查看: 5878|回复: 32
收起左侧

[病毒样本] 高质量,过绝大多数主流【3/42】

  [复制链接]
K7200000
发表于 2012-6-26 14:25:18 | 显示全部楼层 |阅读模式
下载
http://115.com/file/c2i3epjs#setup.exe

Antivirus        Result        Update
AhnLab-V3        -        20120626
AntiVir        BAT/ZhuJou.A        20120626
Antiy-AVL        -        20120626
Avast        -        20120625
AVG        -        20120625
BitDefender        -        20120626
ByteHero        Virus.Win32.Heur.l        20120613
CAT-QuickHeal        -        20120626
ClamAV        -        20120626
Commtouch        ZIP/Bredolab.B!Camelot        20120626
Comodo        -        20120626
DrWeb        -        20120626
Emsisoft        -        20120626
eSafe        -        20120624
F-Prot        -        20120626
F-Secure        -        20120625
Fortinet        -        20120626
GData        -        20120626
Ikarus        -        20120626
Jiangmin        -        20120626
K7AntiVirus        -        20120625
Kaspersky        -        20120626
McAfee        -        20120626
McAfee-GW-Edition        -        20120625
Microsoft        -        20120626
NOD32        -        20120625
Norman        -        20120625
nProtect        -        20120626
Panda        -        20120625
PCTools        -        20120626
Rising        -        20120626
Sophos        -        20120626
SUPERAntiSpyware        -        20120626
Symantec        -        20120626
TheHacker        -        20120625
TotalDefense        -        20120625
TrendMicro        -        20120626
TrendMicro-HouseCall        -        20120625
VBA32        -        20120625
VIPRE        -        20120626
ViRobot        -        20120626
VirusBuster        -        20120625



anubis分析报告
http://anubis.iseclab.org/?action=result&task_id=1cf8885e2ac2ea7f44945a39e414a8d34&format=html

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
消停
头像被屏蔽
发表于 2012-6-26 14:28:39 | 显示全部楼层
诺顿过

完整路径: f:\样本\setup.exe
____________________________
____________________________
开发人员 不可用
版本 不可用
安装时间 2012-6-26 ( 8:33:05 )
上次使用时间 不可用
启动项目 否
____________________________
____________________________
未知
此程序的崩溃历史记录未知。
____________________________
极少用户信任的文件
诺顿社区中有不到 5 名用户使用了此文件。
____________________________
极新的文件
该文件已在不到 1 周前发行。
____________________________
未知
有关此文件的信息不足,无法推荐它。
____________________________
http://112.91.94.185/gdown_group ... &file=setup.exe 已下载文件setup.exe自
112.91.94.185

setup.exe
____________________________
文件指纹 - SHA:
8fcb34032e58855b92dee5f2c86810a204dcc1d63ea1a26ddf629016f6addfdd
____________________________
文件指纹 - MD5:
18cd7cc28afbcc537e9ed3568e46bb20
____________________________
追影子的十三
发表于 2012-6-26 14:33:35 | 显示全部楼层
不是很大啊,为什么不发到论坛

金山报谨慎,几秒后报安全,过FSCS

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
悠柚
发表于 2012-6-26 14:36:18 | 显示全部楼层
@echo off
reg delete HKLM\SYSTEM\ControlSet002
\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318 /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\AFD /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\AppMgmt /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Base /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Boot Bus Extender /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Boot file system /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Browser /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\CryptSvc /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\DcomLaunch /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Dhcp /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\dmadmin /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\dmboot.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\dmio.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\dmload.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\dmserver /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\DnsCache /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\EventLog /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\File system /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Filter /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\HelpSvc /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\ip6fw.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\ipnat.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\LanmanServer /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\LanmanWorkstation /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\LmHosts /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Messenger /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NDIS /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NDIS Wrapper /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetBIOS /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetBIOSGroup /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetBT /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetDDEGroup /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Netlogon /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetMan /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Network /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NetworkProvider /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\NtLmSsp /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\PCI Configuration /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\PlugPlay /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\PNP Filter /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\PNP_TDI /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Primary disk /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\rdpcdd.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\rdpdd.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\rdpwd.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\rdsessmgr /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\RpcSs /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\SCSI Class /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\sermouse.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\SharedAccess /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\sr.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\SRService /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Streams Drivers /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\System Bus Extender /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Tcpip /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\TDI /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tdpipe.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tdtcp.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\termservice /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\vga.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\vgasave.sys /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\WinMgmt /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\WZCSVC /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Ndisuio /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network /f
reg delete HKLM\SYSTEM\ControlSet002\Control\SafeBoot /f


破环安全模式??
K7200000
 楼主| 发表于 2012-6-26 14:37:47 | 显示全部楼层
daixiaoran 发表于 2012-6-26 14:33
不是很大啊,为什么不发到论坛

金山报谨慎,几秒后报安全,过FSCS

网络问题,压缩包发不上来
追影子的十三
发表于 2012-6-26 14:39:42 | 显示全部楼层
看来批处理文件类的病毒依然很给力啊
迷惘的执著
发表于 2012-6-26 14:39:49 | 显示全部楼层
本帖最后由 迷惘的执著 于 2012-6-26 14:41 编辑

Q管侦测到了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
留侯
发表于 2012-6-26 14:59:16 | 显示全部楼层
大蜘蛛Clean。
/tiao眼镜鱼
发表于 2012-6-26 15:04:24 | 显示全部楼层
金山卫士安全,数字杀毒未知
消停
头像被屏蔽
发表于 2012-6-26 15:07:52 | 显示全部楼层
双击过sonar

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-9 07:24 , Processed in 0.075364 second(s), 1 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表