查看: 6684|回复: 21
收起左侧

[病毒样本] 63 pics

[复制链接]
jimmyleo
发表于 2008-10-1 11:39:30 | 显示全部楼层 |阅读模式
63个更新 psw居多.

大家国庆愉快~~




http://xianexs.mail.qq.com/cgi-bin/downloadfilepart/svrid264/NDay.rar?svrid=264&fid=786f4b1a37a67b2388f3a4edcd4c7fe80cf395e757142bc1&&txf_fid=dfa79c3e978b6971b670731de146f6bcfc4e7734&&txf_sid=

提取码:0939b8ff



BitDefender = 56 + 1
G:\Security\Handle\1101a4f74f6150b4b94834fe67a85dbf.exe infected: Trojan.PWS.OnlineGames.ZUL
G:\Security\Handle\1523df4c91906a7141eea288a5badcb0.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\15dbf995ba1a333e81df53b0324ac402.exe infected: Dropped:Generic.Malware.SFdldg.FA956928
G:\Security\Handle\1db7c072da2648ce34d2b667e2435a71.exe infected: Dropped:Trojan.Generic.603631
G:\Security\Handle\1e23d1b66dc953fcaf65b071bceca0c0.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\2990420d65c5b7bffeadc77e7dd7bf23.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\2d9c7554428d7c30c1d58499af6b771b.exe infected: Trojan.PWS.OnlineGames.ZWU
G:\Security\Handle\2fb6aea3a1ed60ac04e6ea55dab188e4.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\3114ca55576ffad179b54c60979a4b7e.exe infected: Trojan.Generic.675959
G:\Security\Handle\33f5b63f4eac4d812a3e490b37540e42.exe infected: BehavesLike:Win32.ExplorerHijack
G:\Security\Handle\3efd9a2d950c9b0430bbb2fba0f324af.exe infected: Trojan.PWS.OnlineGames.ZWI
G:\Security\Handle\4626edb215d707a0b81d993e6c21e1a7.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\48c2ca65c51805a25e9e83fc54873604.exe infected: Trojan.PWS.OnlineGames.ZWN
G:\Security\Handle\4925d53655020eebe4e3d5340f1684db.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\4c41ed8a5a17b4bf8a34c36d246e6dcf.exe infected: Backdoor.Agent.ZVN
G:\Security\Handle\4cd991d7b7d9adda11cce9d34fe45c40.exe infected: Trojan.PWS.OnlineGames.ZWI
G:\Security\Handle\5dad8c52f84d397454adb6d6c25887fe.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\6311a91cfac8172d55add54445d349fa.exe infected: Trojan.Delf.PNE
G:\Security\Handle\67a606cb579e840eb57e5c4fbd916d3e.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\6975b2b0b35b6350a907dcc3a724bc4a.exe infected: Trojan.Dropper.OnlineGames.BA
G:\Security\Handle\6bd30dc457c1d7bff65dbdf5f7acc721.exe infected: Trojan.Dropper.OnlineGames.BA
G:\Security\Handle\6c8c55a95063d9bfb4c4fbf5eb2920ca.exe infected: Trojan.PWS.OnlineGames.ZYD
G:\Security\Handle\6ff762986a995e19ccec18a99bc43fde.exe infected: Trojan.PWS.OnlineGames.ZWN
G:\Security\Handle\71244123140653c1ec5b70c52a8b7d40.exe infected: Trojan.PWS.OnlineGames.ZMC
G:\Security\Handle\72ea3b45b5d105a71168fc7afe30408d.exe infected: Dropped:Trojan.Inject.RL
G:\Security\Handle\7cec558f5e0fedfab291be4ce6ded449.exe infected: Dropped:Trojan.Inject.RL
G:\Security\Handle\815a793235935ffc0e81a4846f189847.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\910375dca3f4de9ae9e7a88b8575db90.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\919376960226d5034decdd79b42baadf.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\92ea8303564177b41504f00f353033b3.jpg suspected: Dropped:Generic.Malware.dld!.323FAFCA
G:\Security\Handle\9f1f2917be2ef168339991d0fd685920.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\a7e9cecd37710127042e161d56e71b92.exe infected: Trojan.PWS.OnlineGames.ZTZ
G:\Security\Handle\a866b332f85d8ae71c003a4b4e7d13d7.exe infected: Trojan.PWS.OnlineGames.ZXJ
G:\Security\Handle\aa06c23f81625458d73b781510af4240.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\aceb7a11140b3a87e258a47ec9c1a004.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\b04c906636140db861b9b6a903034039.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\b5b4f2d7c92ceeef8cb42850aa5dd3dd.exe infected: Trojan.Generic.658846
G:\Security\Handle\b836b9a39f233b37f154b4ad95533e35.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\c0fc2bbe7c39cff31d6ba4ec594caed3.exe infected: Trojan.PWS.OnlineGames.ZWI
G:\Security\Handle\c2762342e584ab7d5cf31fc6ff497aca.exe infected: Dropped:Generic.PWStealer.01DC5B44
G:\Security\Handle\c6b5a55852d225a01cfd42b55e38a711.exe infected: Generic.FWB.2924D7B2
G:\Security\Handle\cd54addebd2ebff1b837c81b1a81dedb.exe infected: Trojan.PWS.OnlineGames.ZWU
G:\Security\Handle\da1c247b1e4b7e80b232c3c20695eca6.exe infected: Trojan.Dropper.OnlineGames.BA
G:\Security\Handle\df965945ae488f9291f5e263c0e1718f.exe infected: Trojan.Crypt.DG
G:\Security\Handle\e25e5d2711a7fde568a2b703923f4ddc.exe infected: Trojan.PWS.OnlineGames.ZWU
G:\Security\Handle\e2afcadb0aa2324addc7b21865c34fec.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\e394cb604b1708801a6ef79ac3fa55f6.exe infected: Trojan.PWS.OnlineGames.ZWL
G:\Security\Handle\e61692f8875d714c029cbdceed785b79.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\e8ef3a683592468506973ff70712471f.exe infected: Dropped:Generic.PWStealer.01DC5B44
G:\Security\Handle\ebe1f19a1eabec513d7dc5e0234a7e08.exe infected: Trojan.PWS.OnlineGames.ZXK
G:\Security\Handle\ec13f7aafb5ce35202dcdd5cb91b5107.exe infected: Dropped:Trojan.PWS.OnlineGames.OPB
G:\Security\Handle\f046530c85a2b04845ebdcacef928ae3.exe infected: Trojan.PWS.OnlineGames.ZWU
G:\Security\Handle\f06cbb09c8055f56ec2d76ba2b7282de.exe infected: Generic.PWStealer.DF6E5BCE
G:\Security\Handle\f3a109fae853af1af49ad38191a91a81.exe infected: Trojan.PWS.WoW.NDP
G:\Security\Handle\f7f7c528dd82286a347b3b8dcf9f7736.exe infected: Trojan.PWS.Lmir.UMH
G:\Security\Handle\fea65a1da07ed702d8ca537726772331.exe infected: Trojan.PWS.OnlineGames.ZXA
G:\Security\Handle\fff912e7ec1bafcf52349092d3bdd7d0.exe infected: Trojan.Generic.718717
Kitman
发表于 2008-10-1 11:48:09 | 显示全部楼层
Begin scan in 'C:\Users\TOSHIBA\Downloads\NDay'
C:\Users\TOSHIBA\Downloads\NDay\1101a4f74f6150b4b94834fe67a85dbf.exe
    [DETECTION] Is the TR/Killav.abn.3 Trojan
    [NOTE]      A backup was created as '4912f2c6.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\1523df4c91906a7141eea288a5badcb0.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4914f2ca.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\15dbf995ba1a333e81df53b0324ac402.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4946f2ca.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\1db7c072da2648ce34d2b667e2435a71.exe
    [DETECTION] Is the TR/Dldr.Malwar.C Trojan
    [NOTE]      A backup was created as '4944f2f9.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\1e23d1b66dc953fcaf65b071bceca0c0.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4914f2fb.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\2990420d65c5b7bffeadc77e7dd7bf23.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '491bf2cf.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\2d9c7554428d7c30c1d58499af6b771b.exe
      [DETECTION] Is the TR/PSW.OnLineGa.aqq Trojan
    [NOTE]      A backup was created as '491bf2fa.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\2fb6aea3a1ed60ac04e6ea55dab188e4.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4944f2fd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\3114ca55576ffad179b54c60979a4b7e.exe
    [DETECTION] Contains recognition pattern of the RKIT/Agent.18560 root kit
    [NOTE]      A backup was created as '4913f2c8.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\33f5b63f4eac4d812a3e490b37540e42.exe
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4948f2ca.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\3efd9a2d950c9b0430bbb2fba0f324af.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4948f2fc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\4626edb215d707a0b81d993e6c21e1a7.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4914f2ce.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\48c2ca65c51805a25e9e83fc54873604.exe
    [DETECTION] Is the TR/Hijacker.Gen Trojan
    [NOTE]      A backup was created as '4945f2d0.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\4925d53655020eebe4e3d5340f1684db.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.OnLineGames.thvu Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4914f2d1.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\4c41ed8a5a17b4bf8a34c36d246e6dcf.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4916f2fb.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\4cd991d7b7d9adda11cce9d34fe45c40.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4946f2fc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\5dad8c52f84d397454adb6d6c25887fe.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4943f2fd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\6311a91cfac8172d55add54445d349fa.exe
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.Wow.ccc Trojan
    [NOTE]      A backup was created as '4913f2cc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\67a606cb579e840eb57e5c4fbd916d3e.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4943f2d0.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\6975b2b0b35b6350a907dcc3a724bc4a.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4919f2d2.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\6bd30dc457c1d7bff65dbdf5f7acc721.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4946f2fb.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\6c8c55a95063d9bfb4c4fbf5eb2920ca.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '491af2fd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\6ff762986a995e19ccec18a99bc43fde.exe
    [DETECTION] Is the TR/Hijacker.Gen Trojan
    [NOTE]      A backup was created as '4948f300.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\71244123140653c1ec5b70c52a8b7d40.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4914f2cb.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\72ea3b45b5d105a71168fc7afe30408d.exe
    [DETECTION] Contains recognition pattern of the DR/Inject.ifp dropper
    [NOTE]      A backup was created as '4947f2cc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\7cec558f5e0fedfab291be4ce6ded449.exe
    [DETECTION] Is the TR/Hook.Shell.664 Trojan
    [NOTE]      A backup was created as '4947f2fd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\815a793235935ffc0e81a4846f189847.exe
    [DETECTION] Is the TR/PSW.Lmir.UMN Trojan
    [NOTE]      A backup was created as '4917f2cb.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\8552d31a1dd4e16df3212c9dfa5e301f.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4917f2d0.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\8f9f7122fa603f96a92e43a650569187.exe
    [DETECTION] Is the TR/ATRAPS.Gen Trojan
    [NOTE]      A backup was created as '491bf301.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\910375dca3f4de9ae9e7a88b8575db90.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4912f2cc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\919376960226d5034decdd79b42baadf.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '491bf2cc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\92ea8303564177b41504f00f353033b3.jpg
      [DETECTION] Contains a recognition pattern of the (harmful) BDS/Backdoor.Gen back-door program
    [NOTE]      A backup was created as '4947f2cd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\9f1f2917be2ef168339991d0fd685920.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4913f301.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\a7e9cecd37710127042e161d56e71b92.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4947f2d3.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\a866b332f85d8ae71c003a4b4e7d13d7.exe
    [DETECTION] Is the TR/ATRAPS.Gen Trojan
    [NOTE]      A backup was created as '4918f2d4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\aa06c23f81625458d73b781510af4240.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.OnLineGames.thvu Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4912f2fd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\ab7b4aad78ce744f337065963648e3f2.exe
    [0] Archive type: RSRC
    --> Object
      [DETECTION] Contains a recognition pattern of the (harmful) BDS/Backdoor.Gen back-door program
    [NOTE]      A backup was created as '4919f2fe.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\aceb7a11140b3a87e258a47ec9c1a004.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4947f2ff.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\b04c906636140db861b9b6a903034039.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4916f2cc.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\b5b4f2d7c92ceeef8cb42850aa5dd3dd.exe
    [DETECTION] Is the TR/Dldr.Delf.mny Trojan
    [NOTE]      A backup was created as '4944f2d1.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\b836b9a39f233b37f154b4ad95533e35.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4915f2d5.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\c0fc2bbe7c39cff31d6ba4ec594caed3.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4948f2cd.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\c2762342e584ab7d5cf31fc6ff497aca.exe
    [DETECTION] Contains recognition pattern of the DR/Inject.ifs dropper
    [NOTE]      A backup was created as '4919f2cf.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\c6b5a55852d225a01cfd42b55e38a711.exe
    [DETECTION] Is the TR/Crypt.NSPM.Gen Trojan
    [NOTE]      A backup was created as '4944f2d3.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\cd54addebd2ebff1b837c81b1a81dedb.exe
      [DETECTION] Is the TR/PSW.Online.bin Trojan
    [NOTE]      A backup was created as '4917f301.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\da1c247b1e4b7e80b232c3c20695eca6.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4913f2fe.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\df965945ae488f9291f5e263c0e1718f.exe
    [DETECTION] Contains recognition pattern of the DR/PcClient.Gen dropper
    [NOTE]      A backup was created as '491bf303.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e25e5d2711a7fde568a2b703923f4ddc.exe
    [DETECTION] Is the TR/Hijacker.Gen Trojan
    [NOTE]      A backup was created as '4917f2cf.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e2afcadb0aa2324addc7b21865c34fec.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4943f2cf.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e394cb604b1708801a6ef79ac3fa55f6.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '491bf2d1.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e61692f8875d714c029cbdceed785b79.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4913f2d4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e6297f55291f61cb20a0317fa5f7bbb2.jpg
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4914f2d4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\e8ef3a683592468506973ff70712471f.exe
    [DETECTION] Contains recognition pattern of the DR/Dldr.BHO.UN dropper
    [NOTE]      A backup was created as '4947f2d6.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\ebe1f19a1eabec513d7dc5e0234a7e08.exe
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4947f300.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\ec13f7aafb5ce35202dcdd5cb91b5107.exe
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      A backup was created as '4a8c558a.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\f046530c85a2b04845ebdcacef928ae3.exe
      [DETECTION] Is the TR/PSW.Online.bin Trojan
    [NOTE]      A backup was created as '4916f2ce.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\f06cbb09c8055f56ec2d76ba2b7282de.exe
    [DETECTION] Is the TR/ATRAPS.Gen Trojan
    [NOTE]      A backup was created as '4918f2ce.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\f3a109fae853af1af49ad38191a91a81.exe
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.Wow.cam Trojan
    [NOTE]      A backup was created as '4943f2d1.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\f7f7c528dd82286a347b3b8dcf9f7736.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4948f2d6.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\fea65a1da07ed702d8ca537726772331.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      A backup was created as '4943f304.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
C:\Users\TOSHIBA\Downloads\NDay\fff912e7ec1bafcf52349092d3bdd7d0.exe
      [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      A backup was created as '4948f305.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2008年10月1日  11:46
Used time: 00:14 Minute(s)

The scan has been done completely.

      1 Scanning directories
     63 Files were scanned
     71 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
     61 files were deleted
      0 files were repaired
     61 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -9 Files not concerned
      0 Archives were scanned
      0 Warnings
     61 Notes
小邪邪
发表于 2008-10-1 11:50:50 | 显示全部楼层
漏了2个了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Kitman
发表于 2008-10-1 11:54:44 | 显示全部楼层
2+1heur
File ID         Filename         Size (Byte)        Result
25148863         5a9d7685a3bacff29...be.exe         378 KB         UNDER ANALYSIS
25148864         6a4d09110d0468008...fa.exe         342 KB         UNDER ANALYSIS
25148865         fff912e7ec1bafcf5...d0.exe         6.11 KB         UNDER ANALYSIS

[ 本帖最后由 Kitman 于 2008-10-1 11:56 编辑 ]
hj5abc
发表于 2008-10-1 11:56:03 | 显示全部楼层
50.




[ 本帖最后由 hj5abc 于 2008-10-1 11:58 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
comehere
发表于 2008-10-1 11:56:14 | 显示全部楼层
我的mcafee 8.7 标准库 只扫描到54 启发开到最高

[ 本帖最后由 comehere 于 2008-10-1 11:57 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
fatezero
发表于 2008-10-1 11:57:38 | 显示全部楼层
卡巴漏了一个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1688388728
发表于 2008-10-1 11:57:53 | 显示全部楼层
检测选中目录和文件:
  C:\Documents and Settings\Administrator\桌面\NDay\

项目: 1101a4f74f6150b4b94834fe67a85dbf.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZUL (Engine A)
项目: 1523df4c91906a7141eea288a5badcb0.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: 15dbf995ba1a333e81df53b0324ac402.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Generic.Malware.SFdldg.FA956928 (Engine A)
项目: 1db7c072da2648ce34d2b667e2435a71.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Trojan.Generic.603631 (Engine A)
项目: 1e23d1b66dc953fcaf65b071bceca0c0.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 2990420d65c5b7bffeadc77e7dd7bf23.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 2d9c7554428d7c30c1d58499af6b771b.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWU (Engine A)
项目: 2fb6aea3a1ed60ac04e6ea55dab188e4.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 3114ca55576ffad179b54c60979a4b7e.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Generic.675959 (Engine A)
项目: 33f5b63f4eac4d812a3e490b37540e42.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: BehavesLike:Win32.ExplorerHijack (Engine A)
项目: 3efd9a2d950c9b0430bbb2fba0f324af.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWI (Engine A)
项目: 4626edb215d707a0b81d993e6c21e1a7.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 48c2ca65c51805a25e9e83fc54873604.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWN (Engine A)
项目: 4925d53655020eebe4e3d5340f1684db.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: 4c41ed8a5a17b4bf8a34c36d246e6dcf.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Backdoor.Agent.ZVN (Engine A)
项目: 4cd991d7b7d9adda11cce9d34fe45c40.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWI (Engine A)
项目: 5dad8c52f84d397454adb6d6c25887fe.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: 6311a91cfac8172d55add54445d349fa.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Delf.PNE (Engine A)
项目: 67a606cb579e840eb57e5c4fbd916d3e.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 6975b2b0b35b6350a907dcc3a724bc4a.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Dropper.OnlineGames.BA (Engine A)
项目: 6bd30dc457c1d7bff65dbdf5f7acc721.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Dropper.OnlineGames.BA (Engine A)
项目: 6c8c55a95063d9bfb4c4fbf5eb2920ca.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZYD (Engine A)
项目: 6ff762986a995e19ccec18a99bc43fde.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWN (Engine A)
项目: 71244123140653c1ec5b70c52a8b7d40.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZMC (Engine A)
项目: 72ea3b45b5d105a71168fc7afe30408d.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Trojan.Inject.RL (Engine A)
项目: 7cec558f5e0fedfab291be4ce6ded449.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Trojan.Inject.RL (Engine A)
项目: 815a793235935ffc0e81a4846f189847.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 8552d31a1dd4e16df3212c9dfa5e301f.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Win32:Trojan-gen {Other} (Engine B)
项目: 910375dca3f4de9ae9e7a88b8575db90.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: 919376960226d5034decdd79b42baadf.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: 92ea8303564177b41504f00f353033b3.jpg
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Win32:Agent-ZRK [Trj] (Engine B)
项目: 9f1f2917be2ef168339991d0fd685920.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: a7e9cecd37710127042e161d56e71b92.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZTZ (Engine A)
项目: a866b332f85d8ae71c003a4b4e7d13d7.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZXJ (Engine A)
项目: aa06c23f81625458d73b781510af4240.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: ab7b4aad78ce744f337065963648e3f2.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Win32:Trojan-gen {Other} (Engine B)
项目: aceb7a11140b3a87e258a47ec9c1a004.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: b04c906636140db861b9b6a903034039.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: b5b4f2d7c92ceeef8cb42850aa5dd3dd.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Generic.658846 (Engine A)
项目: b836b9a39f233b37f154b4ad95533e35.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: c0fc2bbe7c39cff31d6ba4ec594caed3.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWI (Engine A)
项目: c2762342e584ab7d5cf31fc6ff497aca.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Generic.PWStealer.01DC5B44 (Engine A)
项目: c6b5a55852d225a01cfd42b55e38a711.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Generic.FWB.2924D7B2 (Engine A)
项目: cd54addebd2ebff1b837c81b1a81dedb.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWU (Engine A)
项目: da1c247b1e4b7e80b232c3c20695eca6.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Dropper.OnlineGames.BA (Engine A)
项目: df965945ae488f9291f5e263c0e1718f.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Crypt.DG (Engine A)
项目: e25e5d2711a7fde568a2b703923f4ddc.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWU (Engine A)
项目: e2afcadb0aa2324addc7b21865c34fec.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: e394cb604b1708801a6ef79ac3fa55f6.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWL (Engine A)
项目: e61692f8875d714c029cbdceed785b79.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: e6297f55291f61cb20a0317fa5f7bbb2.jpg
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Win32:Trojan-gen {Other} (Engine B)
项目: e8ef3a683592468506973ff70712471f.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Generic.PWStealer.01DC5B44 (Engine A)
项目: ebe1f19a1eabec513d7dc5e0234a7e08.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZXK (Engine A)
项目: ec13f7aafb5ce35202dcdd5cb91b5107.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Dropped:Trojan.PWS.OnlineGames.OPB (Engine A)
项目: f046530c85a2b04845ebdcacef928ae3.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZWU (Engine A)
项目: f06cbb09c8055f56ec2d76ba2b7282de.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Generic.PWStealer.DF6E5BCE (Engine A)
项目: f3a109fae853af1af49ad38191a91a81.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.WoW.NDP (Engine A)
项目: f7f7c528dd82286a347b3b8dcf9f7736.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.Lmir.UMH (Engine A)
项目: fea65a1da07ed702d8ca537726772331.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.PWS.OnlineGames.ZXA (Engine A)
项目: fff912e7ec1bafcf52349092d3bdd7d0.exe
        路径: C:\Documents and Settings\Administrator\桌面\NDay
        状态: 病毒无法清除
        病毒: Trojan.Generic.718717 (Engine A)

检测执行时间: 01.10.2008 11:55
    已检测 63 个文件
    已发现 60 个病毒文件
    已发现 0 个可疑文件
1688388728
发表于 2008-10-1 12:02:35 | 显示全部楼层

还漏2个

C:\Documents and Settings\Administrator\桌面\NDay\8f9f7122fa603f96a92e43a650569187.exe - 已感染 Trojan.DownLoader.origin

[ 本帖最后由 1688388728 于 2008-10-1 12:06 编辑 ]
qianwenxiang
发表于 2008-10-1 12:07:33 | 显示全部楼层
__Velim Lite 4 (未完成版本)扫描日志__
1101a4f74f6150b4b94834fe67a85dbf.exe-TR.REPWS.SerA.QZT[模式1]-已忽略
2d9c7554428d7c30c1d58499af6b771b.exe-TR.PSW.SerJC.ibz[模式2]-已忽略
4925d53655020eebe4e3d5340f1684db.exe-TR.PSW.SerJC.vif[模式2]-已忽略
6c8c55a95063d9bfb4c4fbf5eb2920ca.exe-VIR.MC.Vance.a[模式2]-已忽略
815a793235935ffc0e81a4846f189847.exe-TR.Crypt.TQW[模式1]-已忽略
aa06c23f81625458d73b781510af4240.exe-TR.PSW.SerJC.aej[模式2]-已忽略
b5b4f2d7c92ceeef8cb42850aa5dd3dd.exe-ASM:Malware-gen2[Crypt][模式6]-已忽略
e394cb604b1708801a6ef79ac3fa55f6.exe-VIR.MC.Vance.a[模式2]-已忽略
e6297f55291f61cb20a0317fa5f7bbb2.jpg-TR.Admixture.28E[模式1]-已忽略
 ̄ ̄日志生成完毕@2008-10-1 12:07:02 ̄ ̄
__其中发现了以下已知安全的文件__

 ̄ ̄附加信息输出完毕@2008-10-1 12:07:02 ̄ ̄
  nine 飘过..
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-10 13:15 , Processed in 0.193354 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表