查看: 3143|回复: 16
收起左侧

[病毒样本] b34900 附anubis的沙盘报告

[复制链接]
lanvin
发表于 2007-11-28 23:41:05 | 显示全部楼层 |阅读模式
http://analysis.seclab.tuwien.ac.at/result.php?taskid=5df1cbb6784b2ab42d89907cabc6ed91&refresh=1

anubis沙盘介绍请看我的blog
http://hi.baidu.com/tomatolabs/blog/item/397fc3af5734fff8fbed50d9.html

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Graybird
发表于 2007-11-28 23:43:10 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\setup.rar'
E:\setup.rar
  [0] Archive type: RAR
    --> setup.exe
      [1] Archive type: RAR SFX (self extracting)
      --> Setup.exe
          [DETECTION] File has been compressed with an unusual runtime compression tool (PCK/FSG). Please verify the origin of the file
      [INFO]      The file was deleted!
mofunzone
发表于 2007-11-28 23:57:13 | 显示全部楼层
终于还是稍微的看出了v8和v7的区别了。。
Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\setup.rar'
C:\Users\morgan\Documents\
  setup.rar
    [0] Archive type: RAR
      --> setup.exe
        [1] Archive type: Runtime Packed
        --> Object
        --> Setup.exe
          [2] Archive type: RSRC
          --> Object
          --> Object
              [DETECTION] Is the Trojan horse TR/Crypt.FSPM.Gen
              [WARNING]   Infected files in archives cannot be repaired!
      [WARNING]   The file was ignored!
killloop
发表于 2007-11-29 04:06:03 | 显示全部楼层
20.20.22      
0个
ggcn
发表于 2007-11-29 08:48:45 | 显示全部楼层
红伞V7不报呀,V8报了吗?看来真要换V8了?
Graybird
发表于 2007-11-29 08:54:38 | 显示全部楼层

回复 5楼 ggcn 的帖子

我的V7报了~
will
发表于 2007-11-29 09:08:06 | 显示全部楼层
avast! 飘过~
ggcn
发表于 2007-11-29 09:15:24 | 显示全部楼层
原帖由 Graybird 于 2007-11-29 08:54 发表
我的V7报了~

晕,不是吧

我的
tarting the file scan:
Begin scan in 'C:\Documents and Settings\Administrator\桌面\setup.rar'

End of the scan: 2007年11月29日星期四  09:14
Used time: 00:05 min
The scan has been done completely.
      0 Scanning directories
      3 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      3 Files not concerned
      2 Archives were scanned
      0 Warnings
      0 Notes


我的版本信息是
Productversion build.dat 7.06.00.308 2007-9-19
Search engine avewin32.dll 7.06.00.34 2007-11-27
Virus definition file antivir.vdf 7.00.01.19 2007-11-28
Control Center avcenter.exe 7.02.00.14 2007-11-27
Config Center avconfig.exe 7.02.00.07 2007-8-21
Luke Filewalker avscan.exe 7.00.06.01 2007-8-23
Archive Library avpack32.dll 7.03.00.15 2007-8-3
AntiVir Guard avguard.exe 7.00.00.82 2007-11-27
Filter avgntflt.sys 7.00.00.04 2007-9-17
AntiVir MailGuard avmailc.exe 7.00.01.66 2007-11-27
Engine Service avesvc.exe 7.00.01.04 2007-11-27
Scheduler sched.exe 7.00.00.62 2007-8-28
Updater update.exe 1.02.10.13 2007-8-28
难道没更新?
googlehack
发表于 2007-11-29 12:35:56 | 显示全部楼层
是个木马吧?
Graybird
发表于 2007-11-29 14:07:26 | 显示全部楼层

回复 8楼 ggcn 的帖子

开高启发~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-10 22:12 , Processed in 0.126256 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表