查看: 4235|回复: 25
收起左侧

[病毒样本] 大量全新木馬!!

[复制链接]
sam.to
发表于 2008-9-10 23:32:45 | 显示全部楼层 |阅读模式
特地把卡巴不报的放上來!!

7aa7fc632ccfac14698818beed61e0b2  05.exe!
86ed502940c5b0eb9c8e88647231caa7  10(1).exe!
604c5435f0dab94b57433f4ccbc9ef49  15(1).exe!
948ba41ea73ab4f60ba12019f2ecfb30  22(1).exe!
a724ed3eb878006ac38dcecdb594d79e  28.exe!
6643389b4161f0aab011de273d15d0bf  aa10.exe!
2cc12ce4f06d6697ca7cd76bed87ee98  aa2.exe!
155b5e1074f2e68db20b81e222b31466  aa20.exe!
f83d73f33292bc3a235ee7549de42ed3  aa21.exe!
7b36b3ae1426c028efec598a40619888  aa38.exe!
c1442f7bbdabb838069765a40829df2e  aa6.exe!
ec33d6c38b438b7d7e1e5568da07fe5b  aa9.exe!
fe5aa4b87b8cbf6e4256fb2170e4171f  zzzx.exe!
已上报卡巴!!


Hello,

05.exe_ - Trojan-GameThief.Win32.OnLineGames.tfbw,
10(1).exe_ - Trojan-GameThief.Win32.OnLineGames.tfox,
15(1).exe_ - Trojan-GameThief.Win32.OnLineGames.tfll,
22(1).exe_ - Trojan-GameThief.Win32.OnLineGames.tflm,
28.exe_ - Trojan-GameThief.Win32.OnLineGames.tfmz,
aa10.exe_ - Trojan-GameThief.Win32.OnLineGames.temg,
aa2.exe_ - Trojan-GameThief.Win32.OnLineGames.tfco,
aa20.exe_ - Trojan-GameThief.Win32.OnLineGames.teti,
aa21.exe_ - Trojan-GameThief.Win32.OnLineGames.temi,
aa38.exe_ - Trojan-PSW.Win32.QQPass.dpo,
aa6.exe_ - Trojan-GameThief.Win32.OnLineGames.tfln,
aa9.exe_ - Trojan-GameThief.Win32.OnLineGames.tfoy,
zzzx.exe_ - Trojan-GameThief.Win32.OnLineGames.tfpa

These files are already detected. Please update your antivirus bases.

Please quote all when answering.

--
Best regards, Andrey Ladikov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: 412465214512.rar

[ 本帖最后由 kato9096 于 2008-9-12 16:44 编辑 ]
eyesineyes
发表于 2008-9-10 23:35:02 | 显示全部楼层
Start of the scan: 2008年9月10日  23:34

Starting the file scan:

Begin scan in 'D:\Downloads\firefox\412465214512.rar'
D:\Downloads\firefox\412465214512.rar
    [0] Archive type: RAR
    --> 412465214512\05.exe!
      [DETECTION] Is the TR/Onlinegames.tboi Trojan
    --> 412465214512\10(1).exe!
      [DETECTION] Is the TR/Onlinegames.tboe Trojan
    --> 412465214512\28.exe!
      [DETECTION] Is the TR/Onlinegames.tbod Trojan
    --> 412465214512\aa10.exe!
      [DETECTION] Is the TR/Onlinegames.tboi Trojan
      --> 412465214512\aa2.exe!
          [DETECTION] Is the TR/PSW.Online.Osh.2 Trojan
    --> 412465214512\aa20.exe!
      [DETECTION] Is the TR/Onlinegames.tbod Trojan
      --> 412465214512\aa6.exe!
          [DETECTION] Is the TR/PSW.Online.bin Trojan
    --> 412465214512\aa9.exe!
      [DETECTION] Is the TR/Onlinegames.tboe Trojan
    --> 412465214512\zzzx.exe!
      [DETECTION] Is the TR/Onlinegames.tboe Trojan
    [NOTE]      The file was moved to '48f9e924.qua'!


End of the scan: 2008年9月10日  23:34
Used time: 00:05 Minute(s)

The scan has been done completely.

      0 Scanning directories
     14 Files were scanned
     13 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      0 Warnings
      1 Notes
xyc529
发表于 2008-9-10 23:37:23 | 显示全部楼层
一解压全被红伞给灭了,红伞真是厉害!!
wangjay1980
发表于 2008-9-10 23:39:19 | 显示全部楼层
很牛吗?
972929
发表于 2008-9-10 23:51:43 | 显示全部楼层
诺顿和NOD均发现13个~
allinwonderi
发表于 2008-9-10 23:56:21 | 显示全部楼层

F-Prot 4.4.4

[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\05.exe!->(UPack)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\10(1).exe!->(UPack)
[发现密码盗取病毒: ]        <W32/OnlineGames.AS.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\15(1).exe!->(UPX)
[发现密码盗取病毒: ]        <W32/OnlineGames.AS.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\22(1).exe!->(UPX)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\28.exe!->(UPack)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa10.exe!->(UPack)
[发现密码盗取病毒: ]        <W32/OnlineGames.AQ!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa2.exe!->(UPX)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa20.exe!->(UPack)
[发现密码盗取病毒: ]        <W32/OnlineGames.AS.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa21.exe!->(UPX)
[发现安全风险: ]        <W32/AutoRun.D.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa38.exe!->(UPX)
[发现密码盗取病毒: ]        <W32/OnlineGames.AS.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa6.exe!->(UPX)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\aa9.exe!->(UPack)
[发现安全风险: ]        <W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\412465214512.rar->412465214512\zzzx.exe!->(UPack)
浪滔天
发表于 2008-9-11 00:24:58 | 显示全部楼层
卡8 高启发 剩下一个

2008-09-11 00:20:36        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\05.exe!               
2008-09-11 00:20:42        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\15(1).exe!               
2008-09-11 00:20:44        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\22(1).exe!               
2008-09-11 00:20:46        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\28.exe!               
2008-09-11 00:20:47        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\aa10.exe!               
2008-09-11 00:20:49        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\aa2.exe!               
2008-09-11 00:20:50        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\aa20.exe!               
2008-09-11 00:20:51        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\aa21.exe!               
2008-09-11 00:20:52        已被隔离        木马程序 Heur.Trojan.Generic        F:\病毒样本\412465214512.rar/412465214512\aa6.exe!               
2008-09-11 00:20:56        已清除病毒        木马程序 Trojan-GameThief.Win32.OnLineGames.tdwl        F:\病毒样本\412465214512.rar/412465214512\10(1).exe!//#               
2008-09-11 00:20:56        已清除病毒        木马程序 Trojan-GameThief.Win32.OnLineGames.tdwl        F:\病毒样本\412465214512.rar/412465214512\aa9.exe!//#               
2008-09-11 00:20:56        已清除病毒        木马程序 Trojan-GameThief.Win32.OnLineGames.tdwl        F:\病毒样本\412465214512.rar/412465214512\zzzx.exe!//#


剩下一个高危

[ 本帖最后由 浪滔天 于 2008-9-11 00:27 编辑 ]
barbara
发表于 2008-9-11 01:55:44 | 显示全部楼层
Comodo 启发全灭,有疑议的自己去点。
xuange
发表于 2008-9-11 04:39:43 | 显示全部楼层

AVG 11

\412465214512\05.exe!;"Trojan horse PSW.Generic6.ABHY"
\412465214512\10(1).exe!;"Trojan horse PSW.Generic6.ABBB"
\412465214512\15(1).exe!;"Trojan horse Agent_r.L"
\412465214512\22(1).exe!;"Trojan horse Agent_r.L"
\412465214512\aa10.exe!;"Trojan horse PSW.Generic6.ABHY"
\412465214512\aa20.exe!;"Trojan horse PSW.Generic6.ABED"
\412465214512\aa21.exe!;"Trojan horse Agent_r.L"
\412465214512\aa38.exe!;"Trojan horse PSW.Delf.CAW"
\412465214512\aa6.exe!;"Trojan horse Agent_r.L"
\412465214512\aa9.exe!;"Trojan horse PSW.Generic6.ABBB"
\412465214512\zzzx.exe!;"Trojan horse PSW.Generic6.ABBB"
zlq7zj
发表于 2008-9-11 12:03:33 | 显示全部楼层
没办法 还没下载 咖啡就报了~!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 12:32 , Processed in 0.134734 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表