查看: 4441|回复: 10
收起左侧

[病毒样本] 33

[复制链接]
冷冷
发表于 2009-7-19 13:03:11 | 显示全部楼层 |阅读模式

  1. http://x.w1s2d3.com:662/hai.txt
  2. http://x.w1s2d3.com:662/ai.txt


  3. http://121.12.115.11:886/cao/aa26.exe
  4. http://121.12.115.11:886/cao/aa1.exe
  5. http://121.12.115.11:886/cao/aa2.exe
  6. http://121.12.115.11:886/cao/aa3.exe
  7. http://121.12.115.11:886/cao/aa4.exe
  8. http://121.12.115.11:886/cao/aa5.exe
  9. http://121.12.115.11:886/cao/aa6.exe
  10. http://121.12.115.11:886/cao/aa7.exe
  11. http://121.12.115.11:886/cao/aa8.exe
  12. http://121.12.115.11:886/cao/aa9.exe
  13. http://121.12.115.11:886/cao/aa10.exe
  14. http://121.12.115.11:886/cao/aa11.exe
  15. http://121.12.115.11:886/cao/aa12.exe
  16. http://121.12.115.11:886/cao/aa13.exe
  17. http://121.12.115.11:886/cao/aa14.exe
  18. http://121.12.115.11:886/cao/aa15.exe
  19. http://121.12.115.11:886/cao/aa16.exe
  20. http://121.12.115.11:886/cao/aa17.exe
  21. http://121.12.115.11:886/cao/aa18.exe
  22. http://121.12.115.11:886/cao/aa19.exe
  23. http://121.12.115.11:886/cao/aa20.exe
  24. http://121.12.115.11:886/cao/aa21.exe
  25. http://121.12.115.11:886/cao/aa22.exe
  26. http://121.12.115.11:886/cao/aa23.exe
  27. http://121.12.115.11:886/cao/aa24.exe
  28. http://121.12.115.11:886/cao/aa25.exe
  29. http://121.12.115.11:886/cao/aa27.exe
  30. http://121.12.115.11:886/cao/aa28.exe
  31. http://121.12.115.11:886/cao/aa29.exe
  32. http://121.12.115.11:886/cao/aa30.exe
  33. http://121.12.115.11:886/cao/aa31.exe
  34. http://121.12.115.11:886/cao/ms.exe
  35. http://121.12.115.11:886/cao/fx.exe


  36. http://121.12.115.11:886/cao/aa2.exe
  37. http://121.12.115.11:886/cao/aa3.exe
  38. http://121.12.115.11:886/cao/aa4.exe
  39. http://121.12.115.11:886/cao/aa5.exe
  40. http://121.12.115.11:886/cao/aa6.exe
  41. http://121.12.115.11:886/cao/aa7.exe
  42. http://121.12.115.11:886/cao/aa8.exe
  43. http://121.12.115.11:886/cao/aa9.exe
  44. http://121.12.115.11:886/cao/aa10.exe
  45. http://121.12.115.11:886/cao/aa11.exe
  46. http://121.12.115.11:886/cao/aa12.exe
  47. http://121.12.115.11:886/cao/aa13.exe
  48. http://121.12.115.11:886/cao/aa14.exe
  49. http://121.12.115.11:886/cao/aa15.exe
  50. http://121.12.115.11:886/cao/aa16.exe
  51. http://121.12.115.11:886/cao/aa17.exe
  52. http://121.12.115.11:886/cao/aa18.exe
  53. http://121.12.115.11:886/cao/aa19.exe
  54. http://121.12.115.11:886/cao/aa20.exe
  55. http://121.12.115.11:886/cao/aa21.exe
  56. http://121.12.115.11:886/cao/aa22.exe
  57. http://121.12.115.11:886/cao/aa23.exe
  58. http://121.12.115.11:886/cao/aa24.exe
  59. http://121.12.115.11:886/cao/aa27.exe
  60. http://121.12.115.11:886/cao/aa29.exe
  61. http://121.12.115.11:886/cao/aa30.exe

复制代码

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lingbo110120
发表于 2009-7-19 13:07:00 | 显示全部楼层
费尔MISS 1
已上报
悠柚
发表于 2009-7-19 13:07:13 | 显示全部楼层
BD cls miss 1
不过应该是全灭,那个在线扫描BD是报的,cls难道没有启发

[ 本帖最后由 悠柚 于 2009-7-19 13:09 编辑 ]
HC303
发表于 2009-7-19 13:10:04 | 显示全部楼层
ALL KILLED
Begin scan in 'G:\virus\样本-1'
G:\virus\样本-1\aa1.exe
    [DETECTION] Is the TR/Downloader.Gen Trojan
G:\virus\样本-1\aa10.exe
    --> Object
      [DETECTION] Is the TR/Agent.37416 Trojan
G:\virus\样本-1\aa11.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa12.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa13.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa14.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa15.exe
    --> Object
      [DETECTION] Is the TR/Agent.37416 Trojan
G:\virus\样本-1\aa16.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa17.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> Object
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Is the TR/PSW.Wow.ony Trojan
G:\virus\样本-1\aa18.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa19.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa2.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa20.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa21.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa22.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa23.exe
    [DETECTION] Is the TR/Hijacker.Gen Trojan
G:\virus\样本-1\aa24.exe
    [DETECTION] Is the TR/Crypt.UPKM.Gen Trojan
G:\virus\样本-1\aa25.exe
  [0] Archive type: NSIS
    [DETECTION] Contains recognition pattern of the DR/Dldr.Agent.cfkj dropper
    --> ProgramFilesDir/38.exe
      [DETECTION] Is the TR/Spy.Gen Trojan
G:\virus\样本-1\aa26.exe
    [DETECTION] Is the TR/Dropper.Gen Trojan
G:\virus\样本-1\aa27.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa28.exe
    [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
G:\virus\样本-1\aa29.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa3.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa30(1).exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa31.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa4.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa5.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa6(1).exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa7.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa8.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\aa9.exe
    [DETECTION] Is the TR/Crypt.XDR.Gen Trojan
G:\virus\样本-1\fx.exe
    [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
G:\virus\样本-1\ms.exe
    [DETECTION] Is the TR/Drop.Agent.Zlo.2 Trojan
nosferatu
头像被屏蔽
发表于 2009-7-19 13:16:43 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\attachment\aa1.exe - Win32/TrojanDownloader.Agent.OVM 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa10.exe - 可能是 Win32/PSW.OnLineGames.NUO 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa11.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa12.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa13.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa14.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa15.exe - 可能是 Win32/PSW.OnLineGames.NUO 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa16.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa17.exe - Win32/PSW.OnLineGames.NSU 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa18.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa19.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa2.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa20.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa21.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa22.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa23.exe - Win32/PSW.OnLineGames.NSU 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa24.exe - Win32/PSW.QQPass.NEH 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa25.exe > NSIS > 38.exe - 可能是 Win32/Adware.Cinmus 应用程序 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa26.exe - Win32/Agent.PVI 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa27.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa28.exe - Win32/TrojanDownloader.Caxnet.AA 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa29.exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa3.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa30(1).exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa31.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa4.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa5.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa6(1).exe - 可能是 Win32/PSW.OnLineGames.NRD 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\attachment\aa7.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa8.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\aa9.exe - Win32/PSW.OnLineGames.NRD 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\fx.exe - Win32/TrojanDownloader.Small.OQX 特洛伊木马
C:\Documents and Settings\Administrator\桌面\attachment\ms.exe - Win32/TrojanDownloader.Agent.OOB 特洛伊木马 的变种
失落的手链
发表于 2009-7-19 13:19:16 | 显示全部楼层
瑞星2010

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
小邪邪
发表于 2009-7-19 13:24:22 | 显示全部楼层
31

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-7-19 20:15:46 | 显示全部楼层
2009/7/19 20:12:33        已清除        木马程序 Trojan-Dropper.Win32.Agent.zlo        G:\Temp\Virus\样本-1.rar/ms.exe//PE_Patch//UPack               
2009/7/19 20:12:33        已清除        木马程序 Trojan-Downloader.Win32.Small.jzd        G:\Temp\Virus\样本-1.rar/fx.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bjqs        G:\Temp\Virus\样本-1.rar/aa9.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa8.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bmsn        G:\Temp\Virus\样本-1.rar/aa7.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa6(1).exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bkii        G:\Temp\Virus\样本-1.rar/aa5.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa4.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa31.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa30(1).exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa3.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa29.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-Downloader.Win32.Small.jzw        G:\Temp\Virus\样本-1.rar/aa28.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa27.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-Downloader.Win32.Agent.cfkj        G:\Temp\Virus\样本-1.rar/aa25.exe//data0003               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.OnLineGames.bmkt        G:\Temp\Virus\样本-1.rar/aa23.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa22.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bjqa        G:\Temp\Virus\样本-1.rar/aa21.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bdax        G:\Temp\Virus\样本-1.rar/aa20.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa2.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa19.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa18.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.OnLineGames.bmcm        G:\Temp\Virus\样本-1.rar/aa17.exe//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa16.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa14.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.bnhr        G:\Temp\Virus\样本-1.rar/aa13.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa12.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan-GameThief.Win32.Magania.biht        G:\Temp\Virus\样本-1.rar/aa11.exe//PE_Patch.UPX//UPX               
2009/7/19 20:12:33        已清除        木马程序 Trojan.Win32.Agent2.cglm        G:\Temp\Virus\样本-1.rar/aa10.exe               
2009/7/19 20:12:33        已清除        木马程序 Trojan-Downloader.Win32.Small.jis        G:\Temp\Virus\样本-1.rar/aa1.exe               
2009/7/19 20:12:31        已隔离        病毒 HEUR:Trojan.Win32.Generic        G:\Temp\Virus\样本-1.rar/aa15.exe               

Signature Miss 3,To KL
haol
发表于 2009-7-19 20:39:44 | 显示全部楼层
drweb found 27 threats
尤金卡巴斯基
发表于 2009-7-19 21:22:43 | 显示全部楼层
Hello,

aa15.exe_ - Trojan-GameThief.Win32.OnLineGames.vhag,
aa26.exe_ - Trojan-Dropper.Win32.Agent.awsd

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

aa24.exe_ - Trojan-Spy.Win32.QQLogger.r

This file is already detected. Please update your antivirus bases.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

Best regards, Ilya Tolstikhin
Virus analyst, Kaspersky Lab.
10/1, 1st Volokolamsky Proezd, Moscow, 123060, Russia
Tel./Fax: + 7 (495) 797 8700
http://www.kaspersky.com http://www.viruslist.com
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-1-9 10:47 , Processed in 0.086460 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表