楼主: sam.to
收起左侧

[病毒样本] qd.exe及db1.exe (此帖已完,1394楼有新帖子的地址)

  [复制链接]
sololp 该用户已被删除
发表于 2010-9-1 08:07:32 | 显示全部楼层
submit to MMPC
sam.to
 楼主| 发表于 2010-9-1 12:25:03 | 显示全部楼层
本帖最后由 sam.to 于 2010.9.1 18:48 编辑

4566b6e0c164d9b6ead75da4606dafea   qd.ex2e
c645de9ce591d3c324ac167e074e9e34   db1.ex2e

to kl,ll,mcafee,comodo,avira


A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25870155
db1.ex2e
392 KB
UNDER ANALYSIS
25870156
qd.ex2e
432 KB
UNDER ANALYSIS





Please find a detailed report concerning each individual sample below:
Filename
Result
db1.ex2e
MALWARE

The file 'db1.ex2e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Zlob.401408.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
qd.ex2e
MALWARE

The file 'qd.ex2e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Zlob.442368.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.





db1.ex2e - Trojan-Dropper.Win32.Agent.cxcq
qd.ex2e - Trojan-Dropper.Win32.Agent.cxcr

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Best Regards, Kaspersky Lab
62590423
发表于 2010-9-1 12:26:22 | 显示全部楼层
本帖最后由 62590423 于 2010.9.1 12:36 编辑

eset的广谱还真是顽强啊

卡巴云杀1
jayavira
发表于 2010-9-1 13:32:42 | 显示全部楼层
回复 282楼 sam.to  的帖子
ess 清空
wangyuli100
发表于 2010-9-1 13:38:36 | 显示全部楼层
类别:已解决的安全风险
日期和时间,风险,活动,状态,推荐的操作
2010-9-1 13:37,中,p.dll (Adware.Rugo) 检测方 Auto-Protect,已阻止,已解决 - 不采取操作
类别:已解决的安全风险
日期和时间,风险,活动,状态,推荐的操作,路径 - 文件名
2010-9-1 13:38,高,检测到 qd.exe (qd.exe) (检测方: SONAR),已隔离,已解决 - 不采取操作,c:\documents and settings\administrator\桌面\qd.exe


类别:隔离区
日期和时间,风险,活动,状态,推荐的操作,路径 - 文件名
2010-9-1 13:38,高,检测到 qd.exe (qd.exe) (检测方: SONAR),已隔离,已解决 - 不采取操作,c:\documents and settings\administrator\桌面\qd.exe


类别:SONAR 活动
日期和时间,风险,活动,状态,推荐的操作,路径 - 文件名
2010-9-1 13:38,高,检测到 qd.exe (qd.exe) (检测方: SONAR),已隔离,已解决 - 不采取操作,c:\documents and settings\administrator\桌面\qd.exe



sam.to
 楼主| 发表于 2010-9-1 22:26:17 | 显示全部楼层
本帖最后由 sam.to 于 2010.9.3 11:55 编辑

edd2358797861618fea3db0f9074f022   qd.ex2e
e044569129be715516b2361a1f600759   db1.e2xe

to kl,ll,mcafee,comodo,avira


A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25870669
db1.e2xe
392 KB
UNDER ANALYSIS
25870670
qd.ex2e
432 KB
UNDER ANALYSIS



Please find a detailed report concerning each individual sample below:
Filename
Result
db1.e2xe
MALWARE

The file 'db1.e2xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Zlob.401408.A.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
qd.ex2e
MALWARE

The file 'qd.ex2e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Zlob.401408.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.11.68.







db1.e2xe - Trojan-Dropper.Win32.Agent.cxgo,
qd.ex2e - Trojan-Dropper.Win32.Agent.cxgn

reizhi
发表于 2010-9-1 23:15:12 | 显示全部楼层
TO Symantec
jayavira
发表于 2010-9-2 06:50:28 | 显示全部楼层
回复 286楼 sam.to  的帖子
ess kill
sam.to
 楼主| 发表于 2010-9-2 12:06:10 | 显示全部楼层
本帖最后由 sam.to 于 2010.9.2 15:56 编辑

6146bdf2dc72081b701e0531f5520e67   db1.ex1e
a9a586a271aba8a4e08229a3a6ad845e   qd.exe2

to kl,ll,mcafee,comodo,avira



A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25871195
db1.ex1e
376 KB
UNDER ANALYSIS
25871196
qd.exe2
416 KB
UNDER ANALYSIS





Please find a detailed report concerning each individual sample below:
Filename
Result
db1.ex1e
MALWARE

The file 'db1.ex1e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Zlob.385024.B.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
qd.exe2
MALWARE

The file 'qd.exe2' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Agent.425984.X.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
rasis
发表于 2010-9-2 12:17:53 | 显示全部楼层
750089-289.rar
SP
KILL ALL
Troj/BHO-QJ
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 04:55 , Processed in 0.103675 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表