查看: 4656|回复: 13
收起左侧

[病毒样本] 几个样本,大家看看

[复制链接]
银砾石
发表于 2007-3-10 22:49:06 | 显示全部楼层 |阅读模式
打包了,密码virus

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
XinDOS
发表于 2007-3-10 22:56:11 | 显示全部楼层
卡巴删了几个
以下文件未被清除

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-3-10 22:58:51 | 显示全部楼层
Time        Module        Object        Name        Threat        Action        User        Information
2007-3-10 22:57:51        AMON        file        C:\Documents and Settings\EQ2\桌面\old\old\zt.exe        Win32/PSW.Lineage.DN trojan        quarantined - deleted - error while cleaning - operation unavailable for this type of object        KASPERSK-6C4206\EQ2        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.
2007-3-10 22:57:51        AMON        file        C:\Documents and Settings\EQ2\桌面\old\old\qing.exe        Win32/TrojanDownloader.Agent.UE trojan        quarantined - deleted - error while cleaning - operation unavailable for this type of object        KASPERSK-6C4206\EQ2        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.
2007-3-10 22:57:51        AMON        file        C:\Documents and Settings\EQ2\桌面\old\old\mal.exe        Win32/Dialer.U trojan        quarantined - deleted - error while cleaning - operation unavailable for this type of object        KASPERSK-6C4206\EQ2        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.
2007-3-10 22:57:48        AMON        file        C:\Documents and Settings\EQ2\桌面\old\old\ThankYou.exe        Win32/PSW.QQPass.NBM trojan        quarantined - deleted - error while cleaning - operation unavailable for this type of object        KASPERSK-6C4206\EQ2        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.
2007-3-10 22:57:48        AMON        file        C:\Documents and Settings\EQ2\桌面\old\old\nettool.exe        Win32/Small.NAV worm        quarantined - deleted - error while cleaning - operation unavailable for this type of object        KASPERSK-6C4206\EQ2        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.




还有16个被隔离了。。。。晕。。。。
马力
发表于 2007-3-10 23:01:00 | 显示全部楼层
驱逐舰

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
曲中求
发表于 2007-3-10 23:03:00 | 显示全部楼层
Time        Module        Object        Name        Threat        Action        User        Information
2007-3-10 22:57:51        AMON        file        E:\病毒\old.part1\old\svchost2.exe        probably unknown NewHeur_PE virus        quarantined - deleted                Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:49        AMON        file        E:\病毒\old.part1\old\ewtRmLR.com        probably unknown NewHeur_PE virus        quarantined - deleted                Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:47        AMON        file        E:\病毒\old.part1\old\iexpl0re.exe        a variant of Win32/PSW.Agent.NBX trojan        quarantined - deleted                Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:44        AMON        file        E:\病毒\old.part1\old\auto.bat        probably unknown NewHeur_PE virus        quarantined - deleted                Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:41        AMON        file        E:\病毒\old.part1\old\TdTKYiR.com        probably unknown NewHeur_PE virus        quarantined - deleted                Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:34        AMON        file        E:\病毒\old.part1\old\~tmp7687.exe        probably unknown NewHeur_PE virus        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:31        AMON        file        E:\病毒\old.part1\old\date.exe        probably a variant of Win32/Genetik trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:29        AMON        file        E:\病毒\old.part1\old\muma.exe        a variant of Win32/PSW.QQRob.NAH trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:26        AMON        file        E:\病毒\old.part1\old\update1.exe        a variant of Win32/TrojanDropper.Small.APR trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:03        AMON        file        E:\病毒\old.part1\old\Setup.exe        a variant of Win32/Hupigon trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:57:00        AMON        file        E:\病毒\old.part1\old\zt.exe        Win32/PSW.Lineage.DN trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:56:58        AMON        file        E:\病毒\old.part1\old\qing.exe        Win32/TrojanDownloader.Agent.UE trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:56:55        AMON        file        E:\病毒\old.part1\old\svchost.exe        a variant of Win32/Ginwui trojan        quarantined - deleted        WWW-E1029B2A365         Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:56:53        AMON        file        E:\病毒\old.part1\old\mal.exe        Win32/Dialer.U trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:56:50        AMON        file        E:\病毒\old.part1\old\ThankYou.exe        Win32/PSW.QQPass.NBM trojan        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

2007-3-10 22:56:46        AMON        file        E:\病毒\old.part1\old\nettool.exe        Win32/Small.NAV worm        quarantined - deleted        WWW-E1029B2A365\        Event occurred on a new file created by the application: D:\Program Files\WinRAR\WinRAR.exe. The file was moved to quarantine. You may close this window.

挺壮观的。楼主料够足。。。。
kp2006
头像被屏蔽
发表于 2007-3-10 23:03:13 | 显示全部楼层
信息        2007-03-10 23:02:26        您此次查毒清除了14个病毒                        
信息        2007-03-10 23:02:26        您此次查毒共查出14个病毒以及危险代码                        
信息        2007-03-10 23:02:26        您此次查毒共查了内存模块0个,磁盘引导扇区0个,文件27个                        
信息        2007-03-10 23:02:26        金山毒霸主程序查毒过程结束,查毒方式:命令行查毒                        
病毒        2007-03-10 23:02:26        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\svchost2.exe        Worm.Viking.gm.62702        清除成功        
病毒        2007-03-10 23:02:26        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\ewtRmLR.com        Win32.Hack.NsAnti.ca.43611        清除成功        
病毒        2007-03-10 23:02:26        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\auto.bat        Win32.TrojDownloader.Delf.18432        清除成功        
病毒        2007-03-10 23:02:26        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\TdTKYiR.com        Win32.Hack.NsAnti.ca.43611        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\~tmp7687.exe        Win32.Hack.NsAnti.ca.43611        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\date.exe        Win32.PSWTroj.Zhengtu.tc.126976        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\muma.exe        Win32.Troj.PswQQ.ia.87712        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\Setup.exe        Win32.Hack.Huigezi.dg.757760        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\zt.exe        Win32.Troj.PSWZhengTu.cs.208896        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\svchost.exe        Win32.TrojDownloader.Agent.32256        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\qing.exe        Win32.Troj.Downloader.jf.19968        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\mal.exe        Win32.Troj.Dialer.qy.33195        清除成功        
病毒        2007-03-10 23:02:25        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\ThankYou.exe        Win32.Troj.QQHook.dd.65024        清除成功        
病毒        2007-03-10 23:02:24        D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\OLD[1]\OLD\nettool.exe        Win32.Troj.Vcing.ak.40960        清除成功        
信息        2007-03-10 23:02:12        金山毒霸主程序启动查毒过程,查毒方式:命令行查毒                        
信息        2007-03-10 23:02:12        金山毒霸主程序 启动


D:\Documents and Settings\Administrator\桌面\old[1]\old\update1.exe - a variant of Win32/TrojanDropper.Small.APR trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\iexpl0re.exe - a variant of Win32/PSW.Agent.NBX trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\svchost2.exe - 未查明的 NewHeur_PE virus [7]
D:\Documents and Settings\Administrator\桌面\old[1]\old\nettool.exe - Win32/Small.NAV worm - 无法清除 - 已删除
D:\Documents and Settings\Administrator\桌面\old[1]\old\ThankYou.exe - Win32/PSW.QQPass.NBM trojan - 无法清除 - 已删除
D:\Documents and Settings\Administrator\桌面\old[1]\old\mal.exe - Win32/Dialer.U trojan - 无法清除 - 已删除
D:\Documents and Settings\Administrator\桌面\old[1]\old\qing.exe - Win32/TrojanDownloader.Agent.UE trojan - 无法清除 - 已删除
D:\Documents and Settings\Administrator\桌面\old[1]\old\svchost.exe - a variant of Win32/Ginwui trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\zt.exe - Win32/PSW.Lineage.DN trojan - 无法清除 - 已删除
D:\Documents and Settings\Administrator\桌面\old[1]\old\Setup.exe - a variant of Win32/Hupigon trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\muma.exe - a variant of Win32/PSW.QQRob.NAH trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\date.exe - probably a variant of Win32/Genetik trojan
D:\Documents and Settings\Administrator\桌面\old[1]\old\~tmp7687.exe - 未查明的 NewHeur_PE virus [7]
D:\Documents and Settings\Administrator\桌面\old[1]\old\TdTKYiR.com - 未查明的 NewHeur_PE virus [7]
D:\Documents and Settings\Administrator\桌面\old[1]\old\auto.bat - 未查明的 NewHeur_PE virus [7]
D:\Documents and Settings\Administrator\桌面\old[1]\old\ewtRmLR.com - 未查明的 NewHeur_PE virus [7]
已扫描的文件数目:20
已发现的病毒数目:16
已清除病毒的文件数目:16
完成时间: 23:04:55 总扫描时间:52 秒 (00:00:52)
注意:
[7] 该文件可能感染上未知病毒。

[ 本帖最后由 kp2006 于 2007-3-10 23:05 编辑 ]
曲中求
发表于 2007-3-10 23:04:58 | 显示全部楼层
这是NOD 32最后剩下的:

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
gggh
发表于 2007-3-10 23:34:09 | 显示全部楼层
红伞杀乘一个my.exe
kp2006
头像被屏蔽
发表于 2007-3-10 23:47:51 | 显示全部楼层
kv 12

在 D:\Documents and Settings\Administrator\桌面\old[1]\old\system.bat 中发现 TrojanDownloader.Agent.hmi 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\nettool.exe 中发现 I-Worm/Agent.i 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\ThankYou.exe 中发现 Trojan/PSW.QQPass.bev 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\mal.exe 中发现 Trojan/Dialer.s 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\zt.exe 中发现 Trojan/PSW.Lineage.dvl 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\Setup.exe 中发现 Backdoor/Huigezi.pcq 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\muma.exe 中发现 Trojan/PSW.Agent.bew 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\~tmp7687.exe 中发现 Trojan/PSW.GamePass.ayp 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\TdTKYiR.com 中发现 Backdoor/Agent.grq 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\date.exe 中发现 Trojan/PSW.QQPass.aoo 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\ewtRmLR.com 中发现 Trojan/PSW.GamePass.ceg 病毒, 发现病毒
在 D:\Documents and Settings\Administrator\桌面\old[1]\old\iexpl0re.exe 中发现 Trojan/PSW.GamePass.bkc 病毒, 发现病毒
tun
发表于 2007-3-11 00:53:15 | 显示全部楼层
毒还是一次多些才好玩

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-4-30 11:34 , Processed in 0.137537 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表