查看: 2038|回复: 8
收起左侧

[病毒样本] 搞笑的误杀...

[复制链接]
Sherry.ai
发表于 2009-1-18 11:12:50 | 显示全部楼层 |阅读模式
运行后没有危害...
PS.按ESC退出

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
xiaochi12
发表于 2009-1-18 11:14:27 | 显示全部楼层
類別未登錄?
qianwenxiang
发表于 2009-1-18 11:14:40 | 显示全部楼层
报的joke/bluescreen估计。。
Sherry.ai
 楼主| 发表于 2009-1-18 11:16:24 | 显示全部楼层

回复 3楼 qianwenxiang 的帖子

没有一家报Joke...
都保网马
Palkia
发表于 2009-1-18 11:19:42 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\Nothing.rar'
C:\Documents and Settings\Administrator\桌面\Nothing.rar
    [0] Archive type: RAR
    --> Nothing.scr
      [DETECTION] Contains recognition pattern of the ADSPY/Ag.SSS.518193 adware or spyware
    [NOTE]      The file was deleted!
taoyuan237
发表于 2009-1-18 13:35:48 | 显示全部楼层
I服了YOU。真搞啊
08红伞威点
发表于 2009-1-18 13:52:14 | 显示全部楼层
文件名称 :  090118 Nothing x1.rar
文件大小 :  506198 byte
文件类型 :  RAR archive data, v1d, os
MD5 :  9256bf4f2622c30fd6718ba2db64ab21
SHA1 :  b27c2ab3ea8a932a69411927f4daba9161e1a9be
扫描结果 :  8%的杀软(3/37)报告发现病毒
a-squared4.0.0.29200901161834242009-01-16AdWare.Ag.SSS.518193!IK
AntiVir7.9.0.577.1.1.1352009-01-17ADSPY/Ag.SSS.518193
IkarusT3.1.01.452009.01.18.721692009-01-18AdWare.Ag.SSS.518193
Ag.SSS.518193
The file 'Nothing.scr' has been determined to be 'MALWARE'. Our analysts named the threat ADSPY/Ag.SSS.518193. The term "ADSPY/" denotes adware or spyware. This type of malware is able to change browser settings for example by manipulating registry settings or by using of NTFS-streams. Very often IEexploits are used to manipulate the browserhelp.dll.Detection is added to our virus definition file (VDF) starting with version 7.00.02.23.
--------------------------------------------------------------------------------------------------------------------------------------------------
"ADSPY/" 指 adware 或间谍软体。 这类型的恶意软体能够改变操纵登录设定,举例来说位置的浏览器或 NTFS 的使用。 通常, IEexploits 被用以操纵 browserhelp.dll 。

上沙盘
∞∞∞∞∞
• File Info
NameValue
Size518193
MD523c996ef87463bde3957adee73cd9e20
SHA16b48927fca0ebbdaf241db5d1464e832d2653950
SHA256d73fb530b4ad0bb84cda64cf72b3a9311241de375830f64dbeb66aa49c5653b7
ProcessActive

• Keys Created• Keys Changed• Keys Deleted• Values Created• Values Changed• Values Deleted• Directories Created
NameLast Write TimeCreation TimeLast Access TimeAttr
C:\Documents and Settings\User\Local Settings\Temp\888200912011651052009.01.12 14:51:05.9372009.01.12 14:51:05.8282009.01.12 14:51:05.9370x10

• Directories Changed• Directories Deleted• Files Created
NameSizeLast Write TimeCreation TimeLast Access TimeAttr
C:\Documents and Settings\User\Local Settings\Temp\88820091201165105\AMD.swf1598462006.04.30 18:36:04.0002009.01.12 14:51:05.8432009.01.12 14:51:05.8430x20
C:\Documents and Settings\User\Local Settings\Temp\88820091201165105\config.dat1622006.04.30 20:27:38.0002009.01.12 14:51:05.8592009.01.12 14:51:05.8590x20
C:\Documents and Settings\User\Local Settings\Temp\88820091201165105\config.ini8582006.04.30 20:27:38.0002009.01.12 14:51:05.8432009.01.12 14:51:05.8430x20
C:\Documents and Settings\User\Local Settings\Temp\88820091201165105\Windows XP Blue Screen.swf710492006.04.30 19:40:54.0002009.01.12 14:51:05.8432009.01.12 14:51:05.8430x20

• Files Changed• Files Deleted• Directories Hidden• Files Hidden• Drivers Loaded• Drivers Unloaded• Processes Created• Processes Terminated• Threads Created• Modules Loaded• Windows Api Calls• DNS Queries• HTTP Queries• Verdict
Auto Analysis Verdict
Not Rated as Suspicious

• Mutexes Created or Opened
PIdImage NameAddressMutex Name
0x2a4C:\TEST\sample.exe0x77267e1bZonesCacheCounterMutex
0x2a4C:\TEST\sample.exe0x77267e1bZonesLockedCacheCounterMutex
0x2a4C:\TEST\sample.exe0x772689fcZonesCounterMutex

• Events Created or Opened
PIdImage NameAddressEvent Name
0x2a4C:\TEST\sample.exe0x77de5f48Global\SvcctrlStartEvent_A3752DX

浪滔天
发表于 2009-1-18 14:49:00 | 显示全部楼层
有点意思, 用来吓吓人不错~
willjjyu
发表于 2009-1-19 10:19:00 | 显示全部楼层
赞啊 ! 蓝屏.....
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-20 15:19 , Processed in 0.124471 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表