查看: 2778|回复: 11
收起左侧

[病毒样本] load.exe

[复制链接]
solcroft
发表于 2008-10-23 10:14:25 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
hzyw
头像被屏蔽
发表于 2008-10-23 10:25:31 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
scottxzt
发表于 2008-10-23 11:02:36 | 显示全部楼层
Begin scan in 'C:\Users\IBM\Desktop\load.zip'
C:\Users\IBM\Desktop\load.zip
    [0] Archive type: ZIP
      --> load.exe
          [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
sam.to
发表于 2008-10-23 11:09:30 | 显示全部楼层
Scanned file:   load.zip
load.zip/load.exe - OK
load.zip/load.exe - OK
load.zip/load.exe - OK

TO KL
Nblock
发表于 2008-10-23 11:18:43 | 显示全部楼层
不错的样本 微点可疑程序诊断删除成功

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2008-10-23 11:21:30 | 显示全部楼层
http://www.virustotal.com/analis ... 88a5f47dfb659f6262a

                File load.zip received on 10.23.2008 05:20:26 (CET)
                                Current status:                        Loading ...                        queued                        waiting                        scanning                        finished                        NOT FOUND                        STOPPED               
               
                Result: 12/36 (33.34%)
       
                                                Loading server information...               
                                        Your file is queued in position: ___.
                        Estimated start time is between ___ and ___
.
                        Do not close the window until scan is complete.               
                                        The scanner that was processing your file is stopped at this moment,                        we are going to wait a few seconds to try to recover your result.
                        If you are waiting for more than five minutes you have to resend your file.               
                                        Your file is being scanned by VirusTotal in this moment,
                        results will be shown as they're generated.               
                                                       
                                                                                                                Compact                               
                                                                        Print results                                                                       
                       

               
                                        Your file has expired or does not exists.               
                                        Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time.
                        You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.                                                                                                               
Email:

                                               
                                       
       
                                       
AntivirusVersionLast UpdateResult
AhnLab-V32008.10.22.02008.10.22-
AntiVir7.9.0.52008.10.22TR/Crypt.XPACK.Gen
Authentium5.1.0.42008.10.23-
Avast4.8.1248.02008.10.22Win32:Trojan-gen {Other}
AVG8.0.0.1612008.10.23SHeur.CPGN
BitDefender7.22008.10.23-
CAT-QuickHeal9.502008.10.22-
ClamAV0.93.12008.10.23-
DrWeb4.44.0.091702008.10.23Trojan.PWS.GoldSpy.2309
eSafe7.0.17.02008.10.22Suspicious File
eTrust-Vet31.6.61642008.10.22-
Ewido4.02008.10.22-
F-Prot4.4.4.562008.10.22-
F-Secure8.0.14332.02008.10.23-
Fortinet3.113.0.02008.10.22-
GData192008.10.23Win32:Trojan-gen {Other}
IkarusT3.1.1.44.02008.10.23-
K7AntiVirus7.10.5032008.10.22Trojan.Win32.Malware.1
Kaspersky7.0.0.1252008.10.23-
McAfee54112008.10.22-
Microsoft1.40052008.10.23-
NOD3235472008.10.22-
Norman5.80.022008.10.22W32/Smalltroj.HSYY
Panda9.0.0.42008.10.22Suspicious file
PCTools4.4.2.02008.10.22-
Prevx1V22008.10.23-
Rising20.67.22.002008.10.22-
SecureWeb-Gateway6.7.62008.10.22Trojan.Crypt.XPACK.Gen
Sophos4.34.02008.10.23-
Sunbelt3.1.1745.12008.10.22-
Symantec102008.10.23-
TheHacker6.3.1.0.1242008.10.23-
TrendMicro8.700.0.10042008.10.22PAK_Generic.001
VBA323.12.8.82008.10.22Trojan-Spy.Win32.Goldun.bdb
ViRobot2008.10.23.14332008.10.23-
VirusBuster4.5.11.02008.10.22-
sam.to
发表于 2008-10-23 11:45:27 | 显示全部楼层
Hello,

load.exe3 - Trojan.Win32.Pakes.lgg

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Ostroverkhov Vladimir
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.
yurius
发表于 2008-10-23 11:47:33 | 显示全部楼层
McAfee 已自动阻止并隔离计算机上感染病毒的文件。您可以在 SecurityCenter 的“恢复”窗格中恢复隔离的文件。

关于此 特洛伊木马程序
已检测到: Generic!Artemis (特洛伊木马程序)
隔离来源: C:\Documents and Settings\xxx\桌面\virus\load.exe

特洛伊木马程序以合法程序的身份出现,但可能会损坏重要文件,降低性能,并允许对计算机进行未经授权的访问。
will
发表于 2008-10-23 12:14:35 | 显示全部楼层

Multi Command-Line Scanner Report
-------------------------------------------------------------------------   
D:\Desk\Samples\Collect\MCLS\load.exe   
MD5 Hash: C49C4B57405065C22D49A6AA133006C6   
Type: Generic Win/DOS Executable / Extension: .EXE   

A-squared ----- Nothing   
Avast ----- Win32:Trojan-gen {Other}    
Avg ----- SHeur.CPGN     
Antivir ----- TR/Crypt.XPACK.Gen    
BitDefender ----- Nothing   
ClamWin ----- Broken.Executable    
Dr.Web ----- Trojan.PWS.GoldSpy.2309    
NOD32 ----- Nothing   
Ikarus ----- Nothing   
Jiangmin ----- Nothing   
Kaspersky ----- Nothing   
Kingsoft ----- Win32.Troj.OnlineGameT.bs.1081344    
Vba32 ----- Nothing   

*** 6/13 antivirus engines found virus in this file ***   
-------------------------------------------------------------------------   

Task done @ 2008/10/23 四 12:14:02.15   
kingmuro
头像被屏蔽
发表于 2008-10-23 13:21:52 | 显示全部楼层
过诺顿10.1版本
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-11 11:07 , Processed in 0.125057 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表