查看: 2897|回复: 18
收起左侧

[病毒样本] 挂里面抓的,大家看看是不是毒

[复制链接]
chenyilong58
发表于 2010-10-7 15:52:58 | 显示全部楼层 |阅读模式
RT。。。
瓜皮猫
发表于 2010-10-7 15:56:35 | 显示全部楼层
金山卫士杀
ESS 启发
C:\Users\微亿毫\Desktop\ying.rar > RAR > ying.exe - 可能是 Win32/PSW.OnLineGames.QJV 特洛伊木马 的变种
Simon_v5 该用户已被删除
发表于 2010-10-7 16:02:37 | 显示全部楼层
RT。。。
chenyilong58 发表于 2010.10.7 15:52



怎么抓啊?
chenyilong58
 楼主| 发表于 2010-10-7 16:04:45 | 显示全部楼层
回复 3楼 Simon_v5  的帖子

外挂注入了这个病毒,被NIS2011发现了,于是我恢复,在找到它,压缩,最后倒沙,OK
   
jinzijie
发表于 2010-10-7 16:09:28 | 显示全部楼层
chenyilong58
 楼主| 发表于 2010-10-7 16:11:43 | 显示全部楼层
下外挂360没杀出来,这个倒是查出来了。。。
Simon_v5 该用户已被删除
发表于 2010-10-7 16:12:06 | 显示全部楼层
回复

外挂注入了这个病毒,被NIS2011发现了,于是我恢复,在找到它,压缩,最后倒沙,OK
chenyilong58 发表于 2010.10.7 16:04



其他的抓样本也是这个样子么?
chenyilong58
 楼主| 发表于 2010-10-7 16:27:26 | 显示全部楼层
回复 7楼 Simon_v5  的帖子

不知道别人怎么抓....我就这样抓,不过一般在虚拟机里面抓.....
   
歌歌的人
发表于 2010-10-7 17:24:47 | 显示全部楼层

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

[size=0.9em]0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
ying.rar
Submission date:
2010-10-07 09:21:17 (UTC)
Current status:
queued queued analysing finished

Result:
13/ 42 (31.0%)

VT Community

[size=0.8em]not reviewed
[size=0.8em] Safety score: -


Compact

Print results



AntivirusVersionLast UpdateResult
AhnLab-V32010.10.07.022010.10.07Trojan/Win32.MalPack
AntiVir7.10.12.1432010.10.07TR/Crypt.FKM.Gen
Antiy-AVL2.0.3.72010.10.07-
Authentium5.2.0.52010.10.07W32/Heuristic-210!Eldorado
Avast4.8.1351.02010.10.07-
Avast55.0.594.02010.10.07-
AVG9.0.0.8512010.10.06Suspicion: unknown virus
BitDefender7.22010.10.07-
CAT-QuickHeal11.002010.10.05(Suspicious) - DNAScan
ClamAV0.96.2.0-git2010.10.07PUA.Packed.FSG
Comodo63092010.10.07Heur.Pck.FSG
DrWeb5.0.2.033002010.10.07-
Emsisoft5.0.0.502010.10.07-
eSafe7.0.17.02010.10.06-
eTrust-Vet36.1.78962010.10.07-
F-Prot4.6.2.1172010.10.06W32/Heuristic-210!Eldorado
F-Secure9.0.15370.02010.10.07-
Fortinet4.2.249.02010.10.07-
GData212010.10.07-
IkarusT3.1.1.90.02010.10.07-
Jiangmin13.0.9002010.10.06-
K7AntiVirus9.63.26892010.10.06Riskware
Kaspersky7.0.0.1252010.10.07-
McAfee5.400.0.11582010.10.07-
McAfee-GW-Edition2010.1C2010.10.07-
Microsoft1.62012010.10.07-
NOD3255112010.10.07probably a variant of Win32/PSW.OnLineGames.QJV
Norman6.06.072010.10.06Suspicious_F.gen
nProtect2010-10-07.012010.10.07-
Panda10.0.2.72010.10.06-
PCTools7.0.3.52010.10.07-
Prevx3.02010.10.07-
Rising22.67.02.072010.09.30-
Sophos4.58.02010.10.07Mal/Packer
Sunbelt70042010.10.07-
SUPERAntiSpyware4.40.0.10062010.10.07-
Symantec20101.2.0.1612010.10.07-
TheHacker6.7.0.1.0512010.10.07-
TrendMicro-HouseCall9.120.0.10042010.10.07-
VBA323.12.14.12010.10.06-
ViRobot2010.10.4.40742010.10.07-
VirusBuster12.67.6.02010.10.06Packed/FSG
Additional information
Show all
MD5   : 98e1f97d6aae2ab6c268bfce2e36caad
SHA1  : 4167c59e9788fc03e43a1fb4495f4f5a5e776a56
SHA256: c8021205dfdeed28686037d92ba1495e692fdd308730f2808cc0e84589c0b116
ssdeep: 768:HTRwaFQzU6qPqduyGSMq3qz0Gy2DDjgnG2aEfUS6Hi:HbQznqPqdjGSMl4EDMnG2aeZki
File size : 24645 bytes
First seen: 2010-10-07 07:51:24
Last seen : 2010-10-07 09:21:17
TrID:
RAR Archive (83.3%)
REALbasic Project (16.6%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Authentium): FSG
packers (F-Prot): FSG
packers (Kaspersky): FSG
Symantec reputation:Suspicious.Insight
http://www.virustotal.com/file-scan/report.html?id=c8021205dfdeed28686037d92ba1495e692fdd308730f2808cc0e84589c0b116-1286443277


Knot
发表于 2010-10-7 17:28:26 | 显示全部楼层
很好玩,很戏剧性
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-9 03:33 , Processed in 0.132128 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表