查看: 3587|回复: 18
收起左侧

[病毒样本] 过国内三大杀软的一个新鲜病毒

[复制链接]
rest1min
发表于 2008-1-22 00:07:00 | 显示全部楼层 |阅读模式


扫描结果
扫描结果 :  25%的杀软(9/36)报告发现病毒
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared3.0.0.1262008.01.202008-01-20-
41.099
AntiVir7.6.0.487.0.2.242008-01-21HEUR/Crypted
23.767
Arcavir1.0.42008012111002008-01-21-
8.551
AVAST1.0.8080120-12008-01-20-
10.872
AVG7.5.51.442269.19.8/12352008-01-21-
16.337
BitDefender7.60825.9754727.170472008-01-21Generic.Malware.SB.B60E0278 (suspected)
23.941
CA (VET)9.0.0.14331.3.54752008-01-21-
41.113
ClamAV 0.91.255062008-01-21PUA.Packed.Expressor
0.020
Comodo2.112.0.0.4102008-01-20-
41.428
CP Secure1.1.0.6952008.01.212008-01-21-
19.507
Dr.WEB4.44.0.91702008.01.212008-01-21-
13.221
ewido4.0.0.22008.01.212008-01-21-
40.460
F-PROT4.4.1.52200801202008-01-20-
4.773
F-SECURE5.51.61002008.01.21.022008-01-21Trojan-Downloader.Win32.Agent.hgs [AVP]
0.137
IKARUST3.1.01.152008.01.21.701792008-01-21-
40.515
MKS_VIR2.012008.01.212008-01-21-
13.660
NOD322.70.1028112008-01-21-
0.234
NORMAN5.91.105.902008-01-20-
26.169
nProtect2008-01-21.0111433822008-01-21-
41.118
PrevxV2200801212008-01-21-
42.007
QuickHeal9.002008.01.192008-01-19-
40.681
SOPHOS2.49.14.212008-01-08Mal/Behav-112
29.043
The Hacker6.2.9v001912008-01-19-
40.353
VBA323.12.2.520080120.21432008-01-20Trojan-Downloader.Win32.Agent.hgs
7.910
ViRobot200801212008.01.212008-01-21-
41.531
VirusBuster4.3.19:99.120.5/11.02008-01-21Packed/eXPressor
6.077
卡巴斯基5.5.102008.01.212008-01-21Trojan-Downloader.Win32.Agent.hgs
11.924
安博士V32008.01.19.002008.01.192008-01-19-
41.136
江民杀毒10.00.6502008.01.202008-01-20-
40.983
熊猫卫士9.04.03.00012008.01.202008-01-20-
40.838
瑞星19.020.27.31.002008-01-17-
40.533
赛门铁克1.3.0.2420080120.0052008-01-20-
4.716
趋势8.500-10014.954.122008-01-21-
0.046
迈克菲5.2.0052112008-01-18New Malware.dq
4.169
金山毒霸2007.6.20.2492008.1.212008-01-21-
40.529
飞塔2.81-3.118.6542008-01-21-
40.763
注意: 就算报告发现病毒,也可能是杀软误报,请根据查毒结果自行判断

[ 本帖最后由 rest1min 于 2008-1-22 00:08 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
剑书
头像被屏蔽
发表于 2008-1-22 00:12:15 | 显示全部楼层
Begin scan in 'K:\MCS.rar'
K:\MCS.rar
  [0] Archive type: RAR
  --> MCS.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO]      A backup was created as '47e7c478.qua'  ( QUARANTINE )
      [INFO]      The file was deleted!
dericyeoh
发表于 2008-1-22 00:28:23 | 显示全部楼层
The requested object is INFECTED. The following viruses Trojan-Downloader.Win32.Agent.hgs were found
sjducker
发表于 2008-1-22 01:16:56 | 显示全部楼层
Access to the data has been denied!
Warning: A virus or unwanted program has been found in the HTTP Data.

Requested URL:  bbs.kafan.cn/attachment.php?aid=187506
Information:  Contains suspicious code HEUR/Crypted  


--------------------------------------------------------------------------------
Generated by AntiVir WebGuard 7.01.00.13, AVE 7.6.0.48, VDF 7.0.2.24
冷冷
发表于 2008-1-22 01:20:37 | 显示全部楼层
-------------------------------------------------------------------------------IK
I:\virus\MCS.rar:\MCS.exe - Signature 'Backdoor.Win32.Hupigon.mrv' found
I:\virus\MCS.rar
2 Files scanned
   (1 Archiv with 1 file)
1 Signature found
0 Suspect code-parts found
Used time: 0:00.016

-------------------------------------------------------------------------------CAV
I:\virus\test/MCS.exe: PUA.Packed.Expressor FOUND

----------- SCAN SUMMARY -----------
Known viruses: 193059
Engine version: 0.92
Scanned directories: 1
Scanned files: 1
Infected files: 1
Data scanned: 0.02 MB
Time: 7.156 sec (0 m 7 s)




[ 本帖最后由 冷_冷 于 2008-1-22 01:29 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
king6808
发表于 2008-1-22 03:18:27 | 显示全部楼层
Trojan-Downloader.Win32.Agent.hgs
capsshift
发表于 2008-1-22 10:17:39 | 显示全部楼层
红伞启发了,关红伞运行,微点未报。
醉一生爱妍
发表于 2008-1-22 10:43:15 | 显示全部楼层
on.reg:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wminotify]
"DllName"="wminotify.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000000
"Startup"="EventStartup"

cmdd.bat
:delit
del "C:\Documents and Settings\Administrator\桌面\MCS.exe"
if exist "C:\Documents and Settings\Administrator\桌面\MCS.exe" goto delit
del "cmdd.bat"
醉一生爱妍
发表于 2008-1-22 10:44:27 | 显示全部楼层
DLL 冷已发

[ 本帖最后由 garyyan456 于 2008-1-22 10:45 编辑 ]
spaceplane
发表于 2008-1-22 10:49:30 | 显示全部楼层
AVAST和大蜘蛛继续低迷
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-12 22:21 , Processed in 0.148946 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表