12
返回列表 发新帖
楼主: vm001
收起左侧

[病毒样本] 转远控

[复制链接]
卡巴专家
发表于 2013-8-29 21:42:08 | 显示全部楼层
dongwenqi 发表于 2013-8-29 21:40
搜狗和Q管已经能正常运行了,上面的2个我已经在实机上运行了,已经被阻止运行了

问题是小白不知道这个是木马的话,选择允许的话还是拦不住,警告不够明确
dongwenqi
发表于 2013-8-29 21:45:11 | 显示全部楼层
卡巴专家 发表于 2013-8-29 21:42
问题是小白不知道这个是木马的话,选择允许的话还是拦不住,警告不够明确

说的也是,这点到时提醒了我,关键是小白能用卡巴吗
卡巴专家
发表于 2013-8-29 21:55:09 | 显示全部楼层
dongwenqi 发表于 2013-8-29 21:45
说的也是,这点到时提醒了我,关键是小白能用卡巴吗

小白为什么不能用卡巴
dongwenqi
发表于 2013-8-29 22:03:28 | 显示全部楼层
卡巴专家 发表于 2013-8-29 21:55
小白为什么不能用卡巴

就像你说的警告不够明确,万一小白遇到这个拦截,基本上不看的,都乱点允许,到时会怎样呢
消停
头像被屏蔽
发表于 2013-8-30 11:29:04 | 显示全部楼层
Filename: ppcef.dll
Threat name: WS.Reputation.1
Full Path: f:\norton样本\白加黑\uvi\ppcef.dll

____________________________



Details
Unknown Community Usage,  Unknown Age,  Risk Medium





Origin
Downloaded from
 https://att.kafan.cn/forum.php?mo ... Dc5OTA2N3wxNjIwOTUz





Activity
Actions performed: Actions performed: 1



____________________________



On computers as of 
Not Available


Last Used 
2013-8-30 at 11:28:28


Startup Item 
No


Launched 
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

Medium
This file risk is medium.

Threat type: Insight Network Threat. There are many indications that this file is untrustworthy and therefore not safe



____________________________


https://att.kafan.cn/forum.php?mo ... Dc5OTA2N3wxNjIwOTUz

Downloaded File ppcef.dll Threat name: WS.Reputation.1
from att.kafan.cn

Source: External Media



____________________________

File Actions

File: f:\norton样本\白加黑\uvi\ ppcef.dll Removed
____________________________


File Thumbprint - SHA:
ed1cbf46f1ff20bca4594368f4ac59a58dfe85321065aba1b382391fdb57cff0
File Thumbprint - MD5:
Not available








Filename: stormupdate.dll
Threat name: WS.Reputation.1
Full Path: f:\norton样本\白加黑\uxubxwxwta\uxubxwxwta\stormupdate.dll

____________________________



Details
Unknown Community Usage,  Unknown Age,  Risk Medium





Origin
Downloaded from
 https://att.kafan.cn/forum.php?mo ... Dc5OTA2N3wxNjIwOTUz





Activity
Actions performed: Actions performed: 1



____________________________



On computers as of 
Not Available


Last Used 
2013-8-30 at 11:29:08


Startup Item 
No


Launched 
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

Medium
This file risk is medium.

Threat type: Insight Network Threat. There are many indications that this file is untrustworthy and therefore not safe



____________________________


https://att.kafan.cn/forum.php?mo ... Dc5OTA2N3wxNjIwOTUz

Downloaded File stormupdate.dll Threat name: WS.Reputation.1
from att.kafan.cn

Source: External Media



____________________________

File Actions

File: f:\norton样本\白加黑\uxubxwxwta\uxubxwxwta\ stormupdate.dll Removed
____________________________


File Thumbprint - SHA:
e1512d73872542b3bab7d5ec99005024570efdad40ccda468ba7bc8451aa399a
File Thumbprint - MD5:
Not available
落漠
发表于 2013-8-30 11:33:43 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
代表太阳消灭你
发表于 2013-8-30 11:36:33 | 显示全部楼层
为什么360没反应
Dust-;羅錠
发表于 2013-8-30 23:49:29 | 显示全部楼层
本帖最后由 Dust-;羅錠 于 2013-9-1 01:15 编辑
Dear linchang1997,

Your submission has been analyzed. A corresponding record has been added to the Dr.Web virus database and will be available with the next update.

Threat: BackDoor.Siggen.52105

Thank you for the cooperation.

--
Yours sincerely,
Virus Monitoring Service
Doctor Web Ltd.


主体和衍生物都入库了,但奇怪的是人工分析竟然将EXE也给报了,上报误报后Dr.Web解除了对exe的误报.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 13:58 , Processed in 0.093259 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表