查看: 1976|回复: 9
收起左侧

[已鉴定] PCSL 可疑恶意网站每日分析 20081030

 关闭 [复制链接]
lanvin
发表于 2008-10-30 00:41:04 | 显示全部楼层 |阅读模式
  1. http://61.160.213.143/wl.css
  2. http://61.160.213.143/ma/cw01.exe
  3. http://61.160.213.143/ma/cw02.exe
  4. http://61.160.213.143/ma/cw03.exe
  5. http://61.160.213.143/ma/cw04.exe
  6. http://61.160.213.143/ma/cw05.exe
  7. http://61.160.213.143/ma/cw06.exe
  8. http://61.160.213.143/ma/cw07.exe
  9. http://61.160.213.143/ma/cw08.exe
  10. http://61.160.213.143/ma/cw09.exe
  11. http://61.160.213.143/ma/cw10.exe
  12. http://61.160.213.143/ma/cw11.exe
  13. http://61.160.213.143/ma/cw12.exe
  14. http://61.160.213.143/ma/cw13.exe
  15. http://61.160.213.143/ma/cw14.exe
  16. http://61.160.213.143/ma/cw15.exe
  17. http://61.160.213.143/ma/cw16.exe
  18. http://61.160.213.143/ma/cw17.exe
  19. http://61.160.213.143/ma/cw18.exe
  20. http://61.160.213.143/ma/cw19.exe
  21. http://61.160.213.143/ma/cw20.exe
  22. http://61.160.213.143/ma/cw21.exe
  23. http://61.160.213.143/ma/cw22.exe
  24. http://61.160.213.143/ma/cw23.exe
  25. http://61.160.213.143/ma/cw24.exe
  26. http://61.160.213.143/ma/cw25.exe
  27. http://61.160.213.143/ma/cw26.exe
  28. http://61.160.213.143/ma/cw27.exe
  29. http://61.160.213.143/ma/cw28.exe
  30. http://61.160.213.143/ma/cw29.exe
  31. http://61.160.213.143/ma/cw30.exe
复制代码
嘁。不稀罕~
发表于 2008-10-30 00:49:51 | 显示全部楼层
沙发。。。
2008-10-30_004820.PNG
2008-10-30_004905.PNG
lanvin
 楼主| 发表于 2008-10-30 00:52:17 | 显示全部楼层
阿贝喜欢美国的东西
fzz8848
头像被屏蔽
发表于 2008-10-30 01:50:35 | 显示全部楼层
打包上传
20081030.part1.rar (351.56 KB, 下载次数: 104)

评分

参与人数 1经验 +10 收起 理由
lanvin + 10 版区有你更精彩: )

查看全部评分

嘁。不稀罕~
发表于 2008-10-30 01:59:25 | 显示全部楼层
扫描结果。。。
2008-10-30_015830.PNG
mofunzone
发表于 2008-10-30 02:12:01 | 显示全部楼层
全灭

Starting the file scan:

Begin scan in 'C:\TDDOWNLOAD\wl.css'
C:\TDDOWNLOAD\
  wl.css
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw01.exe'
C:\TDDOWNLOAD\
  cw01.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw02.exe'
C:\TDDOWNLOAD\
  cw02.exe
    [0] Archive type: Runtime Packed
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.MultiFirst.R Trojan
          [WARNING]   Infected files in archives cannot be repaired!
        --> Object
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw03.exe'
C:\TDDOWNLOAD\
  cw03.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw04.exe'
C:\TDDOWNLOAD\
  cw04.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw05.exe'
C:\TDDOWNLOAD\
  cw05.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw06.exe'
C:\TDDOWNLOAD\
  cw06.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw07.exe'
C:\TDDOWNLOAD\
  cw07.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw08.exe'
C:\TDDOWNLOAD\
  cw08.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw09.exe'
C:\TDDOWNLOAD\
  cw09.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.Magania.ainu Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw10.exe'
C:\TDDOWNLOAD\
  cw10.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.Magania.ahzn Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw11.exe'
C:\TDDOWNLOAD\
  cw11.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw12.exe'
C:\TDDOWNLOAD\
  cw12.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw13.exe'
C:\TDDOWNLOAD\
  cw13.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw14.exe'
C:\TDDOWNLOAD\
  cw14.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw15.exe'
C:\TDDOWNLOAD\
  cw15.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw16.exe'
C:\TDDOWNLOAD\
  cw16.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw17.exe'
C:\TDDOWNLOAD\
  cw17.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw18.exe'
C:\TDDOWNLOAD\
  cw18.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw19.exe'
C:\TDDOWNLOAD\
  cw19.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.Magania.ainu Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw20.exe'
C:\TDDOWNLOAD\
  cw20.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw21.exe'
C:\TDDOWNLOAD\
  cw21.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw22.exe'
C:\TDDOWNLOAD\
  cw22.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw23.exe'
C:\TDDOWNLOAD\
  cw23.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw24.exe'
C:\TDDOWNLOAD\
  cw24.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw25.exe'
C:\TDDOWNLOAD\
  cw25.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw26.exe'
C:\TDDOWNLOAD\
  cw26.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw27.exe'
C:\TDDOWNLOAD\
  cw27.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.Magania.ainu Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw28.exe'
C:\TDDOWNLOAD\
  cw28.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw29.exe'
C:\TDDOWNLOAD\
  cw29.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/Thief.Magania.ainu Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!
Begin scan in 'C:\TDDOWNLOAD\cw30.exe'
C:\TDDOWNLOAD\
  cw30.exe
    [0] Archive type: OVL
      --> Object
        [1] Archive type: Runtime Packed
        --> Object
      --> Object
        [1] Archive type: RSRC
        --> Object
          [DETECTION] Is the TR/PSW.OnlineGames.ZWI.3 Trojan
          [WARNING]   Infected files in archives cannot be repaired!
    [DETECTION] Is the TR/Spy.Gen Trojan
    [NOTE]      The file was deleted!


End of the scan: 2008年10月29日  11:11
Used time: 00:06 Minute(s)

The scan has been done completely.

      0 Scanning directories
     31 Files were scanned
     58 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
     31 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
    -27 Files not concerned
      0 Archives were scanned
     28 Warnings
     31 Notes
granthill
发表于 2008-10-30 10:11:02 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw01.exe - Win32/PSW.OnLineGames.NRF 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw02.exe - Win32/PSW.OnLineGames.NRF 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw03.exe - Win32/TrojanDropper.Agent.NMA 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw04.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw05.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw06.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw07.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw08.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw09.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw10.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw11.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw12.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw13.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw14.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw15.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw16.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw17.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw18.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw19.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw20.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw21.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw22.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw23.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw24.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw25.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw26.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw27.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw28.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw29.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\cw30.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种 - 通过删除清除 - 已隔离
C:\Documents and Settings\Administrator\桌面\20081030\20081030\wl.css - Win32/TrojanDownloader.Agent.OBQ 特洛伊木马 的变种 - 通过删除清除 - 已隔离
hzyw
头像被屏蔽
发表于 2008-10-30 12:46:40 | 显示全部楼层
a.jpg

b.jpg
will
发表于 2008-10-30 12:53:01 | 显示全部楼层

Multi Command-Line Scanner Report
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw01.exe   
MD5 Hash: D6787AC81484DE5747485CFFD5B348DA   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-PWS.Win32.Agent.hf!IK    
Avast ----- Win32:Trojan-gen {Other}    
Avg ----- PSW.OnlineGames.BELB     
Antivir ----- TR/Dropper.Gen    
BitDefender ----- Trojan.PWS.Agent.SGC    
ClamWin ----- Trojan.Starter-12    
Dr.Web ----- Trojan.MulDrop.20110    
NOD32 ----- Win32/PSW.OnLineGames.NRF trojan    
Ikarus ----- Trojan-PWS.Win32.Agent.hf    
Jiangmin ----- TrojanSpy.OnLineGames.fbd    
Kaspersky ----- Trojan-GameThief.Win32.Magania.afzm    
Kingsoft ----- Win32.Troj.OnlineGamesT.ty.110709    
Vba32 ----- Win32.PSW.OnLineGames.NRF    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw02.exe   
MD5 Hash: 75230C4239F45FF18C38CA279D54ACDC   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-PWS.Win32.Agent.hf!IK    
Avast ----- Win32:Trojan-gen {Other}    
Avg ----- PSW.Generic6.ANCI     
Antivir ----- TR/PSW.MultiFirst.R    
BitDefender ----- Trojan.PWS.Agent.SGC    
ClamWin ----- Trojan.Starter-12    
Dr.Web ----- Trojan.PWS.Wsgame.8235    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRF trojan    
Ikarus ----- Trojan-PWS.Win32.Agent.hf    
Jiangmin ----- Nothing   
Kaspersky ----- Trojan-GameThief.Win32.OnLineGames.tqly    
Kingsoft ----- Win32.Troj.OnlineGames.fd.126993    
Vba32 ----- Nothing   

*** 11/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw03.exe   
MD5 Hash: 308D1947652329562E1B042FDA9D0814   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-PWS.Win32.Agent.hf!IK    
Avast ----- Nothing   
Avg ----- Generic11.BIJF     
Antivir ----- TR/Dropper.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AABK    
ClamWin ----- Nothing   
Dr.Web ----- Nothing   
NOD32 ----- a variant of Win32/TrojanDropper.Agent.NMA trojan    
Ikarus ----- Trojan-PWS.Win32.Agent.hf    
Jiangmin ----- Nothing   
Kaspersky ----- Trojan-GameThief.Win32.Magania.aiak    
Kingsoft ----- Nothing   
Vba32 ----- Nothing   

*** 7/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw04.exe   
MD5 Hash: D993935ABE0DFBE9F7E8F9FFDA78BB33   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw05.exe   
MD5 Hash: B040DEDD8C181289872D118BE1459C80   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- Nothing   
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 8/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw06.exe   
MD5 Hash: F499702A4EDA4C01E71743CFBC26E75B   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- Nothing   
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 8/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw07.exe   
MD5 Hash: E450287293E0917761BB22A55496C27E   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw08.exe   
MD5 Hash: 4A87E12117EEF5CFD19CB7D29064129E   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw09.exe   
MD5 Hash: 9B4F96834E89DCD55EBAEC036FCC2009   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Rootkit-gen [Rtk]    
Avg ----- PSW.OnlineGames.BEJR     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AACR    
ClamWin ----- Trojan.Mono-9    
Dr.Web ----- Trojan.PWS.Wsgame.8118    
NOD32 ----- Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.isj    
Kaspersky ----- Trojan.Win32.Agent.airl    
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Trojan-GameThief.Win32.OnLineGames.tptl    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw10.exe   
MD5 Hash: 79878CE7107FD6F9627C050DC70974AB   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Rootkit-gen [Rtk]    
Avg ----- Agent.AHHO     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AABO    
ClamWin ----- Trojan.Mono-9    
Dr.Web ----- Trojan.PWS.Wsgame.8118    
NOD32 ----- Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.isj    
Kaspersky ----- Trojan-GameThief.Win32.OnLineGames.tptl    
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Trojan-GameThief.Win32.OnLineGames.tptl    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw11.exe   
MD5 Hash: 322BEECA3349BBADA9238DFDDEB22FDB   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- Nothing   
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 8/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw12.exe   
MD5 Hash: 0B7122556E8FA9E1B965E85BA2A5FB2B   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw13.exe   
MD5 Hash: C46DDBE39BFA671A82FD06390458265D   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw14.exe   
MD5 Hash: 94DEB11077C4914E981B4B30BE669EF4   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw15.exe   
MD5 Hash: 48186D1C974985C365E81116B5346D1F   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw16.exe   
MD5 Hash: 65D1D0F3FC88D70E0B21E402807FA06E   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- Nothing   
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 8/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw17.exe   
MD5 Hash: 544C6752901EC3E205DC88E976A0C2DB   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw18.exe   
MD5 Hash: 1236D7151856C472D701E510DA34A4F9   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw19.exe   
MD5 Hash: 1ABF6324E58295AF355511CE7E7D276D   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Rootkit-gen [Rtk]    
Avg ----- PSW.OnlineGames.BEJR     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AACR    
ClamWin ----- Trojan.Mono-9    
Dr.Web ----- Trojan.PWS.Wsgame.8118    
NOD32 ----- Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.isj    
Kaspersky ----- Trojan.Win32.Agent.airl    
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Trojan-GameThief.Win32.OnLineGames.tptl    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw20.exe   
MD5 Hash: 61DD876E9FDD387A00016E964389C652   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw21.exe   
MD5 Hash: CB49AB535461986DB92F3AA097BBAF75   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- Nothing   
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 8/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw22.exe   
MD5 Hash: 2420343479B5446012BD211757D5624A   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw23.exe   
MD5 Hash: 426B2D9772590733CDAAA25F4DF43214   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw24.exe   
MD5 Hash: F666DEE0E81996492BD28C8821F99E72   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw25.exe   
MD5 Hash: 4D2D9060A476DCCBBDB107FE66F24F5D   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw26.exe   
MD5 Hash: 25F315A9931EB0555813E707B59982A2   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw27.exe   
MD5 Hash: 536FC96084116E82B75EBDFC397A30E9   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Rootkit-gen [Rtk]    
Avg ----- PSW.OnlineGames.BEJR     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AACR    
ClamWin ----- Trojan.Mono-9    
Dr.Web ----- Trojan.PWS.Wsgame.8118    
NOD32 ----- Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.isj    
Kaspersky ----- Trojan.Win32.Agent.airl    
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Trojan-GameThief.Win32.OnLineGames.tptl    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw28.exe   
MD5 Hash: FCD4A4ED83E34FC1B7D8F5518022CC68   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw29.exe   
MD5 Hash: 29EDD710CAC44FB4E16E2200A63C17EC   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Rootkit-gen [Rtk]    
Avg ----- PSW.OnlineGames.BEJR     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Trojan.PWS.OnlineGames.AACR    
ClamWin ----- Trojan.Mono-9    
Dr.Web ----- Trojan.PWS.Wsgame.8118    
NOD32 ----- Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.isj    
Kaspersky ----- Trojan.Win32.Agent.airl    
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Trojan-GameThief.Win32.OnLineGames.tptl    

*** 13/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\cw30.exe   
MD5 Hash: 94855500660BD1AF6D4F8A012FCC7A81   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Nothing   
Avg ----- PSW.OnlineGames.BFEK     
Antivir ----- TR/Spy.Gen    
BitDefender ----- Nothing   
ClamWin ----- Trojan.Spy-54879    
Dr.Web ----- MULDROP.Trojan    
NOD32 ----- a variant of Win32/PSW.OnLineGames.NRD trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanSpy.OnLineGames.euu    
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGamesT.vy.90588    
Vba32 ----- Nothing   

*** 9/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\wl.css   
MD5 Hash: D17B4420224536C3FB06286AC1D7A8C0   
Type: DOS Executable Generic / Extension: .EXE   

A-squared ----- Trojan-Ransom.Win32.Hexzone.cv!IK    
Avast ----- Win32:Trojan-gen {Other}    
Avg ----- PSW.OnlineGames     
Antivir ----- TR/Dropper.Gen    
BitDefender ----- Trojan.Downloader.SinaDLoader.A    
ClamWin ----- Nothing   
Dr.Web ----- Trojan.DownLoad.3198    
NOD32 ----- a variant of Win32/TrojanDownloader.Agent.OBQ trojan    
Ikarus ----- Trojan-Ransom.Win32.Hexzone.cv    
Jiangmin ----- TrojanDownloader.Agent.almk    
Kaspersky ----- Trojan-Downloader.Win32.Agent.wps    
Kingsoft ----- Win32.TrojDownloader.Agent.118784    
Vba32 ----- Trojan-Downloader.Win32.Agent.wps    

*** 12/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   

Task done @ 2008/10/30 四 12:50:38.57   
尤金卡巴斯基
发表于 2008-10-30 18:20:10 | 显示全部楼层
清空

2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw30.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw30.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-Downloader.Win32.Agent.wps        G:\Temp\Virus\20081030\20081030\wl.css               
2008/10/30 18:19:07        已删除        木马程序 Trojan-Downloader.Win32.Agent.wps        G:\Temp\Virus\20081030\20081030\wl.css//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw28.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw28.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw29.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw27.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw29.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw27.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw25.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw26.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw24.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw25.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw26.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw24.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw20.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw20.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw23.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw23.exe//PE_Patch//UPack               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw22.exe               
2008/10/30 18:19:07        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw22.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqrz        G:\Temp\Virus\20081030\20081030\cw21.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqrz        G:\Temp\Virus\20081030\20081030\cw21.exe//PE_Patch//UPack//data0000//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw18.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw18.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw17.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw19.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw17.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw19.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyo        G:\Temp\Virus\20081030\20081030\cw16.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw14.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyo        G:\Temp\Virus\20081030\20081030\cw16.exe//PE_Patch//UPack//data0000//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw15.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw14.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw15.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw13.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw13.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw12.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw12.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyb        G:\Temp\Virus\20081030\20081030\cw11.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyb        G:\Temp\Virus\20081030\20081030\cw11.exe//PE_Patch//UPack//data0000//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw08.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw08.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw09.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan.Win32.Agent.airl        G:\Temp\Virus\20081030\20081030\cw09.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tptl        G:\Temp\Virus\20081030\20081030\cw10.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiya        G:\Temp\Virus\20081030\20081030\cw06.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw07.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw07.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiya        G:\Temp\Virus\20081030\20081030\cw06.exe//PE_Patch//UPack//data0000//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyf        G:\Temp\Virus\20081030\20081030\cw05.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyf        G:\Temp\Virus\20081030\20081030\cw05.exe//PE_Patch//UPack//data0000//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw04.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqsa        G:\Temp\Virus\20081030\20081030\cw04.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.afzm        G:\Temp\Virus\20081030\20081030\cw01.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqly        G:\Temp\Virus\20081030\20081030\cw02.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.afzm        G:\Temp\Virus\20081030\20081030\cw01.exe//PE_Patch//UPack               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.Magania.aiyq        G:\Temp\Virus\20081030\20081030\cw03.exe               
2008/10/30 18:19:06        已删除        木马程序 Trojan-GameThief.Win32.OnLineGames.tqly        G:\Temp\Virus\20081030\20081030\cw02.exe//PE_Patch//UPack
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-17 06:11 , Processed in 0.153283 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表