查看: 2093|回复: 9
收起左侧

[病毒样本] TWO(报的不少)

[复制链接]
schumi小粉
发表于 2009-1-7 15:24:22 | 显示全部楼层 |阅读模式
文件信息
文件名称 :  2.rar
文件大小 :  39889 byte
文件类型 :  RAR archive data, v1d, os
MD5 :  fb913b5124cf132c1556fbf4bf62e9ce
SHA1 :  45f7ed3ae71b296e7ebb6aa8a0331fc274d30e85
扫描结果
扫描结果 :  29%的杀软(11/38)报告发现病毒
时间 :  2009/01/07 15:18:43 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.0.0.29200901062031452009-01-06Exploit.JS.Axdow!IK
6.285
AntiVir7.9.0.457.1.1.742009-01-06HEUR/Malware
1.725
Authentium5.1.12009010618362009-01-06W32/Malware.C.dam!Eldorado (Possible)
1.071
AVAST!3.0.1090106-12009-01-06-
0.006
AVG7.5.52.442270.10.3/18792009-01-06-
2.428
BitDefender7.81008.24124737.230182009-01-07-
2.215
CA (VET)9.0.0.14331.6.62942009-01-06-
13.696
ClamAV0.94.288402009-01-07-
0.016
Comodo3.08842009-01-06-
1.375
CP Secure1.1.0.7152009.01.072009-01-07-
6.363
Dr.Web4.44.0.91702009.01.072009-01-07-
4.028
ewido4.0.0.22008.12.312008-12-31-
5.545
F-Prot4.4.4.56200901062009-01-06W32/Malware.C.dam!Eldorado (generic, not disinfectable)
1.161
F-Secure5.51.61002009.01.07.032009-01-07-
0.143
GData19.2305/19.175200901072009-01-07-
9.020
IkarusT3.1.01.452009.01.06.721092009-01-06Exploit.JS.Axdow
3.576
Microsoft1.42052009.01.062009-01-06Exploit:JS/Axdow.C
7.633
mks_vir2.012009.01.062009-01-06-
2.743
Norman5.93.015.93.002009-01-05W32/Packed_Upack.H
6.305
nProtect20090106.0128421392009-01-06Script-JS/W32.Agent.EC
3.751
Quick Heal10.002009.01.062009-01-06-
0.878
Sophos2.82.14.372009-01-07Mal/EncPk-BW
2.113
Sunbelt475547552008-12-22-
4.795
The Hacker6.3.1.2v002102009-01-06W32/Behav-Heuristic-060
0.480
VBA323.12.8.1020090106.10182009-01-06-
1.540
ViRobot200901062009.01.062009-01-06-
0.492
VirusBuster4.5.11.1010.100.17/7617392009-01-06-
1.013
卡巴斯基5.5.102009.01.072009-01-07-
0.085
安博士V32009.01.07.022009.01.072009-01-07-
1.172
安天2.0.1820090105.19505022009-01-05-
0.016
江民杀毒11.0.7062009.01.072009-01-07-
3.486
熊猫卫士9.05.012009.01.062009-01-06-
3.016
瑞星20.021.11.20.002009-01-07-
0.832
赛门铁克1.3.0.2420090106.0042009-01-06-
0.249
趋势科技8.700-10045.752.012009-01-06-
0.033
迈克菲5.3.0054872009-01-06New Malware.n
2.875
金山毒霸2008.9.8.182009.1.7.142009-01-07-
0.608
飞塔2.81-3.1179.8982009-01-06-
0.613
注意: 就算报告发现病毒,也可能是杀软误报,请根据查毒结果自行判断

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
The EQs
发表于 2009-1-7 15:49:32 | 显示全部楼层
只将那个脚本发给了超人
Dear Don Johnson,

Thank you for your submission.
The detection for this threat will be included in our next signature update.

Regards,

Senior Virus Researcher
ESET spol. s r.o.
qianwenxiang
发表于 2009-1-7 19:04:50 | 显示全部楼层
这个脚本在哪儿发现的?

关于:某站解密的日志(全体输出-  9):

Level 1>http://某某站点.com/flash.htm
Level 1>http://某某站点.com/as.htm
Level 1>http://某某站点.com/14.htm
Level 1>http://某某站点.com/lz.htm
Level 1>http://某某站点.com/sina.htm
Level 1>http://某某站点.com/office.htm
Level 1>http://某某站点.com/nctaudiofile.htm
Level 1>http://某某站点.com/re10.htm
Level 1>http://某某站点.com/re11.htm

日志由 Redoce1.6第28次修正版于 2009-1-7 19:03:28 生成。
darreol
发表于 2009-3-7 20:16:55 | 显示全部楼层
McAfee Found New Malware.n
Sebastian
发表于 2009-3-7 20:19:37 | 显示全部楼层
Starting the file scan:

Begin scan in 'D:\2'
D:\2\opr00AZK
    [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The detection was classified as suspicious.
    [NOTE]      A backup was created as '4a246719.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
D:\2\opr00AYN
    [DETECTION] Contains recognition pattern of the JS/Dldr.IFrame.EX Java script virus
    [NOTE]      A backup was created as '4ba26192.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年3月7日  20:20
Used time: 00:06 Minute(s)

The scan has been done completely.

      1 Scanning directories
      2 Files were scanned
      1 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      2 files were deleted
      0 files were repaired
      2 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      0 Files not concerned
      0 Archives were scanned
      0 Warnings
      2 Notes
尤金卡巴斯基
发表于 2009-3-7 20:21:02 | 显示全部楼层
To KL
Palkia
发表于 2009-3-7 20:24:33 | 显示全部楼层
to rs
kingmuro
头像被屏蔽
发表于 2009-3-7 20:28:44 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
浪人哭泣
头像被屏蔽
发表于 2009-3-7 21:28:06 | 显示全部楼层
NOD32 4.0发现一个
ledled
发表于 2009-3-7 23:37:05 | 显示全部楼层
Name: Packed/Upack
Type: Sequence

Description:


Files:
c:\users\administrator\desktop\2\opr00azk
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-21 11:13 , Processed in 0.088457 second(s), 4 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表