12
返回列表 发新帖
楼主: loveyuwei
收起左侧

[病毒样本] [6.3]有惊无险 又带礼物来了

[复制链接]
水晶
发表于 2008-6-4 20:38:37 | 显示全部楼层
2008-6-4 20:37:59        恶意HTTP对象 <http://bbs.kafan.cn/attachment.p ... s/sys32/14.exe//FSG>: 已检测新变种 病毒 'Invader'。
allinwonderi
发表于 2008-6-4 20:39:55 | 显示全部楼层

ArcaVir2008

[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:DosSys16.Sys <- Trojan.Psw.Qqpass.Cbk : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:13.exe<UPack>:13.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Afqn : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:18.exe<UPack>:18.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Akcs : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:18.exe<UPack>:18.exe<DLLRES>:res1.exe <- Trojan.Psw.Onlinegames.Afqn : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:1AB9A128.EXE<UPack>:1AB9A128.EXE <- Trojan.Popwin.Bfu : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:33.exe <- Trojan.Psw.Qqpass.Cbj : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:33.exe<UPX>:33.exe<DLLRES>:FILE0.exe <- Trojan.Psw.Qqpass.Cbk : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dbhlp32.dlL <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dionpis.dll <- Trojan.Psw.Onlinegames.Akji : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dndsioc.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmbiost.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmsbbqi.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmsjhif.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:huifitc.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:msosdrop00.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:msosfmsq00.dll <- Trojan.Psw.Onlinegames.Ajsq : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:msosptfs00.dll <- Worm.Downloader.Mb : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:nicozftp00.dll <- Trojan.Psw.Onlinegames.Akww : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:nicozftp00.dll<UPack>:nicozftp00.dll <- Trojan.Psw.Onlinegames.Akww : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:SysDaJHv.dll <- Trojan.Psw.Onlinegames.Akcs : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:SysWoWCt.dll <- Trojan.Psw.Onlinegames.Ajnn : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:SysWoWCt.dll<UPack>:SysWoWCt.dll <- Trojan.Psw.Onlinegames.Ajnn : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:unojjlrx.dll <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dbhlp32.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dionpis.exe <- Trojan.Psw.Onlinegames.Akji : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:dndsioc.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmbiost.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmsbbqi.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:fmsjhif.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:huifitc.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus.rar<RAR>:kcjcixin.exe <- Trojan.Psw.OnLineGames.Almz : No action



Scanned objects : 130

Infected objects : 31
allinwonderi
发表于 2008-6-4 20:40:38 | 显示全部楼层

F-Prot 4.4.4

[Found virus]         <W32/InfoStealer!Generic (not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\drivers\ieplus\DosSys16.Sys
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\localtmp\SETUP.EXE->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\11.exe->(embedded)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\13.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\14.exe->(embedded)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\18.exe
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\1AB9A128.EXE->(UPack)
[Found security risk]         <W32/AutoRun.D.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\33.exe->(UPX)
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\4.exe
[Found downloader]         <W32/Downloader.C.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\9AA28F90.DLL
[Found security risk]         <W32/OnlineGames.C.gen!GSA (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\fmsiocps.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msoscqit00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosdohs00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosdrop00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosfmsq00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosjtio00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosmhfp00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosmnsf00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosping00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\msosptfs00.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\nicozftp00.dll
[Found possible security risk]         <W32/Heuristic-210!Eldorado (damaged, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\SysDaJHv.dll->(UPack)
[Found possible security risk]         <W32/Heuristic-210!Eldorado (damaged, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\SysWoWCt.dll->(UPack)
[Found possible security risk]         <W32/Heuristic-210!Eldorado (damaged, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\SysZxacC.dll->(UPack)
[Found security risk]         <W32/OnlineGames.C.gen!GSA (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\sys32\wipicdec.dll
[Found security risk]         <W32/OnlineGames.C.gen!GSA (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus.rar->virus\windows\wipicdec.exe->(embedded)

---------------------------------------------------------------------
Scan ended:        2008-6-4, 20:40:25
Duration:        0:00:20

Scan result:

Scanned files:                 6
Infected objects:         26
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------
BING126
头像被屏蔽
发表于 2008-6-4 20:42:09 | 显示全部楼层
McAfee报了39个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
samancy
发表于 2008-6-4 20:57:02 | 显示全部楼层
费尔小测!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-18 11:58 , Processed in 0.091524 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表