查看: 3891|回复: 13
收起左侧

[病毒样本] 邪门了,红伞未报

[复制链接]
绅博周幸
发表于 2007-2-8 17:44:25 | 显示全部楼层 |阅读模式
RT,蜘蛛也没有

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
野马
发表于 2007-2-8 17:49:22 | 显示全部楼层
可疑程序

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
野马
发表于 2007-2-8 17:52:44 | 显示全部楼层
我感觉我是在安全公司上班呵!
紫外线
发表于 2007-2-8 17:57:18 | 显示全部楼层
原帖由 野马 于 2007-2-8 17:49 发表
可疑程序

nod也没报。。





AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Dropped:Trojan.Spy.Pcapbased.A
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found PossibleThreat!023008
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found Sandbox: Suspicious_F.gen.dropper; [ General information ]

* Decompressing UPX.
* File length: 363008 bytes.

[ Changes to filesystem ]
* Creates file C:\CMD.DLL.
* Creates file C:\WPC..DLL.

[ Changes to registry ]
* Creates value "InternetEx"="c:\sample.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".

[ Network services ]
* Connects to "192.168.0.255" on port 7599 (IP).
* Sends data stream (256 bytes) to remote address "192.168.0.255", port 7599.

[ Process/window information ]
* Creates an event called .
* Will automatically restart after boot (I'll be back...).

[ Signature Scanning ]
* C:\CMD.DLL (11081 bytes) : Suspicious_F.gen.
VirusBuster Found nothing
VBA32 Found Embedded.Trojan.PWS.Lineage (probable variant)
鱼是一只我
发表于 2007-2-8 18:06:20 | 显示全部楼层
驱逐舰过了
yzt1004
发表于 2007-2-8 18:55:58 | 显示全部楼层
AVG再过~~
jimmyleo
发表于 2007-2-8 19:30:35 | 显示全部楼层
--> cmd.exe
      [DETECTION] Contains signature of the dropper DR/Spy.Pcapbased.A

老周 最新红伞[已知]报
daps
发表于 2007-2-9 02:11:16 | 显示全部楼层
pcc报了
mofunzone
发表于 2007-2-9 07:20:02 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\0208.zip'
C:\Documents and Settings\Administrator\My Documents\
  0208.zip
    [0] Archive type: ZIP
    --> cmd.exe
        [DETECTION] Contains signature of the dropper DR/Spy.Pcapbased.A
        [WARNING]   Infected files in archives cannot be repaired!
        [INFO]      The file was deleted!
znzm52
发表于 2007-2-9 09:08:32 | 显示全部楼层
Antivirus Version Update Result
AntiVir 7.3.1.34 02.08.2007 DR/Spy.Pcapbased.A
Authentium 4.93.8 02.08.2007  no virus found
Avast 4.7.936.0 02.08.2007  no virus found
AVG 386 02.08.2007  no virus found
BitDefender 7.2 02.09.2007 Dropped:Trojan.Spy.Pcapbased.A
CAT-QuickHeal 9.00 02.08.2007 (Suspicious) - DNAScan
ClamAV devel-20060426 02.09.2007  no virus found
DrWeb 4.33 02.08.2007  no virus found
eSafe 7.0.14.0 02.08.2007 suspicious Trojan/Worm
eTrust-InoculateIT 30.4.3378 02.08.2007  no virus found
eTrust-Vet 30.4.3378 02.08.2007  no virus found
Ewido 4.0 02.08.2007  no virus found
Fortinet 2.85.0.0 02.08.2007 W32/Generic!tr
F-Prot 4.2.1.29 02.08.2007  no virus found
F-Secure 6.70.13030.0 02.09.2007 Suspicious_F.gen.dropper
Ikarus T3.1.0.31 02.08.2007 Trojan.Spy.Pcapbased.A
Kaspersky 4.0.2.24 02.09.2007  no virus found
McAfee 4959 02.08.2007  no virus found
Microsoft 1.2101 02.08.2007  no virus found
NOD32v2 2047 02.09.2007  no virus found
Norman 5.80.02 02.08.2007 W32/Suspicious_F.gen.dropper
Panda 9.0.0.4 02.08.2007  no virus found
Prevx1 V2 02.09.2007 Trojan.IPV6Mon
Sophos 4.13.0 02.08.2007 Mal/Packer
Sunbelt 2.2.907.0 02.02.2007  no virus found
Symantec 10 02.09.2007  no virus found
TheHacker 6.1.6.053 02.07.2007  no virus found
UNA 1.83 02.08.2007  no virus found
VBA32 3.11.2 02.08.2007 MalwareScope.Backdoor.Hupigon.29
VirusBuster 4.3.19:9 02.08.2007 no virus found
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-27 07:53 , Processed in 0.131129 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表