返回列表 发新帖
楼主: qiqi00612

[病毒样本] 几个星期了MKF还查不出这病毒!这是我上次发布过的杀病毒的病毒完整板

 楼主| 发表于 2007-5-18 00:23:09 | 显示全部楼层
原帖由 playx 于 2007-5-17 16:30 发表

We have analyzed your submission.  The following is a report of our
findings for each file you have submitted:

filename:  u.rar
machine: Machine
result: See the develope ...

发表于 2007-5-18 01:29:18 | 显示全部楼层

filename:  viurs2.rar
machine: Machine
result: See the developer notes

filename: setup.exe
machine: Machine
result: See the developer notes

filename: eyviewer.exe
machine: Machine
result: This file is detected as W32.Looked.BK.

filename: searchtool.dll
machine: Machine
result: This file is detected as Adware.Searchtool.  

filename: horoscopes.exe
machine: Machine
result: See the developer notes

filename: slimjunn.exe
machine: Machine
result: See the developer notes

filename: u.vbe
machine: Machine
result: This file is clean

filename: u.bat
machine: Machine
result: This file is detected as W32.Uisgon.A.  

Developer notes:
viurs2.rar is a container file of type  RAR
setup.exe Our automation was unable to identify any malicious content
in this submission.
The file will be stored for further human analysis  This file is
contained by   viurs2.rar
eyviewer.exe is detected and repaired by NAV with the latest available
definition.  Please follow the instruction at the end of this email
message to install the latest available definitions.  This file is
contained by   viurs2.rar
searchtool.dll is an adware   This file is contained by   viurs2.rar
horoscopes.exe Our automation was unable to identify any malicious
content in this submission.
The file will be stored for further human analysis  This file is
contained by   viurs2.rar
slimjunn.exe The submitted file will just pop up advertisements. It is
safe to delete this file.   This file is contained by   viurs2.rar
u.vbe is a clean file  This file is contained by   viurs2.rar
u.bat is non-repairable threat. Please delete this file and replace it
if necessary. Please follow the instruction at the end of this email
message to install the latest available definitions.  This file is
contained by   viurs2.rar
发表于 2007-5-18 01:56:03 | 显示全部楼层

filename:  ebayshop.rar
machine: Machine
result: See the developer notes

filename: ebayshop.exe
machine: Machine
result: This file is detected as Adware.Kiswin.  

Developer notes:
ebayshop.rar is an infected container file of type  RAR
ebayshop.exe installs Adware.  This file is contained by   ebayshop.rar

filename:  autorun.rar
machine: Machine
result: This file is clean

filename: autorun.inf
machine: Machine
result: This file is clean

Developer notes:
autorun.rar is a container file of type  RAR
autorun.inf is a clean file  This file is contained by   autorun.rar

filename:  AUTOEXEC.rar
machine: Machine
result: This file is clean

filename: AUTOEXEC.BAT
machine: Machine
result: This file is clean

filename: msg-2624-3.txt
machine: Machine
result: This file is clean

Developer notes:
AUTOEXEC.rar is a container file of type  RAR
AUTOEXEC.BAT is a container file of type  MIME. This file is contained
by   AUTOEXEC.rar
msg-2624-3.txt  is a harmless part of a worm-generated email message.  
This file is contained by  AUTOEXEC.BAT
 楼主| 发表于 2007-5-18 10:15:22 | 显示全部楼层
原帖由 playx 于 2007-5-18 01:29 发表

filename:  viurs2.rar
machine: Machine
result: See the developer notes

filename: setup.exe
machine: Machine
result: See the developer not ...

发表于 2007-5-18 13:56:23 | 显示全部楼层

[ 本帖最后由 playx 于 2007-5-18 13:58 编辑 ]
发表于 2007-5-18 14:21:11 | 显示全部楼层
 楼主| 发表于 2007-5-19 00:57:33 | 显示全部楼层
原帖由 wjjxqx 于 2007-5-18 14:21 发表

发表于 2007-5-23 16:15:48 | 显示全部楼层

filename:  viurs1.rar
machine: Machine
result: See the developer notes

filename: desktop.ini
machine: Machine
result: This file is clean

filename: autorun.inf
machine: Machine
result: This file is clean

filename: ebayshop.exe
machine: Machine
result: This file is detected as Adware.Kiswin.  

filename: 8bye.txt
machine: Machine
result: This file is clean

filename: angelinajoliedt.exe
machine: Machine
result: This file is detected as Trojan.Dropper.

filename: AUTOEXEC.BAT
machine: Machine

filename: msg-2624-1.txt
machine: Machine
result: This file is clean

Developer notes:
viurs1.rar is an archive that contains a non-repairable
worm(s)/trojan(s).  Please delete the afflicted file(s) and restore from a known
clean backup, as needed.
desktop.ini is a clean file  This file is contained by   viurs1.rar
autorun.inf is a clean file  This file is contained by   viurs1.rar
ebayshop.exe is an adware   This file is contained by   viurs1.rar
8bye.txt is a clean file  This file is contained by   viurs1.rar
angelinajoliedt.exe is non-repairable threat. Please delete this file
and replace it if necessary. Please follow the instruction at the end of
this email message to install the latest available definitions.  This
file is contained by   viurs1.rar
AUTOEXEC.BAT   This file is contained by   viurs1.rar
msg-2624-1.txt  is a clean file.  This file is contained by  

Symantec Security Response has determined that the sample(s) that you
provided are infected with a virus, worm, or Trojan. We have created
RapidRelease definitions that will detect this threat. Please follow the
instruction at the end of this email message to download and install the
latest RapidRelease definitions.
Downloading and Installing RapidRelease Definition Instructions:
1. Open your Web browser. If you are using a dial-up connection,
connect to any Web site, such as:  http://securityresponse.symantec.com/
2. Click this link to the ftp site:
ftp://ftp.symantec.com/public/en ... releasedefsi32.exe.
If it does not go to the site (this could take a minute or so if you
have a slow connection), copy and paste the address into the address bar
of your Web browser and then press Enter.
3. When a download dialog box appears, save the file to the Windows
4. Double-click the downloaded file and follow the prompts.

Should you have any questions about your submission, please contact
your regional technical support from the Symantec website and give them
the tracking number in the subject of this message.

This message was generated by Symantec Security Response automation.

For USA:
For electronic support options, Symantec provides On-Line Services at
发表于 2007-5-23 17:01:12 | 显示全部楼层


您需要 登录 才可以下载或查看,没有帐号?快速注册

您需要登录后才可以回帖 登录 | 快速注册


手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 09:54 , Processed in 0.107851 second(s), 15 queries .


快速回复 客服 返回顶部 返回列表