查看: 2844|回复: 10
收起左侧

[病毒样本] 2008年11月22日中午收集的17个可疑样本

[复制链接]
zjsxsycj
发表于 2008-11-22 12:46:37 | 显示全部楼层 |阅读模式
2008年11月22日中午收集的17个可疑样本
如果您的安全软件无法查杀,
请及时上报. 谢谢

点击下载2008年11月22日中午收集的17个可疑样本
luxiao200888
发表于 2008-11-22 12:49:53 | 显示全部楼层
提供附件下载

[ 本帖最后由 luxiao200888 于 2008-11-22 13:06 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
liu5678
发表于 2008-11-22 12:50:02 | 显示全部楼层
我晕。
千鸟为什么要运行什么插件啊~
这个插件被我的IE拦截了
然后提示不安全。。
luxiao200888
发表于 2008-11-22 13:02:03 | 显示全部楼层
C:\Documents and Settings\Owner\桌面\新建文件夹\1.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\新建文件夹\18.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Documents and Settings\Owner\桌面\新建文件夹\2.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\新建文件夹\3.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\新建文件夹\4.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\新建文件夹\5.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\新建文件夹\a266.css - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Owner\桌面\新建文件夹\BO1033.exe » NSIS » BackOperHelper.dll - Win32/Rootkit.Agent.NHC trojan
C:\Documents and Settings\Owner\桌面\新建文件夹\BO1033.exe » NSIS » 龏
花间酒
发表于 2008-11-22 13:12:59 | 显示全部楼层
驱逐艦才杀了五个
will
发表于 2008-11-22 13:13:40 | 显示全部楼层
筛选后样本上传
去除了非PE文件(两个swf exploits)+一个无毒的自解压exe
解压了两个NSIS  采集了其中的病毒样本

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
luxiao200888
发表于 2008-11-22 13:14:46 | 显示全部楼层

回复 6楼 will 的帖子

C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/1.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/18.exe - a variant of Win32/PSW.OnLineGames.NSG trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/2.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/3.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/4.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/5.exe - a variant of Win32/AutoRun.Delf.I worm
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/a266.css - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/BackOperHelper.dll - Win32/Rootkit.Agent.NHC trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/etxt.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/new37.exe - a variant of Win32/PSW.Delf.NMX trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/newa.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Owner\桌面\MCLS.zip » ZIP » MCLS/w59.css - probably a variant of Win32/TrojanDownloader.Delf.OGS trojan
欠妳緈諨
发表于 2008-11-22 13:37:09 | 显示全部楼层
使用 G DATA AntiVirus 进行病毒检测
版本 19.0.8308.734
病毒特征库日期 22.11.2008
开始时间: 22.11.2008 13:36
引擎: 引擎 A - BitDefender (AVA 19.1801), 引擎 B - Avast! (AVB 19.116)
高启发: 开启
文件: 开启
系统区域: 关闭
RootKits 检测: 开启

检测选中目录和文件:
  S:\MCLS\

项目: 18.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Trojan.PWS.OnlineGames.ZWU (引擎 A-(BitDefender)), Win32:Trojan-gen {Other} (引擎 B-(AVAST!))
项目: 2.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Win32.Worm.Autorun.NY (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))
项目: 1.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Win32.Worm.Autorun.NY (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))
项目: 3.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Win32.Worm.Autorun.NY (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))
项目: 4.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Win32.Worm.Autorun.NY (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))
项目: 5.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Win32.Worm.Autorun.NY (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))
项目: a266.css
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Rootkit.Agent.AIWN (引擎 A-(BitDefender)), Win32:Rootkit-gen [Rtk] (引擎 B-(AVAST!))
项目: new37.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Trojan.Generic.1153116 (引擎 A-(BitDefender)), Win32:Trojan-gen {Other} (引擎 B-(AVAST!))
项目: etxt.exe
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Trojan.PWS.OnlineGames.ZFO (引擎 A-(BitDefender))
项目: w59.css
        路径: S:\MCLS
        状态: 发现病毒
        病毒: Trojan.Downloader.Losabel.B (引擎 A-(BitDefender)), Win32:Agent-SIM [Trj] (引擎 B-(AVAST!))

检测执行时间: 22.11.2008 13:36
    已检测 12 个文件
    已发现 10 个病毒文件
    已发现 0 个可疑文件
欠妳緈諨
发表于 2008-11-22 13:37:51 | 显示全部楼层
S:\MCLS\1.exe - 特征码 'Trojan-Spy.Win32.Hitpop.C' 被发现
S:\MCLS\18.exe - 特征码 'Trojan-Spy.Win32.Treemz.A' 被发现
S:\MCLS\2.exe - 特征码 'Trojan-Spy.Win32.Hitpop.C' 被发现
S:\MCLS\3.exe - 特征码 'Trojan-Spy.Win32.Hitpop.C' 被发现
S:\MCLS\4.exe - 特征码 'Trojan-Spy.Win32.Hitpop.C' 被发现
S:\MCLS\5.exe - 特征码 'Trojan-Spy.Win32.Hitpop.C' 被发现
S:\MCLS\a266.css - 特征码 'not-a-Virus.Hacktool.Keygen' 被发现
S:\MCLS\BackOperHelper.dll
S:\MCLS\etxt.exe - 特征码 'Trojan-Spy.Win32.Banker.anv' 被发现
S:\MCLS\new37.exe - 特征码 'Backdoor.Win32.Hupigon' 被发现
S:\MCLS\newa.exe - 特征码 'Trojan-Spy.Win32.Banker.anv' 被发现
S:\MCLS\w59.css - 特征码 'Virus.Win32.Agent.SIM' 被发现

        12 文件被扫描
          (0 压缩档 0 文件)
        11 特征码被侦测
        0 可疑代码段被发现
        耗时: 0:00.219
will
发表于 2008-11-22 13:38:25 | 显示全部楼层

Multi Command-Line Scanner Report
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\1.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 20B8F25FC7D981FBF05A910AEBE7FB00

A-squared ----- Trojan-Spy.Win32.Hitpop.C!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Win32.Worm.Autorun.NY
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- a variant of Win32/AutoRun.Delf.I worm
Ikarus ----- Trojan-Spy.Win32.Hitpop.C
Jiangmin ----- Worm/AutoRun.dxt
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 7/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\18.exe
Type: UPX compressed Win32 Executable / Extension: .EXE
MD5 Hash: B2F714D664EC01A1065022878633BB40

A-squared ----- Trojan-Spy.Win32.Treemz.A!IK
Avast ----- Win32:Trojan-gen {Other}
Avg ----- Agent_r.L  
AntiVir ----- TR/PSW.OnlineGames.ttkb.1
BitDefender ----- Trojan.PWS.OnlineGames.ZWU
ClaimWin -----Nothing
Dr.Web ----- Trojan.PWS.Wsgame.8957
Eset ----- a variant of Win32/PSW.OnLineGames.NSG trojan
Ikarus ----- Trojan-Spy.Win32.Treemz.A
Jiangmin ----- Trojan/PSW.OnLineGames.aost
Kaspersky ----- Trojan-GameThief.Win32.OnLineGames.ttqv
Kingsoft ----- Win32.TrojDownloader.Agent.ak.65536
Vba32 ----- Embedded.Trojan-GameThief.Win32.OnLineGames.ttkb

*** 12/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\2.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 6F2067EA2A143A1FE532B69E4C78F74D

A-squared ----- Trojan-Spy.Win32.Hitpop.C!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Win32.Worm.Autorun.NY
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- a variant of Win32/AutoRun.Delf.I worm
Ikarus ----- Trojan-Spy.Win32.Hitpop.C
Jiangmin ----- Worm/AutoRun.dxt
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 7/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\3.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 4482EA388F0A2DFFD9415DC60625462E

A-squared ----- Trojan-Spy.Win32.Hitpop.C!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Win32.Worm.Autorun.NY
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- a variant of Win32/AutoRun.Delf.I worm
Ikarus ----- Trojan-Spy.Win32.Hitpop.C
Jiangmin ----- Worm/AutoRun.dxt
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 7/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\4.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 3A275B2ED078C0342F5CA9316436D064

A-squared ----- Trojan-Spy.Win32.Hitpop.C!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Win32.Worm.Autorun.NY
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- a variant of Win32/AutoRun.Delf.I worm
Ikarus ----- Trojan-Spy.Win32.Hitpop.C
Jiangmin ----- Worm/AutoRun.dxt
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 7/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\5.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 26375F0F45F292DF0208EC0F91B70174

A-squared ----- Trojan-Spy.Win32.Hitpop.C!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Win32.Worm.Autorun.NY
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- a variant of Win32/AutoRun.Delf.I worm
Ikarus ----- Trojan-Spy.Win32.Hitpop.C
Jiangmin ----- Worm/AutoRun.dxt
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 7/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\a266.exe
Type: Win64 Executable Generic / Extension: .EXE
MD5 Hash: 68BBACFE7A268000EF2A3B22CA81EAD9

A-squared ----- not-a-Virus.Hacktool.Keygen!IK
Avast ----- Win32:Rootkit-gen [Rtk]
Avg ----- Downloader.Agent.AOOF  
AntiVir ----- TR/Spy.Gen
BitDefender ----- Rootkit.Agent.AIWN
ClaimWin -----Nothing
Dr.Web ----- DLOADER.Trojan
Eset ----- probably a variant of Win32/Genetik trojan
Ikarus ----- not-a-Virus.Hacktool.Keygen
Jiangmin -----Nothing
Kaspersky ----- Trojan-Dropper.Win32.Agent.zyq
Kingsoft -----Nothing
Vba32 -----Nothing

*** 9/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\BackOperHelper.dll
Type: Win32 Executable MS Visual C++ / Extension: .EXE
MD5 Hash: 913ED32DAF9A8C06678927B1A60BF1AD

A-squared -----Nothing
Avast -----Nothing
Avg -----Nothing
AntiVir ----- TR/Zlob.110592
BitDefender -----Nothing
ClaimWin -----Nothing
Dr.Web -----Nothing
Eset ----- Win32/Rootkit.Agent.NHC trojan
Ikarus -----Nothing
Jiangmin -----Nothing
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 -----Nothing

*** 2/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\etxt.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 65E9441EC40EAF07F990C8979A0D48D9

A-squared ----- Trojan-Spy.Win32.Banker.anv!IK
Avast -----Nothing
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender ----- Trojan.PWS.OnlineGames.ZFO
ClamWin ----- Trojan.ShellHook-2
Dr.Web ----- BackDoor.Pigeon.origin
Eset ----- probably a variant of Win32/Genetik trojan
Ikarus ----- Trojan-Spy.Win32.Banker.anv
Jiangmin ----- Trojan/Pakes.clq
Kaspersky ----- Heur.Trojan.Generic
Kingsoft -----Nothing
Vba32 -----Nothing

*** 9/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\new37.exe
Type: Win32 Executable Generic / Extension: .EXE
MD5 Hash: 9D087F6D85D1109009FF9A1259F2AEA6

A-squared ----- Backdoor.Win32.Hupigon!IK
Avast ----- Win32:Trojan-gen {Other}
Avg ----- Agent.ALZI  
AntiVir ----- TR/Crypt.CFI.Gen
BitDefender ----- Trojan.Generic.1153116
ClamWin ----- PUA.Packed.NPack-3
Dr.Web ----- Trojan.Siggen.557
Eset ----- a variant of Win32/PSW.Delf.NMX trojan
Ikarus ----- Backdoor.Win32.Hupigon
Jiangmin ----- Trojan/PSW.OnLineGames.jxu
Kaspersky ----- Trojan.Win32.Agent.ahzz
Kingsoft ----- Win32.Troj.Agent.495616
Vba32 ----- Trojan.Win32.Agent.ahzz

*** 13/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\newa.exe
Type: DOS Executable Generic / Extension: .EXE
MD5 Hash: 77DD458810B47D8CB86652746834399F

A-squared ----- Trojan-Spy.Win32.Banker.anv!IK
Avast -----Nothing
Avg -----Nothing
AntiVir ----- TR/Dropper.Gen
BitDefender -----Nothing
ClamWin ----- Trojan.ShellHook-2
Dr.Web ----- BackDoor.Pigeon.origin
Eset ----- probably a variant of Win32/Genetik trojan
Ikarus ----- Trojan-Spy.Win32.Banker.anv
Jiangmin ----- Trojan/Pakes.clq
Kaspersky -----Nothing
Kingsoft -----Nothing
Vba32 ----- MalwareScope.Trojan-PSW.Game.7

*** 8/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------
D:\Desk\Samples\Collect\MCLS\w59.exe
Type: Win32 Executable Generic / Extension: .EXE
MD5 Hash: 60048DF1991B072E14803F27EAF6691A

A-squared ----- Virus.Win32.Agent.SIM!IK
Avast ----- Win32:Agent-SIM [Trj]
Avg ----- Downloader.Generic8.DYA  
AntiVir ----- TR/Dldr.Losabel.aea.19
BitDefender ----- Trojan.Downloader.Losabel.B
ClamWin ----- PUA.Packed.NPack-2
Dr.Web ----- Trojan.DownLoad.3520
Eset ----- probably a variant of Win32/TrojanDownloader.Delf.OGS trojan
Ikarus ----- Virus.Win32.Agent.SIM
Jiangmin ----- TrojanDownloader.Losabel.el
Kaspersky ----- Trojan-Downloader.Win32.Losabel.aea
Kingsoft ----- Win32.Troj.OnlineGames.aw.175616
Vba32 ----- Trojan-Downloader.Win32.Losabel.aea

*** 13/13 antivirus engines found virus in this file ***
-------------------------------------------------------------------------

Task done @ 2008/11/22 六 13:36:37.11
Note: The results might be different from that of the GUI version.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-15 10:31 , Processed in 0.130082 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表