查看: 5672|回复: 26
收起左侧

[病毒样本] 经手的42个

[复制链接]
mofunzone
发表于 2007-5-21 05:14:25 | 显示全部楼层 |阅读模式
Starting the file scan:

Begin scan in 'C:\Documents and Settings\morgan\My Documents\123.rar'
C:\Documents and Settings\morgan\My Documents\
  123.rar
    [0] Archive type: RAR
    --> c0nime.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> cmdbcs.exe
    --> crasos.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> jview.exe
    --> kaspersky.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Delf.bga.1
        [WARNING]   Infected files in archives cannot be repaired!
    --> KSVSvc.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.2467
        [WARNING]   Infected files in archives cannot be repaired!
    --> LYLOADER.EXE
        [DETECTION] Is the Trojan horse TR/Agent.nma.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> mhso.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> msccrt.exe
        [DETECTION] Is the Trojan horse TR/Agent.17408.58
        [WARNING]   Infected files in archives cannot be repaired!
    --> nwizAsktao.exe
        [DETECTION] Is the Trojan horse TR/Agent.7680.59
        [WARNING]   Infected files in archives cannot be repaired!
    --> nwizqjsj.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.RC.116
        [WARNING]   Infected files in archives cannot be repaired!
    --> nwizqqfo.exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> nwscript.exe
    --> PeSrvr.exe
    --> PocoFile0.exe
    --> qjso.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> Servera.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> servet.exe
        [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> snetcfg.exe
    --> sunny.exe
        [DETECTION] Is the Trojan horse TR/Agent.4608.65
        [WARNING]   Infected files in archives cannot be repaired!
    --> testexe.exe
        [DETECTION] Is the Trojan horse TR/Drop.Online.rt.2
        [WARNING]   Infected files in archives cannot be repaired!
    --> tintset.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.2481
        [WARNING]   Infected files in archives cannot be repaired!
    --> tlso.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> upxdnd.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QH.44
        [WARNING]   Infected files in archives cannot be repaired!
    --> wlso.exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> woso.exe
        [DETECTION] Is the Trojan horse TR/PSW.WOW.QN.3
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1.exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QH.44
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.QH.44
        [WARNING]   Infected files in archives cannot be repaired!
    --> 2[1].exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 4[1].exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 8[1].exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 8[].exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 9.exe
        [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 9[1].exe
        [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 10[1].exe
        [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 12[1].exe
        [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
        [WARNING]   Infected files in archives cannot be repaired!
    --> 13[1].exe
        [DETECTION] Is the Trojan horse TR/Agent.7680.59
        [WARNING]   Infected files in archives cannot be repaired!
    --> 14[1].exe
        [DETECTION] Contains suspicious code HEUR/Malware
        [WARNING]   Infected files in archives cannot be repaired!
    --> 163a[1].exe
        [DETECTION] Is the Trojan horse TR/Agent.22016.B
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1635[1].exe
        [DETECTION] Is the Trojan horse TR/Agent.19456.49
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1636[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.ES.2101
        [WARNING]   Infected files in archives cannot be repaired!
    --> 1638[1].exe
        [DETECTION] Is the Trojan horse TR/PSW.OnLineGames.RC.116
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!


End of the scan: 2007年5月20日  14:13
Used time: 00:17 min

The scan has been done completely.

      0 Scanning directories
     43 Files were scanned
     36 viruses and/or unwanted programs were found
      3 classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
     37 Warnings
      0 Notes
      0 Hidden objects were found

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2007-5-21 05:20:02 | 显示全部楼层
1/3的壳。。。。。真牛。。。。
mofunzone
 楼主| 发表于 2007-5-21 05:24:50 | 显示全部楼层

回复 #2 EQ2 的帖子

就怕ls的连1/3都杀不到呢
The EQs
发表于 2007-5-21 05:25:18 | 显示全部楼层
Scan performed at: 2007-5-21 5:19:51
Scanning Log
NOD32 version 2278 (20070520) NT
Command line: C:\Documents and Settings\EQ2\桌面\123
Operating memory - is OK

Date: 21.5.2007  Time: 05:19:56
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\123\
C:\Documents and Settings\EQ2\桌面\123\1.exe - Win32/PSW.Agent.NDF trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\10[1].exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\123\12[1].exe - Win32/PSW.Agent.NEB trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\13[1].exe - Win32/PSW.Agent.NEW trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\14[1].exe - a variant of Win32/PSW.Agent.NEW trojan
C:\Documents and Settings\EQ2\桌面\123\1635[1].exe - a variant of Win32/PSW.Agent.NDF trojan
C:\Documents and Settings\EQ2\桌面\123\1636[1].exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\123\1638[1].exe - a variant of Win32/PSW.Agent.NEW trojan
C:\Documents and Settings\EQ2\桌面\123\1[1].exe - Win32/PSW.Agent.NDF trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\2[1].exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\123\4[1].exe - Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\123\8[1].exe - Win32/PSW.Agent.NEB trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\8[].exe - Win32/PSW.Agent.NEB trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\9.exe - Win32/PSW.Delf.NGU trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\9[1].exe - Win32/PSW.Delf.NGU trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\kaspersky.exe - a variant of Win32/TrojanDownloader.Delf.AZM trojan
C:\Documents and Settings\EQ2\桌面\123\KSVSvc.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\123\LYLOADER.EXE - probably a variant of Win32/PSW.Agent.NEC trojan
C:\Documents and Settings\EQ2\桌面\123\mhso.exe - Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\123\msccrt.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\123\nwizAsktao.exe - Win32/PSW.Agent.NEW trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\nwizqjsj.exe - a variant of Win32/PSW.Agent.NEW trojan
C:\Documents and Settings\EQ2\桌面\123\nwizqqfo.exe - a variant of Win32/PSW.Agent.NEW trojan
C:\Documents and Settings\EQ2\桌面\123\PeSrvr.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\123\qjso.exe - Win32/Pacex.Gen virus
C:\Documents and Settings\EQ2\桌面\123\servet.exe - probably a variant of Win32/TrojanDownloader.Delf.BHO trojan
C:\Documents and Settings\EQ2\桌面\123\sunny.exe - probably unknown NewHeur_PE virus [7]
C:\Documents and Settings\EQ2\桌面\123\testexe.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\123\tintset.exe - a variant of Win32/PSW.Agent.NCC trojan
C:\Documents and Settings\EQ2\桌面\123\tlso.exe - Win32/PSW.Agent.NEB trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\upxdnd.exe - Win32/PSW.Agent.NDF trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\wlso.exe - Win32/PSW.Agent.NEB trojan - quarantined - unable to clean - deleted
C:\Documents and Settings\EQ2\桌面\123\woso.exe - Win32/PSW.Agent.NDZ trojan - quarantined - unable to clean - deleted
Number of scanned files: 42
Number of threats found: 33
Number of files cleaned: 33
Time of completion: 05:20:00 Total scanning time: 4 sec (00:00:04)

Notes:
[7] File is probably infected with an unknown virus.
The EQs
发表于 2007-5-21 05:25:45 | 显示全部楼层
1/3杀不到????
mofunzone
 楼主| 发表于 2007-5-21 05:27:28 | 显示全部楼层
这些都老的不行了,一台没抓杀毒的电脑上拉下来的,如果你很喜欢过nod的,自己抓网马去吧,nod根本就不行的
The EQs
发表于 2007-5-21 05:27:57 | 显示全部楼层
不行就不行
绅博周幸
发表于 2007-5-21 05:29:51 | 显示全部楼层
卡巴斯基杀40个,还有7个上报了
mofunzone
 楼主| 发表于 2007-5-21 05:30:34 | 显示全部楼层

回复 #7 EQ2 的帖子

真干脆
昨天抓了4个,2个过nod
我后来实在是懒得分析了后来,那些人的加密都写的怪不垃圾的
而且昨天有一个家伙挂马的时候还把自己的q也扔上去了,qq名叫战狼,他好像是专门写木马的,已经联系上他,希望他可以提供一批免杀给antivir,帮助改进引擎。。
mofunzone
 楼主| 发表于 2007-5-21 05:32:07 | 显示全部楼层

回复 #8 绅博周幸 的帖子

一共就42个,你杀40个,哪里还有7个上报的?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-7 01:11 , Processed in 0.134287 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表