楼主: killloop
收起左侧

[病毒样本] 1

[复制链接]
killloop
 楼主| 发表于 2009-8-1 18:43:35 | 显示全部楼层
过卡巴  



2009-07-31 Trojan.Gamethief.Magania.Bful
2009-08-01 Gen:Trojan.Heur.bmY@Kqi65jc
2009-08-01 Trojan-PWS.Win32.LdPinch!IK
2009-07-31 Trojan-PWS.Win32.LdPinch
2009-07-31 Win32:Agent-ACMH
2009-08-01 Found nothing
2009-07-31 PSW.OnlineGames.2.AJ
2009-07-31 Win32/Kryptik.AAU
2009-07-31 TR/Crypt.ULPM.Gen
2009-07-31 Found nothing
2009-08-01 Gen:Trojan.Heur.bmY@Kqi65jc
2009-07-31 Found nothing
2009-08-01 Trojan.Crypt-215
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-08-01 Mal/EncPk-F
2009-08-01 Trojan.Packed.191
2009-07-31 Malware-Cryptor.Win32.General.4
2009-07-31 Found nothing
2009-07-31 Trojan.DR.OnlineGames.Gen.118
2009-07-31 Found nothing




文件名称 :  1.exe
文件大小 :  24592 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  9577bbde2c4a5f65fbc43cc685f0f340
SHA1 :  801100d1ea2e0ff211cd8d2c61082c1548b1d372

扫描结果
扫描结果 :  49%的杀软(18/37)报告发现病毒
时间 :  2009/08/01 18:39:37 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31Trojan-PWS.Win32.LdPinch!IK
0.329
AntiVir8.2.0.2387.1.5.572009-07-31TR/Crypt.ULPM.Gen
0.460
Arcavir20092009073118112009-07-31Trojan.Gamethief.Magania.Bful
0.068
Authentium5.1.12009073117072009-07-31-
1.159
AVAST!4.7.4090731-02009-07-31Win32:Agent-ACMH [Drp]
0.012
AVG8.5.288270.13.38/22742009-07-31PSW.OnlineGames.2.AJ
0.313
BitDefender7.81008.38703987.269312009-08-01Gen:Trojan.Heur.bmY@Kqi65jc
3.386
CA (VET)9.0.0.14331.6.6649 2009-08-01-
8.012
ClamAV0.95.296402009-08-01Trojan.Crypt-215
0.017
Comodo3.1018342009-08-01-
0.745
CP Secure1.1.0.7152009.08.012009-08-01-
11.513
Dr.Web4.44.0.91702009.08.012009-08-01-
4.959
F-Prot4.4.4.56200907312009-07-31-
1.195
F-Secure7.02.738072009.07.29.102009-07-29-
0.083
GData19.6802/19.421200908012009-08-01Win32:Agent-ACMH [Drp] [Engine:B]
4.699
IkarusT3.1.01.642009.07.31.731372009-07-31Trojan-PWS.Win32.LdPinch
4.169
Microsoft1.49032009.08.012009-08-01-
5.472
Norman6.01.096.01.002009-07-31-
4.007
nProtect20090731.0149870302009-07-31-
6.632
Quick Heal10.002009.07.302009-07-30-
1.103
Sophos2.89.14.442009-08-01Mal/EncPk-F
3.024
Sunbelt530153012009-07-30Trojan.Win32.Magania.gen (v)
1.389
The Hacker6.3.4.3v003752009-07-31-
0.800
VBA323.12.10.920090731.14432009-07-31Malware-Cryptor.Win32.General.4 (suspicious)
1.842
ViRobot200907302009.07.302009-07-30-
0.426
VirusBuster4.5.11.1010.110.1/18252172009-07-31Trojan.DR.OnlineGames.Gen.118
2.834
卡巴斯基5.5.102009.08.012009-08-01-
0.070
安博士V32009.08.01.002009.08.012009-08-01Win32/NSAnti.suspicious
1.096
安天2.0.1820090801.26645222009-08-01-
0.120
江民杀毒11.0.8002009.08.012009-08-01-
3.451
熊猫卫士9.05.012009.07.312009-07-31-
5.058
瑞星20.021.40.44.002009-07-31Trojan.Spy.Win32.Agent.fcn
0.247
赛门铁克1.3.0.2420090731.0042009-07-31Infostealer.Gampass
0.069
趋势科技8.700-10046.336.192009-07-31Possible_Movly-1
0.033
迈克菲5.3.0056942009-07-31Generic Dropper.eb
2.999
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.673
飞塔2.81-3.12010.6672009-08-01-
0.237

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 18:54:30 | 显示全部楼层
卡巴斯基  SuspiciousPacker.Multi.Generic




文件名称 :  1.zip
文件大小 :  463687 byte
文件类型 :  Zip archive data, at least v2.0 to extract
MD5 :  f6219b65874df218fd7ee441ad048434
SHA1 :  813cdf8c56dbe88082907e534b55209944c59c19

扫描结果
扫描结果 :  16%的杀软(6/37)报告发现病毒
时间 :  2009/08/01 18:47:26 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31-
0.641
AntiVir8.2.0.2387.1.5.572009-07-31-
0.720
Arcavir20092009073118112009-07-31W32.Junkcomp
0.192
Authentium5.1.12009073117072009-07-31-
5.537
AVAST!4.7.4090731-02009-07-31Win32:JunkPoly [Cryp]
0.026
AVG8.5.288270.13.38/22742009-07-31-
1.166
BitDefender7.81008.38703987.269312009-08-01-
3.526
CA (VET)9.0.0.14331.6.6649 2009-08-01-
5.668
ClamAV0.95.296402009-08-01-
0.432
Comodo3.1018342009-08-01-
3.902
CP Secure1.1.0.7152009.08.012009-08-01-
11.929
Dr.Web4.44.0.91702009.08.012009-08-01-
5.362
F-Prot4.4.4.56200907312009-07-31-
5.532
F-Secure7.02.738072009.07.29.102009-07-29-
1.492
GData19.6802/19.421200908012009-08-01Win32:JunkPoly [Cryp] [Engine:B]
4.460
IkarusT3.1.01.642009.07.31.731372009-07-31-
4.719
Microsoft1.49032009.08.012009-08-01-
5.578
Norman6.01.096.01.002009-07-31-
4.007
nProtect20090731.0149870302009-07-31-
7.972
Quick Heal10.002009.07.302009-07-30-
1.220
Sophos2.89.14.442009-08-01Mal/HckPk-D
2.819
Sunbelt530153012009-07-30-
1.930
The Hacker6.3.4.3v003752009-07-31-
0.826
VBA323.12.10.920090731.14432009-07-31-
2.129
ViRobot200907302009.07.302009-07-30-
0.428
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
3.322
卡巴斯基5.5.102009.08.012009-08-01-
0.621
安博士V32009.08.01.002009.08.012009-08-01-
1.067
安天2.0.1820090801.26645222009-08-01-
0.119
江民杀毒11.0.8002009.08.012009-08-01Trojan/PSW.QQPianzi.b.Config
3.444
熊猫卫士9.05.012009.07.312009-07-31Malicious Packer   
1.972
瑞星20.021.40.44.002009-07-31-
1.360
赛门铁克1.3.0.2420090731.0042009-07-31-
0.074
趋势科技8.700-10046.336.192009-07-31-
0.088
迈克菲5.3.0056942009-07-31-
3.955
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.630
飞塔2.81-3.12010.6672009-08-01-
0.514



















































































2009-07-31 W32.Junkcomp
2009-08-01 Found nothing
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-07-31 Win32:JunkPoly
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-07-31 Malicious
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-08-01 Found nothing
2009-08-01 Mal/HckPk-D
2009-08-01 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing
2009-07-31 Found nothing

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
killloop
 楼主| 发表于 2009-8-1 18:54:56 | 显示全部楼层
收工
sam.to
发表于 2009-8-1 20:05:15 | 显示全部楼层
29-32 to kl,ll

thanks for share
sam.to
发表于 2009-8-1 20:25:46 | 显示全部楼层
Hello,


1.exe1, jsy.dat, Jsy.exe_

No malicious code were found in these files.

1.exe_ - Trojan.Win32.Agent2.kzn,
456.exe_ - Trojan-GameThief.Win32.OnLineGames.vjcn

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

#25-#28


(我会跟进首3个文件)

[ 本帖最后由 sam.to 于 2009-8-1 20:33 编辑 ]
sam.to
发表于 2009-8-1 20:59:51 | 显示全部楼层
Hello,

New malicious software was found in the attached file. Its detection will be included in the next update.
Thank you for your help.


(29-32)
killloop
 楼主| 发表于 2009-8-1 21:28:21 | 显示全部楼层
文件名称 :  1.exe
文件大小 :  15360 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  ca60547e436d7220820e37177dfde5d2
SHA1 :  b9f7852ae2ac7c6d653cce57b545e091acd15c7f
扫描结果
扫描结果 :  19%的杀软(7/37)报告发现病毒
时间 :  2009/08/01 21:22:43 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared4.5.0.3200907311632452009-07-31-
0.322
AntiVir8.2.0.2387.1.5.572009-07-31TR/Dropper.Gen
0.070
Arcavir20092009080108512009-08-01-
0.060
Authentium5.1.12009073117072009-07-31-
1.186
AVAST!4.7.4090731-02009-07-31-
0.009
AVG8.5.288270.13.38/22742009-07-31-
0.336
BitDefender7.81008.38704367.269332009-08-01-
3.395
CA (VET)9.0.0.14331.6.6649 2009-08-01-
7.177
ClamAV0.95.296402009-08-01-
0.026
Comodo3.1018352009-08-01-
0.752
CP Secure1.1.0.7152009.08.012009-08-01-
11.570
Dr.Web4.44.0.91702009.08.012009-08-01-
5.083
F-Prot4.4.4.56200907312009-07-31-
1.161
F-Secure7.02.738072009.07.29.102009-07-29-
7.637
GData19.6804/19.421200908012009-08-01-
4.520
IkarusT3.1.01.642009.07.31.731372009-07-31-
4.150
Microsoft1.49032009.08.012009-08-01Trojan:Win32/Killav.DK
7.722
Norman6.01.096.01.002009-07-31-
4.005
nProtect20090731.0149870302009-07-31-
6.717
Quick Heal10.002009.07.302009-07-30-
1.104
Sophos2.89.14.442009-08-01Mal/Generic-A
2.835
Sunbelt530153012009-07-30-
1.158
The Hacker6.3.4.3v003752009-07-31-
0.667
VBA323.12.10.920090731.14432009-07-31Win32.Trojan.Downloader (http://...) (suspicious)
1.814
ViRobot200907302009.07.302009-07-30-
0.411
VirusBuster4.5.11.1010.110.1/18252172009-07-31-
2.202
卡巴斯基5.5.102009.08.012009-08-01-
0.055
安博士V32009.08.01.002009.08.012009-08-01-
0.772
安天2.0.1820090801.26645222009-08-01-
0.119
江民杀毒11.0.8002009.08.012009-08-01-
4.343
熊猫卫士9.05.012009.08.012009-08-01-
1.626
瑞星20.021.40.44.002009-07-31RootKit.Win32.Agent.GEN [Suspicious]
1.085
赛门铁克1.3.0.2420090731.0042009-07-31Trojan.Dropper
0.045
趋势科技8.700-10046.336.212009-08-01-
0.158
迈克菲5.3.0056942009-07-31Generic Malware.al!enc
3.081
金山毒霸2009.2.5.152009.7.31.182009-07-31-
0.543
飞塔2.81-3.12010.6672009-08-01-
0.216













































































本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-8-1 21:34:32 | 显示全部楼层
37# To KL
左手
发表于 2009-8-1 21:58:14 | 显示全部楼层
2009-08-01 21:57:13    创建文件      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\system32\sysyhzt9.dll
触发规则:所有程序规则->FD:01…系统文件读写规则->%SystemDrive%\*.dll


2009-08-01 21:57:42    创建文件      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\system32\pyhztS.dll
触发规则:所有程序规则->FD:01…系统文件读写规则->%SystemDrive%\*.dll


2009-08-01 21:57:42    运行应用程序      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\system32\verclsid.exe
命令行:/C {871C5380-42A0-1069-A2EA-08002B30309D} /I {000214E6-0000-0000-C000-000000000046} /X 0x401
触发规则:所有程序规则->AD:02…绝对禁运区->%windir%\system32\*


2009-08-01 21:57:42    修改注册表内容      操作:阻止
进程路径:E:\virus\1.exe
注册表路径:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
注册表名称:Cookies
触发规则:所有程序规则->RD:03…IE浏览器设置保护(黑名单)->*\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

======

2009-08-01 21:59:39    创建文件      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\system32\sysyhzt9.dll
触发规则:所有程序规则->FD-重要文件->*.dll

2009-08-01 22:00:20    创建文件      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\system32\pyhztS.dll
触发规则:所有程序规则->FD-重要文件->*.dll

2009-08-01 22:00:21    运行应用程序      操作:阻止
进程路径:E:\virus\1.exe
文件路径:C:\WINDOWS\explorer.exe
触发规则:应用程序规则->AD-全局->*->%windir%\*

[ 本帖最后由 左手 于 2009-8-1 22:01 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
发表于 2009-8-1 22:49:03 | 显示全部楼层
#37 to ll
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-17 21:34 , Processed in 0.101927 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表