楼主: sam.to
收起左侧

[病毒样本] 过主流2 (天天更新) (此帖完,1024楼有新帖子地址)

  [复制链接]
留侯
发表于 2011-5-28 13:34:19 | 显示全部楼层
978L,大蜘蛛清空:
765735-978\2011-May-28-1138\Cadfix.8.0.Crack.40063.exe, 已感染:  Trojan.DownLoader3.6390
sam.to
 楼主| 发表于 2011-5-30 14:30:56 | 显示全部楼层
本帖最后由 sam.to 于 2011-5-31 17:16 编辑

a8044c8dbda5f3c08ef72a28dcaf78ef  Acoustica.Mixcraft.5.2.152.Crack.52106.exe,
193f8cf6587a7774b16e6178363c92ba  Acoustica.Mixcraft.5.2.152.Keygen.52106.exe,
2921cc90bdd30ff6157ecfde5388ad0e  ArcSoft.PhotoImpression.Gold.6.5.0.95.Crack.52106.exe,
8ebb4262c84ebee5cb41303016197232  ArcSoft.PhotoImpression.Gold.6.5.0.95.Keygen.52106.exe,
a361e4d46855651c35c3e31c5c18cf28  Intuit.QuickBooks.Point.Of.Sale.8.0.Crack.52106.exe,
0a86fac247ff98b5697b433915b753bf  Intuit.QuickBooks.Point.Of.Sale.8.0.Keygen.52106.exe,
c543dc777f81046d735168507e486ff3  Micsoft.Office.Enterprise.2010.Crack.52106.exe,
a9748a5f79e1e064a9bf38a9e55a3938  Micsoft.Office.Enterprise.2010.Keygen.52106.exe,
35c4b3b6d17eb19433620f6f8725b1a7  Shade.12.0.2.Crack.52106.exe,
70786d2af2c177226091738cf43f08d7  Shade.12.0.2.Keygen.52106.exe,
faf42550ce8dd1552e84a25ed64fa569  Win7.ART.Edition.2011.Crack.52106.exe,
6e87ba76e1d2debe6641032fa5808b8e  Win7.ART.Edition.2011.Keygen.52106.exe,


to ll,mcafee,comodo,avira



We received the following archive files:

File ID
Filename
Size (Byte)
Result
26153345
765735-982.rar
65.47 KB
OK
A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
26153346
Acoustica.Mixcra...06.exe,
98 KB
UNDER ANALYSIS
26153347
Acoustica.Mixcra...06.exe,
98 KB
UNDER ANALYSIS
26153348
ArcSoft.PhotoImp...06.exe,
98 KB
UNDER ANALYSIS
26153349
ArcSoft.PhotoImp...06.exe,
98 KB
UNDER ANALYSIS
26153350
Intuit.QuickBook...06.exe,
98 KB
UNDER ANALYSIS
26153351
Intuit.QuickBook...06.exe,
98 KB
UNDER ANALYSIS
26153352
Micsoft.Office.E...06.exe,
98 KB
UNDER ANALYSIS
26153353
Micsoft.Office.E...06.exe,
98 KB
UNDER ANALYSIS
26153354
Shade.12.0.2.Cra...06.exe,
98 KB
UNDER ANALYSIS
26153355
Shade.12.0.2.Key...06.exe,
98 KB
UNDER ANALYSIS
26153356
Win7.ART.Edition...06.exe,
98 KB
UNDER ANALYSIS
26153357
Win7.ART.Edition...06.exe,
98 KB
UNDER ANALYSIS





Please find a detailed report concerning each individual sample below:
Filename         Result          Acoustica.Mixcra...06.exe,          MALWARE

The file 'Acoustica.Mixcraft.5.2.152.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Acoustica.Mixcra...06.exe,          MALWARE

The file 'Acoustica.Mixcraft.5.2.152.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.6. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          ArcSoft.PhotoImp...06.exe,          MALWARE

The file 'ArcSoft.PhotoImpression.Gold.6.5.0.95.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          ArcSoft.PhotoImp...06.exe,          MALWARE

The file 'ArcSoft.PhotoImpression.Gold.6.5.0.95.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Intuit.QuickBook...06.exe,          MALWARE

The file 'Intuit.QuickBooks.Point.Of.Sale.8.0.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Intuit.QuickBook...06.exe,          MALWARE

The file 'Intuit.QuickBooks.Point.Of.Sale.8.0.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Micsoft.Office.E...06.exe,          MALWARE

The file 'Micsoft.Office.Enterprise.2010.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Micsoft.Office.E...06.exe,          MALWARE

The file 'Micsoft.Office.Enterprise.2010.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Shade.12.0.2.Cra...06.exe,          MALWARE

The file 'Shade.12.0.2.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Shade.12.0.2.Key...06.exe,          MALWARE

The file 'Shade.12.0.2.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.4. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Win7.ART.Edition...06.exe,          MALWARE

The file 'Win7.ART.Edition.2011.Crack.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Win7.ART.Edition...06.exe,          MALWARE

The file 'Win7.ART.Edition.2011.Keygen.52106.exe,' has been determined to be 'MALWARE'. Our analysts named the threat TR/Jorik.Skor.agj.1. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aaaaoooo
头像被屏蔽
发表于 2011-5-30 15:16:24 | 显示全部楼层
本帖最后由 aaaaoooo 于 2011-5-30 15:16 编辑

982L
360SD 清空。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
留侯
发表于 2011-5-30 15:24:58 | 显示全部楼层
82L,大蜘蛛清空:
765735-982\2011-May-30-1422\Acoustica.Mixcraft.5.2.152.Crack.52106.exe, 已感染:  Trojan.Siggen2.31974
瓜皮猫
发表于 2011-5-30 18:02:00 | 显示全部楼层
982L
eset  kill
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Acoustica.Mixcraft.5.2.152.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Acoustica.Mixcraft.5.2.152.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\ArcSoft.PhotoImpression.Gold.6.5.0.95.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\ArcSoft.PhotoImpression.Gold.6.5.0.95.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Intuit.QuickBooks.Point.Of.Sale.8.0.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Intuit.QuickBooks.Point.Of.Sale.8.0.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Micsoft.Office.Enterprise.2010.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Micsoft.Office.Enterprise.2010.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Shade.12.0.2.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Shade.12.0.2.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Win7.ART.Edition.2011.Crack.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan
C:\Users\微亿毫\Desktop\765735-982\2011-May-30-1422\Win7.ART.Edition.2011.Keygen.52106.exe, - Win32/TrojanDownloader.FakeAlert.BBT trojan

评分

参与人数 2人气 +2 收起 理由
jayavira + 1 辛苦
hx1997 + 1 很给力!

查看全部评分

网名丢失
发表于 2011-5-31 02:15:24 | 显示全部楼层
哈哈,红伞全杀了
hj5abc
发表于 2011-5-31 10:11:58 | 显示全部楼层
982 MSE KILL ALL NOW
TrojanDownloader:Win32/Renos.PT
armchan
发表于 2011-6-1 14:47:42 | 显示全部楼层
本帖最后由 armchan 于 2011-6-1 14:50 编辑

978和982都杀了12,都清空了,这是982的

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sam.to
 楼主| 发表于 2011-6-2 13:36:13 | 显示全部楼层
本帖最后由 sam.to 于 2011-6-2 22:18 编辑

62c2f95a3980a63dc8553cfa9b148b97  AnyToISO.Converter.Professional.3.2.Crack.45231.exe3
8d00690a40afce83df9248fb2d0ab5aa  AnyToISO.Converter.Professional.3.2.Keygen.45231.exe3
474872f17294295769f38934ebdb6040  Auto.FX.Suite.Collection.Update.26.05.2011.Crack.45231.exe3
ef939cce5c0ac9267960b2df15054daa  Auto.FX.Suite.Collection.Update.26.05.2011.Keygen.45231.exe3
ca935edec4a4b5f42bb8375d85269457  Folder.Lock.6.6.0.Crack.45231.exe3
02987837962feb806bcf322d5fd6e7ff  Folder.Lock.6.6.0.Keygen.45231.exe3
346cbac108ec339f47c7ad2f32667a3d  I.Screen.Recorder.8.0.1.12.Crack.45231.exe3
14491688b2a034dad931b6ea44e44364  I.Screen.Recorder.8.0.1.12.Keygen.45231.exe3
aeddafe1f3861c7da8b33c9c622be3c7  Rio.2011.Crack.45231.exe3
d1c37cfabe8f64b78c27e7cb820b1816  Rio.2011.Keygen.45231.exe3
adf6093adccefc7193ab4165be1281e8  Windows.7.AIO.SP1.And.Office.2010.Crack.45231.exe3
e84372c3bdb25f4d481c87b616b7e4de  Windows.7.AIO.SP1.And.Office.2010.Keygen.45231.exe3
8e8bdfb7d267c33f34e85247f1ac68cd  WinZip.Pro.15.5.9510.Crack.45231.exe3
b6779064512aaa019faa09021784035c  WinZip.Pro.15.5.9510.Keygen.45231.exe3


to kl,ll,mcafee,comodo,avira


File ID
Filename
Size (Byte)
Result
26159428
765735-989.rar
1.01 MB
OK
A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
26159429
AnyToISO.Convert...31.exe3
109 KB
UNDER ANALYSIS
26159430
AnyToISO.Convert...31.exe3
109 KB
UNDER ANALYSIS
26159431
Auto.FX.Suite.Co...31.exe3
109 KB
UNDER ANALYSIS
26159432
Auto.FX.Suite.Co...31.exe3
109 KB
UNDER ANALYSIS
26159433
Folder.Lock.6.6....31.exe3
109 KB
UNDER ANALYSIS
26159434
Folder.Lock.6.6....31.exe3
109 KB
UNDER ANALYSIS
26159435
I.Screen.Recorde...31.exe3
109 KB
UNDER ANALYSIS
26159436
I.Screen.Recorde...31.exe3
109 KB
UNDER ANALYSIS
26159437
Rio.2011.Crack.45231.exe3
109 KB
UNDER ANALYSIS
26159438
Rio.2011.Keygen....31.exe3
109 KB
UNDER ANALYSIS
26159439
Windows.7.AIO.SP...31.exe3
109 KB
UNDER ANALYSIS
26159440
Windows.7.AIO.SP...31.exe3
109 KB
UNDER ANALYSIS
26159441
WinZip.Pro.15.5....31.exe3
109 KB
UNDER ANALYSIS
26159442
WinZip.Pro.15.5....31.exe3
109 KB
UNDER ANALYSIS








Trojan-Downloader.Win32.CodecPack.auzs

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.






Please find a detailed report concerning each individual sample below:
Filename         Result          AnyToISO.Convert...31.exe3          MALWARE

The file 'AnyToISO.Converter.Professional.3.2.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          AnyToISO.Convert...31.exe3          MALWARE

The file 'AnyToISO.Converter.Professional.3.2.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Auto.FX.Suite.Co...31.exe3          MALWARE

The file 'Auto.FX.Suite.Collection.Update.26.05.2011.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Auto.FX.Suite.Co...31.exe3          MALWARE

The file 'Auto.FX.Suite.Collection.Update.26.05.2011.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Folder.Lock.6.6....31.exe3          MALWARE

The file 'Folder.Lock.6.6.0.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Folder.Lock.6.6....31.exe3          MALWARE

The file 'Folder.Lock.6.6.0.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          I.Screen.Recorde...31.exe3          MALWARE

The file 'I.Screen.Recorder.8.0.1.12.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          I.Screen.Recorde...31.exe3          MALWARE

The file 'I.Screen.Recorder.8.0.1.12.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Rio.2011.Crack.45231.exe3          MALWARE

The file 'Rio.2011.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Rio.2011.Keygen....31.exe3          MALWARE

The file 'Rio.2011.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Windows.7.AIO.SP...31.exe3          MALWARE

The file 'Windows.7.AIO.SP1.And.Office.2010.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          Windows.7.AIO.SP...31.exe3          MALWARE

The file 'Windows.7.AIO.SP1.And.Office.2010.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          WinZip.Pro.15.5....31.exe3          MALWARE

The file 'WinZip.Pro.15.5.9510.Crack.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename         Result          WinZip.Pro.15.5....31.exe3          MALWARE

The file 'WinZip.Pro.15.5.9510.Keygen.45231.exe3' has been determined to be 'MALWARE'. Our analysts named the threat TR/Renos.BF. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-31 07:45 , Processed in 0.102487 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表