查看: 2609|回复: 11
收起左侧

[病毒样本] 包包

[复制链接]
tonger2003
发表于 2007-4-17 21:57:25 | 显示全部楼层 |阅读模式
11

[ 本帖最后由 tonger2003 于 2007-4-17 22:03 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
zxy900906
发表于 2007-4-17 22:05:47 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD'
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\0.exe
      [DETECTION] Is the Trojan horse TR/Dldr.VB.asn.2
      [INFO]      A backup was created as '4689d608.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\01.exe
      [DETECTION] Is the Trojan horse TR/Agent.17408.27
      [INFO]      A backup was created as '4652d60b.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\02.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.1662
      [INFO]      A backup was created as '4652d60d.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\03.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4652d60e.qua'!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\04.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.KW.56
      [INFO]      A backup was created as '4652d60f.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\05.exe
      [DETECTION] Is the Trojan horse TR/Proxy.Delf.CA
      [INFO]      A backup was created as '4652d610.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\06.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was moved to '4652d612.qua'!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\07.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      The file was moved to '4652d613.qua'!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\08.exe
      [DETECTION] Is the Trojan horse TR/Agent.17920.29
      [INFO]      A backup was created as '4652d614.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\09.exe
      [DETECTION] Contains signature of the dropper DR/Boran.Z.99
      [INFO]      A backup was created as '4652d615.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\10.exe
      [DETECTION] Contains signature of the dropper DR/Dldr.Agent.bcd.19
      [INFO]      A backup was created as '47faad92.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\Ghook.dll
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.JJ.60
      [INFO]      A backup was created as '4693d645.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD\TDDOWNLOAD\svchost.exe
      [DETECTION] Is the Trojan horse TR/PSW.Onlinegames.EB.3
      [INFO]      A backup was created as '4687d653.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
The EQs
发表于 2007-4-17 22:08:54 | 显示全部楼层
Scan performed at: 2007-4-17 22:08:55
Scanning Log
NOD32 version 2198 (20070417) NT
Command line: C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD
Operating memory - is OK

Date: 17.4.2007  Time: 22:08:59
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\01.exe - probably a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\02.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\03.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\04.exe - Win32/PSW.Agent.NDP trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\05.exe ?FSG v2.0 - Win32/PSW.Delf.NGW trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\06.exe - Win32/Agent.NHN trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\08.exe - Win32/PSW.Agent.NDF trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\TDDOWNLOAD\TDDOWNLOAD\svchost.exe - Win32/PSW.Delf.NGV trojan - quarantined - unable to clean - deleted
Number of scanned files: 16
Number of threats found: 8
Number of files cleaned: 8
Time of completion: 22:09:01 Total scanning time: 2 sec (00:00:02)
aoyang
头像被屏蔽
发表于 2007-4-17 22:11:55 | 显示全部楼层
费尔扫描杀了9个
The EQs
发表于 2007-4-17 22:13:06 | 显示全部楼层
发现看nod32扫描也是一种乐趣。。。能发现nod32脱哪些壳。。。。
欠妳緈諨
发表于 2007-4-17 22:40:29 | 显示全部楼层
蜘蛛扫了8个
jlennon
头像被屏蔽
发表于 2007-4-17 22:44:55 | 显示全部楼层
Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of
Start time: 2007-4-17 22:43
Engine(s): BD-Engine (BD 17.3326)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: 0.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: DeepScan:Generic.Malware.dld!!.EC9890A9 (BD-Engine)
Object: 01.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Generic.Malware.SgPWS.C2D7668E (BD-Engine)
Object: 02.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Generic.Malware.SdldgPWS.78704969 (BD-Engine)
Object: 03.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan.PWS.OnLineGames.ARI (BD-Engine)
Object: 04.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan.PWS.OnLineGames.ARM (BD-Engine)
Object: 05.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: DeepScan:Generic.Malware.SFBdld.E3F7C6FE (BD-Engine)
Object: 06.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Generic.Malware.SdldPWS.4D2FF865 (BD-Engine)
Object: 08.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Generic.Malware.SdldPWS.833D63E1 (BD-Engine)
Object: (NSIS o) lzma_solid_nsis0001
        In archive: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD\09.exe
        Status: Virus detected
        Virus: Adware.Boran.AT (BD-Engine)
Object: 09.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Adware.Boran.AT (BD-Engine)
Object: svchost.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan.PWS.Onlinegames.EB (BD-Engine)
Analysis complete: 2007-4-17 22:43
    13 files checked
    10 infected files detected
    0 suspected files detected
jlennon
头像被屏蔽
发表于 2007-4-17 22:47:07 | 显示全部楼层
Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2007-4-17
Start time: 2007-4-17 22:46
Engine(s): KAV engine (AVK 17.3590)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: 0.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-Downloader.Win32.VB.asn (KAV engine)
Object: 01.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.es (KAV engine)
Object: 03.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.oe (KAV engine)
Object: 04.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.kw (KAV engine)
Object: 05.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.np (KAV engine)
Object: 06.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.oe (KAV engine)
Object: 08.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.es (KAV engine)
Object: stream data0001
        In archive: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD\09.exe
        Status: Virus detected
        Virus: not-a-virus:AdWare.Win32.Boran.z (KAV engine)
Object: 09.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: not-a-virus:AdWare.Win32.Boran.z (KAV engine)
Object: stream data0003
        In archive: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD\10.exe
        Status: Virus detected
        Virus: Trojan-Downloader.Win32.Agent.bcd (KAV engine)
Object: 10.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-Downloader.Win32.Agent.bcd (KAV engine)
Object: Ghook.dll
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.jj (KAV engine)
Object: svchost.exe
        Path: C:\Documents and Settings\Administrator\桌面\TDDOWNLOAD[1]\TDDOWNLOAD
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.gm (KAV engine)
Analysis complete: 2007-4-17 22:46
    13 files checked
    11 infected files detected
    0 suspected files detected
bridgewr
发表于 2007-4-18 15:54:46 | 显示全部楼层
微点5个已知,其他等会上情况
bridgewr
发表于 2007-4-18 15:59:24 | 显示全部楼层
9和10是流氓,Ghook.dll微点没报,本身对系统是无害滴,其他微点杀光

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-2 10:14 , Processed in 0.143413 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表