查看: 2839|回复: 19
收起左侧

[病毒样本] worm zhelatin 109

[复制链接]
jimmyleo
发表于 2008-2-14 21:59:55 | 显示全部楼层 |阅读模式
hunters 团队合作 效率高

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qianwenxiang
发表于 2008-2-14 22:02:41 | 显示全部楼层
avast 080211-0, 2008-02-11只报了一个..
冷冷
发表于 2008-2-14 22:03:32 | 显示全部楼层

IK

        110 Files scanned
          (1 Archiv with 109 files)
        1 Signature found
        0 Suspect code-parts found
        Used time: 0:01.203
qianwenxiang
发表于 2008-2-14 22:05:35 | 显示全部楼层
开始扫描,时间  2008-2-14 22:04:36
事件发生:2008-2-14 22:04:36
发现病毒:C:\Test\0802\Data14\Collection\win32(1).exe
病毒名称: Common Trojan
未对该文件做出任何动作。
事件发生:2008-2-14 22:04:37
发现病毒:C:\Test\0802\Data14\Collection\win32(30).exe
病毒名称:TR.Dldr.4454
未对该文件做出任何动作。
事件发生:2008-2-14 22:04:37
发现病毒:C:\Test\0802\Data14\Collection\win32(46).exe
病毒名称:TR.Dldr.38D3
未对该文件做出任何动作。
事件发生:2008-2-14 22:04:38
发现病毒:C:\Test\0802\Data14\Collection\win32(82).exe
病毒名称:TR.Dldr.1C42F
未对该文件做出任何动作。
扫描已经结束,时间  2008-2-14 22:04:38

适当提高VELIM的误报率的结果
rest1min
发表于 2008-2-14 22:05:42 | 显示全部楼层
KV2008全挂,卡巴1个。
无尽藏海
发表于 2008-2-14 22:06:13 | 显示全部楼层
F:\virus\Collection1.rar » RAR » win32(1).exe - probably a variant of Win32/Statik application
F:\virus\Collection1.rar » RAR » win32(9).exe - probably a variant of Win32/TrojanDownloader.Small.AWA trojan
F:\virus\Collection1.rar » RAR » win32(50).exe - probably a variant of Win32/Statik application

好刺激
ykz1991
发表于 2008-2-14 22:06:22 | 显示全部楼层

antivir 109

Starting the file scan:

Begin scan in 'D:\Virus\Collection2.rar'
D:\Virus\Collection2.rar
  [0] Archive type: RAR
  --> win32(1).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(2).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(3).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(4).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(5).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(6).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(7).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(8).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(9).exe
      [DETECTION] Is the Trojan horse TR/Crypt.F.Gen
  --> win32(10).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(11).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(12).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(13).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(14).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(15).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(16).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(17).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(18).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(19).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(20).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(21).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(22).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(23).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(24).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(25).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(26).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(27).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(28).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(29).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(30).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(31).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(32).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(33).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(34).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(35).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(36).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(37).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(38).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(39).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(40).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(41).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(42).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(43).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(44).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(45).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(46).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(47).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(48).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(49).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(50).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(51).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(52).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(53).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(54).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(55).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(56).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(57).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(58).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(59).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(60).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(61).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(62).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(63).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(64).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(65).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(66).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(67).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(68).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(69).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(70).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(71).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(72).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(73).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(74).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(75).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(76).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(77).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(78).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(79).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(80).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(81).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(82).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(83).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(84).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(85).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(86).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(87).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(88).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(89).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(90).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(91).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(92).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(93).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(94).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(95).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(96).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(97).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(98).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(99).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(100).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(101).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(102).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(103).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(104).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(105).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(106).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(107).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32(108).exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
  --> win32.exe
      [DETECTION] Contains detection pattern of the worm WORM/Zhelatin.Gen
      [WARNING]   The file was ignored!


End of the scan: 2008年2月14日  22:05
Used time: 00:14 min

The scan has been done completely.

      0 Scanning directories
    110 Files were scanned
    109 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine

      0 files were renamed
      0 Files cannot be scanned
      1 Files not concerned
      1 Archives were scanned
      1 Warnings
      0 Notes
ykz1991
发表于 2008-2-14 22:06:55 | 显示全部楼层
Gen的强大威力
jimmyleo
 楼主| 发表于 2008-2-14 22:07:31 | 显示全部楼层
avira的gen搞错一个TR/Crypt.F.Gen
壳啊壳...
ykz1991
发表于 2008-2-14 22:08:46 | 显示全部楼层

回复 9楼 jimmyleo 的帖子

e
查杀率也提高不少
样本区很多都用这个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-29 13:53 , Processed in 0.129293 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表