查看: 5650|回复: 31
收起左侧

[病毒样本] 昨晚中标

[复制链接]
aerbeisi
发表于 2008-11-25 12:35:57 | 显示全部楼层 |阅读模式
NOD32失守,目前我全盘exe被感染,昨晚卡巴也是杀不了的,今天卡巴可以查出,但是清不了毒。还有这个毒变态在被感染的exe被加入了强制重启命令,只要我点了被感染的exe,马上重启,顺便再中一次毒。o(∩_∩)o...哈哈

文件 LSASS.rar 接收于 2008.11.25 05:15:10 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.11.24.32008.11.24-
AntiVir7.9.0.352008.11.24HEUR/Malware
Authentium5.1.0.42008.11.24W32/SelfStarterInternetTrojan!Maximus
Avast4.8.1281.02008.11.24-
AVG8.0.0.1992008.11.24-
BitDefender7.22008.11.25Generic.Malware.Sdld.5E3488C7
CAT-QuickHeal10.002008.11.25-
ClamAV0.94.12008.11.25-
DrWeb4.44.0.091702008.11.24-
eSafe7.0.17.02008.11.24Suspicious File
eTrust-Vet31.6.62262008.11.25-
Ewido4.02008.11.24-
F-Prot4.4.4.562008.11.24W32/SelfStarterInternetTrojan!Maximus
F-Secure8.0.14332.02008.11.25-
Fortinet3.117.0.02008.11.25-
GData192008.11.25-
IkarusT3.1.1.45.02008.11.25Win32.SuspectCrc
K7AntiVirus7.10.5322008.11.24-
Kaspersky7.0.0.1252008.11.25Trojan-Downloader.Win32.Banload.ygl
McAfee54442008.11.24-
McAfee+Artemis54442008.11.24Generic!Artemis
Microsoft1.41042008.11.25-
NOD3236372008.11.24-
Norman5.80.022008.11.24-
Panda9.0.0.42008.11.24Suspicious file
PCTools4.4.2.02008.11.24-
Prevx1V22008.11.25-
Rising21.05.10.002008.11.25-
SecureWeb-Gateway6.7.62008.11.24Heuristic.Malware
Sophos4.35.02008.11.24Mal/Heuri-E
Sunbelt3.1.1823.22008.11.22Virus.Win32.Xorer.F (vf)
Symantec102008.11.25Downloader
TheHacker6.3.1.1.1622008.11.25-
TrendMicro8.700.0.10042008.11.25PAK_Generic.001



随便挑了一个被感染的exe,选了个文件比较小的。有清毒的没,能清毒的我就换上杀毒,无法清毒,就重装程序了。颇有熊猫和磁碟机的风范。某杀软的确报了xorer,:-)

文件 Lingoes.rar 接收于 2008.11.25 05:29:38 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.11.24.32008.11.24-
AntiVir7.9.0.352008.11.24-
Authentium5.1.0.42008.11.24W32/SelfStarterInternetTrojan!Maximus
Avast4.8.1281.02008.11.24-
AVG8.0.0.1992008.11.24-
BitDefender7.22008.11.25Generic.Malware.Sdld.5E3488C7
CAT-QuickHeal10.002008.11.25-
ClamAV0.94.12008.11.25-
DrWeb4.44.0.091702008.11.24-
eSafe7.0.17.02008.11.24Suspicious File
eTrust-Vet31.6.62262008.11.25-
Ewido4.02008.11.24-
F-Prot4.4.4.562008.11.24W32/SelfStarterInternetTrojan!Maximus
F-Secure8.0.14332.02008.11.25-
Fortinet3.117.0.02008.11.25-
GData192008.11.25-
IkarusT3.1.1.45.02008.11.25-
K7AntiVirus7.10.5322008.11.24-
Kaspersky7.0.0.1252008.11.25Trojan-Downloader.Win32.Banload.ygl
McAfee54442008.11.24-
McAfee+Artemis54442008.11.24-
Microsoft1.41042008.11.25-
NOD3236372008.11.24-
Norman5.80.022008.11.24-
Panda9.0.0.42008.11.24Suspicious file
PCTools4.4.2.02008.11.24-
Prevx1V22008.11.25-
Rising21.05.10.002008.11.25-
SecureWeb-Gateway6.7.62008.11.24-
Sophos4.35.02008.11.24Mal/Heuri-E
Sunbelt3.1.1823.22008.11.22Virus.Win32.Xorer.F (vf)
Symantec102008.11.25Downloader

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kingmuro
头像被屏蔽
发表于 2008-11-25 12:46:15 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aerbeisi
 楼主| 发表于 2008-11-25 12:49:56 | 显示全部楼层
lingoes清毒了吗?呵呵
aerbeisi
 楼主| 发表于 2008-11-25 12:52:22 | 显示全部楼层
希望比较渺茫,查到的基本上都是启发。
aerbeisi
 楼主| 发表于 2008-11-25 13:10:26 | 显示全部楼层
  • Submission details:
    • Submission received: 25 November 2008, 15:47:24
    • Processing time: 6 min 11 sec
    • Submitted sample:
      • File MD5: 0x8381F4529A05B6AA2EA0821E64777A41
      • Filesize: 10,240 bytes
      • Alias & packer info:
  • Summary of the findings:
What's been foundSeverity Level
Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode.
Contains characteristics of an identified security risk.


Technical Details:
Possible Security Risk
  • Attention! The following threat category was identified:
Threat CategoryDescription
A program that downloads files to the local computer that may represent security risk


File System Modifications
  • The following file was created in the system:
#Filename(s)File SizeFile MD5Alias
1[file and pathname of the sample #1] 10,240 bytes0x8381F4529A05B6AA2EA0821E64777A41Downloader [Symantec]
Mal/Heuri-E, Mal/Emogen-P [Sophos]
packed with PE_Patch.UPX [Kaspersky Lab]


Memory Modifications
  • There was a new process created in the system:
Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]45,056 bytes


Registry Modifications
  • The following Registry Keys were deleted: (删安全模式注册表)
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
  • The following Registry Values were deleted:
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
      • (Default) = "DiskDrive"
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
      • (Default) = "DiskDrive"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
      • (Default) = "DiskDrive"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
      • (Default) = "DiskDrive"

Other details
  • Analysis of the file resources indicate the following possible country of origin:(原产地)
China
  • To mark the presence in the system, the following Mutex object was created:
    • I AM RUNNING
  • A system request is initiated to shut down the system to a point at which it is safe to turn off the power.(关机)
Redevil
发表于 2008-11-25 13:18:38 | 显示全部楼层
卡巴两个都杀
至于清除
楼主自己慢慢来吧
aerbeisi
 楼主| 发表于 2008-11-25 13:21:45 | 显示全部楼层
我昨晚上报卡巴的。
西风萧雨
发表于 2008-11-25 13:43:50 | 显示全部楼层

微点报告“未知木马;


解压没反应,运行微点报警拦截了~~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
西风萧雨
发表于 2008-11-25 13:54:10 | 显示全部楼层

对金山的病毒分析能力彻底无语·~~

快倒是很快,但是这样的结果也太~~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aerbeisi
 楼主| 发表于 2008-11-25 13:55:40 | 显示全部楼层
自动分析的比较矬。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-20 05:11 , Processed in 0.150086 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表