楼主: The EQs
收起左侧

[病毒样本] 2个

[复制链接]
sam.to
发表于 2008-8-29 17:46:58 | 显示全部楼层
File 456456.zip received on 08.29.2008 11:47:33 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 27/36 (75%)
Loading server information...
Your file is queued in position: 2.
Estimated start time is between 42 and 60 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:        
       
Antivirus         Version         Last Update         Result
AhnLab-V3        2008.8.29.0        2008.08.29        -
AntiVir        7.8.1.23        2008.08.29        TR/Dropper.Gen
Authentium        5.1.0.4        2008.08.29        W32/Nilage.gen!GSA
Avast        4.8.1195.0        2008.08.28        -
AVG        8.0.0.161        2008.08.29        -
BitDefender        7.2        2008.08.29        Generic.Malware.Sdldspg.6E960B47
CAT-QuickHeal        9.50        2008.08.26        (Suspicious) - DNAScan
ClamAV        0.93.1        2008.08.29        PUA.Packed.UPack-2
DrWeb        4.44.0.09170        2008.08.29        Trojan.PWS.Gamania.origin
eSafe        7.0.17.0        2008.08.28        Suspicious File
eTrust-Vet        31.6.6055        2008.08.29        -
Ewido        4.0        2008.08.28        -
F-Prot        4.4.4.56        2008.08.29        W32/Nilage.gen!GSA
F-Secure        7.60.13501.0        2008.08.29        W32/Suspicious_U.gen
Fortinet        3.14.0.0        2008.08.29        -
GData        19        2008.08.29        Worm.Win32.AutoRun.lxh
Ikarus        T3.1.1.34.0        2008.08.29        Backdoor.Win32.Rbot.aeu
K7AntiVirus        7.10.431        2008.08.29        -
Kaspersky        7.0.0.125        2008.08.29        Worm.Win32.AutoRun.lxh
McAfee        5372        2008.08.28        New Malware.aj
Microsoft        1.3807        2008.08.25        TrojanSpy:Win32/Hitpop.gen!C
NOD32v2        3397        2008.08.28        a variant of Win32/AutoRun.JX
Norman        5.80.02        2008.08.28        W32/Suspicious_U.gen
Panda        9.0.0.4        2008.08.29        Suspicious file
PCTools        4.4.2.0        2008.08.28        Packed/Upack
Prevx1        V2        2008.08.29        -
Rising        20.59.41.00        2008.08.29        Trojan.DL.Win32.MyDown.aj
Sophos        4.33.0        2008.08.29        Sus/Dropper-R
Sunbelt        3.1.1592.1        2008.08.29        VIPRE.Suspicious
Symantec        10        2008.08.29        W32.SillyDC
TheHacker        6.3.0.6.064        2008.08.27        W32/Behav-Heuristic-060
TrendMicro        8.700.0.1004        2008.08.29        PAK_Generic.006
VBA32        3.12.8.4        2008.08.29        suspected of Backdoor.XiaoBird.5 (paranoid heuristics)
ViRobot        2008.8.29.1355        2008.08.29        -
VirusBuster        4.5.11.0        2008.08.28        Packed/Upack
Webwasher-Gateway        6.6.2        2008.08.29        Trojan.Dropper.Gen


File update.zip received on 08.29.2008 11:47:49 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 8/36 (22.23%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:        
       
Antivirus         Version         Last Update         Result
AhnLab-V3        2008.8.29.0        2008.08.29        -
AntiVir        7.8.1.23        2008.08.29        -
Authentium        5.1.0.4        2008.08.29        -
Avast        4.8.1195.0        2008.08.28        -
AVG        8.0.0.161        2008.08.29        Downloader.Generic7.AIZP
BitDefender        7.2        2008.08.29        -
CAT-QuickHeal        9.50        2008.08.26        -
ClamAV        0.93.1        2008.08.29        -
DrWeb        4.44.0.09170        2008.08.29        -
eSafe        7.0.17.0        2008.08.28        -
eTrust-Vet        31.6.6055        2008.08.29        -
Ewido        4.0        2008.08.28        -
F-Prot        4.4.4.56        2008.08.29        -
F-Secure        7.60.13501.0        2008.08.29        Trojan-Downloader:W32/Agent.HLG
Fortinet        3.14.0.0        2008.08.29        -
GData        19        2008.08.29        Trojan-Downloader.Win32.Agent.adyc
Ikarus        T3.1.1.34.0        2008.08.29        -
K7AntiVirus        7.10.431        2008.08.29        -
Kaspersky        7.0.0.125        2008.08.29        Trojan-Downloader.Win32.Agent.adyc
McAfee        5372        2008.08.28        -
Microsoft        1.3807        2008.08.25        -
NOD32v2        3397        2008.08.28        Win32/TrojanDownloader.Agent.OEF
Norman        5.80.02        2008.08.28        -
Panda        9.0.0.4        2008.08.29        -
PCTools        4.4.2.0        2008.08.28        -
Prevx1        V2        2008.08.29        Suspicious
Rising        20.59.41.00        2008.08.29        -
Sophos        4.33.0        2008.08.29        -
Sunbelt        3.1.1592.1        2008.08.29        -
Symantec        10        2008.08.29        -
TheHacker        6.3.0.6.064        2008.08.27        -
TrendMicro        8.700.0.1004        2008.08.29        Possible_DLDER
VBA32        3.12.8.4        2008.08.29        -
ViRobot        2008.8.29.1355        2008.08.29        -
VirusBuster        4.5.11.0        2008.08.28        -
Webwasher-Gateway        6.6.2        2008.08.29        Worm.Win32.Malware.gen!84 (suspicious)

[ 本帖最后由 kato9096 于 2008-8-29 17:49 编辑 ]
qigang
发表于 2008-8-29 20:36:19 | 显示全部楼层

5/1

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.DL.Win32.MyDown.aj

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.59.42
allinwonderi
发表于 2008-8-29 20:37:39 | 显示全部楼层

F-Prot 4.4.4

W32/Nilage.gen!GSA (not disinfectable, 普通)>        C:\Download Files\456456.zip->456456.exe->(UPack)
allinwonderi
发表于 2008-8-29 20:40:55 | 显示全部楼层
那个update.zip , Webwasher-Gateway   的报法很奇怪, 难道自己有新的引擎?不是Avira, McAfee, Sophos三引擎的说以前上报过类似的,如果红伞更新了定义,WG会用红伞的定义替换这种报法。

[ 本帖最后由 allinwonderi 于 2008-8-29 20:44 编辑 ]
尤金卡巴斯基
发表于 2008-8-29 22:42:59 | 显示全部楼层
2008/8/29 22:42:27        已清除        病毒 Worm.Win32.AutoRun.lxh        G:\Temp\Virus\456456.zip/456456.exe//PE_Patch//UPack               
2008/8/29 22:42:26        已清除        木马程序 Trojan-Downloader.Win32.Agent.adyc        G:\Temp\Virus\update.zip/update.exe
老桥段
头像被屏蔽
发表于 2008-8-29 23:13:52 | 显示全部楼层
第一个红伞和费尔都报,第二个都不报,但是费尔的在线扫描出来是木马

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
碧水寒潭
发表于 2008-8-29 23:14:29 | 显示全部楼层
Start of the scan: 2008年8月29日  23:13

Starting the file scan:

Begin scan in 'C:\Documents and Settings\acer\桌面\样本'
C:\Documents and Settings\acer\桌面\样本\456456.zip
    [0] Archive type: ZIP
    --> 456456.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    [NOTE]      The file was deleted!
C:\Documents and Settings\acer\桌面\样本\update.zip
    [0] Archive type: ZIP
    --> update.exe
      [DETECTION] Is the TR/Drop.Small.dci Trojan
    [NOTE]      The file was deleted!


End of the scan: 2008年8月29日  23:13
Used time: 00:12 Minute(s)
Ghoenix
发表于 2008-8-29 23:38:01 | 显示全部楼层
ess
update.zip > ZIP > update.exe - Win32/TrojanDownloader.Agent.OEF 特洛伊木马
456456.zip > ZIP > 456456.exe - Win32/AutoRun.JX 蠕虫 的变种
老桥段
头像被屏蔽
发表于 2008-8-30 11:02:15 | 显示全部楼层
昨天晚上update还都不报的,今天又全报了,红伞和费尔
sueuvip
发表于 2008-8-30 11:31:55 | 显示全部楼层
High security alert!!!
You are not permitted to download the file "update.zip" because it is infected with the virus "W32/Agent.ADYC!tr.dldr".

URL = http://bbs.kafan.cn/attachment.p ... 94&t=1220067031

File quarantined as: .

http://www.fortinet.com/ve?vid=549833
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-10 19:58 , Processed in 0.105792 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表