查看: 5235|回复: 20
收起左侧

[病毒样本] Xorer

[复制链接]
绅博周幸
发表于 2008-3-14 09:28:02 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
绅博周幸
 楼主| 发表于 2008-3-14 09:29:41 | 显示全部楼层
AhnLab-V3 2008.3.14.0 2008.03.13 -
AntiVir 7.6.0.73 2008.03.13 TR/Drop.Xorer.C
Authentium 4.93.8 2008.03.13 -
Avast 4.7.1098.0 2008.03.13 Win32:Xorer-J
AVG 7.5.0.516 2008.03.13 Worm/AutoRun.AR
BitDefender 7.2 2008.03.14 -
CAT-QuickHeal 9.50 2008.03.13 -
ClamAV 0.92.1 2008.03.13 -
DrWeb 4.44.0.09170 2008.03.13 Win32.HLLP.Rox.origin
eSafe 7.0.15.0 2008.03.09 suspicious Trojan/Worm
eTrust-Vet 31.3.5613 2008.03.13 -
Ewido 4.0 2008.03.13 -
FileAdvisor 1 2008.03.14 -
Fortinet 3.14.0.0 2008.03.13 -
F-Prot 4.4.2.54 2008.03.13 -
F-Secure 6.70.13260.0 2008.03.14 -
Ikarus T3.1.1.20 2008.03.14 -
Kaspersky 7.0.0.125 2008.03.14 Heur.Trojan.Generic
McAfee 5251 2008.03.13 -
Microsoft 1.3301 2008.03.13 Virus:Win32/Xorer.F
NOD32v2 2946 2008.03.14 probably a variant of Win32/Xorer
Norman 5.80.02 2008.03.13 -
Panda 9.0.0.4 2008.03.13 Suspicious file
Prevx1 V2 2008.03.14 -
Rising 20.35.32.00 2008.03.13 -
Sophos 4.27.0 2008.03.14 -
Sunbelt 3.0.930.0 2008.03.05 -
Symantec 10 2008.03.14 -
TheHacker 6.2.92.245 2008.03.14 -
VBA32 3.12.6.2 2008.03.13 -
VirusBuster 4.3.26:9 2008.03.13 Win32.Xorer.Gen
Webwasher-Gateway 6.6.2 2008.03.13 Trojan.Drop.Xorer.C
秋叶濛濛
发表于 2008-3-14 09:38:05 | 显示全部楼层
Starting the file scan:

Begin scan in 'F:\Virus\setup.rar'
F:\Virus\setup.rar
  [0] Archive type: RAR
    --> setup.exe
      [1] Archive type: RAR SFX (self extracting)
      --> Setup.exe
          [DETECTION] Is the Trojan horse TR/Drop.Xorer.C
      [INFO]      The file was deleted!
leonfg
发表于 2008-3-14 09:48:47 | 显示全部楼层
ESET
C:\Documents and Settings\GUNDAM\桌面\setup.rar » RAR » setup.exe » RAR » Setup.exe - probably a variant of Win32/Xorer virus
Redevil
发表于 2008-3-14 10:12:57 | 显示全部楼层
ACCESS DENIED
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://bbs.kafan.cn/attachment.php?aid=219289

The folowing error was encountered:

The requested object is INFECTED. The following viruses Heur.Trojan.Generic were found

Please contact your service provider if you feel this is incorrect.



--------------------------------------------------------------------------------

Generated Fri Mar 14 10:13:50 2008 by Kaspersky Internet Security 7.0





卡巴能启发磁碟机
fireworld
发表于 2008-3-14 10:18:05 | 显示全部楼层
又见磁碟机啊 ^_^
Nblock
发表于 2008-3-14 10:26:09 | 显示全部楼层
木马程序生成以下文件:
1) D:\TEMP\RARSFX0\SETUP.EXE
是否删除木马程序及其衍生物?
ballakay
发表于 2008-3-14 10:29:56 | 显示全部楼层
已上报FS!
spaceplane
发表于 2008-3-14 10:32:29 | 显示全部楼层
FS不认识?
ballakay
发表于 2008-3-14 11:21:08 | 显示全部楼层
Hello,
Thank you for your e-mail.
The file you sent was found to be malicious.
An appropriate detection will be added in one of the next database updates.
Our latest database updates are available here:
http://www.f-secure.com/download-purchase/updates.shtml
Have a nice day!
FS速度呀!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 11:19 , Processed in 0.129238 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表