查看: 1761|回复: 8
收起左侧

[病毒样本] virus

[复制链接]
电影结束了
发表于 2008-6-4 09:54:16 | 显示全部楼层 |阅读模式

不知道几个。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
nosferatu
头像被屏蔽
发表于 2008-6-4 09:57:45 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\virus1'
C:\Documents and Settings\Administrator\桌面\virus1\0.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\1.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.almb
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\10.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\12.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\13.exe
      [DETECTION] Is the Trojan horse TR/PSW.16493
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\14.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.almz
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\15.exe
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\16.exe
      [DETECTION] Is the Trojan horse TR/PSW.18417.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\18.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.allu
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\19.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.ahnr
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\21.exe
      [DETECTION] Is the Trojan horse TR/PSW.18397
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\23.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.alor.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\24.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.almh.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\26.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.akyh.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\27.exe
      [DETECTION] Is the Trojan horse TR/Agent.43569
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\28.exe
      [DETECTION] Is the Trojan horse TR/Drop.Spy.Pca.A.1
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\3.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.almd
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\5.exe
      [DETECTION] Is the Trojan horse TR/ATRAPS.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\6.exe
  [0] Archive type: OVL
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.aldu
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\7.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NVI.235
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\8.exe
  [0] Archive type: OVL
    --> Object
      [1] Archive type: RSRC
      --> Object
          [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aom
      [DETECTION] Is the Trojan horse TR/Spy.Gen
      [NOTE]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\virus1\9.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.alme.1
      [NOTE]      The file was deleted!


End of the scan: 星期三 2008年6月4日  09:56
Used time: 00:15 min

The scan has been done completely.

      1 Scanning directories
     22 Files were scanned
     24 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     22 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -2 Files not concerned
      0 Archives were scanned
      0 Warnings
     22 Notes
小邪邪
发表于 2008-6-4 10:20:17 | 显示全部楼层
AVK(3engine):清光
挪威的冬天
发表于 2008-6-4 12:43:41 | 显示全部楼层
信息        2008-06-04  12:43:28        您此次查毒隔离了22个文件                       
信息        2008-06-04  12:43:28        您此次查毒共查出22个病毒以及危险代码                       
信息        2008-06-04  12:43:28        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件47个                       
信息        2008-06-04  12:43:28        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒
feihongtian 该用户已被删除
发表于 2008-6-4 17:51:51 | 显示全部楼层
Drweb 20/22

EAV

正在扫描日志
病毒库版本: 3156 (20080603)
日期: 2008-6-4  时间: 17:52:11
已扫描的磁盘、文件夹和文件: C:\Documents and Settings\sky\桌面\virus10
C:\Documents and Settings\sky\桌面\virus10\1.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\10.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\12.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\13.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\14.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\15.exe - 可能是 Win32/PSW.WOW.WU 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\16.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\18.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马
C:\Documents and Settings\sky\桌面\virus10\19.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\21.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\23.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\24.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\26.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\27.exe - 未查明的 NewHeur_PE 病毒 [7]
C:\Documents and Settings\sky\桌面\virus10\28.exe - Win32/Delf.CSN 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\3.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\5.exe - Win32/PSW.QQPass.NCZ 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\6.exe - Win32/PSW.OnLineGames.XZN 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\7.exe - Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\8.exe - Win32/PSW.OnLineGames.XZN 特洛伊木马 的变种
C:\Documents and Settings\sky\桌面\virus10\9.exe - 可能是 Win32/PSW.OnLineGames.NWC 特洛伊木马 的变种
已扫描的对象数: 22
发现的威胁数: 21
已清除对象数:0
完成时间: 17:52:13  总扫描时间: 2 秒 (00:00:02)
备注:
[7] 对象可能感染了未知病毒。
qigang
发表于 2008-6-4 20:40:14 | 显示全部楼层

42/22

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Backdoor.Win32.Agent.yff
病毒: Backdoor.Win32.Agent.yff
病毒: Trojan.PSW.Win32.GameOL.nvb
病毒: Trojan.PSW.Win32.QQPass.dnh
病毒: Trojan.PSW.Win32.XYOnline.afb
病毒: RootKit.Win32.Undef.ib   
病毒: RootKit.Win32.Undef.ib   
病毒: Trojan.PSW.Win32.GameOL.nsq
病毒: Trojan.PSW.Win32.LMir.bqd

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.47.22
allinwonderi
发表于 2008-6-4 20:45:08 | 显示全部楼层

ArcaVir2008

[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe <- Trojan.Delf.Awy : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe<DLLRES>:EXE0.exe <- Trojan.Delf.Awy : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe<DLLRES>:DLL2.exe <- Trojan.Delf.Awy : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe<DLLRES>:DLL3.exe <- Variant:Trojan.Delf.Awy : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe<DLLRES>:DLL4.exe <- Trojan.Hupigon.Byyk : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:28.exe<FSG>:28.exe<DLLRES>:DLL4.exe<UPack>:DLL4.exe <- Variant:Trojan.Ircbot.Vo : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:0.exe<FSG>:0.exe <- Trojan.Psw.Onlinegames.Flr : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:1.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:6.exe <- Trojan.Psw.Onlinegames.Aldw : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:7.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:10.exe <- Trojan.Psw.Onlinegames.Ajti : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:12.exe <- Trojan.Psw.Onlinegames.Ajsz : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:14.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:15.exe<UPack>:15.exe <- Trojan.Psw.Lmir.Bpc : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:15.exe<UPack>:15.exe<DLLRES>:J9996660.exe <- Variant:Trojan.Psw.Lmir.Bpc : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar<RAR>:16.exe <- Trojan.Psw.OnLineGames.Almz : No action
C:\Documents and Settings\All Users\Documents\Test\virus1.part2.rar<RAR>:27.exe<FSG>:27.exe <- Variant:Trojan.Startpage.Aqf : No action



Scanned objects : 56

Infected objects : 17
allinwonderi
发表于 2008-6-4 20:46:07 | 显示全部楼层

F-Prot 4.4.4

[Found possible security risk]         <W32/Heuristic-159!Eldorado (damaged, not disinfectable)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->28.exe->(FSG)
[Found security risk]         <W32/OnlineGames.C.gen!GSA (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->1.exe->(embedded)
[Found security risk]         <W32/AutoRun.D.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->5.exe->(UPX)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->6.exe->exefile->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->8.exe->exefile->(UPack)
[Found security risk]         <W32/Injector.A.gen!Eldorado (not disinfectable, generic)>        C:\Documents and Settings\All Users\Documents\Test\virus1.part1.rar->15.exe

---------------------------------------------------------------------
Scan ended:        2008-6-4, 20:45:25
Duration:        0:00:05

Scan result:

Scanned files:                 7
Infected objects:         6
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------
rwufo
发表于 2008-6-4 21:57:32 | 显示全部楼层
  吓死我了,TMD 二十二个 警报的声音确实不好听。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-18 04:38 , Processed in 0.128562 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表