查看: 3583|回复: 15
收起左侧

[误报文件] 小红伞报电信互联星空宽带登录器(附带小红伞邮件回复)

[复制链接]
245867683
发表于 2011-10-20 10:37:36 | 显示全部楼层 |阅读模式
本帖最后由 245867683 于 2011-10-20 16:11 编辑

从官方下载的,已经上传至115盘上报给小红伞人工分析的结果依然为木马,电信搞的什么啊

http://115.com/file/dn91v0dj

Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC00862387.

We received the following archive files:

File ID        Filename        Size (Byte)        Result
26353485        NKSetup25v24_nc.zip        15.41 MB        OK
A listing of files contained inside archives alongside their results can be found below:

File ID        Filename        Size (Byte)        Result
26353486        NKSetup25v24_nc.exe        15.49 MB        MALWARE

Please find a detailed report concerning each individual sample below:

Filename        Result
NKSetup25v24_nc.exe        MALWARE

The file 'NKSetup25v24_nc.exe' has been determined to be 'MALWARE'.Our analysts named the threat TR/Horse.SDS.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.09.138.
Alternatively you can see the analysis result here:
http://analysis.avira.com/sample ... p;incidentid=862387

An overview of all your submissions can be found here:
http://analysis.avira.com/sample ... TXPnVCGjybVTCkB271j

We recommend to use our upload form for further submissions. In case the result is known it will be shown in realtime to you. Furthermore files which are considered to be false positive suspictions can only be submitted using this method. http://analysis.avira.com/samples/index.php?lang=en


Please note: If you have specific questions please address them to support@avira.com

Kind regards
Avira Virus Lab

---------------------------------------------
Avira Operations GmbH & Co. KG
Kaplaneiweg 1, 88069 Tettnang, Germany
Phone: +49 (0) 7542-500 0
Fax: +49 (0) 7542-500 3000
Internet: http://www.avira.com

CEO: Tjark Auerbach
Headquarter: Tettnang
Commercial register: AG Ulm HRB 630992

---------------------------------------------
jayavira
发表于 2011-10-20 10:39:53 | 显示全部楼层
互联星空也可以说是流氓软件啊
小墙头
发表于 2011-10-20 10:49:15 | 显示全部楼层
A2安全
抱金砖
发表于 2011-10-20 11:13:06 | 显示全部楼层
不被报才不正常呢
这货真不是什么好东西
倾枫锝渔♂
发表于 2011-10-20 12:19:30 | 显示全部楼层
教室的无线不给力~~~
不下了~~~
留侯
发表于 2011-10-20 12:27:15 | 显示全部楼层
大蜘蛛:
NKSetup25v24_nc.exe\wm_hooks.dll - is riskware program Program.RemoteAdmin
245867683
 楼主| 发表于 2011-10-20 12:55:40 | 显示全部楼层
留侯 发表于 2011-10-20 12:27
大蜘蛛:
NKSetup25v24_nc.exe\wm_hooks.dll - is riskware program Program.RemoteAdmin

汗,国外杀软基本都报
245867683
 楼主| 发表于 2011-10-20 12:56:17 | 显示全部楼层
抱金砖 发表于 2011-10-20 11:13
不被报才不正常呢
这货真不是什么好东西

没办法,不装这东西在学校无法联网
ADSLgg
发表于 2011-10-20 12:59:35 | 显示全部楼层
TR/horse。sds
抱金砖
发表于 2011-10-20 13:40:44 | 显示全部楼层
估计它代码里有一些比较恶心的收集信息以及定时弹广告功能
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-8-22 11:00 , Processed in 0.142704 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表