查看: 5531|回复: 25
收起左侧

[病毒样本] 某软件又不行了,不过被趋势科技封锁了

  [复制链接]
绅博周幸
发表于 2011-9-11 17:25:48 | 显示全部楼层 |阅读模式




AhnLab-V3 2011.09.10.00 2011.09.10 Backdoor/Win32.IRC
AntiVir 7.11.14.161 2011.09.09 BDS/IRCBot.A.40
Antiy-AVL 2.0.3.7 2011.09.11 Trojan/Win32.Small
Avast 4.8.1351.0 2011.09.10 -
Avast5 5.0.677.0 2011.09.10 -
AVG 10.0.0.1190 2011.09.11 BackDoor.Generic12.CKAK
BitDefender 7.2 2011.09.11 -
ByteHero 1.0.0.1 2011.09.10 -
CAT-QuickHeal 11.00 2011.09.10 -
ClamAV 0.97.0.0 2011.09.11 -
Commtouch 5.3.2.6 2011.09.10 W32/BackdoorX.DKPY
Comodo 10072 2011.09.11 -
DrWeb 5.0.2.03300 2011.09.11 -
Emsisoft 5.1.0.11 2011.09.11 Trojan-Downloader.Win32.Small!IK
eSafe 7.0.17.0 2011.09.07 Win32.BDSIRCBot.A
eTrust-Vet 36.1.8550 2011.09.10 -
F-Prot 4.6.2.117 2011.09.10 W32/BackdoorX.DKPY
F-Secure 9.0.16440.0 2011.09.11 -
Fortinet 4.3.370.0 2011.09.11 -
GData 22 2011.09.11 -
Ikarus T3.1.1.107.0 2011.09.11 Trojan-Downloader.Win32.Small
Jiangmin 13.0.900 2011.09.10 -
K7AntiVirus 9.112.5114 2011.09.09 Backdoor
Kaspersky 9.0.0.837 2011.09.11 -
McAfee 5.400.0.1158 2011.09.11 Generic BackDoor!bfe
McAfee-GW-Edition 2010.1D 2011.09.10 Generic BackDoor!bfe
Microsoft 1.7604 2011.09.11 Backdoor:Win32/IRCbot
NOD32 6453 2011.09.11 probably a variant of Win32/Agent.LNQQLFF
Norman 6.07.11 2011.09.10 W32/Suspicious_Gen2.DJOLA
nProtect 2011-09-11.01 2011.09.11 -
Panda 10.0.3.5 2011.09.10 Trj/CI.A
PCTools 8.0.0.5 2011.09.11 Backdoor.IRC.B!rem
Prevx 3.0 2011.09.11 -
Rising 23.74.03.03 2011.09.09 Trojan.Win32.Generic.1247367C
Sophos 4.69.0 2011.09.11 Mal/Generic-L
SUPERAntiSpyware 4.40.0.1006 2011.09.10 -
Symantec 20111.2.0.82 2011.09.11 Backdoor.IRC.Bot
TheHacker 6.7.0.1.293 2011.09.10 -
TrendMicro 9.500.0.1008 2011.09.09 TROJ_GEN.R4AC1DL
TrendMicro-HouseCall 9.500.0.1008 2011.09.11 TROJ_GEN.R4AC1DL
VBA32 3.12.16.4 2011.09.09 -
VIPRE 10439 2011.09.11 Trojan.Win32.Generic!BT
ViRobot 2011.9.10.4666 2011.09.10 -
VirusBuster 14.0.206.1 2011.09.10 -

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jayavira
发表于 2011-9-11 17:28:43 | 显示全部楼层
需要安装,不测试了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
绅博周幸
 楼主| 发表于 2011-9-11 17:30:56 | 显示全部楼层
jayavira 发表于 2011-9-11 17:28
需要安装,不测试了

安装看看
ubuntu2011
发表于 2011-9-11 17:31:22 | 显示全部楼层
windows defender报警,求分析行为
jayavira
发表于 2011-9-11 17:32:12 | 显示全部楼层
绅博周幸 发表于 2011-9-11 17:30
安装看看

比较麻烦啊
所以还是算了
XMonster
发表于 2011-9-11 17:32:58 | 显示全部楼层
绅博周幸 发表于 2011-9-11 17:30
安装看看

神马都木有。。
绅博周幸
 楼主| 发表于 2011-9-11 17:33:28 | 显示全部楼层
本帖最后由 绅博周幸 于 2011-9-11 17:36 编辑
ubuntu2011 发表于 2011-9-11 17:31
windows defender报警,求分析行为


非常明显的Backdoor.IRC.Bot



Backdoor.IRC.Bot is a generic detection for Trojan horses that open a back door on the compromised computer and connect to Internet Relay Chat (IRC) channels to launch distributed denial of service (DDoS) attacks.

Background information
A Backdoor.IRC.Bot is a type of Trojan horse that opens a back door on the compromised computer using Internet Relay Chat (IRC) channels, allowing a remote attacker to perform various functions. In particular, this type of Trojan - also known as a 'bot' as it allows the attacker to gain control of the compromised computer - creates a type of network of computers, called a botnet, to launch distributed denial of service (DDoS) attacks at a specific target.

A malicious author creates the Trojan and distributes it using a variety of methods, such as placing it on peer-to-peer websites or spamming it as an email attachment. (Its worth remembering that Trojans do not self-replicate, hence the malicious author needs to utilize other vehicles for it to spread.) Once the threat has compromised a computer, it joins a predetermined IRC channel and awaits instructions from the malicious author. As this process is completed almost, if not completely, silently - for example, the Trojan may have been bundled with a video file and while that video plays normally, the Trojan is installed in the background - the user is unaware that his or her computer has been compromised and that a back door is now open.

Once the malicious author has compromised multiple computers and built the botnet - there have been cases of botnets containing tens of thousands of computers - the author will issue commands for the botnet to perform a DDoS attack. A denial of service is as the name suggests, whereby the target server is overwhelmed by numerous simultaneous connection requests, therefore denying access to any new connections.
绅博周幸
 楼主| 发表于 2011-9-11 17:34:30 | 显示全部楼层
dm34343667 发表于 2011-9-11 17:32
神马都木有。。

你装了就知道
jayavira
发表于 2011-9-11 17:38:15 | 显示全部楼层
后门木马

文件信息
文件名称:D:\下载文件夹\dana-setup-de.exe
文件大小:
403 Kb
内部名称:
无内部名称
文件签名:
无文件签名信息
文件描述:
后门木马
文件MD5:
1d6fe0aeb0c9c3dba10d48749ac7a302
XMonster
发表于 2011-9-11 17:38:34 | 显示全部楼层
绅博周幸 发表于 2011-9-11 17:34
你装了就知道

我装了..


木有神马诶。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-17 12:05 , Processed in 0.154063 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表