查看: 2621|回复: 15
收起左侧

[病毒样本] 3

[复制链接]
sam.to
发表于 2008-7-18 19:34:58 | 显示全部楼层 |阅读模式
已刪除: 特洛伊木馬程式 Trojan-GameThief.Win32.Magania.xdb        檔案: C:\Documents and Settings\kato9096\桌面\3.rar/居然有這個地名.jar3/居然有這個地名.cmd/3.exe
已刪除: 特洛伊木馬程式 Trojan-GameThief.Win32.Magania.wyf        檔案: C:\Documents and Settings\kato9096\桌面\3.rar/WishesCard.scr/3.exe

卡巴报2,有个不报,上报到卡巴.



Hello.
This file is already detected. Please update your bases.

Sincerely yours,
Andrey Bezborodov,
Virus Analyst.
_____________________
Kaspersky Lab Ltd
Moscow, Russia
Tel/Fax : +7 (095) 797-8700
E-mail  : newvirus@kaspersky.com
Internet: http://www.kaspersky.com, http://www.viruslist.com

[ 本帖最后由 kato9096 于 2008-7-18 23:08 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Nerazzurri
发表于 2008-7-18 19:39:04 | 显示全部楼层

3

2008-7-18        19:38:34        1216381114        Nerazzurri        3848        Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Nerazzurri\桌面\3.RAR\程尺舧?搂??.cmd3" file.  
2008-7-18        19:38:37        1216381117        Nerazzurri        3848        Sign of "Win32:Monga [Trj]" has been found in "C:\Documents and Settings\Nerazzurri\桌面\3.RAR\WishesCard.scr\3.exe" file.  
2008-7-18        19:38:37        1216381117        Nerazzurri        3848        Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Nerazzurri\桌面\3.RAR\WishesCard.scr" file.
Nerazzurri
发表于 2008-7-18 19:40:05 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Nerazzurri\桌面\3.RAR'
C:\Documents and Settings\Nerazzurri\桌面\3.RAR
    [0] Archive type: RAR
      --> ᄅ~ᄉMᆭᄈᄈoᆳᅮᆭaᆭW.jar3
        [1] Archive type: ZIP
        --> ᄅ~ᄉMᆭᄈᄈoᆳᅮᆭaᆭW.cmd
          [2] Archive type: RAR SFX (self extracting)
          --> 3.exe
            [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
发表帖子[完成后可按 C      --> 뽀ᄈ￟ᅤwᆪ{ᅡᄃᆰᆱᆳ?.cmd3
        [1] Archive type: RAR SFX (self extracting)
        --> 16.exe
          [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> WishesCard.scr
      [DETECTION] Is the TR/Drop.Agen.313409 Trojan
      --> WishesCard.scr
        [1] Archive type: RAR SFX (self extracting)
        --> 3.exe
          [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
Kitman
发表于 2008-7-18 19:41:10 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Administrator\桌面\WishesCard.scr'
C:\Documents and Settings\Administrator\桌面\WishesCard.scr
    [0] Archive type: RAR SFX (self extracting)
    --> 3.exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [DETECTION] Is the TR/Drop.Agen.313409 Trojan
    [NOTE]      A backup was created as '48f38192.qua'  ( QUARANTINE )
    [NOTE]      Attempting to perform action using the ARK lib.
    [NOTE]      A backup was created as '48f38193.qua'  ( QUARANTINE )
Begin scan in 'C:\Documents and Settings\Administrator\桌面\居然有這個地名.jar3'
C:\Documents and Settings\Administrator\桌面\居然有這個地名.jar3
    [0] Archive type: ZIP
      --> ᄅ~ᄉMᆭᄈᄈoᆳᅮᆭaᆭW.cmd
        [1] Archive type: RAR SFX (self extracting)
        --> 3.exe
          [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as 'af89f260.qua'  ( QUARANTINE )
    [NOTE]      Attempting to perform action using the ARK lib.
    [NOTE]      A backup was created as 'ad3fb9d9.qua'  ( QUARANTINE )
Begin scan in 'C:\Documents and Settings\Administrator\桌面\最喜歡ㄌ禮物唷.cmd3'
C:\Documents and Settings\Administrator\桌面\最喜歡ㄌ禮物唷.cmd3
    [0] Archive type: RAR SFX (self extracting)
    --> 16.exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as 'b3e1d6c6.qua'  ( QUARANTINE )
    [NOTE]      Attempting to perform action using the ARK lib.
    [NOTE]      A backup was created as 'b1579d7f.qua'  ( QUARANTINE )


End of the scan: 2008年7月18日  19:40
Used time: 00:03 Minute(s)

The scan has been done completely.

      0 Scanning directories
     13 Files were scanned
      4 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      6 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      9 Files not concerned
      7 Archives were scanned
      0 Warnings
      3 Notes
wangjay1980
发表于 2008-7-18 19:42:42 | 显示全部楼层
80分

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
傻猪猪米走鸡
发表于 2008-7-18 19:51:05 | 显示全部楼层

地名

File _____________________.jar3 received on 07.18.2008 13:52:31 (CET)
                                Current status:                        Loading ...                        queued                        waiting                        scanning                        finished                        NOT FOUND                        STOPPED               
               
                Result: 13/33 (39.4%)
       
                                                Loading server information...               
                                        Your file is queued in position: ___.
                        Estimated start time is between ___ and ___
.
                        Do not close the window until scan is complete.               
                                        The scanner that was processing your file is stopped at this moment,                        we are going to wait a few seconds to try to recover your result.
                        If you are waiting for more than five minutes you have to resend your file.               
                                        Your file is being scanned by VirusTotal in this moment,
                        results will be shown as they're generated.               
                                                       
                                                                                                                Compact                               
                                                                        Print results                                                                       
                       

               
                                        Your file has expired or does not exists.               
                                        Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time.
                        You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.                                                                                                               
Email:

                                               
                                       
       
                       
AntivirusVersionLast UpdateResult
AhnLab-V32008.7.17.02008.07.18-
AntiVir7.8.0.682008.07.18DR/Turk.A
Authentium5.1.0.42008.07.18-
Avast4.8.1195.02008.07.18-
AVG8.0.0.1302008.07.18Win32/Heur
BitDefender7.22008.07.18-
CAT-QuickHeal9.502008.07.17-
ClamAV0.93.12008.07.18-
DrWeb4.44.0.091702008.07.18-
eSafe7.0.17.02008.07.17Suspicious File
eTrust-Vet31.6.59652008.07.18-
Ewido4.02008.07.18-
F-Prot4.4.4.562008.07.18-
F-Secure7.60.13501.02008.07.18-
Fortinet3.14.0.02008.07.18-
GData2.0.7306.10232008.07.18Trojan-GameThief.Win32.Magania.xdb
IkarusT3.1.1.34.02008.07.18Trojan.Win32.Helpud.A
Kaspersky7.0.0.1252008.07.18Trojan-GameThief.Win32.Magania.xdb
McAfee53412008.07.18PWS-LegMir.gen.k
Microsoft1.37042008.07.18TrojanSpy:Win32/OnLineGames.ZDR
NOD32v232782008.07.18-
Norman5.80.022008.07.18-
Panda9.0.0.42008.07.17Suspicious file
Prevx1V22008.07.18-
Rising20.53.42.002008.07.18-
Sophos4.31.02008.07.18Mal/EncPk-CE
Sunbelt3.1.1536.12008.07.17-
Symantec102008.07.18-
TheHacker6.2.96.3812008.07.16-
TrendMicro8.700.0.10042008.07.18PAK_Generic.005
VBA323.12.8.02008.07.17-
VirusBuster4.5.11.02008.07.17Trojan.Lineage.Gen!Pac.3
Webwasher-Gateway6.6.22008.07.18Trojan.Crypt.XPACK.Gen
                       
Additional information
File size: 234124 bytes
MD5...: 0c6a5e3c5e5b7c14c5e896be6befee58
SHA1..: 1efd734573b12f09a72fdca668a571e68b7e31ba
SHA256: e83f1a01959ead97bb0d163d76fe3ba18dcc7f5a810a86f566e7162312d6fd82
SHA512: 40a1d3f78eb18def24103b1bd65cc056f13ec7948d117dd6b4c5b9f6143013eb
e2122d1c4051d74cb91458109d60c8611e51049868054a80711f5e057ba72be6
PEiD..: -
PEInfo: -
packers (F-Prot): RAR


[ 本帖最后由 傻猪猪米走鸡 于 2008-7-18 20:08 编辑 ]
BING126
头像被屏蔽
发表于 2008-7-18 19:52:36 | 显示全部楼层
McAfee报了。。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
allinwonderi
发表于 2008-7-18 19:56:16 | 显示全部楼层

Norman Virus Control 5.99 1

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
电影结束了
发表于 2008-7-18 20:00:54 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
 楼主| 发表于 2008-7-18 23:07:53 | 显示全部楼层
Hello.
This file is already detected. Please update your bases.

Sincerely yours,
Andrey Bezborodov,
Virus Analyst.
_____________________
Kaspersky Lab Ltd
Moscow, Russia
Tel/Fax : +7 (095) 797-8700
E-mail  : newvirus@kaspersky.com
Internet: http://www.kaspersky.com, http://www.viruslist.com
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-7 03:50 , Processed in 0.136592 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表