楼主: 604730161
收起左侧

[病毒样本] 我把让nis2011睡着、神器NPE倒下、小A残废、360连尸骨都找不着的样本提取了(已解决)

  [复制链接]
jayavira
发表于 2010-10-24 13:43:44 | 显示全部楼层
ess kill1个,另一个不是病毒啊

2010-10-24 13:52:10        文件系统实时防护        文件        D:\下载文件夹\SysLive.exe        可能是 Win32/AutoRun.Delf.EP 蠕虫 的变种        通过删除清除 - 已隔离        WWW-738C9D7CF42\Administrator        在应用程序新建的文件上发生事件: D:\Program Files\WinRAR\WinRAR.exe.

http://camas.comodo.com/cgi-bin/ ... 9ffc390d357fc85e6d6
aaa839
发表于 2010-10-24 14:47:31 | 显示全部楼层
We received the following archive files:
File ID         Filename        Size (Byte)        Result
25927825         virus.rar        119.92 KB        OK


A listing of files contained inside archives alongside their results can be found below:File ID         Filename        Size (Byte)        Result
25927826         CHANGE.LOG         568 Byte         UNDER ANALYSIS
25927827         CHANGE.LOG         460 Byte         UNDER ANALYSIS
25710438         AutoRun.inf         167 Byte         CLEAN
25927828         SysLive.exe         44.69 KB         MALWARE
12900536         INFO2         20 Byte         KNOWN CLEAN
19467257         DESKTOP.INI         65 Byte         KNOWN CLEAN
7958267         install.exe         150.02 KB         KNOWN CLEAN



Please find a detailed report concerning each individual sample below: Filename        Result
CHANGE.LOG         UNDER ANALYSIS


The file 'CHANGE.LOG' has been determined to be 'UNDER ANALYSIS'.
Filename        Result
CHANGE.LOG         UNDER ANALYSIS


The file 'CHANGE.LOG' has been determined to be 'UNDER ANALYSIS'.
Filename        Result
AutoRun.inf         CLEAN


The file 'AutoRun.inf' has been determined to be 'CLEAN'. Our analysts did not discover any malicious content.
Filename        Result
SysLive.exe         MALWARE


The file 'SysLive.exe' has been determined to be 'MALWARE'. Our analysts named the threat Worm/Abuse.AW. The term "WORM/" denotes a worm that is able to spread itself for instance over the Internet (using eMail, peer-to-peer networks, IRC networks etc.).Detection is added to our virus definition file (VDF) starting with version 7.01.06.204. Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: TR/Crypt.XPACK.Gen.
Filename        Result
INFO2         KNOWN CLEAN


The file 'INFO2' has been determined to be 'KNOWN CLEAN'. In particular this means that we could not find any malicious content. Please note that the file is part of 'Microsoft Windows XP Mode 1 '.
Filename        Result
DESKTOP.INI         KNOWN CLEAN


The file 'DESKTOP.INI' has been determined to be 'KNOWN CLEAN'. In particular this means that we could not find any malicious content. Please note that the file is part of 'Microsoft Windows XP Mode 1 '.
Filename        Result
install.exe         KNOWN CLEAN


The file 'install.exe' has been determined to be 'KNOWN CLEAN'. In particular this means that we could not find any malicious content. Please note that the file is part of 'Ashampoo ClipFinder HD 0 '.

Please note that you will receive an email which will contain the results shown above. In case the final outcome of the analysis is not yet finished for all files the notification will be sent once ready.
pipi1987
头像被屏蔽
发表于 2010-10-24 15:23:20 | 显示全部楼层
1x to avg
xukai3100
发表于 2010-10-24 15:44:16 | 显示全部楼层
360没反应
hansyu
发表于 2010-10-24 16:18:05 | 显示全部楼层
启发,to xandora(panda)
XMonster
发表于 2010-10-24 16:36:29 | 显示全部楼层
360 无压力kill
xiaoyaosanren
发表于 2010-10-24 16:57:25 | 显示全部楼层
老毒了 有图有真相


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
fatezero
发表于 2010-10-24 17:39:08 | 显示全部楼层
KIS

检测到威胁: Trojan.Win32.AutoRun.ard           AutoRun.inf               
检测到威胁: Worm.Win32.Abuse.aw         SysLive.exe/
s8706042
发表于 2010-10-24 23:28:14 | 显示全部楼层
PC-Cillin 2011: Mal_Otorun1
superkill
发表于 2010-10-25 00:13:14 | 显示全部楼层
mse 发现一个SysLive.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-9 11:24 , Processed in 0.084818 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表