楼主: will
收起左侧

[讨论] 红伞误报收集站

 关闭 [复制链接]
zhangxueyou
发表于 2008-5-12 15:09:53 | 显示全部楼层

红伞报autorun病毒防火墙的VirusDef.dll文件为TR/Cinmus.167936

软件名称:autorun病毒防火墙的VirusDef.dll文件
下载地址:http://download.pchome.net/utili ... detail-66081-0.html
误报名称:TR/Cinmus.167936
尚未上报,请楼主帮忙上报,谢谢

评分

参与人数 1经验 +1 收起 理由
yimike + 1 感谢提供分享

查看全部评分

ykz1991
发表于 2008-5-14 16:38:12 | 显示全部楼层

回复 11楼 zhangxueyou 的帖子

请将误报文件以附件发上来,谢谢
无尽藏海
发表于 2008-5-14 22:20:06 | 显示全部楼层

回复 11楼 zhangxueyou 的帖子

File ID         Filename        Size (Byte)        Result
3812465         VirusDef.dll         164 KB         FALSE POSITIVE



Please find a detailed report concerning each individual sample below: Filename        Result         VirusDef.dll         FALSE POSITIVE


The file 'VirusDef.dll' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will not be removed due to the fact that the file contains unencrypted malicious patterns. This is an indicator that a legitimate detection or removal program did not encrypt parts that are used to identify malicious content. Please contact the manufacture of this file.


貌似这玩意以前上报过误报……“Please contact the manufacture of this file.”,呵呵

评分

参与人数 1经验 +3 收起 理由
yimike + 3 版区有你更精彩: )

查看全部评分

nvhaichina
发表于 2008-5-15 17:25:46 | 显示全部楼层
误报的病毒,谢谢了,我不太懂上报

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +1 收起 理由
yimike + 1 版区有你更精彩: )

查看全部评分

urge
发表于 2008-5-16 14:51:17 | 显示全部楼层

红伞报网游天龙八部的Launch.exe和Launch.bin文件为ADSPY/Sohu.k

软件名称:网游天龙八部的Launch.exe和Launch.bin文件
下载地址:http://download.tl.sohu.com/tlbb/TLBB_0.33.0580.exe
误报名称:ADSPY/Sohu.k
尚未上报
说明:下载下来的安装程序没报毒,是安装完,并且自动升级到最新版本才报毒的.
希望大家能帮忙上报一下,谢谢了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +1 收起 理由
yimike + 1 版区有你更精彩: )

查看全部评分

无尽藏海
发表于 2008-5-17 10:17:08 | 显示全部楼层

回复 14楼 nvhaichina 的帖子

File ID         Filename        Size (Byte)        Result
25019772         HostsSetter.exe         44 KB         MALWARE
25019773         SMX.dll         233.5 KB         DAMAGED FILE (UNKNOWN)
25019774         x##.dll         204.5 KB         DAMAGED FILE (UNKNOWN)
25019777         ########.txt         129 Byte         CLEAN
25019775         ######.ALG         2.27 KB         CLEAN
25019776         ######.dll         307.33 KB         CLEAN

The file 'HostsSetter.exe' has been determined to be 'MALWARE'. Our analysts named the threat PCK/PESpin. File has been compressed with an unusual runtime compression tool. Please make sure that this file comes from a trustworthy source.This malware is detected by a special detection routine from the engine module.

The file 'SMX.dll' has been determined to be 'DAMAGED FILE (UNKNOWN)'. In particular this means that this file is damaged and not working properly. We could not find any malicious content. However the heuristic detection module may still detect this particular file even though it is damaged. In that case we will not adjust and remove detection for this damaged file.

The file 'x##.dll' has been determined to be 'DAMAGED FILE (UNKNOWN)'. In particular this means that this file is damaged and not working properly. We could not find any malicious content. However the heuristic detection module may still detect this particular file even though it is damaged. In that case we will not adjust and remove detection for this damaged file.

评分

参与人数 1经验 +50 收起 理由
yimike + 50 版区有你更精彩: )

查看全部评分

注册马甲真难
发表于 2008-5-19 09:47:38 | 显示全部楼层
文件名/软件名:魔兽中文名修改器
误报名:TR/FlyStudio.D.22
下载地址/链接地址:U9资源分享置顶帖(http://bbs.uuu9.com/viewthread.php?tid=1287514&extra=page%3D1
附件:
是否上报:未上报
(PS:刚接触伞,还不知怎么上报,有人教下吗?3Q~)

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +1 收起 理由
yimike + 1 版区有你更精彩: )

查看全部评分

zhangxueyou
发表于 2008-5-19 10:35:17 | 显示全部楼层

回复 12楼 ykz1991 的帖子

附件不会上传啊,选项里没有,可能我积分不够,今天上传到virustotal,红伞还是报的,以前我是上报过的,记得是无尽藏海帮我上报的吧。
下载地址是http://download.pchome.net/utili ... detail-66081-0.html,把下载到的压缩包解压缩后就看到VirusDef.dll这个文件,谢谢了

评分

参与人数 1经验 +1 收起 理由
yimike + 1 版区有你更精彩: )

查看全部评分

无尽藏海
发表于 2008-5-19 16:04:00 | 显示全部楼层

回复 18楼 zhangxueyou 的帖子

Detection will not be removed due to the fact that the file contains unencrypted malicious patterns.
自己加排除吧,红伞不会排除的

评分

参与人数 1经验 +3 收起 理由
yimike + 3 版区有你更精彩: )

查看全部评分

无尽藏海
发表于 2008-5-19 16:40:17 | 显示全部楼层
The file 'Launch.exe' has been determined to be 'MALWARE'. Our analysts named the threat ADSPY/Sohu.K. The term "ADSPY/" denotes adware or spyware. This type of malware is able to change browser settings for example by manipulating registry settings or by using of NTFS-streams. Very often IEexploits are used to manipulate the browserhelp.dll.Detection is added to our virus definition file (VDF) starting with version 6.39.00.127.

报的无误~

评分

参与人数 1经验 +3 收起 理由
yimike + 3 版区有你更精彩: )

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-13 22:39 , Processed in 0.097947 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表