查看: 4959|回复: 15
收起左侧

[病毒样本] 可疑样本:at.exe(2/41报毒,4.88%)

[复制链接]
quirk
发表于 2009-8-29 19:07:50 | 显示全部楼层 |阅读模式
C:\DOCUME~1\***\LOCALS~1\TEMP\AT.EXE

迅雷加载,瑞星主动防御提示,阻止。


反病毒引擎版本最后更新扫描结果
a-squared4.5.0.242009.08.29-
AhnLab-V35.0.0.22009.08.29-
AntiVir7.9.1.72009.08.28TR/Dropper.Gen
Antiy-AVL2.0.3.72009.08.24-
Authentium5.1.2.42009.08.29-
Avast4.8.1335.02009.08.28-
AVG8.5.0.4062009.08.29-
BitDefender7.22009.08.29-
CAT-QuickHeal10.002009.08.29-
ClamAV0.94.12009.08.29-
Comodo21242009.08.29-
DrWeb5.0.0.121822009.08.29-
eSafe7.0.17.02009.08.27-
eTrust-Vet31.6.67072009.08.28-
F-Prot4.5.1.852009.08.29-
F-Secure8.0.14470.02009.08.28-
Fortinet3.120.0.02009.08.29-
GData192009.08.29-
IkarusT3.1.1.68.02009.08.29-
Jiangmin11.0.8002009.08.29-
K7AntiVirus7.10.8302009.08.28-
Kaspersky7.0.0.1252009.08.29-
McAfee57232009.08.28-
McAfee+Artemis57232009.08.28-
McAfee-GW-Edition6.8.52009.08.29Trojan.Dropper.Gen
Microsoft1.50052009.08.29-
NOD3243792009.08.29-
Norman2009.08.28-
nProtect2009.1.8.02009.08.29-
Panda10.0.2.22009.08.28-
PCTools4.4.2.02009.08.28-
Prevx3.02009.08.29-
Rising21.44.40.002009.08.28-
Sophos4.45.02009.08.29-
Sunbelt3.2.1858.22009.08.29-
Symantec1.4.4.122009.08.29-
TheHacker6.3.4.3.3902009.08.28-
TrendMicro8.950.0.10942009.08.28-
VBA323.12.10.102009.08.29-
ViRobot2009.8.28.19072009.08.28-
VirusBuster4.6.5.02009.08.28-






密码:virus

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
saskecn
发表于 2009-8-29 19:10:38 | 显示全部楼层

回复 1楼 quirk 的帖子

这个以前论坛还想发过
Avert Sample Analysis
Issue Number: 5479261   
Virus Researcher: Arun Sabapathy
McAfee Avert Labs, Bangalore, India
Identified: Generic.TRA

Thank you for submitting your suspicious file.

Synopsis -

at.exe - Generic.TRA

Attached is a file for extra detection, which will be included in a future DAT set.

EXTRA.DAT
The file should be copied into the directory where the other DAT files reside (with default installation, C:\Program Files\Common Files\McAfee\Engine).

Otherwise, use the find/search utility on your computer search to for the following file:
McScan32.dll

Then copy the Extra.dat we have sent you to the same folder where one of the above is located.
Once you have copied the file, reboot the system for the driver to be loaded.

Further information about Extra.DATs can be found at http://vil.mcafeesecurity.com/vil/systemhelpdocs/extradat.aspx.

Solution -

To ensure that you have the maximum available capability of detecting and cleaning this malware on your system, please make sure you have the latest engine.

DAT updates are available at: http://www.mcafee.com/apps/downloads/security_updates/dat.asp

Support -

Virus Research accepts file-samples for analysis and possible inclusion into AV signature DAT sets. We are also prepared to answer general virus questions.

All product-related questions and comments can be addressed through technical support and customer service, including:

* Product installation and update questions
* Product usage questions
* Specific operating system/version questions
* Assistance with detection and cleaning or removal of viruses or trojans

Please use the following link to reach our technical support group for McAfee products.

Corporate Customers:
<http://www.mcafee.com/us/support/index.html>

Single User/Retail Customers:
<http://service.mcafee.com/default.aspx>

Regards,

Arun Sabapathy
McAfee Avert Labs
A division of McAfee, Inc.
--------------------------
McAfee Avert Labs Blog <http://www.avertlabs.com/research/blog/>
AudioParasitics - The Official PodCast of McAfee  Avert Labs <http://podcasts.mcafee.com/audioparasitics>
--------------------------
Safe online? Avoid dangerous web sites using McAfee SiteAdvisor -  a FREE download from http://www.siteadvisor.com?cid=27092. Don't search or surf without it!

*Disclaimer*
Avert Labs researchers subject extra.dat files to a careful automatic test suite to verify their detection, and in order to reduce the possibility of "false alarm" detections or other issues and to improve their overall reliability. Note, however, that the McAfee Quality Assurance team has NOT tested or approved these files for release. McAfee Makes no warranty that these files will be free from errors or other interruptions or that they will meet your requirements. To the maximum extent permitted by applicable law, MCAFEE DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT WITH RESPECT TO THESE FILES.  Some states and jurisdictions do not allow limitations on implied warranties, so the above limitation may not apply to you. The foregoing provisions shall be enforceable to the maximum extent permitted by applicable law.
悠柚
发表于 2009-8-29 19:13:17 | 显示全部楼层
Submit to IObit
hu3167343
发表于 2009-8-29 19:23:53 | 显示全部楼层

回复 3楼 悠柚 的帖子

乃怎么每次都这么前排
星空下的吻
发表于 2009-8-29 19:45:48 | 显示全部楼层
卡巴 miss
运行后提示无签名文件,限制运行后试图调用CMD,这里就阻止了
估计不是什么好东东
HIPS党继续......
gzy_hao
发表于 2009-8-29 19:58:44 | 显示全部楼层
To SSr
250662772
发表于 2009-8-29 20:03:23 | 显示全部楼层
日志不完整,
2009-8-29 20:01:33    修改注册表值    阻止
进程: c:\documents and settings\administrator\桌面\at.exe
目标: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSN\Parameters\ServiceDll
值: %SystemRoot%\System32\MsPMSNSvr.dll
规则: [注册表组]自动运行 -> [注册表]HKEY_LOCAL_MACHINE\system\currentcontrolset\services*

2009-8-29 20:01:33    修改注册表值    阻止
进程: c:\documents and settings\administrator\桌面\at.exe
目标: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSN\Start
值: 0x00000002(2)
规则: [注册表组]自动运行 -> [注册表]HKEY_LOCAL_MACHINE\system\currentcontrolset\services*

2009-8-29 20:01:33    创建文件    阻止
进程: c:\documents and settings\administrator\桌面\at.exe
目标: C:\WINDOWS\system32\MsPMSNSvr.dll
规则: [文件组]高优先阻止建 -> [文件]c:\windows\system32\*

2009-8-29 20:02:16    启动驱动程序或服务    阻止
进程: c:\documents and settings\administrator\桌面\at.exe
目标: Portable Media Serial Number Service
文件路径: C:\WINDOWS\System32\svchost.exe -k netsvcs
规则: [应用程序]*

2009-8-29 20:02:16    创建文件    允许
进程: c:\documents and settings\administrator\桌面\at.exe
目标: F:\temp\$yym6myy.bat
规则: [应用程序组]应用程序 -> [应用程序]c:\documents and settings\*\桌面\*.exe -> [文件]f:\temp\*; *.*

2009-8-29 20:02:16    创建新进程    阻止
进程: c:\documents and settings\administrator\桌面\at.exe
目标: c:\windows\system32\cmd.exe
命令行: cmd /c F:\temp\$yym6myy.bat
规则: [应用程序]* -> [子应用程序]*\cmd.exe
尤金卡巴斯基
发表于 2009-8-29 21:06:43 | 显示全部楼层
To KL
wliao
发表于 2009-8-29 21:11:28 | 显示全部楼层
Online Armor


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
主动防御
发表于 2009-8-29 21:19:45 | 显示全部楼层
已上报瑞星云安全自动分析系统
RS20090829205804828503
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 13:24 , Processed in 0.079004 second(s), 3 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表