查看: 2970|回复: 12
收起左侧

[病毒样本] 文件伪装王的生成物

[复制链接]
RickyBoy
发表于 2009-12-7 05:03:19 | 显示全部楼层 |阅读模式
IK只报ins_cs

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kalynn84
发表于 2009-12-7 07:59:52 | 显示全部楼层
Win32:Adware-gen [Adw]
悠柚
发表于 2009-12-7 11:11:04 | 显示全部楼层
SD with Antivirus miss all
fatezero
发表于 2009-12-7 11:17:30 | 显示全部楼层
木马程序 Trojan.Win32.Agent.cxjy        E:\download\ins_cs.rar       
病毒 HEUR:Trojan.Win32.StartPage        E:\download\fusong.rar/fusong.exe
无尽藏海
发表于 2009-12-7 11:35:53 | 显示全部楼层
结果: 找到 1 恶意软件
BehavesLike:Trojan.StartPage (怀疑的感染)
D:\Virus\fusong.rar\fusong.exe

--------------------------------------------------------------------------------

找到危险软件
Application.Generic.242195 (危险软件)
D:\Virus\ins_cs.rar\ins_cs.exe
D:\Virus\ins_cs.rar
C.C.
发表于 2009-12-7 12:35:27 | 显示全部楼层
to avira
328397663
发表于 2009-12-7 13:15:36 | 显示全部楼层
回复 1# RickyBoy 效率有了。但是准确率有些低。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
fatezero
发表于 2009-12-7 13:39:38 | 显示全部楼层
红伞

The file 'crverify.exe' has been determined to be 'CLEAN'. Our analysts did not discover any malicious content.

........................................................................................................................................

卡巴

Hello,
crverify.exe
No malicious code was found in this file.
will
发表于 2009-12-7 13:49:08 | 显示全部楼层
crverify.exe   ---   Clean(Not-a-malware)
fusong.exe   ---   Malware/W32.StartPage
[ Changes to filesystem ]
   * Creates file C:\Documents and Settings\Administrator\Local Settings\Temp\forqd75.exe
   * Creates file C:\Documents and Settings\Administrator\Local Settings\Temp\haozip_v1.5.3180.x86_tiny.200084.exe
   * Creates file C:\Documents and Settings\Administrator\Local Settings\Temp\pplivesetup_forqd75.exe
   * Creates file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q78DYP3J\pplivesetup_forqd75[1].exe

[ Changes to registry ]
   * Creates value "ip_haoya=01000000" in key HKEY_LOCAL_MACHINE\software\ExFlags
   * Creates value "ip_ppli=01000000" in key HKEY_LOCAL_MACHINE\software\ExFlags
   * Modifies value "Start Page=http://www.2345.com/?304" in key HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main
          old value "Start Page=about:blank"

[ Network services ]
   * Looks for an Internet connection.
   * Connects to "222.73.218.127" on port 80.
   * Connects to "127.0.0.1" on port 2875.
   * Connects to "61.55.164.84" on port 80.


ins_cs.exe   ---   Suspicious/W32.Clicker
[ Changes to filesystem ]
   * Creates file C:\Documents and Settings\Administrator\Cookies\administrator@www.yahoo[1].txt
   * Creates file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\67b9_appcompat.txt
   * Deletes file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\67b9_appcompat.txt

[ Network services ]
   * Looks for an Internet connection.
   * Connects to "209.131.36.158" on port 80.
   * Connects to "98.137.149.56" on port 80.
   * Opens next URLs:
     http://www.yahoo.com
jayavira
发表于 2009-12-7 15:04:01 | 显示全部楼层
ess kill2个。to1个
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 00:57 , Processed in 0.083761 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表