732106 13306129.exe 5.36 KB DAMAGED FILE (UNKNOWN)
3732109 33120719.exe 9.54 KB DAMAGED FILE (UNKNOWN)
3732110 42260861.exe 9.58 KB DAMAGED FILE (UNKNOWN)
199234 A0D13601.exe 8.5 KB CLEAN
3732117 A6AEA151.exe 6.77 KB DAMAGED FILE (UNKNOWN)
3732118 B578B381.exe 7.03 KB DAMAGED FILE (UNKNOWN)
3732119 BCCC62E0.exe 10.99 KB DAMAGED FILE (UNKNOWN)
3732120 C0B1890A.exe 10.99 KB DAMAGED FILE (UNKNOWN)
1315310 C4BA6B18.exe 6.81 KB DAMAGED FILE (UNKNOWN)
595970 C24B51FC.sys 4.83 KB CLEAN
3732121 EED49A78.exe 8.44 KB DAMAGED FILE (UNKNOWN)
scottxzt
发表于 2008-5-7 09:55:38 | 显示全部楼层

DRWEB 29

17_69527_41568809542c991.rar\1B7F4C90.sys;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.NtRootKit.1041;;
17_69527_41568809542c991.rar\5B6E099D.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Gamania.8998;;
17_69527_41568809542c991.rar\12F373F7.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.Goner.50;;
17_69527_41568809542c991.rar\55D5CC15.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.Popuper;;
17_69527_41568809542c991.rar\5E1E7D0D.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.HDDKill.511;;
17_69527_41568809542c991.rar\29DDD92D.sys;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Gamania.6393;;
17_69527_41568809542c991.rar\1FC3F279.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.2412;;
17_69527_41568809542c991.rar\078870BE.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3448;;
17_69527_41568809542c991.rar\41FEC741.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3429;;
17_69527_41568809542c991.rar\0FEC2F6C.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3501;;
17_69527_41568809542c991.rar\549654F7.tmp;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3051;;
17_69527_41568809542c991.rar\213A6D52.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Gamania.7720;;
17_69527_41568809542c991.rar\2C2125BD.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Gamania.7720;;
17_69527_41568809542c991.rar\F5663BF7.tmp;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.2963;;
17_69527_41568809542c991.rar\FD6A38ED.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.2663;;
17_69527_41568809542c991.rar\88AB2F6C.tmp;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3163;;
17_69527_41568809542c991.rar\81D3A1E0.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3451;;
17_69527_41568809542c991.rar\E2DD595B.tmp;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.1738;;
17_69527_41568809542c991.rar\DF859A44.tmp;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.DownLoader.47705;;
17_69527_41568809542c991.rar\C47604BD.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.2313;;
17_69527_41568809542c991.rar\D9428229.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.Popuper;;
17_69527_41568809542c991.rar\8E384A86.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.DownLoader.36483;;
17_69527_41568809542c991.rar\ECFFF489.dat;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.2413;;
17_69527_41568809542c991.rar\A59AFE82.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;可能 DLOADER.Trojan;;
17_69527_41568809542c991.rar\9A6CC0ED.sys;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3592;;
17_69527_41568809542c991.rar\C4BA6B18.exe;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.Packed.142;;
17_69527_41568809542c991.rar\A3F1431E.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Wsgame.3283;;
17_69527_41568809542c991.rar\A81C0866.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.DownLoader.47704;;
17_69527_41568809542c991.rar\C874FEB0.dll;C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar;Trojan.PWS.Gamania.6441;;
17_69527_41568809542c991.rar;C:\Documents and Settings\Administrator\桌面;发现压缩文件中有被感染的对象;;
残缺的唯美
发表于 2008-5-7 10:03:07 | 显示全部楼层
30
Hacktool.Rootkit
病毒 ID: 16268
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[1b7f4c90.sys] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[5b6e099d.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[12f373f7.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan.Zlob
病毒 ID: 4254
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[55d5cc15.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[29ddd92d.sys] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[1fc3f279.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan.Packed.18
病毒 ID: 53522
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[079ce54f.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[078870be.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[41fec741.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan Horse
病毒 ID: 25464
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[56d750ce.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[0fec2f6c.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[549654f7.tmp] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[213a6d52.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[2c2125bd.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[f5663bf7.tmp] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[fd6a38ed.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[88ab2f6c.tmp] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[81d3a1e0.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[e2dd595b.tmp] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Hacktool.Rootkit
病毒 ID: 16268
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[df859a44.tmp] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[c47604bd.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan.Zlob
病毒 ID: 4254
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[d9428229.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan Horse
病毒 ID: 25464
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[8e384a86.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer
病毒 ID: 24770
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[ecfff489.dat] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[9a6cc0ed.sys] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan.Packed.13
病毒 ID: 53517
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[c4ba6b18.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[a3f1431e.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Downloader
病毒 ID: 26637
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[a81c0866.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Infostealer.Gampass
病毒 ID: 40673
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[c874feb0.dll] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染


Trojan Horse
病毒 ID: 25464
类型: 已压缩
风险: 高 (高 隐蔽性,高 清除可能,高 性能,高 隐私)  
类别: 病毒
状态: 删除失败
-----------
1 文件
[ccd54802.exe] 位于[d:\users\ekincheng\desktop\17_69527_41568809542c991.rar] - 已感染
wayaya
发表于 2008-5-7 10:03:14 | 显示全部楼层
原帖由 foxkissme 于 2008-5-7 09:43 发表
微点干掉了33个。。。小红伞才四个

哥们,不对,小红伞是干掉31个,还剩下26个文件
lookbooker
发表于 2008-5-7 10:12:23 | 显示全部楼层
小红伞高启发扫出28个
Avira AntiVir Premium
Report file date: 2008年5月7日  10:10

Scanning for 1253417 virus strains and unwanted programs.

Licensed to:      feng zeng
Serial number:    1101637722-PEPWE-0001
Platform:         Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Boot mode:        Normally booted
Username:         Administrator
Computer name:    MICROSOF-48AD1D

Version information:
BUILD.DAT     : 8.1.00.331      19215 Bytes    2008-4-9 16:10:00
AVSCAN.EXE    : 8.1.2.12       311553 Bytes   2008-3-18 03:02:56
AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2008-2-7 02:43:37
LUKE.DLL      : 8.1.2.9        151809 Bytes   2008-2-28 02:41:23
LUKERES.DLL   : 8.1.2.1         12033 Bytes   2008-2-21 02:28:40
ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   2007-7-18 04:33:34
ANTIVIR1.VDF  : 7.0.3.2       5447168 Bytes    2008-3-7 07:08:58
ANTIVIR2.VDF  : 7.0.4.0       1554432 Bytes    2008-5-5 16:16:28
ANTIVIR3.VDF  : 7.0.4.8         26624 Bytes    2008-5-6 01:04:41
Engineversion : 8.1.0.37  
AEVDF.DLL     : 8.1.0.5        102772 Bytes   2008-2-25 03:58:21
AESCRIPT.DLL  : 8.1.0.28       233851 Bytes    2008-5-2 14:23:12
AESCN.DLL     : 8.1.0.15       119157 Bytes    2008-5-2 14:22:49
AERDL.DLL     : 8.1.0.20       418165 Bytes    2008-5-2 14:22:35
AEPACK.DLL    : 8.1.1.4        364918 Bytes    2008-5-2 14:21:20
AEOFFICE.DLL  : 8.1.0.18       192890 Bytes    2008-5-2 14:20:26
AEHEUR.DLL    : 8.1.0.21      1196407 Bytes    2008-5-2 14:20:04
AEHELP.DLL    : 8.1.0.14       115063 Bytes    2008-5-2 14:17:53
AEGEN.DLL     : 8.1.0.18       299381 Bytes    2008-5-2 14:17:42
AEEMU.DLL     : 8.1.0.5        430450 Bytes    2008-4-7 09:34:43
AECORE.DLL    : 8.1.0.27       168310 Bytes    2008-5-2 14:17:17
AVWINLL.DLL   : 1.0.0.7         14593 Bytes   2008-1-23 11:07:53
AVPREF.DLL    : 8.0.0.1         25857 Bytes   2008-2-18 04:37:50
AVREP.DLL     : 7.0.0.1        155688 Bytes   2007-4-16 07:26:47
AVREG.DLL     : 8.0.0.0         30977 Bytes   2008-1-23 11:07:49
AVARKT.DLL    : 1.0.0.23       307457 Bytes   2008-2-12 02:29:23
AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2008-2-28 02:31:31
SQLITE3.DLL   : 3.3.17.1       339968 Bytes   2008-1-22 11:28:02
SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   2008-1-23 11:08:39
NETNT.DLL     : 8.0.0.1          7937 Bytes   2008-1-25 06:05:10
RCIMAGE.DLL   : 8.0.0.31      2564353 Bytes   2008-2-28 03:19:50
RCTEXT.DLL    : 8.0.32.0        86273 Bytes    2008-3-6 05:45:45

Configuration settings for the scan:
Jobname..........................: ShlExt
Configuration file...............: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\35773e90.avp
Logging..........................: low
Primary action...................: repair
Secondary action.................: delete
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: off
Scan all files...................: Use file extension list
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: high

Start of the scan: 2008年5月7日  10:10

Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar'
C:\Documents and Settings\Administrator\桌面\17_69527_41568809542c991.rar
  [0] Archive type: RAR
  --> 1B7F4C90.sys
      [DETECTION] Contains detection pattern of the rootkit RKIT/Ring0.A
  --> 5B6E099D.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.VB.7
  --> 12F373F7.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.VB.8
  --> 55D5CC15.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zlob.RY
  --> 29DDD92D.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 1FC3F279.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.jwb
  --> 079CE54F.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> 6DF52419.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> 078870BE.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.11503
    --> 41FEC741.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.QYJ
  --> 0FEC2F6C.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rmi
  --> 549654F7.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 213A6D52.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.RPD.2
  --> 2C2125BD.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.RPD.2
  --> F5663BF7.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 88AB2F6C.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 81D3A1E0.exe
      [DETECTION] Is the Trojan horse TR/Drop.Agent.11987
  --> E2DD595B.tmp
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> DF859A44.tmp
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.epw.1
  --> C47604BD.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> D9428229.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Zlob.Gen
  --> 8E384A86.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    --> ECFFF489.dat
          [DETECTION] Is the Trojan horse TR/PSW.OnLi.iiu.1.A
  --> 89E7E97A.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> A59AFE82.exe
      [DETECTION] Contains detection pattern of the worm WORM/Autorun.cpu
  --> 9A6CC0ED.sys
      [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> A3F1431E.dll
          [DETECTION] Is the Trojan horse TR/PSW.Online.gyo.2
  --> A81C0866.dll
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.aio
    --> C874FEB0.dll
          [DETECTION] Is the Trojan horse TR/PSW.Onlineg.KC.2
  --> CCD54802.exe
      [DETECTION] Is the Trojan horse TR/Heita
      [NOTE]      A backup was created as '48800fbe.qua'  ( QUARANTINE )
      [NOTE]      The file was deleted!


End of the scan: 2008年5月7日  10:10
Used time: 00:05 min

The scan has been done completely.

      0 Scanning directories
     58 Files were scanned
     28 viruses and/or unwanted programs were found
      3 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     30 Files not concerned
      1 Archives were scanned
      0 Warnings
      1 Notes
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-16 01:40 , Processed in 0.135892 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表