12
返回列表 发新帖
楼主: will
收起左侧

[病毒样本] 大清早挖的28个

[复制链接]
末日逐沙
头像被屏蔽
发表于 2008-11-22 12:27:15 | 显示全部楼层
解压之后万代千秋,红伞永久
估计是柴子设置的没有扫描压缩包的功能

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zwl2828
发表于 2008-11-22 12:28:54 | 显示全部楼层

ESET Smart Security

28/28

C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/app.exe - Win32/BHO.NJF trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm01.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm02.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm03.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm05.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm07.exe - probably a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm08.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm10.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm14.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm16.exe - probably a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm17.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm19.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm21.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm24.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm25.exe - probably a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm26.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm28.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm31.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm35.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm36.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm37.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm55.exe - probably unknown NewHeur_PE virus
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm56.exe - Win32/PSW.WOW.CUG trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm57.exe - Win32/PSW.WOW.NFQ trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/bmmm64.exe - Win32/PSW.Delf.NNI trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/msgswcam.dll - Win32/BHO.NJF trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/set.exe - a variant of Win32/TrojanDownloader.Small.OFU trojan
C:\Users\Wesley\Downloads\MCLS.zip » ZIP » MCLS/WowInitcode.exe - Win32/PSW.WOW.CUG trojan
花间酒
发表于 2008-11-22 13:09:54 | 显示全部楼层
bmmm56.exe
msgswcam.dll
驱逐艦不報
rok827
发表于 2008-11-22 13:56:07 | 显示全部楼层

ess 669 那个备注是啥意思?

正在扫描日志
病毒库版本: 3632 (20081121)
日期: 2008-11-22  时间: 13:54:17
已扫描的磁盘、文件夹和文件: C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/app.exe - Win32/BHO.NJF 特洛伊木马
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm01.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm02.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm03.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm05.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm07.exe - 可能是 Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm08.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm10.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm14.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm16.exe - 可能是 Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm17.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm19.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm21.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm24.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm25.exe - 可能是 Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm26.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm28.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm31.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm35.exe - Win32/PSW.OnLineGames.NSG 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm36.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm37.exe - Win32/PSW.OnLineGames.NXI 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm55.exe - 未查明的 NewHeur_PE 病毒 [7]
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm56.exe - Win32/PSW.WOW.CUG 特洛伊木马
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm57.exe - Win32/PSW.WOW.NFQ 特洛伊木马
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/bmmm64.exe - Win32/PSW.Delf.NNI 特洛伊木马
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/msgswcam.dll - Win32/BHO.NJF 特洛伊木马
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/set.exe - Win32/TrojanDownloader.Small.OFU 特洛伊木马 的变种
C:\Documents and Settings\Shane Roddick\桌面\MCLS.zip > ZIP > MCLS/WowInitcode.exe - Win32/PSW.WOW.CUG 特洛伊木马
已扫描的对象数: 29
发现的威胁数: 28
已清除对象数:0
完成时间: 13:54:18  总扫描时间: 1 秒 (00:00:01)

备注:
[7] 对象可能感染了未知病毒。
312612205
发表于 2008-11-22 14:03:57 | 显示全部楼层
File MCLS.zip received on 11.22.2008 07:01:42 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 35/37 (94.6%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results  
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:  
  

Antivirus Version Last Update Result
AhnLab-V3 2008.11.21.0 2008.11.21 -
AntiVir 7.9.0.35 2008.11.21 TR/Drop.RQU.6
Authentium 5.1.0.4 2008.11.22 W32/OnlineGames.AS.gen!Eldorado
Avast 4.8.1281.0 2008.11.21 Win32:Trojan-gen {Other}
AVG 8.0.0.199 2008.11.21 Worm/Generic.NDU
BitDefender 7.2 2008.11.22 Trojan.Dropper.RQU
CAT-QuickHeal 10.00 2008.11.21 TrojanDropper.Agent.ytf
ClamAV 0.94.1 2008.11.21 Trojan.Spy-55698
DrWeb 4.44.0.09170 2008.11.22 Trojan.PWS.Finanz.292
eSafe 7.0.17.0 2008.11.19 Suspicious File
eTrust-Vet 31.6.6222 2008.11.22 Win32/Treemz!generic
Ewido 4.0 2008.11.21 Trojan.Inject.kw
F-Prot 4.4.4.56 2008.11.21 W32/OnlineGames.AS.gen!Eldorado
F-Secure 8.0.14332.0 2008.11.22 Trojan-Dropper.Win32.Agent.ytf
Fortinet 3.117.0.0 2008.11.21 PossibleThreat
GData 19 2008.11.22 Trojan.Dropper.RQU
Ikarus T3.1.1.45.0 2008.11.22 Virus.Win32.Trojan
K7AntiVirus 7.10.530 2008.11.21 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2008.11.22 Trojan-Dropper.Win32.Agent.ytf
McAfee 5441 2008.11.21 New Malware.bj
McAfee+Artemis 5441 2008.11.21 Generic!Artemis
Microsoft 1.4104 2008.11.22 TrojanDropper:Win32/Agent.FA
NOD32 3632 2008.11.21 Win32/BHO.NJF
Norman 5.80.02 2008.11.21 W32/P2PWorm.ABL
Panda 9.0.0.4 2008.11.22 Generic Malware
PCTools 4.4.2.0 2008.11.21 Trojan.DR.Lmir.Gen.4
Prevx1 V2 2008.11.22 -
Rising 21.04.50.00 2008.11.22 Trojan.DL.Win32.Mnless.bkq
SecureWeb-Gateway 6.7.6 2008.11.22 Trojan.Drop.RQU.6
Sophos 4.35.0 2008.11.22 Mal/Behav-112
Sunbelt 3.1.1823.2 2008.11.22 Trojan.Win32.Packed.gen (v)
Symantec 10 2008.11.22 Infostealer.Gampass
TheHacker 6.3.1.1.159 2008.11.19 Trojan/Dropper.Agent.ytf
TrendMicro 8.700.0.1004 2008.11.21 PAK_Generic.001
VBA32 3.12.8.9 2008.11.21 Trojan-Dropper.Win32.Agent.ytf
ViRobot 2008.11.18.1474 2008.11.18 Trojan.Win32.PSWIGames.13312.DO
VirusBuster 4.5.11.0 2008.11.21 Trojan.OnlineGames.Gen.104
Additional information
File size: 412609 bytes
MD5...: efb8e1d3eec74a6e2d30fee159333d49
SHA1..: 277b1eda5b9b120f1f88a54ad6919977da05527d
SHA256: fcb6d215786945b8e209c0361c8c7d22b07e0c021c69675bc7fb6b97f83a8d78
SHA512: afebeb0b5a100e50fb412e698f49331ddd8a97b115f7f9ceaa6217048ebed91e
ffea136a4fb2c6324b63f9cb4bb66c748ea3acffb625b3579cb31e217a645eb2
PEiD..: -
TrID..: File type identification
ZIP compressed archive (99.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: -
packers (Kaspersky): PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX, PE_Patch.UPX, UPX
packers (F-Prot): UPX, FSG
packers (Authentium): UPX, UPX, UPX, UPX, UPX, UPX, UPX, UPX, FSG
packers (Avast): UPX, UPX, UPX, UPX, UPX, FSG
jpzy
发表于 2008-11-22 15:26:42 | 显示全部楼层
忽然发现Microsoft Forefront Client也扫压缩包啊!昨天下载的几个因为都有密码,所以没有杀。我一直以为它不扫压缩包呢!

下载完成以后,Forefront提示发现威胁,点击清除以后,压缩包就没了~!

选取消,然后解压缩,清除以后剩下两个文件:set.exe,bmmm57.exe!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-14 08:12 , Processed in 0.099060 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表