查看: 1846|回复: 6
收起左侧

[病毒样本] 5x

[复制链接]
Palkia
发表于 2008-12-20 19:15:14 | 显示全部楼层 |阅读模式
ris 0

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
luxiao200888
发表于 2008-12-20 19:55:26 | 显示全部楼层
avira
su-tt
发表于 2008-12-20 19:55:48 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\virus[1]\135C1D2FEECD4D02832EF83FBB59EBA7 - Win32/Spy.Banker.PQT 特洛伊木马 的变种
C:\Documents and Settings\Administrator\桌面\virus[1]\378A60CC7C43A07309CB5DBF6A547B6D - Win32/Agent.OKA 特洛伊木马
C:\Documents and Settings\Administrator\桌面\virus[1]\D994B2C30456381828664DA257533A42 - Win32/Delf.NTS 特洛伊木马
其余上报ESET
syfwxmh
发表于 2008-12-20 19:59:57 | 显示全部楼层
TO KL

特征杀1
08红伞威点
发表于 2008-12-20 20:01:39 | 显示全部楼层
文件名称 :   32EC9BD3E458C247E6BC6559594857F2.rar
文件大小 :   834769 byte
扫描结果 :   15%的杀软(6/39)报告发现病毒 http://virscan.org/report/f877f2d1fa591379e4943c1a727555ee.html
a-squared 4.0.0.28 20081219013143 2008-12-19 Trojan-PWS.Win32.Agent.kv!IK
Authentium 5.1.1 200812192224 2008-12-19 W32/Agent.BI.gen!Eldorado (Possible)
F-Prot 4.4.4.56 20081219 2008-12-19 W32/Agent.BI.gen!Eldorado (generic, not disinfectable)
Ikarus T3.1.01.45 2008.12.20.72035 2008-12-20 Trojan-PWS.Win32.Agent.kv
Sunbelt 4754 4754 2008-12-10 Trojan.Win32.Startpage
VBA32 3.12.8.10 20081219.2214 2008-12-19 Embedded.Trojan.Win32.Rodog (suspicious)
-------------------------------------------------------------------------------------------
文件名称 :   135C1D2FEECD4D02832EF83FBB59EBA7.rar
文件大小 :   2814226 byte
扫描结果 :   5%的杀软(2/39)报告发现病毒 http://virscan.org/report/3a7fcae2b98e1ecdffe8d7f46a2934b5.html
Authentium 5.1.1 200812192224 2008-12-19 W32/Downloader.F.gen!Eldorado (Possible)
F-Prot 4.4.4.56 20081219 2008-12-19 W32/Downloader.F.gen!Eldorado (generic, not disinfectable)
----------------------------------------------------------------------------------------------
文件名称 :   01149D241C8D73F247EC9AEE95063D5D.rar
文件大小 :   393907 byte
扫描结果 :   全部的杀毒软件报告没有发现病毒! http://virscan.org/report/3a7fcae2b98e1ecdffe8d7f46a2934b5.html
-----------------------------------------------------------------------------------------------
文件名称 :   D994B2C30456381828664DA257533A42.rar
文件大小 :   217933 byte
扫描结果 :   10%的杀软(4/39)报告发现病毒 http://virscan.org/report/f877f2d1fa591379e4943c1a727555ee.html
Authentium 5.1.1 200812192224 2008-12-19 W32/Heuristic-210!Eldorado (Heuristic)
F-Prot 4.4.4.56 20081219 2008-12-19 Possible W32/Heuristic-210!Eldorado (not disinfectable)
Quick Heal 10.00 2008.12.20 2008-12-20 Suspicious - DNAScan
VBA32 3.12.8.10 20081219.2214 2008-12-19 Win32.Delf.NTS
∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞∞
File ID FilenameSize (Byte)Result
25215878 135C1D2FEECD4D02832E...A7 2.73 MB UNDER ANALYSIS
25215674 32EC9BD3E458C247E6BC...F2 2.26 MB UNDER ANALYSIS
25215879 D994B2C3045638182866...42 222.5 KB UNDER ANALYSIS


红伞上报3个。
luxiao200888
发表于 2008-12-20 20:07:07 | 显示全部楼层
Begin scan in 'C:\Documents and Settings\Owner\桌面\新建文件夹'
C:\Documents and Settings\Owner\桌面\新建文件夹\378A60CC7C43A07309CB5DBF6A547B6D
    [DETECTION] Is the TR/Hijacker.Gen Trojan
08红伞威点
发表于 2008-12-22 21:17:48 | 显示全部楼层

回复 5楼 08红伞威点 的帖子

File ID  Filename Size (Byte) Result
25215877  样本x3.rar 3.69 MB OK

A listing of files contained inside archives alongside their results can be found below:

File ID  Filename Size (Byte) Result
25215878  135C1D2FEECD4D02832E...A7  2.73 MB  MALWARE
25215674  32EC9BD3E458C247E6BC...F2  2.26 MB  CLEAN
25215879  D994B2C3045638182866...42  222.5 KB  MALWARE


Please find a detailed report concerning each individual sample below:

Filename Result
135C1D2FEECD4D02832E...A7  MALWARE

The file '135C1D2FEECD4D02832EF83FBB59EBA7' has been determined to be 'MALWARE'. Our analysts named the threat TR/Banker.Banker.acbs. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.01.01.16.

Filename Result
32EC9BD3E458C247E6BC...F2  CLEAN

The file '32EC9BD3E458C247E6BC6559594857F2' has been determined to be 'CLEAN'. Our analysts did not discovered any malicious content.

Filename Result
D994B2C3045638182866...42  MALWARE

The file 'D994B2C30456381828664DA257533A42' has been determined to be 'MALWARE'. Our analysts named the threat TR/Banker.Banker.abzs. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.01.01.15.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-4 02:14 , Processed in 0.135233 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表