查看: 3677|回复: 24
收起左侧

[病毒样本] 1个【5月16日2点更新】【5月15日13点25分更新】

[复制链接]
killloop
发表于 2009-5-8 19:51:30 | 显示全部楼层 |阅读模式

============================================



2009年5月9日晚21点更新:   
告诉过他,我盯上你了,你更新一个,我就报一个,竟敢还更新。
不让上传图片,无效的图片文件。
=============================================
5月11日17点更新:
=============================================
5月12日22点更新:
=============================================
5月13日20点更新:
=============================================
5月15日12点更新:  今日16点,有人在我之前用多引擎扫描过了。
=============================================
5月16日2点更新:

a-squared4.0.0.32200905141701412009-05-14Virus.Win32.Agent!IK
2.144
AntiVir8.2.0.1687.1.3.2152009-05-15HEUR/Malware
0.643
Arcavir20092009051517212009-05-15-
0.067
Authentium5.1.12009051513362009-05-15W32/Heuristic-210!Eldorado (Heuristic)
6.951
AVAST!4.7.4090515-02009-05-15Win32:Agent-ADVJ [Rtk]
0.176
AVG8.5.286270.12.32/21172009-05-16-
9.290
BitDefender7.81008.29824327.254272009-05-16-
3.563
CA (VET)9.0.0.14331.6.6507 2009-05-16-
5.226
ClamAV0.9593632009-05-15-
0.460
Comodo3.811572009-05-08-
0.746
CP Secure1.1.0.7152009.05.152009-05-15Troj.GameThief.W32.OnLineGames.tcdi
9.235
Dr.Web4.44.0.91702009.05.162009-05-16-
5.412
F-Prot4.4.4.56200905152009-05-15Possible W32/Heuristic-210!Eldorado (damaged, not disinfectable)
8.031
F-Secure5.51.61002009.05.15.052009-05-15-
0.584
GData19.5236/19.331200905162009-05-16Trojan-GameThief.Win32.OnLineGames.bmaz [Engine:A]
4.485
IkarusT3.1.01.492009.05.15.727242009-05-15Virus.Win32.Agent
3.332
Microsoft1.46022009.05.152009-05-15VirTool:Win32/Obfuscator.C(Suspicious)
6.234
mks_vir2.012009.05.152009-05-15-
3.688
Norman6.01.056.01.002009-05-15-
4.011
nProtect20090516.0137000252009-05-16-
5.714
Quick Heal10.002009.05.152009-05-15-
1.382
Sophos2.86.04.412009-05-16Mal/EncPk-BW
2.510
Sunbelt513651362009-05-14-
0.959
The Hacker6.3.4.1v003262009-05-15-
0.616
VBA323.12.10.520090515.14452009-05-15-
2.973
ViRobot200905152009.05.152009-05-15-
0.415
VirusBuster4.5.11.1010.105.27/13778362009-05-15Packed/Upack
3.480
卡巴斯基5.5.102009.05.162009-05-16Trojan-GameThief.Win32.OnLineGames.bmaz
0.400
安博士V32009.05.15.022009.05.152009-05-15-
0.874
安天2.0.1820090515.24168422009-05-15-
0.121
江民杀毒11.0.7062009.05.132009-05-13-
2.026
熊猫卫士9.05.012009.05.152009-05-15Suspicious file
3.837
瑞星20.021.29.44.002009-05-15-
1.644
赛门铁克1.3.0.2420090515.0032009-05-15-
0.226
趋势科技8.700-10046.134.042009-05-15-
2.242
迈克菲5.3.0056162009-05-15New Malware.n
3.141
金山毒霸2009.2.5.152009.5.15.212009-05-15-
0.600
飞塔2.81-3.11710.3942009-05-15PossibleThreat
0.356

















a-squared4.0.0.1012009.05.16Virus.Win32.Agent!IK
AhnLab-V35.0.0.22009.05.15-
AntiVir7.9.0.1682009.05.15HEUR/Malware
Antiy-AVL2.0.3.12009.05.15-
Authentium5.1.2.42009.05.15W32/Heuristic-210!Eldorado
Avast4.8.1335.02009.05.15Win32:Agent-ADVJ
AVG8.5.0.3362009.05.15Suspicion: unknown virus
BitDefender7.22009.05.16-
CAT-QuickHeal10.002009.05.15-
ClamAV0.94.12009.05.15-
Comodo11572009.05.08-
DrWeb5.0.0.121822009.05.16-
eSafe7.0.17.02009.05.14Win32.Looked.gen
eTrust-Vet31.6.65082009.05.16-
F-Prot4.4.4.562009.05.15W32/Heuristic-210!Eldorado
F-Secure8.0.14470.02009.05.15W32/Packed_Upack.H
Fortinet3.117.0.02009.05.16PossibleThreat
GData192009.05.16Win32:Agent-ADVJ
IkarusT3.1.1.49.02009.05.16Virus.Win32.Agent
K7AntiVirus7.10.7352009.05.14Generic.Packed.Upack
Kaspersky7.0.0.1252009.05.16Trojan-GameThief.Win32.OnLineGames.bmaz
McAfee56162009.05.15New Malware.n
McAfee+Artemis56162009.05.15Artemis!8D77305B8AC7
McAfee-GW-Edition6.7.62009.05.15Heuristic.Malware
Microsoft1.46022009.05.15VirTool:Win32/Obfuscator.C
NOD3240802009.05.15-
Norman6.01.052009.05.16-
nProtect2009.1.8.02009.05.16-
Panda10.0.0.142009.05.15Suspicious file
PCTools4.4.2.02009.05.15Packed/Upack
Prevx3.02009.05.16-
Rising21.29.50.002009.05.16Trojan.Win32.Nodef.jde
Sophos4.41.02009.05.16Mal/EncPk-BW
Sunbelt3.2.1858.22009.05.16-
Symantec1.4.4.122009.05.16-
TheHacker6.3.4.1.3262009.05.15-
TrendMicro8.950.0.10922009.05.15PAK_Generic.001
VBA323.12.10.52009.05.16-
ViRobot2009.5.15.17372009.05.15-
VirusBuster4.6.5.02009.05.15Packed/Upack















=============================================
这是它开发的另一个挂:卡巴启发,5月9日上报卡巴外挂2.4版至今没有回复。
5月11日23点更新2.6版已上报江民
=============================================
5月15日13点25分更新,14点有人用多引擎扫描,压缩包里的内容与11日基本相同(没检查MD5),只是更新了这个Plus.dll文件(没检查MD5),裸奔没测主防。

软件名称 引擎版本 病毒库版本 病毒库时间 扫描结果 时间
a-squared 4.0.0.32 20090514170141 2009-05-14 - 2.158
AntiVir 8.2.0.166 7.1.3.209 2009-05-15 - 0.536
Arcavir 2009 200905141900 2009-05-14 - 0.087
Authentium 5.1.1 200905141846 2009-05-14 W32/Banload.E.gen!Eldorado (Possible) 1.119
AVAST! 4.7.4 090514-0 2009-05-14 - 0.082
AVG 8.5.286 270.12.31/2116 2009-05-15 - 3.540
BitDefender 7.81008.2978604 7.25411 2009-05-15 - 2.819
CA (VET) 9.0.0.143 31.6.6505  2009-05-15 - 8.564
ClamAV 0.95 9360 2009-05-15 - 0.240
Comodo 3.8 1157 2009-05-08 - 0.966
CP Secure 1.1.0.715 2009.05.15 2009-05-15 - 9.044
Dr.Web 4.44.0.9170 2009.05.15 2009-05-15 - 4.735
F-Prot 4.4.4.56 20090514 2009-05-14 W32/Banload.E.gen!Eldorado (generic, not disinfectable) 1.128
F-Secure 5.51.6100 2009.05.15.01 2009-05-15 - 3.581
GData 19.5229/19.330 20090515 2009-05-15 - 4.291
Ikarus T3.1.01.49 2009.05.15.72721 2009-05-15 - 3.238
Microsoft 1.4602 2009.05.15 2009-05-15 - 5.207
mks_vir 2.01 2009.05.15 2009-05-15 - 3.258
Norman 6.01.05 6.01.00 2009-05-14 - 2.018
nProtect 20090515.01 3689808 2009-05-15 - 8.351
Quick Heal 10.00 2009.05.15 2009-05-15 - 1.770
Sophos 2.86.0 4.41 2009-05-15 - 2.471
Sunbelt 5136 5136 2009-05-14 - 1.152
The Hacker 6.3.4.1 v00326 2009-05-15 - 0.730
VBA32 3.12.10.5 20090514.1440 2009-05-14 - 2.203
ViRobot 20090514 2009.05.14 2009-05-14 - 0.545
VirusBuster 4.5.11.10 10.105.26/1354980 2009-05-14 - 2.542
卡巴斯基 5.5.10 2009.05.15 2009-05-15 - 0.141
安博士V3 2009.05.15.02 2009.05.15 2009-05-15 - 0.746
安天 2.0.18 20090515.2416842 2009-05-15 - 0.118
江民杀毒 11.0.706 2009.05.13 2009-05-13 - 2.417
熊猫卫士 9.05.01 2009.05.14 2009-05-14 - 1.828
瑞星 20.0 21.29.42.00 2009-05-15 - 1.211
赛门铁克 1.3.0.24 20090514.002 2009-05-14 - 0.117
趋势科技 8.700-1004 6.132.04 2009-05-15 - 0.035
迈克菲 5.3.00 5615 2009-05-14 - 3.357
金山毒霸 2009.2.5.15 2009.5.15.18 2009-05-15 - 0.601
飞塔 2.81-3.117 10.391 2009-05-15 - 0.447



反病毒引擎 版本 最后更新 扫描结果
a-squared 4.0.0.101 2009.05.15 -
AhnLab-V3 5.0.0.2 2009.05.15 -
AntiVir 7.9.0.166 2009.05.15 -
Antiy-AVL 2.0.3.1 2009.05.15 -
Authentium 5.1.2.4 2009.05.14 W32/Banload.E.gen!Eldorado
Avast 4.8.1335.0 2009.05.15 -
AVG 8.5.0.336 2009.05.15 -
BitDefender 7.2 2009.05.15 -
CAT-QuickHeal 10.00 2009.05.15 -
ClamAV 0.94.1 2009.05.15 -
Comodo 1157 2009.05.08 -
DrWeb 5.0.0.12182 2009.05.15 -
eSafe 7.0.17.0 2009.05.14 -
eTrust-Vet 31.6.6506 2009.05.15 -
F-Prot 4.4.4.56 2009.05.14 W32/Banload.E.gen!Eldorado
F-Secure 8.0.14470.0 2009.05.15 -
Fortinet 3.117.0.0 2009.05.15 -
GData 19 2009.05.15 -
Ikarus T3.1.1.49.0 2009.05.15 -
K7AntiVirus 7.10.735 2009.05.14 -
Kaspersky 7.0.0.125 2009.05.15 -
McAfee 5615 2009.05.14 -
McAfee+Artemis 5615 2009.05.14 -
McAfee-GW-Edition 6.7.6 2009.05.15 -
Microsoft 1.4602 2009.05.15 -
NOD32 4078 2009.05.15 -
Norman 6.01.05 2009.05.14 -
nProtect 2009.1.8.0 2009.05.15 -
Panda 10.0.0.14 2009.05.15 -
PCTools 4.4.2.0 2009.05.15 -
Prevx 3.0 2009.05.15 -
Rising 21.29.42.00 2009.05.15 -
Sophos 4.41.0 2009.05.15 -
Sunbelt 3.2.1858.2 2009.05.15 -
Symantec 1.4.4.12 2009.05.15 -
TheHacker 6.3.4.1.326 2009.05.15 -
TrendMicro 8.950.0.1092 2009.05.15 -
VBA32 3.12.10.5 2009.05.15 -
ViRobot 2009.5.15.1736 2009.05.15 -
VirusBuster 4.6.5.0 2009.05.14 -

[ 本帖最后由 killloop 于 2009-5-16 13:25 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mofunzone
发表于 2009-5-8 20:00:59 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\Administrator\Desktop\wg3.50'
C:\Users\Administrator\Desktop\wg3.50\wg3.50\测试补丁.exe
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
C:\Users\Administrator\Desktop\wg3.50\wg3.50\防封防掉.exe
  [0] Archive type: RAR SFX (self extracting)
    [NOTE]      The file was deleted!
    --> ᄇ¬ᅧᅯᄇᄍᄊᄀ.exe
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan


End of the scan: 2009年5月8日  05:00
Used time: 00:03 Minute(s)

The scan has been done completely.

      2 Scanned directories
      6 Files were scanned
      2 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      2 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      4 Files not concerned
      1 Archives were scanned
      0 Warnings
      2 Notes
kingsheet
发表于 2009-5-8 20:19:01 | 显示全部楼层
卡巴不报
雨宫优子
发表于 2009-5-8 20:25:05 | 显示全部楼层
不得不说...........我必须编辑你的内容...
麻烦你每次发这类东西....把广告性内容编辑掉好不....
webweb
发表于 2009-5-8 21:26:16 | 显示全部楼层
貌似广告是 论坛 加上的
BING126
头像被屏蔽
发表于 2009-5-8 21:57:09 | 显示全部楼层
McAfee 报了2个。。
syfwxmh
发表于 2009-5-8 22:01:06 | 显示全部楼层
Hello,


AU_.EXE,
DNF??????????.url,
DNF????.exe,
????.txt

No malicious code were found in these files.

????.exe,
????.exe - Trojan-PSW.Win32.QQPass.hqx

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.
Sebastian
发表于 2009-5-9 06:18:01 | 显示全部楼层
D:\kafan\wg3.50\测试补丁.exe         已检测: Win32.HLLW.Wace!IK
D:\kafan\wg3.50\防封防掉.exe/测试补丁.exe         已检测: Win32.HLLW.Wace!IK
kalynn84
发表于 2009-5-9 06:34:44 | 显示全部楼层
Win32:Agent-ADVJ [Rtk]
左手
发表于 2009-5-9 11:51:55 | 显示全部楼层
2009-05-09 11:51:26    直接操作系统内核      操作:阻止并结束进程
进程路径:E:\virus\wg3.50\测试补丁.exe

触发规则:应用程序规则->A05-高危操作询问->*.*

[:16:]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-13 12:11 , Processed in 0.137419 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表