查看: 3071|回复: 15
收起左侧

[病毒样本] 预备今天的早餐,10个

[复制链接]
troika
发表于 2007-5-2 03:34:50 | 显示全部楼层 |阅读模式
呵呵

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wyrmboy
发表于 2007-5-2 04:11:58 | 显示全部楼层
今天新装的卡7~扫了11个
mofunzone
发表于 2007-5-2 06:18:21 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\2.rar'
C:\Documents and Settings\morgan\My Documents\
  2.rar
    [0] Archive type: RAR
    --> jh0430[1].exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> mh0429[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QY.3
        [WARNING]   Infected files in archives cannot be repaired!
    --> moyu0430[1].exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> qj0421[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.JJ.72
        [WARNING]   Infected files in archives cannot be repaired!
    --> servers[1].exe
        [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> update3[1].exe
        [DETECTION] Contains signature of the worm WORM/Agent.AZ.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> upxdnd.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> wl0429[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QY.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> wm0425[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.Magania.FR.6
        [WARNING]   Infected files in archives cannot be repaired!
    --> wow0501[1].exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年5月1日  15:18
Used time: 00:09 min

The scan has been done completely.

      0 Scanning directories
     11 Files were scanned
     10 viruses and/or unwanted programs were found
      4 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -3 Files not concerned
      1 Archives were scanned
     11 Warnings
      0 Notes
      0 Hidden objects were found
jlennon
头像被屏蔽
发表于 2007-5-2 06:35:48 | 显示全部楼层

我是幸福的,祝贺红军挺进欧冠决赛

Virus check with AntiVirusKit
Version 16.0.7
Virus signatures of 2007-4-25
Start time: 2007-5-2 6:34
Engine(s): KAV engine (AVK 17.4126), BD-Engine (BD 17.3645)
Heuristic: On
Archives: On
System areas: On

Check system areas...
Check selected directories and files...
Object: jh0430[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan.PWS.OnLineGames.ARI (BD-Engine)
Object: mh0429[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.qy (KAV engine), Generic.Malware.SgPWS.A2CF5445 (BD-Engine)
Object: moyu0430[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Generic.Malware.SdldPWS.8E6343DB (BD-Engine)
Object: qj0421[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.jj (KAV engine), Generic.Malware.SFBdld.81A47A00 (BD-Engine)
Object: servers[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Generic.Malware.BE!dldspg.F254B59C (BD-Engine)
Object: update3[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Backdoor.Hupigon.DRM (BD-Engine)
Object: upxdnd.exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.es (KAV engine), Generic.Malware.SdldPWS.977AAD9D (BD-Engine)
Object: wl0429[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.qy (KAV engine), Generic.Malware.SdldgPWS.0F582D67 (BD-Engine)
Object: wm0425[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Trojan-PSW.Win32.OnLineGames.jj (KAV engine), DeepScan:Generic.Malware.SFBdld.C8C84589 (BD-Engine)
Object: wow0501[1].exe
        Path: C:\Documents and Settings\Administrator\桌面\2
        Status: Move file into quarantine
        Virus: Generic.Malware.SdldgPWS.ADF134A1 (BD-Engine)
Analysis complete: 2007-5-2 6:34
    10 files checked
    10 infected files detected
    0 suspected files detected
The EQs
发表于 2007-5-2 07:21:48 | 显示全部楼层
Scan performed at: 2007-5-2 7:21:41
Scanning Log
NOD32 version 2233 (20070501) NT
Command line: C:\Documents and Settings\EQ2\桌面\2.rar
Operating memory - is OK

Date: 2.5.2007  Time: 07:21:45
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\2.rar
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?jh0430[1].exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?mh0429[1].exe - probably a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?moyu0430[1].exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?servers[1].exe - probably a variant of Win32/Spy.Delf.NEN trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?update3[1].exe - a variant of Win32/Agent.NEO trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?upxdnd.exe - a variant of Win32/PSW.Agent.NDF trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?wl0429[1].exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?wm0425[1].exe - Win32/PSW.Delf.NHC trojan - was a part of the deleted object
C:\Documents and Settings\EQ2\桌面\2.rar ?RAR ?wow0501[1].exe - a variant of Win32/PSW.Agent.NCC trojan
Number of scanned files: 11
Number of threats found: 9
Number of files cleaned: 1
Time of completion: 07:21:47 Total scanning time: 2 sec (00:00:02)

Notes:
[7] File is probably infected with an unknown virus.
tracydk
发表于 2007-5-2 08:25:48 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\样本\2.rar'
F:\样本\2.rar
  [0] Archive type: RAR
  --> jh0430[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> mh0429[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QY.3
  --> moyu0430[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> qj0421[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.JJ.72
  --> servers[1].exe
      [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
  --> update3[1].exe
      [DETECTION] Contains signature of the worm WORM/Agent.AZ.1
  --> upxdnd.exe
      [DETECTION] Contains suspicious code HEUR/Malware
  --> wl0429[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QY.1
  --> wm0425[1].exe
      [DETECTION] Is the Trojan horse TR/PSW.Magania.FR.6
  --> wow0501[1].exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was deleted!
金剑
头像被屏蔽
发表于 2007-5-2 08:38:47 | 显示全部楼层
風暴勝者V2繁體版本(http: //www.v0day.com)
_________您的安全是我們的責任_______________
載入病毒庫…進行整理…分配內存…可以使用



===============================================
   ___________病毒查杀结果__________________


===============================================

2007年5月2日8时38分35秒 開始查殺C:\Documents and Settings\Administrator\桌面\2
  未知的木馬病毒(啟發) C:\Documents and Settings\Administrator\桌面\2\qj0421[1].exe 操作:阻止運行
  未知的木馬病毒(啟發) C:\Documents and Settings\Administrator\桌面\2\servers[1].exe 操作:阻止運行
  未知的木馬病毒(啟發) C:\Documents and Settings\Administrator\桌面\2\update3[1].exe 操作:阻止運行
  未知的木馬病毒(啟發) C:\Documents and Settings\Administrator\桌面\2\wm0425[1].exe 操作:阻止運行
=========================================

_________文件性质分析结果________________
"带壳"仅指文件性质,仅供专业人员分析使用。


C:\Documents and Settings\Administrator\桌面\2\qj0421[1].exe 帶殼文件(已經脫殼): UPX加壳
C:\Documents and Settings\Administrator\桌面\2\wm0425[1].exe 帶殼文件(已經脫殼): UPX加壳
-----------------------------------------

2007年5月2日8时38分35秒收起線程…100%查殺完畢!
掃描文件: 10查殺病毒: 4
wangfeng66
发表于 2007-5-2 09:13:20 | 显示全部楼层
F:\2[1].rar\jh0430[1].exe - probably infected with BACKDOOR.Trojan
F:\2[1].rar\mh0429[1].exe - infected with Trojan.PWS.Wsgame
F:\2[1].rar\moyu0430[1].exe - infected with Trojan.PWS.Wsgame
F:\2[1].rar\qj0421[1].exe - infected with Trojan.MulDrop.5762
F:\2[1].rar\servers[1].exe - probably infected with MULDROP.Trojan
F:\2[1].rar\update3[1].exe - infected with Trojan.Popwin
F:\2[1].rar\upxdnd.exe - infected with Trojan.PWS.Wsgame
F:\2[1].rar\wl0429[1].exe - probably infected with BACKDOOR.Trojan
F:\2[1].rar\wm0425[1].exe - infected with Trojan.MulDrop.5762
F:\2[1].rar\wow0501[1].exe - probably infected with BACKDOOR.Trojan

DRWEB 再报10个
红心王子
发表于 2007-5-2 10:07:07 | 显示全部楼层
早餐吃的真饱,全消灭了:

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
soul20010
发表于 2007-5-2 10:12:19 | 显示全部楼层
Result: 9 malware found
Trojan-PSW.Win32.OnLineGames.es (virus)

    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\jh0430[1].exe
    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\upxdnd.exe
    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\wow0501[1].exe

Trojan-PSW.Win32.OnLineGames.qy (virus)

    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\mh0429[1].exe
    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\wl0429[1].exe

Trojan-PSW.Win32.OnLineGames.jj (virus)

    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\qj0421[1].exe
    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\wm0425[1].exe

Trojan-Spy.Win32.Agent.pn (virus)

    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\servers[1].exe

Worm.Win32.Agent.az (virus)

    * C:\Documents and Settings\ÉÙÁÖ\×ÀÃæ\2.rar\update3[1].exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 22:51 , Processed in 0.124744 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表