查看: 2430|回复: 11
收起左侧

[病毒样本] 一打12个(过所有主流)

[复制链接]
sam.to
发表于 2009-6-5 12:52:47 | 显示全部楼层 |阅读模式
53d436248ef30e00388f081b46761be9   file.exe1
dea3d7b3537056a52404695bfb49cecc   file.exe2
b146cca775e426a5d49ec5a70007a54e   file.exe3
e3efc9d007ed06f12566594e837a803e   file.exe4
b858e3bdf0571b847c3a2ab24bcaf533   file.exe5
06c1b8368e0cc48750d3d80e062d4f2b   file.exe6
6f4632dd8511b9f0bfd392bf8e0b6c08   file.exe7
5bf929ecff775b617bfafd88f237c6ef   file.exe8
cbf2d5776b27c7e50272a9e58bbd631a   file.exe9
1ef306e2b6226f67357db15fc887aad6   file.exe10
1c36e3cadefdd4e357327dcb1853ac19   file.exe11
9a1eab17cede9f7f02ee3d4defb3de0b   file.exe12
to kl,eset,lavasoft,comodo,
https://www.virustotal.com/anali ... 6902a5da-1244177543
http://sample.nod32.com.hk/index ... 4370e6c2908fa884e75


Hello,


file.exe1 - Trojan.Win32.TDSS.afuo,

file.exe10 - Trojan.Win32.TDSS.afup,

file.exe11 - Trojan.Win32.TDSS.afuq,

file.exe12 - Trojan.Win32.TDSS.afur,

file.exe2 - Trojan.Win32.TDSS.afus,

file.exe3 - Trojan.Win32.TDSS.afuv,

file.exe4 - Trojan.Win32.TDSS.afuw,

file.exe6 - Trojan.Win32.TDSS.afuy,

file.exe7 - Trojan.Win32.TDSS.afuz,

file.exe8 - Trojan.Win32.TDSS.afva,

file.exe9 - Trojan.Win32.TDSS.afvb,

file.exe_ - Trojan.Win32.TDSS.afux

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

[ 本帖最后由 sam.to 于 2009-6-5 17:12 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
悠柚
发表于 2009-6-5 12:55:55 | 显示全部楼层
换头像了?(难道是因为昨天的一个毒?
D:\TDDownload\012.rar/file.exe1         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe10         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe11         已检测: Trojan-Downloader.Win32.Boltolog!IK
D:\TDDownload\012.rar/file.exe12         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe2         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe3         已检测: Trojan-Downloader.Win32.Boltolog!IK
D:\TDDownload\012.rar/file.exe4         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe5         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe6         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe7         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe8         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe9         已检测: Rootkit.Win32.TDSS!IK
Whitlack
发表于 2009-6-5 12:57:00 | 显示全部楼层
Start of the scan: 2009年6月5日  12:56

Starting the file scan:

Begin scan in 'C:\Documents and Settings\xxxxx\桌面\012.rar'
C:\Documents and Settings\xxxxx\桌面\012.rar
  [0] Archive type: RAR
    --> file.exe1
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe10
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe11
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe12
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe2
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe3
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe4
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe5
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe6
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe7
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe8
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    --> file.exe9
      [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      A backup was created as '4a5aa59b.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!


End of the scan: 2009年6月5日  12:56
Used time: 00:00 Minute(s)

The scan has been done completely.

[ 本帖最后由 Whitlack 于 2009-6-5 13:00 编辑 ]
ningjingzz
发表于 2009-6-5 13:05:32 | 显示全部楼层
Avira AntiVir Professional

D:\012\file.exe1
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe10
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe11
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe12
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe2
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe3
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe4
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe5
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe6
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe7
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe8
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
D:\012\file.exe9
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was deleted!
bjkk988
发表于 2009-6-5 13:07:00 | 显示全部楼层
扫描结果 :  18%的杀软(7/38)报告发现病毒
时间 :  2009/06/05 13:00:03 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.0.0.32200906040132252009-06-04Rootkit.Win32.TDSS!IK
5.126
AntiVir8.2.0.1807.1.4.592009-06-04TR/Crypt.XPACK.Gen
0.324
Arcavir20092009060416082009-06-04-
0.495
Authentium5.1.12009060416522009-06-04-
2.436
AVAST!4.7.4090604-02009-06-04-
0.060
AVG8.5.286270.12.53/21552009-06-05-
5.238
BitDefender7.81008.33355057.258112009-06-05-
3.106
CA (VET)9.0.0.14331.6.6539 2009-06-05Win32/TDSS!packed unknown type.
5.908
ClamAV0.95.194212009-06-05-
0.258
Comodo3.912602009-06-05-
0.757
CP Secure1.1.0.7152009.06.032009-06-03-
10.557
Dr.Web4.44.0.91702009.06.052009-06-05Trojan.Packed.365
4.668
F-Prot4.4.4.56200906042009-06-04-
2.088
F-Secure5.51.61002009.06.05.032009-06-05-
0.471
GData19.5617/19.353200906052009-06-05-
4.539
IkarusT3.1.01.572009.06.03.728142009-06-03Rootkit.Win32.TDSS
10.303
Microsoft1.47012009.06.042009-06-04Trojan:Win32/Alureon.gen!J
10.041
mks_vir2.012009.06.052009-06-05-
4.568
Norman6.01.056.01.002009-06-02-
4.005
nProtect20090604.0140703762009-06-04-
5.393
Quick Heal10.002009.06.052009-06-05-
1.647
Sophos2.87.14.422009-06-05-
2.527
Sunbelt517051702009-06-04-
1.483
The Hacker6.3.4.3v003402009-06-04-
1.248
VBA323.12.10.620090604.14122009-06-04-
9.451
ViRobot200906042009.06.042009-06-04-
0.423
VirusBuster4.5.11.1010.107.2/15756862009-06-04-
2.076
卡巴斯基5.5.102009.06.052009-06-05-
0.393
安博士V32009.06.05.002009.06.052009-06-05-
0.996
安天2.0.1820090604.24980512009-06-04-
0.702
江民杀毒11.0.7062009.06.032009-06-03-
2.084
熊猫卫士9.05.012009.06.042009-06-04Suspicious file
1.916
瑞星20.021.32.40.002009-06-05-
1.170
赛门铁克1.3.0.2420090604.0022009-06-04-
0.324
趋势科技8.700-10046.170.082009-06-04-
0.083
迈克菲5.3.0056362009-06-04-
3.502
金山毒霸2009.2.5.152009.6.4.212009-06-04-
0.510
飞塔2.81-3.11710.4662009-06-04-
kingmuro
头像被屏蔽
发表于 2009-6-5 14:35:43 | 显示全部楼层
过avast4.8
sam.to
 楼主| 发表于 2009-6-5 17:13:23 | 显示全部楼层
原帖由 悠柚 于 2009-6-5 12:55 发表
换头像了?(难道是因为昨天的一个毒?
D:\TDDownload\012.rar/file.exe1         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/file.exe10         已检测: Rootkit.Win32.TDSS!IK
D:\TDDownload\012.rar/fil ...

那个毒不是第一个,更換头像只是巧合
feihongtian 该用户已被删除
发表于 2009-6-5 19:12:24 | 显示全部楼层
Panda 2010 All kill
ansen98
发表于 2009-6-5 19:25:42 | 显示全部楼层
红伞全屠
luxiao200888
发表于 2009-6-5 20:09:03 | 显示全部楼层
微点虚拟.kill all
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-18 04:26 , Processed in 0.135916 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表