查看: 4587|回复: 12
收起左侧

[病毒样本] 2014-07-28 #29

[复制链接]
malware1
发表于 2014-7-29 04:23:14 | 显示全部楼层 |阅读模式
http://kuai.xunlei.com/d/XLDoFDIAvbDWUwQAc23

密码 infected

已将以下杀软漏报的文件上报至对应厂商:

Anvisoft
Avast
Avira
Baidu
BitDefender
Comodo
Dr.Web
Emsisoft
ESET
F-Prot
F-Secure
Fortinet
Ikarus
Immunet
K7
Kaspersky
Kompas
Malwarebytes
McAfee
Microsoft
Nano
Nictatech
Outpost
Panda
PCMAV
Qihoo 360
Quick Heal
Sophos
Spybot
Symantec
TotalDefense
Trend Micro
Trojan Killer
Twister
Vipre
VirIT
Xvirus
Zillya

评分

参与人数 1人气 +1 收起 理由
zmzcy + 1 版区有你更精彩: )

查看全部评分

折腾哥
发表于 2014-7-29 05:40:25 | 显示全部楼层
又听见 卡巴斯基的 更挤声
fzshot
发表于 2014-7-29 05:42:13 | 显示全部楼层
FSIS 18x kill 11x miss
结果: 找到 18 恶意软件
Suspicious:W32/Malware!Gemini (怀疑的感染)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\invoice_28.07.doc.exe
    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\uisap.exe

Gen:Variant.Kazy.221317 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\rundll32.exe\Temp.exe

Trojan.Generic.11584013 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\bill.2563034.PDF_____.exe 操作: 已隔离

Gen:Variant.Symmi.2655 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\111nocrypt.exe 操作: 已隔离

Gen:Variant.Kazy.418781 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\loplayer.exe 操作: 已隔离

Trojan.Generic.11586118 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\1.exe 操作: 已隔离

Trojan.GenericKD.1780640 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\Imminent_Lol.exe 操作: 已隔离

Trojan.Generic.11586862 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\lu.exe 操作: 已隔离

Trojan.GenericKD.1780735 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\Order 3731.exe 操作: 已隔离

Trojan.Generic.11587443 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\HiddenSightCrypter.V2.exe 操作: 已隔离

Trojan.Generic.11586886 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\selfie.scr 操作: 已隔离

Gen:Trojan.Heur.JP.cuW@au@1Wmki (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\1(1).exe 操作: 已隔离

Gen:Variant.Kazy.417946 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\player.exe 操作: 已隔离
    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\play.exe 操作: 已隔离

Trojan:W32/Agent.DVBL (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\Order details 001-8821901-992107.exe 操作: 已隔离

Gen:Heur.MSIL.Krypt.5 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\server.exe 操作: 已隔离

Gen:Variant.Graftor.149152 (病毒)

    C:\Users\PRODUCTION I.G\Desktop\2014-07-28_29\2014-07-28_29\PurchaseOrder.exe 操作: 已隔离
Luca.l
发表于 2014-7-29 08:45:56 | 显示全部楼层
管家

火绒

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
1654637359
发表于 2014-7-29 09:44:11 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
fuzhk
发表于 2014-7-29 10:23:01 | 显示全部楼层
我讨厌咖啡的区别对待,VSE这种病毒居然24/29
Flying_Bird
发表于 2014-7-29 10:29:11 | 显示全部楼层
EAV missed 1x.
D:\Download\2014-07-28_29\1(1).exe - Win32/TrojanDownloader.Agent.SBP 特洛伊木马 的变种
D:\Download\2014-07-28_29\1.exe - MSIL/PSW.Agent.OMJ 特洛伊木马 的变种
D:\Download\2014-07-28_29\111.exe - Win32/Spy.Zbot.AAU 特洛伊木马
D:\Download\2014-07-28_29\111nocrypt.exe - Win32/Spy.Zbot.AAU 特洛伊木马 的变种
D:\Download\2014-07-28_29\2.exe - Win32/Agent.QMF 特洛伊木马
D:\Download\2014-07-28_29\333.exe - Win32/Agent.QMF 特洛伊木马
D:\Download\2014-07-28_29\bill.2563034.PDF_____.exe - Win32/TrojanDownloader.Zurgop.BK 特洛伊木马
D:\Download\2014-07-28_29\e3753a3.exe - Win32/Filecoder.CO 特洛伊木马
D:\Download\2014-07-28_29\Imminent_Lol.exe - MSIL/Spy.Agent.JG 特洛伊木马
D:\Download\2014-07-28_29\invoice_28.07.doc.exe - Win32/TrojanDownloader.Small.PSD 特洛伊木马
D:\Download\2014-07-28_29\loplayer.exe - Win32/TrojanDownloader.Zurgop.BK 特洛伊木马
D:\Download\2014-07-28_29\lu.exe - MSIL/PSW.Agent.OMJ 特洛伊木马 的变种
D:\Download\2014-07-28_29\maria photo sexy.vbs - VBS/Kryptik.BQ 特洛伊木马
D:\Download\2014-07-28_29\N727.exe > RAR > CMT - RAR/Agent.AN 特洛伊木马
D:\Download\2014-07-28_29\N727.exe > RAR > ErKSdk.exe > AUTOIT >  - 压缩文件已损坏
D:\Download\2014-07-28_29\Order 3731.exe - Win32/Spy.Zbot.AAQ 特洛伊木马
D:\Download\2014-07-28_29\Order details 001-8821901-992107.exe - Win32/TrojanDownloader.Small.PSD 特洛伊木马
D:\Download\2014-07-28_29\play.exe - Win32/Kryptik.CHGO 特洛伊木马 的变种
D:\Download\2014-07-28_29\player.exe - Win32/Kryptik.CGZY 特洛伊木马 的变种
D:\Download\2014-07-28_29\Purchase Order.exe > RAR > CMT - RAR/Agent.AN 特洛伊木马
D:\Download\2014-07-28_29\Purchase Order.exe > RAR > ZhKxnqlIwpa.exe > AUTOIT >  - 压缩文件已损坏
D:\Download\2014-07-28_29\PurchaseOrder.exe - Win32/Kryptik.CHME 特洛伊木马 的变种
D:\Download\2014-07-28_29\report_form2_28-07-2014.pdf.scr - Win32/TrojanDownloader.Agent.SBP 特洛伊木马
D:\Download\2014-07-28_29\rundll32.exe > RAR > Temp.exe - MSIL/Injector.CJX 特洛伊木马 的变种
D:\Download\2014-07-28_29\selfie.scr - Win32/Fynloski.AM 特洛伊木马
D:\Download\2014-07-28_29\server.exe - MSIL/Autorun.Spy.Agent.AU 蠕虫 的变种
D:\Download\2014-07-28_29\shipping documents.exe - MSIL/Autorun.Spy.Agent.AU 蠕虫
D:\Download\2014-07-28_29\Transfer_Slip.scr - MSIL/Injector.ENF 特洛伊木马 的变种
D:\Download\2014-07-28_29\uisap.exe - Win32/Spy.Zbot.AAU 特洛伊木马
D:\Download\2014-07-28_29\US28072014EU.scr - Win32/TrojanDownloader.Waski.F 特洛伊木马
Dust-;羅錠
发表于 2014-7-29 10:44:13 | 显示全部楼层
IKARUS
[29.07.2014 10:43:11] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\1(1).exe - SIGNATURE FOUND "Trojan-Downloader.Win32.Agent"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\1.exe - SIGNATURE FOUND "Trojan.Spy"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\111nocrypt.exe - SIGNATURE FOUND "Backdoor.Win32.Hupigon"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\2.exe - SIGNATURE FOUND "Trojan.Win32.Kryptik"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\333.exe - SIGNATURE FOUND "Trojan.Agent"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\bill.2563034.PDF_____.exe - SIGNATURE FOUND "Trojan.Win32.Stardo"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\HiddenSightCrypter.V2.exe - SIGNATURE FOUND "Worm.Win32.Rebhip"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\Imminent_Lol.exe - SIGNATURE FOUND "Trojan.Dropper.MSIL8"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\invoice_28.07.doc.exe - SIGNATURE FOUND "Trojan.Win32.Badur"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\loplayer.exe - SIGNATURE FOUND "Trojan-Spy.Zbot"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\lu.exe - SIGNATURE FOUND "Trojan.MSIL.PSW"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\maria photo sexy.vbs - SIGNATURE FOUND "Trojan.VBS.Kryptik"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\N727.exe - SIGNATURE FOUND "Trojan-Spy.Zbot"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\Order 3731.exe - SIGNATURE FOUND "Trojan-Spy.Win32.Zbot"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\Order details 001-8821901-992107.exe - SIGNATURE FOUND "Trojan-Spy.Agent"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\play.exe - SIGNATURE FOUND "Trojan.Win32.Kryptik"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\player.exe - SIGNATURE FOUND "Trojan.Win32.Kryptik"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\Purchase Order.exe - SIGNATURE FOUND "Trojan.Inject"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\PurchaseOrder.exe - SIGNATURE FOUND "Trojan.Win32.Kryptik"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\report_form2_28-07-2014.pdf.scr - SIGNATURE FOUND "Trojan-Spy.Zbot"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\rundll32.exe - SIGNATURE FOUND "Trojan.Inject"
[29.07.2014 10:43:12] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\server.exe - SIGNATURE FOUND "Trojan-PWS.MSIL"
[29.07.2014 10:43:14] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\Transfer_Slip.scr - SIGNATURE FOUND "Trojan.MSIL.Injector"
[29.07.2014 10:43:14] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\uisap.exe - SIGNATURE FOUND "Trojan.Win32.Spy"
[29.07.2014 10:43:14] File scanned: C:\Users\lin\Downloads\2014-07-28_29\2014-07-28_29\US28072014EU.scr - SIGNATURE FOUND "Win32.Outbreak"
[29.07.2014 10:43:14] ----------------------------------------------------
[29.07.2014 10:43:14] Files scanned: 29
[29.07.2014 10:43:14] Virus found: 25
zxcqwe
发表于 2014-7-29 14:55:54 | 显示全部楼层
avast 27/29
2014-7-29 14:52:47        C:\Documents and Settings\Administrator\桌面\复件 setup0535 (1).exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:52:53        C:\Documents and Settings\Administrator\桌面\复件 setup0535.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:27        C:\RECYCLER\S-1-5-21-515967899-1292428093-682003330-500\Dc48.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:32        C:\RECYCLER\S-1-5-21-515967899-1292428093-682003330-500\Dc49.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:47        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\report_form2_28-07-2014.pdf.scr [L] Win32:Trojan-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:47        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\selfie.scr [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:47        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\Transfer_Slip.scr [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:47        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\US28072014EU.scr [L] Win32:Trojan-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\1(1).exe [L] Win32:AvatarDrp-A [Trj] (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\1.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\111.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\111nocrypt.exe [L] Sf:Injector-H [Trj] (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\2.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\333.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\bill.2563034.PDF_____.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\e3753a3.exe [L] Win32:Evo-gen [Susp] (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\HiddenSightCrypter.V2.exe [L] Win32:Evo-gen [Susp] (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\Imminent_Lol.exe [L] MSIL:GenMalicious-CI [Trj] (0)
文件已成功移至隔离区...
2014-7-29 14:53:48        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\invoice_28.07.doc.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\loplayer.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\lu.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\Order 3731.exe [L] Win32:Trojan-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\Order details 001-8821901-992107.exe [L] Win32:Trojan-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\play.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\player.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\PurchaseOrder.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\rundll32.exe|>Temp.exe [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:49        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\server.exe|>[Embedded_I#04df8] [L] Win32:Malware-gen (0)
文件已成功移至隔离区...
2014-7-29 14:53:50        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\uisap.exe [L] Win32:Dropper-gen [Drp] (0)
文件已成功移至隔离区...
2014-7-29 14:54:40        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\N727.exe [L] FileRepMetagen [Malware] (0)
移动文件至隔离区时发生错误: 另一个程序正在使用此文件,进程无法访问。
文件已成功删除...
2014-7-29 14:55:10        C:\Documents and Settings\Administrator\桌面\2014-07-28_29\2014-07-28_29\shipping documents.exe [L] FileRepMetagen [Malware] (0)
文件已成功移至隔离区...
tomochan
发表于 2014-7-29 15:42:47 | 显示全部楼层

前来刷新下管家成绩,20X


comodo 11X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-18 04:04 , Processed in 0.126671 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表