楼主: jehovah_king
收起左侧

[病毒样本] 实验中的技术(更新至3.5)

[复制链接]
su-tt
发表于 2008-2-4 16:01:30 | 显示全部楼层
Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC00120333.




We received the following archive files:



File ID  Filename  Size (Byte) Result
3718998  virus3.0.rar 655.67 KB OK

A listing of files contained inside archives alongside their results can be found below:

File ID  Filename  Size (Byte) Result
3718996  virus3.0.exe  977.26 KB  CLEAN


Please find a detailed report concerning each individual sample below:

Filename Result
virus3.0.exe  CLEAN

The file 'virus3.0.exe' has been determined to be 'CLEAN'. Our analysts did not discovered any malicious content.


Alternatively you can see the analysis result here:
http://analysis.avira.com/sample ... p;incidentid=120333

An overview of all your submissions can be found here:
http://analysis.avira.com/sample ... jR36vX2NXj4VntRrzXm


Please note: The detection of Spy/Adware is not available in the product "AntiVir PersonalEdition Classic". Please address specific questions to support@avira.com

Kind regards
Avira Virus Lab
ALEXBLAIR
发表于 2008-2-4 17:42:30 | 显示全部楼层

3.5继续报

detected: Trojan program Trojan-Dropper.BAT.Agent.q        URL: http://bbs.kafan.cn/attachment.p ... //data.rar//vir.bat
报bat的
估计是你那个bat没有修改的关系
Graybird
发表于 2008-2-4 17:46:12 | 显示全部楼层
The file 'virus4.0.exe' has been determined to be 'MALWARE'. Our analysts named the threat DR/Agent.QE. The term "DR/" denotes a program that is able to place a virus or a malware discretely on a system.Detection will be added to our virus definition file (VDF) with one of the next updates.
jehovah_king
头像被屏蔽
 楼主| 发表于 2008-2-4 17:47:23 | 显示全部楼层

回复 42楼 ALEXBLAIR 的帖子

bat本来就没改
因为主要更新的是切片
你看看大小


不过今早的vt还是全免

原帖被封了、换了个地方
http://bbs.kafan.cn/viewthread.php?tid=197784&extra=page%3D2
jehovah_king
头像被屏蔽
 楼主| 发表于 2008-2-4 17:48:47 | 显示全部楼层
感谢大家一直以来的关注与支持

这是这项技术的最后一次更新
从此停止更深入的探究
因为这可能已经是这项免杀技术的极致了
由于我不了解内存方面的技术,又除了qbasic以外不会编程,一直过不了监控,下一次关于这的测试就遥遥无期了,也许是几个月,也许是几年,也许永远没有了 谁知道呢  


大家尽可以上报到任何反病毒厂商,因为这病毒似乎没什么明显的特征码好提的
如果报的是病毒切片(几乎不可能,看看切片文件大小就知道了 )大不了再切小点,
如果报的是.bat那就更简单了随便加几个 ver\shutdown -a\...就又免杀了
su-tt
发表于 2008-2-4 18:42:08 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\virus3[1].5.rar'
C:\Documents and Settings\Administrator\桌面\virus3[1].5.rar
  [0] Archive type: RAR
  --> virus4.0.exe
      [DETECTION] Contains detection pattern of the dropper DR/Drop.Agent.Q
      [WARNING]   The file was ignored!


End of the scan: 2008年2月4日  18:41
Used time: 00:17 min

The scan has been done completely.

      0 Scanning directories
   2279 Files were scanned
      1 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
   2278 Files not concerned
      2 Archives were scanned
      1 Warnings
      0 Notes
su-tt
发表于 2008-2-4 18:45:42 | 显示全部楼层
大蜘蛛继续无视
醉一生爱妍
发表于 2008-2-4 22:27:51 | 显示全部楼层
费尔无视··

貌似这个东西生成碎片的时候占的CPU都是100

配置不好的容易生成时候崩溃掉
yitp
发表于 2008-2-4 23:15:47 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\virus3[1].5.rar'
C:\Documents and Settings\Administrator\桌面\virus3[1].5.rar
  [0] Archive type: RAR
  --> virus4.0.exe
      [DETECTION] Contains detection pattern of the dropper DR/Drop.Agent.Q
      [INFO]      The file was deleted!
yitp
发表于 2008-2-4 23:16:11 | 显示全部楼层
Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC00120265.



A listing of files alongside their results can be found below:

File ID  Filename  Size (Byte) Result
3718872  virus.com  495.42 KB  MALWARE


Please find a detailed report concerning each individual sample below:

Filename Result
virus.com  MALWARE

The file 'virus.com' has been determined to be 'MALWARE'. Virus name is DROPPER (en) Detection will be added to our virus definition file (VDF) with one of the next updates.


Alternatively you can see the analysis result here:
http://analysis.avira.com/sample ... p;incidentid=120265

An overview of all your submissions can be found here:
http://analysis.avira.com/sample ... BWWw4JrOBFYR00ExgC7


Please note: The detection of Spy/Adware is not available in the product "AntiVir PersonalEdition Classic". Please address specific questions to support@avira.com

Kind regards
Avira Virus Lab

---------------------------------------------
Avira GmbH
Lindauer Str. 21, D-88069 Tettnang, Germany
Phone: +49 (0) 7542-500 0
Fax: +49 (0) 7542-525 10
Internet: http://www.avira.com

CEO: Tjark Auerbach
Headquarter: Tettnang
Commercial register: AG Ulm HRB 630992
---------------------------------------------
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-26 03:01 , Processed in 0.087269 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表