查看: 5958|回复: 38
收起左侧

[病毒样本] 精睿样本测试(16.7.5)

  [复制链接]
轩夏
发表于 2016-7-5 09:12:29 | 显示全部楼层 |阅读模式
地址:

https://pan.baidu.com/s/1o8ivkNo  提取密码  5xxk

密码:bbs.vc52.cn
数量:50
540923555
发表于 2016-7-5 09:17:11 | 显示全部楼层
本帖最后由 540923555 于 2016-7-5 09:36 编辑

wd占位

联网扫描
查杀+修复=25个。。。。尼玛今天扫描死机两次。。。。难道是我昨晚开了insider更新通道的原因??!!
轩夏
 楼主| 发表于 2016-7-5 09:21:46 | 显示全部楼层
MSE x22

[mw_shl_code=css,true]Scan started on Tue Jul 05 09:20:14 2016

C:\Users\XuanXia\Desktop\2016.7.5\01.vir                Infected: Backdoor:Win32/Nosrawec.A
C:\Users\XuanXia\Desktop\2016.7.5\03.vir->(UTF-16LE)    Infected: TrojanDownloader:JS/Nemucod
C:\Users\XuanXia\Desktop\2016.7.5\04.vir                Infected: TrojanDownloader:JS/Swabfex.P
C:\Users\XuanXia\Desktop\2016.7.5\06.vir                Infected: TrojanDownloader:Win32/Silcon
C:\Users\XuanXia\Desktop\2016.7.5\07.vir                Infected: TrojanDownloader:JS/Nemucod.FJ
C:\Users\XuanXia\Desktop\2016.7.5\10.vir                Infected: Ransom:Win32/Ranscrape
C:\Users\XuanXia\Desktop\2016.7.5\16.vir                Infected: Ransom:Win32/Exxroute
C:\Users\XuanXia\Desktop\2016.7.5\18.vir                Infected: Trojan:JS/Redirector.QE
C:\Users\XuanXia\Desktop\2016.7.5\19.vir                Infected: Worm:Win32/Kasidet
C:\Users\XuanXia\Desktop\2016.7.5\21.vir                Infected: Ransom:Win32/Exxroute
C:\Users\XuanXia\Desktop\2016.7.5\24.vir                Infected: DDoS:Win32/Nitol.B [submit_sample]
C:\Users\XuanXia\Desktop\2016.7.5\27.vir                Infected: Backdoor:Win32/Farfli.DA
C:\Users\XuanXia\Desktop\2016.7.5\28.vir->(UPX)         Infected: Trojan:Win32/Bulta!rfn [non_writable_container]
C:\Users\XuanXia\Desktop\2016.7.5\30.vir                Infected: TrojanDownloader:Win32/Zdowbot.B
C:\Users\XuanXia\Desktop\2016.7.5\31.vir                Infected: TrojanSpy:MSIL/Omaneat.C
C:\Users\XuanXia\Desktop\2016.7.5\37.vir                Infected: Trojan:Win32/Xtrat
C:\Users\XuanXia\Desktop\2016.7.5\38.vir                Infected: Trojan:Win32/Bulta!rfn
C:\Users\XuanXia\Desktop\2016.7.5\41.vir                Infected: TrojanDownloader:Win32/Silcon
C:\Users\XuanXia\Desktop\2016.7.5\43.vir                Infected: Trojan:Win32/Matsnu.Q
C:\Users\XuanXia\Desktop\2016.7.5\45.vir                Infected: TrojanDropper:O97M/Zlader
C:\Users\XuanXia\Desktop\2016.7.5\46.vir                Infected: TrojanSpy:MSIL/Omaneat!rfn
C:\Users\XuanXia\Desktop\2016.7.5\50.vir                Infected: VirTool:Win32/Injector.IM
Successfully checked: C:\Users\XuanXia\Desktop\2016.7.5

Scan ended on Tue Jul 05 09:20:54 2016[/mw_shl_code]
蓝天二号
发表于 2016-7-5 09:23:33 | 显示全部楼层
卡巴斯基 19X





本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
水墨静音
发表于 2016-7-5 09:29:18 | 显示全部楼层
本帖最后由 水墨静音 于 2016-7-5 09:31 编辑

腾讯管家国际版37X
AVG 38X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
XZ8SM7Sx0bVkoUV
发表于 2016-7-5 09:29:30 | 显示全部楼层
火绒 13/50

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
好想用EMSI
发表于 2016-7-5 09:39:28 | 显示全部楼层
360TS今天表现如神呀
360 Total Security扫描日志

扫描时间:2016-07-05 09:37:16
扫描用时:00:00:44
扫描项目总数:80
威胁总数:38
处理威胁数:38

扫描选项
----------------------
扫描压缩包:是
常规引擎设置:Bitdefender引擎, 小红伞引擎

扫描内容
----------------------
D:\360极速浏览器下载\2016.7.5\

扫描结果
======================
高风险项目
----------------------
D:\360极速浏览器下载\2016.7.5\02.vir.docx        macro.office.07vba.gen.1        已处理
D:\360极速浏览器下载\2016.7.5\32.vir.docx        macro.office.07vba.gen.1        已处理
D:\360极速浏览器下载\2016.7.5\01.vir.exe        TR.Agent.hedp.1        已处理
D:\360极速浏览器下载\2016.7.5\09.vir.exe        TR.Dropper.Gen        已处理
D:\360极速浏览器下载\2016.7.5\06.vir.exe        TR.Crypt.XPACK.Gen3        已处理
D:\360极速浏览器下载\2016.7.5\05.vir.exe        TR.Dropper.Gen        已处理
D:\360极速浏览器下载\2016.7.5\13.vir.exe        TR.Crypt.XPACK.Gen        已处理
D:\360极速浏览器下载\2016.7.5\24.vir.exe        HIDDENEXT.Crypted        已处理
D:\360极速浏览器下载\2016.7.5\25.vir.exe        HIDDENEXT.Crypted        已处理
D:\360极速浏览器下载\2016.7.5\29.vir.exe        TR.Dropper.Gen        已处理
D:\360极速浏览器下载\2016.7.5\31.vir.exe        TR.Dropper.Gen        已处理
D:\360极速浏览器下载\2016.7.5\37.vir.exe        HIDDENEXT.Crypted        已处理
D:\360极速浏览器下载\2016.7.5\38.vir.dll        TR.Kryptik.avp.8        已处理
D:\360极速浏览器下载\2016.7.5\03.vir        Trojan.JS.Agent.MBG        已处理
D:\360极速浏览器下载\2016.7.5\04.vir        Trojan.JS.RMJ        已处理
D:\360极速浏览器下载\2016.7.5\17.vir        Trojan.Linux.Ddos.C        已处理
D:\360极速浏览器下载\2016.7.5\49.vir        Trojan.JS.Agent.MCG        已处理
D:\360极速浏览器下载\2016.7.5\16.vir.dll        Gen:Variant.Razy.74906        已处理
D:\360极速浏览器下载\2016.7.5\19.vir.exe        Trojan.Rasftuby.Gen.11        已处理
D:\360极速浏览器下载\2016.7.5\20.vir.exe        Gen:Variant.MSILPerseus.38676        已处理
D:\360极速浏览器下载\2016.7.5\27.vir.exe        Trojan.GenericKD.3363343        已处理
D:\360极速浏览器下载\2016.7.5\21.vir.dll        Trojan.GenericKD.3364380        已处理
D:\360极速浏览器下载\2016.7.5\28.vir.exe        Trojan.AgentWDCR.GYH        已处理
D:\360极速浏览器下载\2016.7.5\30.vir.exe        Trojan.Dropper.Agent.WFS        已处理
D:\360极速浏览器下载\2016.7.5\34.vir.exe        Gen:Trojan.Heur.Crifi.zm1@aC4D5Qeic        已处理
D:\360极速浏览器下载\2016.7.5\12.vir.exe        Gen:Variant.Graftor.269175        已处理
D:\360极速浏览器下载\2016.7.5\41.vir.exe        Gen:Variant.Razy.74455        已处理
D:\360极速浏览器下载\2016.7.5\35.vir.exe        Trojan.GenericKD.3370499        已处理
D:\360极速浏览器下载\2016.7.5\10.vir.exe        Trojan.Agent.BUHO        已处理
D:\360极速浏览器下载\2016.7.5\43.vir.exe        Gen:Variant.Razy.74895        已处理
D:\360极速浏览器下载\2016.7.5\46.vir.exe        Gen:Variant.Barys.53586        已处理
D:\360极速浏览器下载\2016.7.5\47.vir.exe        Trojan.GenericKD.3356846        已处理
D:\360极速浏览器下载\2016.7.5\07.vir.JS        Trojan.GenericKD.3266391        已处理
D:\360极速浏览器下载\2016.7.5\45.vir.doc        w97m.Downloader.DPD        已处理
D:\360极速浏览器下载\2016.7.5\42.vir.JS        Trojan.GenericKD.3363831        已处理
D:\360极速浏览器下载\2016.7.5\50.vir.exe        Trojan.GenericKD.3354205        已处理
D:\360极速浏览器下载\2016.7.5\48.vir.exe        Gen:Variant.Symmi.7904        已处理
D:\360极速浏览器下载\2016.7.5\36.vir.zip        Trojan.GenericKD.3333039        已处理

还上传了一个
km2002
发表于 2016-7-5 09:56:07 | 显示全部楼层
费尔扫描 7X

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
傻猪猪米走鸡
发表于 2016-7-5 10:18:37 | 显示全部楼层
ESET余下11个文件。
Log
Scan Log
Version of virus signature database: 13752P (20160704)
Date: 2016/7/5  Time: 10:17:14
Scanned disks, folders and files: C:\Users\galax\Downloads\2016.7.5
C:\Users\galax\Downloads\2016.7.5\2016.7.5\01.vir - a variant of Win32/SchwarzeSonne.B trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\02.vir » ZIP » xl/vbaProject.bin - VBA/TrojanDownloader.Agent.BIW trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\03.vir - VBS/Agent.NJD worm - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\04.vir - JS/TrojanDownloader.Nemucod.AGH trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\05.vir - a variant of MSIL/TrojanDropper.Agent.AQJ trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\06.vir - Win32/TrojanDownloader.Nymaim.BA trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\07.vir - JS/TrojanDownloader.Nemucod.ABI trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\10.vir - Win32/Filecoder.Enigma.E trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\11.vir - JS/Iframe.JT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\12.vir - a variant of Win32/Agent.XOB trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\15.vir - probably unknown NewHeur_PE virus [7] - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\16.vir - a variant of Win32/Kryptik.FBKF trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\17.vir - Linux/Ddostf.A trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\18.vir - JS/TrojanDownloader.FakejQuery.A trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\19.vir » RAR » server.sfx.exe - Win32/Kasidet.AB worm - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\21.vir - a variant of Win32/Kryptik.FBHO trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\24.vir - a variant of Win32/ServStart.O worm - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\25.vir - a variant of Win32/HackTool.Crack.DM trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\26.vir » ZIP » word/vbaProject.bin - VBA/TrojanDownloader.Agent.BIS trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\27.vir - a variant of Win32/Injector.CICS trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\28.vir - Win32/Injector.CUHQ trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\29.vir » CONFUSER » uncompressed.exe - a variant of MSIL/Packed.MultiPacked.BN trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\29.vir » CONFUSER » deobfuscated.exe - archive damaged
C:\Users\galax\Downloads\2016.7.5\2016.7.5\30.vir - Win32/Agent.RWB trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\31.vir - MSIL/Agent.ABP trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\32.vir » ZIP » xl/vbaProject.bin - VBA/TrojanDownloader.Agent.BIW trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\33.vir » LHA » RBC Credit Note.exe - a variant of Win32/Kryptik.FBFM trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\34.vir » CAB » M.exe - a variant of Win32/Injector.CXKJ trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\35.vir - a variant of MSIL/Packed.CodeWall.K trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » u.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » q.class - a variant of Java/Adwind.VJ trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » o.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » m.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » n.class - a variant of Java/Adwind.VJ trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » Load.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » i.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » k.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » r.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\36.vir » ZIP » s.class - Java/Adwind.VT trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\37.vir - a variant of Win32/Injector.DBFS trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\38.vir - a variant of Win32/PSW.Fareit.A trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\41.vir - a variant of Win32/Kryptik.FBIW trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\43.vir - Win32/TrojanDownloader.Nymaim.BA trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\44.vir » ZIP » word/vbaProject.bin - VBA/TrojanDownloader.Agent.BIS trojan - action selection postponed until scan completion
C:\Users\galax\Downloads\2016.7.5\2016.7.5\46.vir - MSIL/Agent.YW trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\47.vir - Win32/Boaxxe.EJ trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\48.vir - a variant of Win32/Kryptik.EMPD trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\49.vir - JS/TrojanDownloader.Nemucod.AHD trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\50.vir - Win32/Spy.Bebloh.K trojan - cleaned by deleting [1]
C:\Users\galax\Downloads\2016.7.5\2016.7.5\02.vir » ZIP » xl/vbaProject.bin - VBA/TrojanDownloader.Agent.BIW trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\15.vir - probably unknown NewHeur_PE virus [7] - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\19.vir » RAR » server.sfx.exe - Win32/Kasidet.AB worm - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\25.vir - a variant of Win32/HackTool.Crack.DM trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\26.vir » ZIP » word/vbaProject.bin - VBA/TrojanDownloader.Agent.BIS trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\32.vir » ZIP » xl/vbaProject.bin - VBA/TrojanDownloader.Agent.BIW trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\34.vir » CAB » M.exe - a variant of Win32/Injector.CXKJ trojan - deleted
C:\Users\galax\Downloads\2016.7.5\2016.7.5\44.vir » ZIP » word/vbaProject.bin - VBA/TrojanDownloader.Agent.BIS trojan - deleted
Number of scanned objects: 126
Number of threats found: 48
Number of cleaned objects: 48
Time of completion: 10:17:27  Total scanning time: 13 sec (00:00:13)

Notes:
[1] Object has been deleted as it only contained the virus body.
[7] Object is probably infected with an unknown virus.
傻猪猪米走鸡
发表于 2016-7-5 10:25:21 | 显示全部楼层
Time;Module;Event;User
2016/7/5 10:19:42;ESET Kernel;File  'C:\Users\galax\Downloads\2016.7.5\2016.7.5\22.vir' was sent to ESET for analysis.;
2016/7/5 10:19:54;ESET Kernel;File  'C:\Users\galax\Downloads\2016.7.5\2016.7.5\23.vir' was sent to ESET for analysis.;
2016/7/5 10:20:00;ESET Kernel;File  'C:\Users\galax\Downloads\2016.7.5\2016.7.5\39.vir' was sent to ESET for analysis.;
2016/7/5 10:20:06;ESET Kernel;File  'C:\Users\galax\Downloads\2016.7.5\2016.7.5\40.vir' was sent to ESET for analysis.;
2016/7/5 10:20:14;ESET Kernel;File  'C:\Users\galax\Downloads\2016.7.5\2016.7.5\42.vir' was sent to ESET for analysis.;
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 15:10 , Processed in 0.117166 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表