楼主: killloop
收起左侧

[病毒样本] 1

[复制链接]
killloop
 楼主| 发表于 2009-8-1 17:34:06 | 显示全部楼层
文件名称 : 2.exe
文件大小 :  18944 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  a775acfdcbdfbb829247f4456463d203
SHA1 :  e71fab2861868f0d5ed62c0610f6ff701c08b6bb
扫描结果
扫描结果 :  30%的杀软(11/37)报告发现病毒
时间 :  2009/08/01 17:26:10 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Trojan-Dropper.Win32.Nemqe!IK
0.346
AntiVir8.2.0.2387.1.5.572009-07-31TR/Crypt.ULPM.Gen
0.170
Arcavir20092009073118112009-07-31Trojan.Gamethief.Onlinegames.Vgnq
0.074
Authentium5.1.12009073117072009-07-31-
1.289
AVAST!4.7.4090731-02009-07-31-
0.016
AVG8.5.288270.13.38/22742009-07-31-
0.354
BitDefender7.81008.38703987.269312009-08-01Gen:Trojan.Heur.bmW@!dM7Uiab
3.433
CA (VET)9.0.0.14331.6.6649 2009-08-01-
5.702
ClamAV0.95.296402009-08-01-
0.529
Comodo3.1018332009-08-01-
0.829
CP Secure1.1.0.7152009.08.012009-08-01-
11.537
Dr.Web4.44.0.91702009.08.012009-08-01-
4.965
F-Prot4.4.4.56200907312009-07-31-
1.244
F-Secure7.02.738072009.07.29.102009-07-29-
0.081
GData19.6801/19.421200908012009-08-01-
4.663
IkarusT3.1.01.642009.07.31.731372009-07-31Trojan-Dropper.Win32.Nemqe
4.049
Microsoft1.49032009.08.012009-08-01TrojanDropper:Win32/Nemqe.B
5.123
Norman6.01.096.01.002009-07-31-
4.006
nProtect20090731.0149870302009-07-31-
8.099
Quick Heal10.002009.07.302009-07-30-
1.801
Sophos2.89.14.442009-08-01Mal/HckPk-E
2.816
Sunbelt530153012009-07-30-
1.196
The Hacker6.3.4.3v003752009-07-31-
0.697
VBA323.12.10.920090731.14432009-07-31-
2.555
ViRobot200907302009.07.302009-07-30-
0.427
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
3.131
卡巴斯基5.5.102009.08.012009-08-01-
0.058
安博士V32009.07.31.042009.07.312009-07-31Win32/NSAnti.suspicious
0.836
安天2.0.1820090801.26645222009-08-01-
0.125
江民杀毒11.0.8002009.08.012009-08-01-
12.603
熊猫卫士9.05.012009.07.312009-07-31-
2.544
瑞星20.021.40.44.002009-07-31Dropper.Win32.Mnless.GEN [Suspicious]
1.491
赛门铁克1.3.0.2420090731.0042009-07-31Suspicious.MH690
0.051
趋势科技8.700-10046.336.192009-07-31-
0.043
迈克菲5.3.0056942009-07-31New Malware.bl
3.261
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.519
飞塔2.81-3.12010.6672009-08-01-
0.337








































































文件名称 :  1.exe
文件大小 :  571967 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  582daf403e45b1dbcaec41b2af7025d7
SHA1 :  0b89c312ffaa249486f880eaedc946505e0b4b5d

扫描结果
扫描结果 :  62%的杀软(23/37)报告发现病毒
时间 :  2009/08/01 17:21:33 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Virus.Win32.Agent.COH!IK
0.385
AntiVir8.2.0.2387.1.5.572009-07-31TR/Dropper.Gen
0.175
Arcavir20092009073118112009-07-31Trojan.Muldrop
0.047
Authentium5.1.12009073117072009-07-31W32/Nuj.A.gen!Eldorado (Possible)
1.156
AVAST!4.7.4090731-02009-07-31Win32:Trojan-gen {Other}
0.024
AVG8.5.288270.13.38/22742009-07-31SHeur.CMDD
0.304
BitDefender7.81008.38703987.269312009-08-01-
3.613
CA (VET)9.0.0.14331.6.6649 2009-08-01Win32/SillyAutorun.ALB worm.
5.258
ClamAV0.95.296402009-08-01Trojan.Agent-64034
0.089
Comodo3.1018332009-08-01TrojWare.Win32.TrojanDropper.VB.~AAAG
0.816
CP Secure1.1.0.7152009.08.012009-08-01Troj.Spy.W32.Agent.pn
12.666
Dr.Web4.44.0.91702009.08.012009-08-01Trojan.MulDrop.33005
4.970
F-Prot4.4.4.56200907312009-07-31W32/Nuj.A.gen!Eldorado (generic, not disinfectable)
1.144
F-Secure7.02.738072009.07.29.102009-07-29-
0.134
GData19.6801/19.421200908012009-08-01Win32:Trojan-gen {Other} [Engine:B]
5.599
IkarusT3.1.01.642009.07.31.731372009-07-31Virus.Win32.Agent.COH
4.580
Microsoft1.49032009.08.012009-08-01-
6.439
Norman6.01.096.01.002009-07-31W32/Smalldoor.EVMY
4.005
nProtect20090731.0149870302009-07-31Trojan/W32.Agent.571967
8.116
Quick Heal10.002009.07.302009-07-30-
1.275
Sophos2.89.14.442009-08-01Mal/Generic-A
2.773
Sunbelt530153012009-07-30Bulk Trojan
1.065
The Hacker6.3.4.3v003752009-07-31-
1.057
VBA323.12.10.920090731.14432009-07-31Trojan.Win32.Agent.bfnb
2.120
ViRobot200907302009.07.302009-07-30-
0.660
VirusBuster4.5.11.1010.110.1/18252172009-07-31Worm.Autorun.KKZ
2.231
卡巴斯基5.5.102009.08.012009-08-01-
0.206
安博士V32009.07.31.042009.07.312009-07-31Win-Trojan/Xema.variant
0.888
安天2.0.1820090801.26645222009-08-01-
0.171
江民杀毒11.0.8002009.08.012009-08-01-
9.538
熊猫卫士9.05.012009.07.312009-07-31-
3.581
瑞星20.021.40.44.002009-07-31-
1.068
赛门铁克1.3.0.2420090731.0042009-07-31-
0.626
趋势科技8.700-10046.336.192009-07-31-
0.040
迈克菲5.3.0056942009-07-31BackDoor-DRV.gen.c
2.991
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.603
飞塔2.81-3.12010.6672009-08-01PossibleThreat
0.169






















































































2个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 17:47:19 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2009-8-1 17:48:43 | 显示全部楼层
Hello,

1.exe1 - Trojan-Dropper.Win32.Agent.aysg,
1.exe_ - Trojan-Dropper.Win32.Agent.aysd,
2.dll - Trojan-Dropper.Win32.Agent.ayse,
taobao.exe_ - Trojan.BAT.Qhost.fj

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.
sam.to
发表于 2009-8-1 17:49:28 | 显示全部楼层
17,19,20,21,22 to kl,ll

[ 本帖最后由 sam.to 于 2009-8-1 17:50 编辑 ]
killloop
 楼主| 发表于 2009-8-1 17:54:38 | 显示全部楼层
扫描结果 :  14%的杀软(5/37)报告发现病毒
时间 :  2009/08/01 17:49:19 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31-
0.349
AntiVir8.2.0.2387.1.5.572009-07-31TR/Crypt.ULPM.Gen
0.076
Arcavir20092009073118112009-07-31-
0.092
Authentium5.1.12009073117072009-07-31-
1.167
AVAST!4.7.4090731-02009-07-31-
0.012
AVG8.5.288270.13.38/22742009-07-31-
0.408
BitDefender7.81008.38703987.269312009-08-01-
3.379
CA (VET)9.0.0.14331.6.6649 2009-08-01-
5.574
ClamAV0.95.296402009-08-01-
0.038
Comodo3.1018332009-08-01-
0.757
CP Secure1.1.0.7152009.08.012009-08-01-
11.553
Dr.Web4.44.0.91702009.08.012009-08-01-
5.002
F-Prot4.4.4.56200907312009-07-31-
1.166
F-Secure7.02.738072009.07.29.102009-07-29-
0.083
GData19.6801/19.421200908012009-08-01-
4.775
IkarusT3.1.01.642009.07.31.731372009-07-31-
4.093
Microsoft1.49032009.08.012009-08-01-
5.529
Norman6.01.096.01.002009-07-31-
4.009
nProtect20090731.0149870302009-07-31-
7.394
Quick Heal10.002009.07.302009-07-30-
1.054
Sophos2.89.14.442009-08-01Mal/HckPk-A
2.740
Sunbelt530153012009-07-30-
1.180
The Hacker6.3.4.3v003752009-07-31-
0.710
VBA323.12.10.920090731.14432009-07-31Malware-Cryptor.Win32.General.4 (suspicious)
1.956
ViRobot200907302009.07.302009-07-30-
0.410
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
2.226
卡巴斯基5.5.102009.08.012009-08-01-
0.060
安博士V32009.08.01.002009.08.012009-08-01-
0.744
安天2.0.1820090801.26645222009-08-01-
0.118
江民杀毒11.0.8002009.08.012009-08-01-
4.073
熊猫卫士9.05.012009.07.312009-07-31Suspicious file
1.844
瑞星20.021.40.44.002009-07-31-
0.803
赛门铁克1.3.0.2420090731.0042009-07-31-
0.052
趋势科技8.700-10046.336.192009-07-31-
0.051
迈克菲5.3.0056942009-07-31New Malware.bl
3.078
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.496
飞塔2.81-3.12010.6672009-08-01-
0.221

2009-07-31 Found nothing
2009-08-01 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-07-31 Win32/Kryptik.AAU
2009-07-31 TR/Crypt.ULPM.Gen
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-08-01 Mal/HckPk-A
2009-08-01 Found nothing
2009-07-31 Malware-Cryptor.Win32.General.4
2009-07-31 Found nothing
2009-07-31 Found nothing


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 18:06:49 | 显示全部楼层
MD5相同,有人扫过.

文件名称 :  456.exe
文件大小 :  44818 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  8635cf0752fbb2da00b2b6c8463ee61e
SHA1 :  7b997d72c3cd42114668ef0a47e580322933a867
扫描结果
扫描结果 :  54%的杀软(20/37)报告发现病毒
时间 :  2009/08/01 18:02:37 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Virus.Win32.Agent.WOW!IK
0.417
AntiVir8.2.0.2387.1.5.572009-07-31TR/Dropper.Gen
0.324
Arcavir20092009073118112009-07-31-
0.042
Authentium5.1.12009073117072009-07-31W32/Heuristic-400!Eldorado (Heuristic)
3.384
AVAST!4.7.4090731-02009-07-31-
0.018
AVG8.5.288270.13.38/22742009-07-31Win32/Cryptor
0.648
BitDefender7.81008.38703987.269312009-08-01BehavesLike:Trojan.ShellHook
4.017
CA (VET)9.0.0.14331.6.6649 2009-08-01-
5.689
ClamAV0.95.296402009-08-01-
0.014
Comodo3.1018342009-08-01TrojWare.Win32.Magania.~D
4.710
CP Secure1.1.0.7152009.08.012009-08-01-
11.745
Dr.Web4.44.0.91702009.08.012009-08-01-
4.975
F-Prot4.4.4.56200907312009-07-31Possible W32/Heuristic-400!Eldorado (not disinfectable)
3.130
F-Secure7.02.738072009.07.29.102009-07-29-
0.377
GData19.6801/19.421200908012009-08-01-
3.884
IkarusT3.1.01.642009.07.31.731372009-07-31Virus.Win32.Agent.WOW
4.047
Microsoft1.49032009.08.012009-08-01PWS:Win32/Frethog.AF
7.513
Norman6.01.096.01.002009-07-31Dialer.dam
4.006
nProtect20090731.0149870302009-07-31Trojan/W32.ShellHook.44818
6.049
Quick Heal10.002009.07.302009-07-30Suspicious - DNAScan
1.045
Sophos2.89.14.442009-08-01Mal/Generic-A
2.735
Sunbelt530153012009-07-30Trojan.ShellHook
1.267
The Hacker6.3.4.3v003752009-07-31-
0.704
VBA323.12.10.920090731.14432009-07-31Malware-Dropper.Win32.Inject.gen
1.926
ViRobot200907302009.07.302009-07-30-
0.441
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
2.212
卡巴斯基5.5.102009.08.012009-08-01-
0.200
安博士V32009.08.01.002009.08.012009-08-01-
1.379
安天2.0.1820090801.26645222009-08-01-
0.120
江民杀毒11.0.8002009.08.012009-08-01-
4.668
熊猫卫士9.05.012009.07.312009-07-31-
2.208
瑞星20.021.40.44.002009-07-31Trojan.Spy.Win32.Agent.fcm
0.589
赛门铁克1.3.0.2420090731.0042009-07-31Suspicious.MH690
0.504
趋势科技8.700-10046.336.192009-07-31-
0.043
迈克菲5.3.0056942009-07-31Generic PWS.y!gx
3.006
金山毒霸2009.2.5.152009.7.31.182009-07-31Win32.Troj.OnLineG.44818
0.476
飞塔2.81-3.12010.6672009-08-01PossibleThreat
0.183









































































本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 18:12:41 | 显示全部楼层
VT上有扫过,卡巴不报.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 18:17:08 | 显示全部楼层
2009/06/17   有人扫过.

重新扫描  可疑代码









文件名称 :  1.exe
文件大小 :  663552 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  4dda92b5e9e8fe9ad126c530035b8b99
SHA1 :  adcfce7d341fa4681040e2777cb52c3744189db3

扫描结果
扫描结果 :  5%的杀软(2/37)报告发现病毒
时间 :  2009/08/01 18:15:26 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Virus.Win32.Beagle.ABW!IK
0.441
AntiVir8.2.0.2387.1.5.572009-07-31-
0.272
Arcavir20092009073118112009-07-31-
0.091
Authentium5.1.12009073117072009-07-31-
1.785
AVAST!4.7.4090731-02009-07-31-
0.088
AVG8.5.288270.13.38/22742009-07-31-
1.629
BitDefender7.81008.38703987.269312009-08-01-
3.594
CA (VET)9.0.0.14331.6.6649 2009-08-01-
9.240
ClamAV0.95.296402009-08-01-
0.117
Comodo3.1018342009-08-01-
2.363
CP Secure1.1.0.7152009.08.012009-08-01-
11.715
Dr.Web4.44.0.91702009.08.012009-08-01-
5.063
F-Prot4.4.4.56200907312009-07-31-
1.628
F-Secure7.02.738072009.07.29.102009-07-29-
0.164
GData19.6801/19.421200908012009-08-01-
6.417
IkarusT3.1.01.642009.07.31.731372009-07-31Virus.Win32.Beagle.ABW
4.059
Microsoft1.49032009.08.012009-08-01-
7.658
Norman6.01.096.01.002009-07-31-
4.010
nProtect20090731.0149870302009-07-31-
6.761
Quick Heal10.002009.07.302009-07-30-
1.248
Sophos2.89.14.442009-08-01-
2.769
Sunbelt530153012009-07-30-
1.113
The Hacker6.3.4.3v003752009-07-31-
1.500
VBA323.12.10.920090731.14432009-07-31-
2.084
ViRobot200907302009.07.302009-07-30-
0.424
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
2.496
卡巴斯基5.5.102009.08.012009-08-01-
0.106
安博士V32009.08.01.002009.08.012009-08-01-
0.949
安天2.0.1820090801.26645222009-08-01-
0.121
江民杀毒11.0.8002009.08.012009-08-01-
8.273
熊猫卫士9.05.012009.07.312009-07-31-
2.245
瑞星20.021.40.44.002009-07-31-
1.052
赛门铁克1.3.0.2420090731.0042009-07-31-
0.342
趋势科技8.700-10046.336.192009-07-31-
0.056
迈克菲5.3.0056942009-07-31-
3.750
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.571
飞塔2.81-3.12010.6672009-08-01-
0.364


[ 本帖最后由 killloop 于 2009-8-1 18:20 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2009-8-1 18:29:32 | 显示全部楼层
25-28 to kl,ll
killloop
 楼主| 发表于 2009-8-1 18:37:05 | 显示全部楼层
带数字签名




文件名称 :  1.exe
文件大小 :  26450 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  227ba68a3f7e00ca481894f3945f949d
SHA1 :  da088257a1358f647772b761e26722c138630dcd
扫描结果
扫描结果 :  46%的杀软(17/37)报告发现病毒
时间 :  2009/08/01 18:32:42 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Virus.Win32.Dogrobot!IK
0.491
AntiVir8.2.0.2387.1.5.572009-07-31TR/Dldr.Agent.xsd
0.388
Arcavir20092009073118112009-07-31-
0.042
Authentium5.1.12009073117072009-07-31-
1.185
AVAST!4.7.4090731-02009-07-31Win32:Dogrobot [Drp]
0.003
AVG8.5.288270.13.38/22742009-07-31PSW.OnlineGames3.JFR
0.303
BitDefender7.81008.38703987.269312009-08-01Trojan.Generic.1564508
3.380
CA (VET)9.0.0.14331.6.6649 2009-08-01-
7.093
ClamAV0.95.296402009-08-01-
0.010
Comodo3.1018342009-08-01-
0.793
CP Secure1.1.0.7152009.08.012009-08-01-
11.596
Dr.Web4.44.0.91702009.08.012009-08-01Trojan.PWS.Wsgame.12378
4.967
F-Prot4.4.4.56200907312009-07-31-
1.157
F-Secure7.02.738072009.07.29.102009-07-29-
0.081
GData19.6802/19.421200908012009-08-01Win32:Dogrobot [Drp] [Engine:B]
5.053
IkarusT3.1.01.642009.07.31.731372009-07-31Virus.Win32.Dogrobot
4.047
Microsoft1.49032009.08.012009-08-01PWS:Win32/Lolyda.AH
5.713
Norman6.01.096.01.002009-07-31-
4.008
nProtect20090731.0149870302009-07-31-
6.906
Quick Heal10.002009.07.302009-07-30Suspicious - DNAScan
1.583
Sophos2.89.14.442009-08-01-
2.741
Sunbelt530153012009-07-30Trojan.1
1.036
The Hacker6.3.4.3v003752009-07-31-
0.684
VBA323.12.10.920090731.14432009-07-31-
1.818
ViRobot200907302009.07.302009-07-30-
0.506
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
2.187
卡巴斯基5.5.102009.08.012009-08-01-
0.053
安博士V32009.08.01.002009.08.012009-08-01-
0.896
安天2.0.1820090801.26645222009-08-01Trojan/Win32.OnLineGames.vgor[GameThief]
0.119
江民杀毒11.0.8002009.08.012009-08-01Trojan/PSW.OnLineGames.axcf
3.370
熊猫卫士9.05.012009.07.312009-07-31Suspicious file
2.571
瑞星20.021.40.44.002009-07-31Packer.Win32.Agent.aq [Suspicious]
1.244
赛门铁克1.3.0.2420090731.0042009-07-31Infostealer.Onlinegame
0.095
趋势科技8.700-10046.336.192009-07-31-
0.043
迈克菲5.3.0056942009-07-31-
3.079
金山毒霸2009.2.5.152009.7.31.182009-07-31Win32.Troj.Agent.bn.26450
0.556
飞塔2.81-3.12010.6672009-08-01-
0.217













































































2009-07-31 Found nothing
2009-08-01 Trojan.Generic.1564508
2009-08-01 Virus.Win32.Dogrobot!IK
2009-07-31 Virus.Win32.Dogrobot
2009-07-31 Win32:Dogrobot
2009-08-01 Found nothing
2009-07-31 PSW.OnlineGames3.JFR
2009-07-31 Found nothing
2009-07-31 TR/Dldr.Agent.xsd
2009-07-31 Found nothing
2009-08-01 Trojan.Generic.1564508
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-08-01 Found nothing
2009-08-01 Trojan.PWS.Wsgame.12378
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing




本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-17 21:34 , Processed in 0.119219 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表