楼主: sam.to
收起左侧

[病毒样本] 过主流2 (天天更新) (此帖完,1024楼有新帖子地址)

  [复制链接]
sam.to
 楼主| 发表于 2010-9-9 15:28:57 | 显示全部楼层
本帖最后由 sam.to 于 2010.9.9 19:03 编辑

6e5ec7f3971beae12ae5dffd04e3bc8d  Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Crack.40063.exe8
31dd4b11a71666fb16220baa7b9e55c9  Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Keygen.40063.exe8
2b5bdad88b1f0cf5af239fe949aaf12a  onOne.PhotoTools.2.5.3.Crack.40063.exe8
a6011a8227c30ce8aab683e3e72cb15e  onOne.PhotoTools.2.5.3.Keygen.40063.exe8
1bdceef794b5d4d41035e7dc5fcd305c  RegCure.3.0.0.0.Crack.40063.exe8
a70d3e913535d7313debba1d72f32eee  RegCure.3.0.0.0.Keygen.40063.exe8
1a4edb48d4096fa66b41a92bd6b1c6c3  RL.Vision.Flash.Renamer.6.41.Crack.40063.exe8
b54449444f37db9daa6a8aaa65f0738b  RL.Vision.Flash.Renamer.6.41.Keygen.40063.exe8
c2849ca223267246e04c325ddbfd3ad4  USB.Disk.Security.5.3.0.36.Crack.40063.exe8
e12a33ea60870c80332723538666d7f3  USB.Disk.Security.5.3.0.36.Keygen.40063.exe8
b12cd3b40deec039e81470c9cf2a8257  WinX.DVD.Ripper.Platinum.5.11.1.Crack.40063.exe8
628f24517113ef01f4f31238ab2a8231  WinX.DVD.Ripper.Platinum.5.11.1.Keygen.40063.exe8

to ll,mcafee,comodo,avira



File ID
Filename
Size (Byte)
Result
25878872
765735-121.rar
85.94 KB
OK
A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25878873
Corel.PaintShop....63.exe8
128.5 KB
UNDER ANALYSIS
25878874
Corel.PaintShop....63.exe8
128.5 KB
UNDER ANALYSIS
25878875
onOne.PhotoTools...63.exe8
128.5 KB
UNDER ANALYSIS
25878876
onOne.PhotoTools...63.exe8
128.5 KB
UNDER ANALYSIS
25878877
RegCure.3.0.0.0....63.exe8
128.5 KB
UNDER ANALYSIS
25878878
RegCure.3.0.0.0....63.exe8
128.5 KB
UNDER ANALYSIS
25878879
RL.Vision.Flash....63.exe8
128.5 KB
UNDER ANALYSIS
25878880
RL.Vision.Flash....63.exe8
128.5 KB
UNDER ANALYSIS
25878881
USB.Disk.Securit...63.exe8
128.5 KB
UNDER ANALYSIS
25878882
USB.Disk.Securit...63.exe8
128.5 KB
UNDER ANALYSIS
25878883
WinX.DVD.Ripper....63.exe8
128.5 KB
UNDER ANALYSIS
25878884
WinX.DVD.Ripper....63.exe8
128.5 KB
UNDER ANALYSIS



Please find a detailed report concerning each individual sample below:
Filename
Result
Corel.PaintShop....63.exe8
MALWARE

The file 'Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AG.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Corel.PaintShop....63.exe8
MALWARE

The file 'Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AI.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
onOne.PhotoTools...63.exe8
MALWARE

The file 'onOne.PhotoTools.2.5.3.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AJ.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
onOne.PhotoTools...63.exe8
MALWARE

The file 'onOne.PhotoTools.2.5.3.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AD.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
RegCure.3.0.0.0....63.exe8
MALWARE

The file 'RegCure.3.0.0.0.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AE.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
RegCure.3.0.0.0....63.exe8
MALWARE

The file 'RegCure.3.0.0.0.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AF.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
RL.Vision.Flash....63.exe8
MALWARE

The file 'RL.Vision.Flash.Renamer.6.41.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AH.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
RL.Vision.Flash....63.exe8
MALWARE

The file 'RL.Vision.Flash.Renamer.6.41.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AK.A.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
USB.Disk.Securit...63.exe8
MALWARE

The file 'USB.Disk.Security.5.3.0.36.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AL.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
USB.Disk.Securit...63.exe8
MALWARE

The file 'USB.Disk.Security.5.3.0.36.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AM.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
WinX.DVD.Ripper....63.exe8
MALWARE

The file 'WinX.DVD.Ripper.Platinum.5.11.1.Crack.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AN.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
WinX.DVD.Ripper....63.exe8
MALWARE

The file 'WinX.DVD.Ripper.Platinum.5.11.1.Keygen.40063.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Renos.AO.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.

jinliang5000
发表于 2010-9-9 15:31:40 | 显示全部楼层
回复 120楼 sam.to  的帖子
115那个

   
jayavira
发表于 2010-9-9 15:35:05 | 显示全部楼层
回复 121楼 sam.to  的帖子
ess 清空
vmzy
发表于 2010-9-9 16:23:38 | 显示全部楼层
360杀毒清空
2010-Sep-9-1522\Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\Corel.PaintShop.Photo.Pro.X3.13.2.0.41.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\onOne.PhotoTools.2.5.3.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\onOne.PhotoTools.2.5.3.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\RegCure.3.0.0.0.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\RegCure.3.0.0.0.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\RL.Vision.Flash.Renamer.6.41.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\RL.Vision.Flash.Renamer.6.41.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\USB.Disk.Security.5.3.0.36.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\USB.Disk.Security.5.3.0.36.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\WinX.DVD.Ripper.Platinum.5.11.1.Crack.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
2010-Sep-9-1522\WinX.DVD.Ripper.Platinum.5.11.1.Keygen.40063.exe8        可疑木马(Trojan.Generic.KD.34763)
rasis
发表于 2010-9-9 16:57:08 | 显示全部楼层
SP  KILL ALL
lianyeguzhou
发表于 2010-9-10 09:16:03 | 显示全部楼层
回复 1楼 sam.to  的帖子


    最讨厌加密码还不告诉密码,
62590423
发表于 2010-9-10 09:20:31 | 显示全部楼层
回复 126楼 lianyeguzhou  的帖子

通常情况下,密码只有virus/infected两种可能
   
sam.to
 楼主| 发表于 2010-9-10 17:57:08 | 显示全部楼层
本帖最后由 sam.to 于 2010.9.10 22:05 编辑

569585ee2a218a3fb9a8f7f450c42a12  MPEG4.Direct.Maker.6.3.0.220.Crack.45231.exe8
e39ab10606da1218ebebd9cd8c9ea7a1  MPEG4.Direct.Maker.6.3.0.220.Keygen.45231.exe8
6fa4bd79b21fe3d35f158d0a199311d7  Natura.Sound.Therapy.3.0.Crack.45231.exe8
f1cb5365b9a83107463c63fde0d7b324  Natura.Sound.Therapy.3.0.Keygen.45231.exe8
93d9ead769bb1d3e1e70351b0add0179  Odin.Frame.Photo.Creator.2.5.Crack.45231.exe8
011a23cdad59c3e9d69998e95d092f3b  Odin.Frame.Photo.Creator.2.5.Keygen.45231.exe8
d8a6e08f57c6c125b61948aa9ecfb6bc  Sun.River.Systems.Heatseek.Gold.1.4.2.0.Crack.45231.exe8
68a04de5eb1bbdd4443e4cd92fb573ed  Sun.River.Systems.Heatseek.Gold.1.4.2.0.Keygen.45231.exe8
1876bf45fc694d71f4280e12dbda436c  SWF.Decompiler.Premium.2.2.1.1380.Crack.45231.exe8
8344c3fb093b80ca87417a937d06b6bd  SWF.Decompiler.Premium.2.2.1.1380.Keygen.45231.exe8
c3255523ff6790e79d0fff28a6f30471  Xilisoft.MKV.Converter.5.1.26.0814.Crack.45231.exe8
24c995840d4953ff4c5706a4e80b1114  Xilisoft.MKV.Converter.5.1.26.0814.Keygen.45231.exe8


to kl,ll,mcafee,comodo,avira



File ID
Filename
Size (Byte)
Result
25879981
765735-128.rar
93.85 KB
OK
A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25879982
MPEG4.Direct.Mak...31.exe8
155.5 KB
UNDER ANALYSIS
25879983
MPEG4.Direct.Mak...31.exe8
155.5 KB
UNDER ANALYSIS
25879984
Natura.Sound.The...31.exe8
155.5 KB
UNDER ANALYSIS
25879985
Natura.Sound.The...31.exe8
155.5 KB
UNDER ANALYSIS
25879986
Odin.Frame.Photo...31.exe8
155.5 KB
UNDER ANALYSIS
25879987
Odin.Frame.Photo...31.exe8
155.5 KB
UNDER ANALYSIS
25879988
Sun.River.System...31.exe8
155.5 KB
UNDER ANALYSIS
25879989
Sun.River.System...31.exe8
155.5 KB
UNDER ANALYSIS
25879990
SWF.Decompiler.P...31.exe8
155.5 KB
UNDER ANALYSIS
25879991
SWF.Decompiler.P...31.exe8
155.5 KB
UNDER ANALYSIS
25879992
Xilisoft.MKV.Con...31.exe8
155.5 KB
UNDER ANALYSIS
25879993
Xilisoft.MKV.Con...31.exe8
155.5 KB
UNDER ANALYSIS







Hello,

Trojan-Downloader.Win32.CodecPack.mmx

New malicious software was found in the attached file. Its detection will be included in the next update.
Thank you for your help.

Please quote all when answering.
-----------------
Regards, Kirill Kruglov
Virus Analyst, Kaspersky Lab.



Please find a detailed report concerning each individual sample below:
Filename
Result
MPEG4.Direct.Mak...31.exe8
MALWARE

The file 'MPEG4.Direct.Maker.6.3.0.220.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.JV.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
MPEG4.Direct.Mak...31.exe8
MALWARE

The file 'MPEG4.Direct.Maker.6.3.0.220.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.JW.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Natura.Sound.The...31.exe8
MALWARE

The file 'Natura.Sound.Therapy.3.0.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.JX.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Natura.Sound.The...31.exe8
MALWARE

The file 'Natura.Sound.Therapy.3.0.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.JY.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Odin.Frame.Photo...31.exe8
MALWARE

The file 'Odin.Frame.Photo.Creator.2.5.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.JZ.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Odin.Frame.Photo...31.exe8
MALWARE

The file 'Odin.Frame.Photo.Creator.2.5.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KD.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Sun.River.System...31.exe8
MALWARE

The file 'Sun.River.Systems.Heatseek.Gold.1.4.2.0.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KE.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Sun.River.System...31.exe8
MALWARE

The file 'Sun.River.Systems.Heatseek.Gold.1.4.2.0.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KF.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
SWF.Decompiler.P...31.exe8
MALWARE

The file 'SWF.Decompiler.Premium.2.2.1.1380.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KG.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
SWF.Decompiler.P...31.exe8
MALWARE

The file 'SWF.Decompiler.Premium.2.2.1.1380.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KH.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Xilisoft.MKV.Con...31.exe8
MALWARE

The file 'Xilisoft.MKV.Converter.5.1.26.0814.Crack.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KJ.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Xilisoft.MKV.Con...31.exe8
MALWARE

The file 'Xilisoft.MKV.Converter.5.1.26.0814.Keygen.45231.exe8' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Fakealert.KK.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.

414447992
发表于 2010-9-10 18:51:35 | 显示全部楼层
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-30 11:45 , Processed in 0.094345 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表