查看: 3453|回复: 11
收起左侧

[病毒样本] MD5 : d4cfda3d7cbc3e0675b01735ab9b94b7

[复制链接]
nosferatu
头像被屏蔽
发表于 2008-5-28 05:12:29 | 显示全部楼层 |阅读模式

VirSCAN.org Scanned Report :
Scanned time   : 2008/05/28 05:02:18 (CST)
Scanner results: 25%的杀软(9/36)报告发现病毒

Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      3.5.0.18        2008.05.26        2008-05-26  3.75   -
安博士V3       2008.05.27.01   2008.05.27        2008-05-27  1.19   -
AntiVir        7.8.0.19        7.0.4.101         2008-05-27  2.78   -
Arcavir        1.0.4           200805271137      2008-05-27  1.62   -
AVAST          1.0.8           080527-1          2008-05-27  3.06   -
AVG            7.5.51.442      269.24.1/1469     2008-05-27  2.47   -
BitDefender    7.60825.1245277 7.19209           2008-05-28  8.60   Trojan.Peed.JJM
CA (VET)       9.0.0.143       31.4.5826         2008-05-27  11.05  -
ClamAV         0.93            7269              2008-05-28  0.04   -
Comodo         2.11            2.0.0.537         2008-05-27  1.78   -
CP Secure      1.1.0.715       2008.05.27        2008-05-27  9.72   -
Dr.WEB         4.44.0.9170     2008.05.27        2008-05-27  4.89   Trojan.DownLoader.62005
ewido          4.0.0.2         2008.05.27        2008-05-27  3.02   -
F-PROT         4.4.1.52        20080526          2008-05-26  2.10   -
F-SECURE       5.51.6100       2008.05.27.06     2008-05-27  4.52   -
飞塔           2.81-3.11       9.135             2008-05-27  6.34   Suspicious
ViRobot        20080527        2008.05.27        2008-05-27  0.66   -
IKARUS         T3.1.01.26      2008.05.27.70825  2008-05-27  2.65   MalwareScope.Worm.Nuwar-Glowa.1
江民杀毒       11.00.703       2008.05.27 09:20:322008-05-27 09:20:321.60   -
卡巴斯基       5.5.10          2008.05.27        2008-05-27  15.67  -
金山毒霸       2008.1.14.15    2008.5.27.18      2008-05-27  1.65   -
迈克菲         5.2.00          5304              2008-05-27  5.16   -
Microsoft      1.3520          2008.05.27        2008-05-27  11.27  TrojanDropper:Win32/Nuwar.gen!lds
MKS_VIR        2.01            2008.05.27        2008-05-27  3.06   -
NORMAN         5.92.08         5.92.00           2008-05-27  7.55   -
熊猫卫士       9.04.03.0001    2008.05.27        2008-05-27  3.69   Suspicious file
趋势           8.700-1004      5.300.08          2008-05-27  0.00   -
Prevx          V2              20080527          2008-05-27  12.99  Generic.Malware
QuickHeal      9.00            2008.05.26        2008-05-26  0.43   -
瑞星           20.0            20.46.12.00       2008-05-27  4.54   -
SOPHOS         2.74.1          4.30              2008-05-28  8.66   Mal/EncPk-DA
赛门铁克       1.3.0.24        20080527.003      2008-05-27  1.28   -
nProtect       2008-05-27.00   1514351           2008-05-27  7.39   -
The Hacker     6.2.92          v00320            2008-05-26  1.92   -
VBA32          3.12.6.6        20080526.2148     2008-05-26  36.14  MalwareScope.Worm.Nuwar-Glowa.1
VirusBuster    4.3.19:9        9.130.6/11.0      2008-05-27  2.13   -

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2008-5-28 05:18:32 | 显示全部楼层
The file 'video.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Agent.ncp. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
palfan
发表于 2008-5-28 05:57:54 | 显示全部楼层
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.5.28.02008.05.27-
AntiVir7.8.0.192008.05.27-
Authentium5.1.0.42008.05.27-
Avast4.8.1195.02008.05.27-
AVG7.5.0.5162008.05.27-
BitDefender7.22008.05.27Trojan.Peed.JJM
CAT-QuickHeal9.502008.05.26(Suspicious) - DNAScan
ClamAV0.92.12008.05.27-
DrWeb4.44.0.091702008.05.27Trojan.DownLoader.62005
eSafe7.0.15.02008.05.27Suspicious File
eTrust-Vet31.4.58262008.05.27-
Ewido4.02008.05.27-
F-Prot4.4.4.562008.05.27-
F-Secure6.70.13260.02008.05.27-
Fortinet3.14.0.02008.05.27-
GData2.0.7306.10232008.05.27-
IkarusT3.1.1.26.02008.05.27MalwareScope.Worm.Nuwar-Glowa.1
Kaspersky7.0.0.1252008.05.27-
McAfee53042008.05.27-
MicrosoftNone2008.05.27-
NOD32v231362008.05.27Win32/Agent.ETH
Norman5.80.022008.05.27-
Panda9.0.0.42008.05.27-
Prevx1V22008.05.27Malicious Software
Rising20.46.12.002008.05.27-
Sophos4.29.02008.05.27Mal/EncPk-DA
Sunbelt3.0.1123.12008.05.17-
Symantec102008.05.27-
TheHacker6.2.92.3212008.05.27-
VBA323.12.6.62008.05.27MalwareScope.Worm.Nuwar-Glowa.1
VirusBuster4.3.26:92008.05.27-
Webwasher-Gateway6.6.22008.05.27Worm.Win32.Malware.gen (suspicious)


-----------------------------------------------------------------------------------------------

Submission Summary:
  • Submission details:
    • Submission received: 28 May 2008, 07:51:29
    • Processing time: 4 min 21 sec
    • Submitted sample:
      • File MD5: 0xADEAD0FDAF21ADD54B3E26B1BCD13545
      • Filesize: 107,008 bytes
  • Summary of the findings:
What's been foundSeverity Level
Produces outbound traffic.
Contains characteristics of an identified security risk.


Technical Details:
Possible Security Risk

  • Attention! Characteristics of the following security risk was identified in the system:
Security RiskDescription
Trojan-Downloader.AgentTrojan.Downloader.Agent downloads and installs other malware onto infected machine.


File System Modifications

  • The following file was created in the system:
#Filename(s)File SizeFile MD5
1%System%\CbEvtSvc.exe
[file and pathname of the sample #1]
107,008 bytes0xADEAD0FDAF21ADD54B3E26B1BCD13545

  • Note:
    • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Memory Modifications

  • There were new processes created in the system:
Process NameProcess FilenameMain Module Size
CbEvtSvc.exe%System%\cbevtsvc.exe131,072 bytes
[filename of the sample #1][file and pathname of the sample #1]131,072 bytes

  • There was a new service created in the system:
Service NameDisplay NameStatusService Filename
CbEvtSvcCbEvtSvc"Running"%System%\CbEvtSvc.exe -k netsvcs


Registry Modifications

  • The following Registry Keys were created:
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC\0000
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC\0000\Control
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc\Security
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc\Enum
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000\Control
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc\Security
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc\Enum
  • The newly created Registry Values are:
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC\0000\Control]
      • *NewlyCreated* = 0x00000000
      • ActiveService = "CbEvtSvc"
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC\0000]
      • Service = "CbEvtSvc"
      • Legacy = 0x00000001
      • ConfigFlags = 0x00000000
      • Class = "LegacyDriver"
      • ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
      • DeviceDesc = "CbEvtSvc"
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CBEVTSVC]
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc\Enum]
      • 0 = "Root\LEGACY_CBEVTSVC\0000"
      • Count = 0x00000001
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc\Security]
      • Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc]
      • Type = 0x00000010
      • Start = 0x00000002
      • ErrorControl = 0x00000001
      • ImagePath = "%System%\CbEvtSvc.exe -k netsvcs"
      • DisplayName = "CbEvtSvc"
      • ObjectName = "LocalSystem"
      • Opt = (zero-length binary value)
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000\Control]
      • *NewlyCreated* = 0x00000000
      • ActiveService = "CbEvtSvc"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000]
      • Service = "CbEvtSvc"
      • Legacy = 0x00000001
      • ConfigFlags = 0x00000000
      • Class = "LegacyDriver"
      • ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
      • DeviceDesc = "CbEvtSvc"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC]
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc\Enum]
      • 0 = "Root\LEGACY_CBEVTSVC\0000"
      • Count = 0x00000001
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc\Security]
      • Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc]
      • Type = 0x00000010
      • Start = 0x00000002
      • ErrorControl = 0x00000001
      • ImagePath = "%System%\CbEvtSvc.exe -k netsvcs"
      • DisplayName = "CbEvtSvc"
      • ObjectName = "LocalSystem"
      • Opt = (zero-length binary value)
  • The following Registry Values were modified:
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
      • (Default) = 0x0000000B
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
      • (Default) = 0x0000000B

Other details

  • There was registered attempt to establish connection with the remote host. The connection details are:
Remote HostPort Number
72.9.98.234 443[/tr][/tr]


Outbound traffic (potentially malicious)

  • There was an outbound traffic produced on port 443:
00000000 | 1603 0100 4101 0000 3D03 0148 3C82 EF31 | ....A...=..H<..100000010 | F936 6088 AC66 72C2 FDFA 0361 D815 A683 | .6`..fr....a....00000020 | 2C16 067E CB07 9BA5 5E19 C100 0016 0004 | ,..~....^.......00000030 | 0005 000A 0009 0064 0062 0003 0006 0013 | .......d.b......00000040 | 0012 0063 0100                          | ...c..[/td]



http://www.threatexpert.com/report.aspx?md5=adead0fdaf21add54b3e26b1bcd13545

-----------------------------------------------------------------------------------------------
PS.准备睡觉咯...................
woai_jolin
发表于 2008-5-28 06:32:24 | 显示全部楼层
Scan performed at: 2008/5/28 6:32:10
Scanning Log
NOD32 version 3136 (20080527) NT
Command line: G:\v\video.rar
C:\Program Files\Eset\nod32.exe - is OK

Date: 28.5.2008  Time: 06:32:12
Anti-Stealth technology is enabled.
Scanned disks, folders and files: G:\v\video.rar
G:\v\video.rar ?RAR ?video.exe - Win32/Agent.ETH trojan
G:\v\video.rar:Zone.Identifier - is OK
Number of scanned files: 2
Number of threats found: 1
Time of completion: 06:32:12 Total scanning time: 0 sec (00:00:00)
gaojun7206
发表于 2008-5-28 11:31:34 | 显示全部楼层
video.exe 已被病毒感染 :  Trojan.DownLoader.62005
sqsszzq
头像被屏蔽
发表于 2008-5-28 13:50:09 | 显示全部楼层
最后一个,闪人

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
电影结束了
发表于 2008-5-28 14:03:09 | 显示全部楼层
啥时TF能够像上报一样弄清自己的问题去修复就好了。。。。
哎。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
tracydk
发表于 2008-5-28 18:04:42 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
allinwonderi
发表于 2008-5-28 19:53:17 | 显示全部楼层

ArcaVir2008

[Scanning : C:\Documents and Settings\All Users\Documents\Test]


C:\Documents and Settings\All Users\Documents\Test\video.rar<RAR>:video.exe <- Trojan.Downloader.Bja : No action



Scanned objects : 2

Infected objects : 1
allinwonderi
发表于 2008-5-28 19:53:51 | 显示全部楼层

F-Prot 4.4.4

MISS
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-15 10:54 , Processed in 0.135758 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表