12
返回列表 发新帖
楼主: 电影结束了
收起左侧

[病毒样本] *26

[复制链接]
醉一生爱妍
发表于 2008-7-5 19:39:18 | 显示全部楼层
MicroVita AntiSpyware  
_____________________________________________
                                          
             风暴微塔反间谍 T2
[强力查杀各种Win32位的病毒,木马,蠕虫,恶意软件]                  
                   http://221.10.254.214/
----------------------------------------------
开始扫描……


正在检查启动……
[C:\Documents and Settings\Administrator\桌面\26\MMBAIKOK1100.exe]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:19614  MD5:ad2862c002b27215c9fb22a77ce66461


[C:\Documents and Settings\Administrator\桌面\26\MMCBDKTK1086.exe]
                    …………发现Spy!报告:[2] [1] Win32.F/S.ByDwing
文件信息:  大小:18950  MD5:33981d3e79eba57b62d09228469f756e


[C:\Documents and Settings\Administrator\桌面\26\MMDXYBQE1040.exe]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:18783  MD5:46a2418ac5071646bc2e20178141adfd


[C:\Documents and Settings\Administrator\桌面\26\MMKAFNFW1110.exe]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:19219  MD5:07d44fd898c03c0a10dd9a8c41005609


[C:\Documents and Settings\Administrator\桌面\26\MMMHXGGD1070.exe]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:19926  MD5:ef3f769aff76076b9d6d15798d5924dd


[C:\Documents and Settings\Administrator\桌面\26\kcien32.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:16870  MD5:40854577907e234ebbdf33a1d6bb45cc


[C:\Documents and Settings\Administrator\桌面\26\MMBAIKOK1100.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:11494  MD5:b020b00d3e1e6c196f3d1270ab523d36


[C:\Documents and Settings\Administrator\桌面\26\MMCBDKTK1086.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:10834  MD5:9c17302404e85e618c50a4f54d25f29a


[C:\Documents and Settings\Administrator\桌面\26\MMDXYBQE1040.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:10675  MD5:92460325c6c8f3fa60d4f9dd16cea575


[C:\Documents and Settings\Administrator\桌面\26\MMKAFNFW1110.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:11107  MD5:e02c6997dbf42aec9d4de0ca465c79dd


[C:\Documents and Settings\Administrator\桌面\26\MMMHXGGD1070.dll]
                    …………发现Spy!报告:[1] Win32.F/S.ByDwing
文件信息:  大小:11818  MD5:3428d060075c58126c9542273f36681c


文件数:22   病毒数:11  比重:0.5
OK  扫描完毕!

  ***日志解释
[4] 集中有害分析引擎
[3] 全局系统判断引擎   
[2] 文件特征码引擎
[1] 文件启发式引擎
醉一生爱妍
发表于 2008-7-5 19:40:01 | 显示全部楼层
已发现病毒数量: 22 nod
allinwonderi
发表于 2008-7-5 20:31:49 | 显示全部楼层

ArcaVir2008

[Scanning : C:\Download Files]


C:\Download Files\26.zip<ZIP>:ddserh.dll <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file0.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file1.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file2.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file3.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file4.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:ddserh.dll<DLLRES>:file5.exe <- Trojan.Psw.Onlinegames.Rxrb : No action
C:\Download Files\26.zip<ZIP>:Hdv32.sys <- Trojan.Gamethief.Onlinegames.Rxyi : No action
C:\Download Files\26.zip<ZIP>:MMCBDKTK1086.exe <- Trojan.Psw.Onlinegames.Aqta : No action
C:\Download Files\26.zip<ZIP>:MMCBDKTK1086.exe<UPack>:MMCBDKTK1086.exe<DLLRES>:res0.exe <- Trojan.Psw.Onlinegames.Argb : No action
C:\Download Files\26.zip<ZIP>:MMDXYBQE1040.dll <- Trojan.Gamethief.Onlinegames.Rxxx : No action
C:\Download Files\26.zip<ZIP>:MMDXYBQE1040.exe <- Trojan.Gamethief.Onlinegames.Rxxx : No action
C:\Download Files\26.zip<ZIP>:MMDXYBQE1040.exe<UPack>:MMDXYBQE1040.exe<DLLRES>:res0.exe <- Trojan.Gamethief.Onlinegames.Rxyi : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file0.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file1.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file2.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file3.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file4.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:wyhesm.dll<DLLRES>:file5.exe <- Trojan.Psw.Onlinegames.Rxwd : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file0.exe <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file1.exe <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file2.exe <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file3.exe <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file4.exe <- Trojan.Psw.Onlinegames.Rxon : No action
C:\Download Files\26.zip<ZIP>:zefdst.dll<DLLRES>:file5.exe <- Trojan.Psw.Onlinegames.Rxon : No action



Scanned objects : 103

Infected objects : 27
allinwonderi
发表于 2008-7-5 20:32:23 | 显示全部楼层

F-Prot 4.4.4

[Found security risk]         <W32/SYStroj.N.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->Hdv32.sys
[Found virus]         <W32/InfoStealer!Generic (not disinfectable)>        C:\Download Files\26.zip->jfrwdh.dll
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->kcien32.dll
[Found possible security risk]         <W32/Heuristic-257!Eldorado (not disinfectable)>        C:\Download Files\26.zip->kcien32.exe->(NSPack)->(PE_Patch)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMBAIKOK1100.dll->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMBAIKOK1100.exe->exefile->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMCBDKTK1086.dll->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMCBDKTK1086.exe->exefile->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMDXYBQE1040.dll->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMDXYBQE1040.exe->exefile->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMKAFNFW1110.dll->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMKAFNFW1110.exe->exefile->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMMHXGGD1070.dll->(UPack)
[Found security risk]         <W32/Agent.L.gen!Eldorado (not disinfectable, generic)>        C:\Download Files\26.zip->MMMHXGGD1070.exe->exefile->(UPack)
[Found virus]         <W32/InfoStealer!Generic (not disinfectable)>        C:\Download Files\26.zip->Windows64.Sys

---------------------------------------------------------------------
Scan ended:        2008-7-5, 20:32:11
Duration:        0:00:05

Scan result:

Scanned files:                 6
Infected objects:         15
Disinfected objects:         0
Quarantined files:         0
---------------------------------------------------------------------
qigang
发表于 2008-7-5 21:21:00 | 显示全部楼层

39/20

瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.PSW.Win32.GameOL.oof
病毒: Trojan.PSW.Win32.GameOL.ofz
病毒: RootKit.Win32.Undef.km   
病毒: Trojan.PSW.Win32.GameOL.oom
病毒: Trojan.PSW.Win32.GameOL.oog
病毒: Trojan.PSW.Win32.GameOL.oda
病毒: Trojan.PSW.Win32.XYOnline.afz
病毒: Trojan.PSW.Win32.GameOL.omf
病毒: Trojan.PSW.Win32.GameOL.oom
病毒: Trojan.PSW.Win32.GameOL.okz

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.51.52
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-23 01:24 , Processed in 0.077012 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表