查看: 4403|回复: 11
收起左侧

[病毒样本] FakeAV

[复制链接]
sbbdms
发表于 2009-11-22 16:45:15 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ronnie1987
发表于 2009-11-22 16:53:17 | 显示全部楼层
NIS2010没有扫描出来,但是解压后被干掉了~~~~~~~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-11-22 16:53:20 | 显示全部楼层
To KL
adad2008
头像被屏蔽
发表于 2009-11-22 16:57:32 | 显示全部楼层
kv主动防御报危险

e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     创建注册表键     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders     2009-11-22 17:00:26     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     创建注册表键     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders     2009-11-22 17:00:57     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData = E:\Documents and Settings\All Users.WINT\Application Data     2009-11-22 17:00:57     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory = E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5     2009-11-22 17:01:00     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path1\CachePath = E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache1     2009-11-22 17:01:01     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path2\CachePath = E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache2     2009-11-22 17:01:01     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path3\CachePath = E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache3     2009-11-22 17:01:02     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     修改注册表     HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path4\CachePath = E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache4     2009-11-22 17:01:03     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     发现可疑程序     
创建注册表键;
修改注册表;
创建文件;
创建进程(运行程序);     2009-11-22 17:01:18     
e:\documents and settings\administrator\桌面\antimalware[1]\antimalware.exe     发现可疑程序     
创建注册表键;
修改注册表;
创建文件;
创建进程(运行程序);
连接网络;     2009-11-22 17:01:24

[ 本帖最后由 adad2008 于 2009-11-22 17:02 编辑 ]
尤金卡巴斯基
发表于 2009-11-22 17:34:02 | 显示全部楼层
New malicious software was found in the attached file. Its detection will be included in the next update.
Thank you for your help.

Trojan.Win32.FraudPack.aaul
fengtaks
发表于 2009-11-22 17:39:07 | 显示全部楼层
ESET
antimalware.exe - Win32/Kryptik.BBM 特洛伊木马 的变种 - 通过删除清除 - 已隔离
to VB & PA
linjw
发表于 2009-11-22 17:56:01 | 显示全部楼层
Filename        Result
antimalware.exe         UNDER ANALYSIS


The file 'antimalware.exe' has been determined to be 'UNDER ANALYSIS'.
星空下的吻
发表于 2009-11-22 18:37:42 | 显示全部楼层
360 miss
BING126
头像被屏蔽
发表于 2009-11-22 21:32:42 | 显示全部楼层
McAfee 报了可疑月神。。
kalynn84
发表于 2009-11-23 12:13:14 | 显示全部楼层
Win32:Malware-gen
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 00:57 , Processed in 0.089879 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表