查看: 4601|回复: 15
收起左侧

[病毒样本] 围巾加木马

[复制链接]
wangjay1980
发表于 2007-4-12 22:13:10 | 显示全部楼层 |阅读模式
听雨今天中标的产物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-4-12 22:16:50 | 显示全部楼层

nod32杀了13个。。。。。

Scan performed at: 2007-4-12 22:16:46
Scanning Log
NOD32 version 2183 (20070412) NT
Command line: C:\Documents and Settings\EQ2\桌面\Internet_Explorer
Operating memory - is OK

Date: 12.4.2007  Time: 22:16:49
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\Internet_Explorer\
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\Documents and Settings\Administrator\Local Settings\Temp\upxdnd.dll - a variant of Win32/PSW.Agent.NDF trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\Documents and Settings\Administrator\Local Settings\Temp\upxdnd.exe - a variant of Win32/PSW.Agent.NDF trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\Documents and Settings\Administrator\桌面\rundl132.exe - Win32/Viking.CH virus - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\Logo1_.exe - Win32/Viking.CH virus - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\mpppds.exe - probably a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\msccrt.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\RichDll.dll - Win32/Viking.CC virus - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\scmdbcs.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\winform.exe - probably a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\system32\mpppds.dll - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\system32\scmdbcs.dll - probably a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\system32\winform.dll - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\Internet_Explorer\WINDOWS\uninstall\rundl132.exe - Win32/Viking.CH virus - quarantined - unable to clean - deleted
Number of scanned files: 29
Number of threats found: 13
Number of files cleaned: 13
Time of completion: 22:16:52 Total scanning time: 3 sec (00:00:03)
zengmingwh
发表于 2007-4-12 22:17:07 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\download\bingdu\Internet Explorer.rar'
C:\download\bingdu\Internet Explorer.rar
  [0] Archive type: RAR
  --> Program Files\Internet Explorer\SERVICES.EXE
      [DETECTION] Is the Trojan horse TR/Drop.Delf.aom
      [1] Archive type: RAR SFX (self extracting)
      --> systemt.exe
          [DETECTION] Is the Trojan horse TR/Spy.Agent.QP.1
  --> WINDOWS\uninstall\rundl132.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\system32\mpppds.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.616
  --> WINDOWS\system32\msccrt.dll
      [DETECTION] Is the Trojan horse TR/Agent.9216.18
  --> WINDOWS\system32\scmdbcs.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> WINDOWS\system32\slai.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> WINDOWS\system32\Winhttps.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NW
  --> WINDOWS\system32\winform.dll
      [DETECTION] Is the Trojan horse TR/Drop.OnLineGames
  --> WINDOWS\mpppds.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.608
  --> WINDOWS\msccrt.exe
      [DETECTION] Is the Trojan horse TR/Agent.15872.31
  --> WINDOWS\scmdbcs.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ARI.127
  --> WINDOWS\Logo1_.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\RichDll.dll
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\winform.exe
      [DETECTION] Is the Trojan horse TR/Drop.OnLineGames
  --> Recycled\Dc11.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> Recycled\Dc8.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> Recycled\Dc6.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NW
  --> Recycled\Dc9.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.NW
  --> Documents and Settings\Administrator\Local Settings\Temp\upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.1625
  --> Documents and Settings\Administrator\Local Settings\Temp\upxdnd.exe
      [DETECTION] Is the Trojan horse TR/Agent.17920.25
  --> Documents and Settings\Administrator\×ÀÃæ\rundl132.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [INFO]      The file was deleted!
promised
发表于 2007-4-12 22:27:46 | 显示全部楼层
里面一堆鞭尸
运行即退
170912556
头像被屏蔽
发表于 2007-4-12 22:31:44 | 显示全部楼层
瑞星杀了14个。。。。。
童年
头像被屏蔽
发表于 2007-4-12 22:35:09 | 显示全部楼层
小红伞扫出21个~!!

Starting the file scan:

Begin scan in 'F:\Download\Internet Explorer.rar'
F:\Download\Internet Explorer.rar
  [0] Archive type: RAR
  --> Program Files\Internet Explorer\SERVICES.EXE
      [DETECTION] Is the Trojan horse TR/Drop.Delf.aom
      [1] Archive type: RAR SFX (self extracting)
      --> systemt.exe
          [DETECTION] Is the Trojan horse TR/Spy.Agent.QP.1
  --> WINDOWS\uninstall\rundl132.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\system32\mpppds.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.616
  --> WINDOWS\system32\msccrt.dll
      [DETECTION] Is the Trojan horse TR/Agent.9216.18
  --> WINDOWS\system32\scmdbcs.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> WINDOWS\system32\slai.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> WINDOWS\system32\winform.dll
      [DETECTION] Is the Trojan horse TR/Drop.OnLineGames
  --> WINDOWS\mpppds.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.608
  --> WINDOWS\msccrt.exe
      [DETECTION] Is the Trojan horse TR/Agent.15872.31
  --> WINDOWS\scmdbcs.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> WINDOWS\Logo1_.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\RichDll.dll
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
  --> WINDOWS\winform.exe
      [DETECTION] Is the Trojan horse TR/Drop.OnLineGames
  --> Recycled\Dc11.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> Recycled\Dc8.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> Recycled\Dc6.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> Recycled\Dc9.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
  --> Documents and Settings\Administrator\Local Settings\Temp\upxdnd.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.1625
  --> Documents and Settings\Administrator\Local Settings\Temp\upxdnd.exe
      [DETECTION] Is the Trojan horse TR/Agent.17920.25
  --> Documents and Settings\Administrator\×à??\rundl132.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [INFO]      The file was moved to '46924326.qua'!
小邪邪
发表于 2007-4-12 22:36:18 | 显示全部楼层

MCAFEE

监控阻挡掉一个,另又查杀了14个

2007-4-12 22:33:32
已由访问保护规则禁止
Internet Explorer\Program Files\Internet Explorer\SERVICES.EXE
防病毒标准保护:禁止伪装 Windows 进程
已阻止的操作: 创建

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
楚凡
发表于 2007-4-12 22:44:13 | 显示全部楼层
还是小伞强~!!!!!
听雨醉
发表于 2007-4-12 22:49:38 | 显示全部楼层
累死我鸟,舍生忘死、以身试毒终于搞到的样本,可惜一些exe已被感染。。。
solcroft
发表于 2007-4-12 22:52:44 | 显示全部楼层
avast!杀了14个,除了Recycled目录里两个同样病毒的.exe其他的都是无法执行的东西...

* avast! Report
* This file is generated automatically
*
* Task 'Simple user interface' used
* Started on Friday, April 13, 2007
* VPS: 000733-0, 11/04/2007
*

C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Documents and Settings\Administrator\Local Settings\Temp\upxdnd.exe [L] Win32:OnLineGames-JC [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Documents and Settings\Administrator\??\rundl132.exe [L] Win32:Tibs-ADO [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Program Files\Internet Explorer\SERVICES.EXE\systemt.exe [L] Win32:Agent-FQA [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Program Files\Internet Explorer\SERVICES.EXE [L] Win32:Trojan-gen. {Other} (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Recycled\Dc11.exe [L] Win32:OnLineGames-JC [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\Recycled\Dc8.exe [L] Win32:OnLineGames-JC [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\Logo1_.exe [L] Win32:Tibs-ADO [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\mpppds.exe [L] Win32:OnLineGames-GO [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\msccrt.exe [L] Win32:OnLineGames-CP [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\RichDll.dll [L] Win32:Tibs-ADO [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\scmdbcs.exe [L] Win32:OnLineGames-JC [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\system32\mpppds.dll [L] Win32:OnLineGames-HB [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\uninstall\rundl132.exe [L] Win32:Tibs-ADO [Trj] (0)
File was successfully deleted...
C:\Documents and Settings\Virtual Machine\Desktop\Internet Explorer\WINDOWS\winform.exe [L] Win32:OnLineGames-JC [Trj] (0)
File was successfully deleted...
Infected files: 14
Total files: 32
Total folders: 12
Total size: 3.5 MB

*
* Task stopped: Friday, April 13, 2007
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 11:01 , Processed in 0.149641 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表