查看: 4016|回复: 16
收起左侧

[病毒样本] 1 20090711

[复制链接]
killloop
发表于 2009-7-11 13:31:03 | 显示全部楼层 |阅读模式
扫描结果 :  21%的杀软(8/38)报告发现病毒
时间 :  2009/07/11 13:23:21 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.1200907110531382009-07-11Trojan-Downloader.Win32.Perkesh!IK
0.415
AntiVir8.2.0.2047.1.4.2192009-07-10TR/Rootkit.Gen
0.289
Arcavir20092009071015092009-07-10-
0.037
Authentium5.1.12009071016472009-07-10-
1.179
AVAST!4.7.4090710-02009-07-10-
0.005
AVG8.5.288270.13.10/22302009-07-11Win32/Heur
0.324
BitDefender7.81008.36739237.265072009-07-11Dropped:Generic.Malware.PVPk!g.690F9527
3.223
CA (VET)9.0.0.14331.6.6607 2009-07-10-
7.630
ClamAV0.95.295522009-07-10-
0.011
Comodo3.1016122009-07-11-
0.723
CP Secure1.1.0.7152009.07.082009-07-08-
11.012
Dr.Web4.44.0.91702009.07.112009-07-11-
4.862
F-Prot4.4.4.56200907102009-07-10-
1.161
F-Secure5.51.61002009.07.10.112009-07-10-
0.075
GData19.6384/19.392200907112009-07-11-
4.313
IkarusT3.1.01.642009.07.11.730142009-07-11Trojan-Downloader.Win32.Perkesh
3.095
Microsoft1.48032009.07.112009-07-11TrojanDownloader:Win32/Perkesh.gen!A
5.061
mks_vir2.012009.07.112009-07-11-
3.205
Norman6.01.096.01.002009-07-09-
4.008
nProtect20090711.0146983502009-07-11-
6.140
Quick Heal10.002009.07.102009-07-10-
1.014
Sophos2.88.04.432009-07-11-
2.806
Sunbelt524352432009-07-10-
1.003
The Hacker6.3.4.3v003652009-07-10-
0.659
VBA323.12.10.820090710.15212009-07-10-
2.051
ViRobot200907102009.07.102009-07-10-
0.410
VirusBuster4.5.11.1010.108.3/18535122009-07-10-
2.255
卡巴斯基5.5.102009.07.112009-07-11-
0.061
安博士V32009.07.10.012009.07.102009-07-10-
0.938
安天2.0.1820090711.26123612009-07-11-
0.120
江民杀毒11.0.8002009.07.092009-07-09-
3.880
熊猫卫士9.05.012009.07.102009-07-10Trj/Downloader.MDW  
1.981
瑞星20.021.37.44.002009-07-10-
0.786
赛门铁克1.3.0.2420090710.0032009-07-10Trojan.Dropper
0.046
趋势科技8.700-10046.266.082009-07-10-
0.027
迈克菲5.3.0056722009-07-10-
2.948
金山毒霸2009.2.5.152009.7.10.212009-07-10-
0.465
飞塔2.81-3.12010.5932009-07-10-
0.204


2009-07-10 Found nothing
2009-07-11 Dropped:Generic.Malware.PVPk!g.690F9527
2009-07-11 Trojan-Downloader.Win32.Perkesh!IK
2009-07-11 Trojan-Downloader.Win32.Perkesh
2009-07-10 Found nothing
2009-07-11 Found nothing
2009-07-10 Win32/Heur
2009-07-11 Found nothing
2009-07-10 TR/Rootkit.Gen
2009-07-10 Found nothing
2009-07-11 Dropped:Generic.Malware.PVPk!g.690F9527
2009-07-10 Trj/Downloader.MDW
2009-07-10 Found nothing
2009-07-10 Found nothing
2009-07-09 Found nothing
2009-07-11 Found nothing
2009-07-11 Found nothing
2009-07-10 Found nothing
2009-07-08 Found nothing
2009-07-10 Found nothing
2009-07-10 Found nothing



反病毒引擎版本最后更新扫描结果
a-squared4.5.0.182009.07.11Trojan-Downloader.Win32.Perkesh!IK
AhnLab-V35.0.0.22009.07.10-
AntiVir7.9.0.2042009.07.10TR/Rootkit.Gen
Antiy-AVL2.0.3.12009.07.10-
Authentium5.1.2.42009.07.10-
Avast4.8.1335.02009.07.10-
AVG8.5.0.3872009.07.10Win32/Heur
BitDefender7.22009.07.11Dropped:Generic.Malware.PVPk!g.690F9527
CAT-QuickHeal10.002009.07.10-
ClamAV0.94.12009.07.10-
Comodo16122009.07.11-
DrWeb5.0.0.121822009.07.11-
eSafe7.0.17.02009.07.09-
eTrust-Vet31.6.66082009.07.10-
F-Prot4.4.4.562009.07.10-
F-Secure8.0.14470.02009.07.10Suspicious:W32/Malware!Gemini
Fortinet3.120.0.02009.07.11-
GData192009.07.11Dropped:Generic.Malware.PVPk!g.690F9527
IkarusT3.1.1.64.02009.07.11Trojan-Downloader.Win32.Perkesh
Jiangmin11.0.7062009.07.09-
K7AntiVirus7.10.7892009.07.10-
Kaspersky7.0.0.1252009.07.11Trojan.Win32.Agent.cprg
McAfee56722009.07.10-
McAfee+Artemis56722009.07.10-
McAfee-GW-Edition6.8.52009.07.10Heuristic.LooksLike.Win32.A
Microsoft1.48032009.07.11TrojanDownloader:Win32/Perkesh.gen!A
NOD3242332009.07.11-
Norman6.01.092009.07.10-
nProtect2009.1.8.02009.07.11-
Panda10.0.0.142009.07.10Trj/Downloader.MDW
PCTools4.4.2.02009.07.10-
Prevx3.02009.07.11-
Rising21.37.44.002009.07.10-
Sophos4.43.02009.07.11-
Sunbelt3.2.1858.22009.07.10Trojan-Downloader.Win32.Sfn!cobra (v)
Symantec1.4.4.122009.07.11Trojan.Dropper
TheHacker6.3.4.3.3652009.07.11-
TrendMicro8.950.0.10942009.07.10-
VBA323.12.10.82009.07.11-
ViRobot2009.7.11.18302009.07.11-
VirusBuster4.6.5.02009.07.10-


已报江民

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
allinwonderi
发表于 2009-7-11 13:33:54 | 显示全部楼层

回复 1楼 killloop 的帖子

[ General information ]
    * Accesses executable file from resource section.
    * Creating several executable files on hard-drive.
    * File length:        29392 bytes.
    * MD5 hash: ad8d78d47bdd3e3833bd9e875795417a.

[ Changes to filesystem ]
    * Creates file C:\WINDOWS\TEMP\935Fuck.dll.
    * Creates file C:\WINDOWS\SYSTEM32\Drivers\NsDnldr3.sys.
    * Creates file C:\WINDOWS\TEMP\55386503.bat.
    * Deletes file /f "C:\sample.exe".

[ Changes to registry ]
    * Creates key "HKLM\System\CurrentControlSet\Services\MY260".
    * Sets value "ImagePath"="C:\WINDOWS\SYSTEM32\Drivers\NsDnldr3.sys" in key "HKLM\System\CurrentControlSet\Services\MY260".
    * Sets value "DisplayName"="MY260" in key "HKLM\System\CurrentControlSet\Services\MY260".
    * Accesses Registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost".

[ Process/window information ]
    * Enumerates running processes.
    * Enumerates running processes several parses....
    * Attempts to access service "MY260".
    * Creates service "MY260 (MY260)" as "C:\WINDOWS\SYSTEM32\Drivers\NsDnldr3.sys".
    * Installing kernel driver "\Device\MY260".
    * Driver "\Device\MY260" hooks kernel IRP "CREATE".
    * Driver "\Device\MY260" hooks kernel IRP "CREATE_NAMED_PIPE".
    * Driver "\Device\MY260" hooks kernel IRP "CLOSE".
    * Driver "\Device\MY260" hooks kernel IRP "READ".
    * Driver "\Device\MY260" hooks kernel IRP "WRITE".
    * Driver "\Device\MY260" hooks kernel IRP "QUERY_INFORMATION".
    * Driver "\Device\MY260" hooks kernel IRP "SET_INFORMATION".
    * Driver "\Device\MY260" hooks kernel IRP "QUERY_EA".
    * Driver "\Device\MY260" hooks kernel IRP "SET_EA".
    * Driver "\Device\MY260" hooks kernel IRP "FLUSH_BUFFERS".
    * Driver "\Device\MY260" hooks kernel IRP "QUERY_VOLUME_INFORMATION".
    * Driver "\Device\MY260" hooks kernel IRP "SET_VOLUME_INFORMATION".
    * Driver "\Device\MY260" hooks kernel IRP "DIRECTORY_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "FILE_SYSTEM_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "DEVICE_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "INTERNAL_DEVICE_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "SHUTDOWN".
    * Driver "\Device\MY260" hooks kernel IRP "LOCK_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "CLEANUP".
    * Driver "\Device\MY260" hooks kernel IRP "CREATE_MAILSLOT".
    * Driver "\Device\MY260" hooks kernel IRP "QUERY_SECURITY".
    * Driver "\Device\MY260" hooks kernel IRP "SET_SECURITY".
    * Driver "\Device\MY260" hooks kernel IRP "POWER".
    * Driver "\Device\MY260" hooks kernel IRP "SYSTEM_CONTROL".
    * Driver "\Device\MY260" hooks kernel IRP "DEVICE_CHANGE".
    * Driver "\Device\MY260" hooks kernel IRP "QUERY_QUOTA".
    * Driver "\Device\MY260" hooks kernel IRP "SET_QUOTA".
    * Attemps to open C:\WINDOWS\TEMP\55386503.bat NULL.
    * Creates process "CMD.EXE".

[ Signature Scanning ]
    * C:\WINDOWS\TEMP\935Fuck.dll (25600 bytes) : no signature detection.
    * C:\WINDOWS\SYSTEM32\Drivers\NsDnldr3.sys (2192 bytes) : no signature detection.
    * C:\WINDOWS\TEMP\55386503.bat (61 bytes) : no signature detection.
sam.to
发表于 2009-7-11 13:36:31 | 显示全部楼层
to kl,ll
kingmuro
头像被屏蔽
发表于 2009-7-11 13:41:11 | 显示全部楼层
过卡巴6.0,看来卡巴的病毒数据不是同步更新啊,卡巴7.0可以杀
xyao
发表于 2009-7-11 13:46:49 | 显示全部楼层
TF

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kingmuro
头像被屏蔽
发表于 2009-7-11 13:48:32 | 显示全部楼层
过大蜘蛛
悠柚
发表于 2009-7-11 13:51:39 | 显示全部楼层
D:\TDDownload\1.rar/1.exe         已检测: Trojan-Downloader.Win32.Perkesh!IK
angir
发表于 2009-7-11 13:57:39 | 显示全部楼层
奇怪,卡巴10竟然被过了
To KL
kkgh
发表于 2009-7-11 14:07:49 | 显示全部楼层
瑞星  Trojan.Win32.Generic.11EA5387
dreams521
发表于 2009-7-11 14:12:14 | 显示全部楼层
to mpav
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-1-8 11:14 , Processed in 0.084128 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表