查看: 12224|回复: 43
收起左侧

[病毒样本] [FraudPack/Agent]video.cfg(第11次更新)已开新帖!

[复制链接]
sam.to
发表于 2008-9-11 22:59:42 | 显示全部楼层 |阅读模式
9月11:
32695860855ce400c030a52284cfc494  video.cfg (56836 bytes)
已上报到卡巴

==========================================================
9月12:
5f09d1cf9b80835cf36e619c21232c34  video.cfg(40964 bytes)
已上报到卡巴

==========================================================
9月12第2次:
18dea7412c005cca23f61deef63bb41a  video.cfg(54276 bytes)
已上报到卡巴
Hello,

video.cfg - Trojan.Win32.FraudPack.jr

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Vyacheslav Zakorzhevsky
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

==========================================================
9月15:
43e6c07dacb6a03333d0a02ca743ed2f  video.cfg(53252 bytes)
TO KL
Hello.
New malicious software was found in the attached file.
It's detection will be included in the next update. Thank you for your help.
-----------------
Regards, Namestnikov Yury
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus@kaspersky.com
http://www.kaspersky.com   http://www.viruslist.com
报:Trojan.Win32.Agent.adrf

==========================================================
9月16:
b25438a25806e83525483d2a771a0340  3video.cfg
78a1ddbe42baa78883b963ace2ad91b6  0video.cfg
0c709f8f942d2d1b812a3fb62237e648  1video.cfg
0229ff54c00e2324f83437c44b1a7640  2video.cfg
(53252 bytes)
to kl
Hello,

0video.cfg - Trojan.Win32.FraudPack.nk,
1video.cfg - Trojan.Win32.FraudPack.np,
2video.cfg - Trojan.Win32.FraudPack.nl,
3video.cfg - Trojan.Win32.FraudPack.nm

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Denis Maslennikov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

==========================================================
9月16第2次:81个(53252 bytes)
.................................
Hello,

video(1).cfg, video(76).cfg - Trojan.Win32.FraudPack.oy,
video(10).cfg, video(11).cfg, video(12).cfg, video(13).cfg, video(15).cfg, video(16).cfg, video(18).cfg, video(19).cfg, video(2).cfg, video(20).cfg, video(21).cfg, video(22).cfg, video(23).cfg, video(24).cfg, video(25).cfg, video(26).cfg, video(27).cfg, video(28).cfg, video(29).cfg, video(3).cfg, video(30).cfg, video(32).cfg, video(33).cfg, video(34).cfg, video(35).cfg, video(37).cfg, video(38).cfg, video(39).cfg, video(4).cfg, video(40).cfg, video(42).cfg, video(43).cfg, video(44).cfg, video(45).cfg, video(46).cfg, video(47).cfg, video(49).cfg, video(5).cfg, video(50).cfg, video(51).cfg, video(52).cfg, video(53).cfg, video(54).cfg, video(55).cfg, video(56).cfg, video(57).cfg, video(58).cfg, video(59).cfg, video(6).cfg, video(60).cfg, video(61).cfg, video(64).cfg, video(65).cfg, video(66).cfg, video(67).cfg, video(68).cfg, video(69).cfg, video(7).cfg, video(70).cfg, video(71).cfg, video(72).cfg, video(73).cfg, video(74).cfg, video(75).cfg, video(77).cfg, video(78).cfg, video(79).cfg, video(8).cfg, video(80).cfg, video(9).cfg, video.cfg - Trojan-Downloader.Win32.FraudLoad.vceg,
video(14).cfg - Trojan.Win32.FraudPack.oz,
video(17).cfg - Trojan.Win32.FraudPack.pc,
video(31).cfg - Trojan.Win32.FraudPack.pb,
video(36).cfg - Trojan.Win32.FraudPack.rf,
video(41).cfg - Trojan.Win32.FraudPack.pa,
video(48).cfg - Trojan.Win32.FraudPack.ox,
video(62).cfg - Trojan.Win32.FraudPack.pd,
video(63).cfg - Trojan.Win32.FraudPack.pr

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Ilya Tolstikhin



TO KL
==========================================================
9月16第3次:51个(55300 bytes)
.........................
Hello,

video(1).cfg, video(10).cfg, video(11).cfg, video(12).cfg, video(13).cfg, video(14).cfg, video(15).cfg, video(17).cfg, video(19).cfg, video(2).cfg, video(20).cfg, video(21).cfg, video(22).cfg, video(23).cfg, video(24).cfg, video(25).cfg, video(26).cfg, video(27).cfg, video(28).cfg, video(29).cfg, video(3).cfg, video(30).cfg, video(31).cfg, video(32).cfg, video(33).cfg, video(34).cfg, video(35).cfg, video(36).cfg, video(37).cfg, video(38).cfg, video(39).cfg, video(40).cfg, video(41).cfg, video(42).cfg, video(43).cfg, video(44).cfg, video(45).cfg, video(46).cfg, video(47).cfg, video(48).cfg, video(49).cfg, video(5).cfg, video(50).cfg, video(6).cfg, video(7).cfg, video(8).cfg, video(9).cfg, video.cfg - Trojan.Win32.FraudPack.rz,
video(16).cfg - Trojan.Win32.FraudPack.pn,
video(18).cfg - Trojan.Win32.FraudPack.pm,
video(4).cfg - Trojan.Win32.FraudPack.pk

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
TO KL


==========================================================
9月17(28个)
e3aea80de817515972033410b5476c44  video(1).cfg
703b9226a0746944e678fbfaf5f8e077  video(10).cfg
9f0c910bcd6366ef9baf1ea294c6aa05  video(11).cfg
77a683de6220c4f802c84ae705bccbd0  video(12).cfg
7b8f8891bec0a045a87a2349f54c7c37  video(13).cfg
f0ccae8f4fdb55dfdcf2d240e5df5aa8  video(14).cfg
a26ae0652060b0ca8939a0f3decff3de  video(15).cfg
ffd8d54445edc8000f100697f4ee2075  video(16).cfg
50e0fb9e21e5f07f2d9d141cd8dad347  video(17).cfg
e67afdc9bb32ff701548398f847c7fcc  video(18).cfg
97b48e31301dc4410cdb8daef7396b5d  video(19).cfg
d5e50009d51628b1d0e88011a1e91cfe  video(2).cfg
43079c8048429dc716b9cbba756274be  video(20).cfg
050e92a419bd38192d4b906c11a78bcd  video(21).cfg
a2035835a7fd756a5331e961ee32b6b1  video(22).cfg
7c932aa022116824b2b99055053dd9a6  video(23).cfg
8255d33fa419cc02650df60465009f16  video(24).cfg
187589369123296f759dd88f72577375  video(25).cfg
23869dba662dc719106645b9aee3a511  video(26).cfg
f4cbe5f59d0db8337744390ebd571d3c  video(27).cfg
0a2e66b166e2533ed3bc25bb999ae169  video(3).cfg
e5fe80ad70ae2eb60585d50b9bc18265  video(4).cfg
271aca872e4f8e80468c5612a86a8ed2  video(5).cfg
9513807a36f0594de3f98229a781306b  video(6).cfg
eb136562db20c6862f4900bf459aa624  video(7).cfg
b57a47b882a79823b0b09cf1a7b49e0d  video(8).cfg
c9742a237168e16c3724fd9ff8af2096  video(9).cfg
e881a50447ca3baa0af2df7f26d9a90d  video.cfg
TO KL
Hello,

video(1).cfg, video(10).cfg, video(12).cfg, video(13).cfg, video(14).cfg, video(15).cfg, video(16).cfg, video(17).cfg, video(18).cfg, video(19).cfg, video(2).cfg, video(20).cfg, video(21).cfg, video(22).cfg, video(23).cfg, video(24).cfg, video(25).cfg, video(26).cfg, video(27).cfg, video(3).cfg, video(4).cfg, video(5).cfg, video(6).cfg, video(7).cfg, video(8).cfg, video(9).cfg, video.cfg - Trojan.Win32.FraudPack.rz,
video(11).cfg - Trojan.Win32.FraudPack.ru

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Andrey Bezborodov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

==========================================================
9月17第2次:11个(55300 bytes)
cfbe2d5fc51956db40e3b85a49e919d4  video(1).cfg
af03779916526ecf91c649ec5a46f9be  video(6).cfg
97726f61a6c3de186421c8e483af073a  video(2).cfg
9661bc3afce9d7b2504da7460bcee8af  video(9).cfg
8ab2b3bd3cfaedf4239da366ee7177e9  video(8).cfg
89082b8c012f78292af3f552aa0244e1  video(10).cfg
881f879711c0d53230a61c11db7fe50a  video(5).cfg
71f7dbe239662f76026f2c9d95c26e33  video(3).cfg
5ee02e9c7080e26b78ccdeeb429fe97e  video(4).cfg
2dcbb420d762b5e4de6459b7572ccb17  video(7).cfg
2795def825460fc14506affd1a12ea23  video.cfg
TO KL
Hello,

video(1).cfg - Trojan.Win32.FraudPack.sg,
video(10).cfg, video(2).cfg, video(3).cfg, video(4).cfg, video(5).cfg, video(6).cfg, video(7).cfg, video(8).cfg, video(9).cfg - Trojan.Win32.FraudPack.sh

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

video.cfg - Trojan.Win32.FraudPack.rt

This file is already detected. Please update your antivirus bases.

Please quote all when answering.

--
Best regards, Andrey Bezborodov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.

==========================================================
9月17第3次:16个(55300 bytes)
267857357a09f60fa591e004bb237261  video(15).cfg
3eaf3f3d58df80bc7cf11491e9e07fd9  video(3).cfg
44b7ec539590dd07a325912c138efef5  video(14).cfg
4dea4b8d142019811dfbd4b8b2662bd2  video(7).cfg
731d352cbe5b440a0db13ef564c0830f  video(11).cfg
74d37211dcd805e069d2828e4d59a489  video(8).cfg
7d745fcd8e81ba1dae1ac78679c7a844  video(9).cfg
a7fa956ea6af467801521bf1ca708938  video(1).cfg
b127bf8f6e84736b935ef3459210cd07  video(13).cfg
c421da1766e859e319f75cf380c412a9  video.cfg
c655dc31d54308db8b3e42e3dca42df0  video(5).cfg
d152fc3cb958c27f498e9060f0f69609  video(12).cfg
dbe30cd7092d6590954a46abfc24856b  video(10).cfg
e30a1fd412e66051762a5a7b9c62a01f  video(4).cfg
e5814ae31c4cdcaf8c15db2b3ce4e4d6  video(6).cfg
f7cfcd9dd05cfb65121dca359371d3e5  video(2).cfg
TO KL
video(1).cfg, video(10).cfg, video(11).cfg, video(12).cfg, video(13).cfg, video(14).cfg, video(15).cfg, video(2).cfg, video(3).cfg, video(4).cfg, video(5).cfg, video(6).cfg, video(7).cfg, video(8).cfg, video(9).cfg, video.cfg - Trojan.Win32.FraudPack.sh

==========================================================
9月18:(36个,(55300 bytes)
00e1c619ffc4443a65afa1bfc305e15e  video(6).cfg
028a80de1a6ee903c683d79397eb66f6  video(19).cfg
044ee239884e792e1c9084518c368efb  video(1).cfg
09ed5f07f29efdcd0bdd8a44f77adc41  video(11).cfg
0a7e0b8fada3fae2f96d1265890a26a3  video(16).cfg
0c47cf0e6b645523390b3fa3ffd60ec9  video(33).cfg
16d2b3b392264b4be9a346d67d0bfefd  video(15).cfg
1e3dcafb51046621c74de50a21162b3b  video(29).cfg
30b0f6104608337cc8546b4523854083  video(32).cfg
37ef20a6bdf83f6230f4d0a5d0e0e121  video(28).cfg
3e14afd3c0ddee3b7ff02ae2ab1f53cb  video(23).cfg
40eb6dbefa9a5169e905613c4202430b  video(5).cfg
4abd59bf63866fc25e9776b04702cba3  video(14).cfg
57f82fb176a75daa15271d2b4a3bea52  video(20).cfg
62d964085ed50185145a94431cfb1898  video(31).cfg
67d4c2e48e079d77b5f6630fbcbf492c  video(30).cfg
6aa36bbb38d326d7ef2d68fc5cb071da  video(3).cfg
70b8048f7d8ee1b61a023671681bd4bf  video(13).cfg
73ed884972505ff293510d6fdc8605ce  video.cfg
76872791bc886bf35b6ce6a8cbc51da8  video(35).cfg
78f628826eecfd66a328513f8f2afed9  video(4).cfg
7d9407fec3e590d3f2eecfba9c730dd8  video(7).cfg
86ce85229c9b4c8518973908ad3ec774  video(24).cfg
876abcfae35cdd61f11b4236881ff868  video(2).cfg
92d354a8a4c77f9ae2bf0ffc10fc47e3  video(25).cfg
9d2a6f33b26a9f433ec909f8f388937f  video(12).cfg
a3206b8c3e7949b9876eaedeee52fc80  video(22).cfg
a6ebe322e6f66eda44141c5a605ec1ae  video(26).cfg
a7a275d90dfdd791dbe826caa3bf8a92  video(9).cfg
b2be89247cc987d357303d28d1f0a009  video(34).cfg
c508f89ae853694acfc28fe1ba6209ea  video(10).cfg
c5e8b0988738385b07c25b9e641d44a5  video(8).cfg
d153e0e75fc2f78bdede5550ba6087fa  video(21).cfg
dbcd855142c1e5f5d97c932257933732  video(17).cfg
dd625e9a5afb2755a3bcf58ecfb148c0  video(27).cfg
fc6e7b2e0d3cf11751ebfd0ee53c4418  video(18).cfg
TO KL

==========================================================
9月19:51个,55300 bytes
fe099bef9e38e4671070a120bab8cebf  video(1).cfg
fd8be2757654d8009a1d10d5cc4adf45  video(23).cfg
faa4056f85c58945c50547ccd23ae37c  video(44).cfg
ec4fe06a65f3be70585b93e7d17ac65c  video(50).cfg
e4b905705a01da214634a0fe92b8ce38  video(11).cfg
e4632fad7825282308352b3050d99589  video(39).cfg
e26d3e816c69e57e4b9bcbb4ac890908  video(2).cfg
dbf7cdccbf77f2612be3a932334d3691  video(26).cfg
daf1afadb0700e4411e5d5a591909bd3  video(34).cfg
d747d5072eb407aa64338548fccc0054  video(12).cfg
d4e5a3e2c3cfa14497d5c221e8b2cf60  video(31).cfg
d462f62df67ed7e1d8c8e868a9552bc3  video(43).cfg
d14775da2b9ebdaea3a725984d94c6c1  video(49).cfg
d0a5cd4415263a92644fd6cddf8a7635  video(25).cfg
d074d0cad927c665141b51621a9eb9a6  video(10).cfg
d02254f3884a4836217a576337dae114  video(18).cfg
cd80676e0e0a00e8f23ee7df4c7bc0ae  video(38).cfg
c68d6de98c2b563c812798c1756334f5  video(14).cfg
bb6ef0db4d1dcae6db76ce663c3cd991  video(15).cfg
adf4eb9f877e9733acc121920c117283  video(41).cfg
a810c85917004020fa26386b1a07be6b  video(29).cfg
a4667d5e202550ce5c2b8acd33478775  video(21).cfg
9f5d061960c44b5ef7c9d8e767e3f6d6  video(37).cfg
9863be4d646c6610856ce950bcb363fb  video(32).cfg
983bf0046e76a83235315790871b547d  video(5).cfg
8e142a11075304dbc5590693720194a4  video(45).cfg
80ff640d63517f9460296b00dc16b8e6  video(27).cfg
7b690dda6deead0f48ab920db79d4259  video(47).cfg
70d3a8a69ad54e69587e09e8ce55e5dd  video(33).cfg
6a8eaab7c5b87277bb541292032d1550  video(19).cfg
616af18ac5ce5ecca4705bb7fc9e41d6  video(42).cfg
614b1f7fae2670dc3ecaa95ce922561f  video(20).cfg
5d9dedcc98fb93c2f0ab5fbb28fee098  video(22).cfg
4b8be88796fa41ae786620d4f11c855b  video(4).cfg
4829794dfcd1ea3b1c3824471119ecb5  video(8).cfg
4452a39fb61a20885524cf332bebae81  video(48).cfg
4326e752114f2f1f6c778ee4834f7b4f  video(35).cfg
37f16aa77f25dadfa37174f4c3e04664  video.cfg
37a1f07ddd331e93fe6b698bf81dc596  video(6).cfg
377d495aec76adf80db820646fb86534  video(3).cfg
360216cd93b94515496dca15e7ecae92  video(28).cfg
239f690ee285dd264d35cb5ba878ca5d  video(24).cfg
2307a467b718c4b261908616900a0f6d  video(36).cfg
10d2eb456108a0a67619f9c47d1806bb  video(9).cfg
098917434a84731bc06df7530e67b7f8  video(17).cfg
0826383812e2f04b0fd8cac62bceb7ed  video(13).cfg
074087fb16813cc655598b2408ca71b7  video(16).cfg
071d3f1c396ce5eee0e6bc238d2aaa32  video(46).cfg
053f27ebe777d91fcd6d55ebfc147b11  video(40).cfg
00d719b3aa5790b17e23c69a45c80501  video(30).cfg
004b9d64415327b897c2044b4a6c46e0  video(7).cfg
TO KL
Hello. New malicious software was found in the attached file. Its detection will be included in the next update. Thank you for your help. -----------------Regards, Evgeny AseevVirus Analyst, Kaspersky Lab. Ph.: +7(095) 797-8700E-mail: newvirus@kaspersky.comhttp://www.kaspersky.com   http://www.viruslist.com  


==========================================================


因字数限制而开新帖:
http://bbs.kafan.cn/viewthread.php?tid=331710

[ 本帖最后由 kato9096 于 2008-9-22 15:29 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +8 收起 理由
qianwenxiang + 8 加分鼓励

查看全部评分

Kitman
发表于 2008-9-11 23:24:36 | 显示全部楼层
已上报到AVIRA
The file 'video.cfg' has been determined to be 'MALWARE'. Our analysts named the threat TR/Dldr.Small.ewk. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
尤金卡巴斯基
发表于 2008-9-12 17:02:13 | 显示全部楼层
2008/9/12 17:01:42        已清除        木马程序 Trojan.Win32.FraudPack.ik        G:\Temp\Virus\video(cfg).rar/video.cfg
sam.to
 楼主| 发表于 2008-9-12 17:02:58 | 显示全部楼层
第一次更新
Palkia
发表于 2008-9-12 18:51:44 | 显示全部楼层
金山 0
fzz8848
头像被屏蔽
发表于 2008-9-12 19:08:40 | 显示全部楼层
Begin scan in 'E:\Download\Virus\video(cfg).rar'
E:\Download\Virus\video(cfg).rar
    [0] Archive type: RAR
    --> video.cfg
      [DETECTION] Is the TR/FraudPack.HY Trojan
    [NOTE]      The file was deleted!
Kitman
发表于 2008-9-12 19:44:29 | 显示全部楼层

回复 4楼 kato9096 的帖子

The file 'video.cfg' has been determined to be 'UNDER ANALYSIS'.
The file 'video.cfg' has been determined to be 'MALWARE'. 
Our analysts named the threat TR/Dldr.Agent.xad. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates. 


[ 本帖最后由 Kitman 于 2008-9-12 20:42 编辑 ]
BING126
头像被屏蔽
发表于 2008-9-12 19:50:04 | 显示全部楼层
McAfee  miss
sam.to
 楼主| 发表于 2008-9-12 23:57:53 | 显示全部楼层
第2次更新
sam.to
 楼主| 发表于 2008-9-14 21:00:26 | 显示全部楼层
傘不报这些文件,有人上报嗎?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-21 18:29 , Processed in 0.145404 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表