楼主: kurakimai
收起左侧

[病毒样本] CLIENT 103楼更新

  [复制链接]
kurakimai
 楼主| 发表于 2011-5-4 19:42:54 | 显示全部楼层
UPDATE
咆哮的蜗牛
发表于 2011-5-4 19:45:09 | 显示全部楼层
11L qvm20
留侯
发表于 2011-5-4 19:45:48 | 显示全部楼层
過大蜘蛛,已上報!
3801187
发表于 2011-5-4 20:32:31 | 显示全部楼层
金山毒霸云鉴定管理器
http://www.ijinshan.com

文件安全信息:
文件路径:C:\Users\qwead\Desktop\client1.exe
文件状况:安全

文件广度:

文件鉴定时间:2011-05-04 20:29:38

文件签名:
文件指纹-MD5:d41d8cd98f00b204e9800998ecf8427e
瓜皮猫
发表于 2011-5-4 20:45:27 | 显示全部楼层
本帖最后由 三生缘石 于 2011-5-4 21:07 编辑

11L
to eset
[/quote]
[quote]Dear 微亿毫,

Thank you for your submission.
The detection for this threat will be included in our next signature update.

client.exe - Win32/Kelihos.A trojan

Regards,

Dalibor Drzik
Malware Researcher
ESET spol. s r.o.

zaqwsx1208
头像被屏蔽
发表于 2011-5-4 20:47:44 | 显示全部楼层
11L
KIS 检测到两威胁
lf968
发表于 2011-5-4 20:56:41 | 显示全部楼层
Firewall: Automatic decision        2011/5/4 20:52        Blocked        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access blocked to: 127.0.0.1:50214
Firewall: User decision        2011/5/4 20:52        Blocked        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access blocked to: 192.168.1.100:80
Firewall: User decision        2011/5/4 20:52        Blocked        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access blocked to: (xfstat.qq.com) 127.0.0.1:50208
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 122.100.69.5:80
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: (xfstat.qq.com) 127.0.0.1:50205
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 119.201.243.41:80
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: (xfstat.qq.com) 127.0.0.1:50202
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 192.168.1.100:80
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 14.32.101.44:80
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 121.143.148.14:80
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: (xfstat.qq.com) 127.0.0.1:50197
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 14.32.101.44:80
Program Guard: client.exe        2011/5/4 20:52        Blocked        C:\Users\xxxx\Desktop\client\client.exe wants to get a list of the files F:\*
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: 14.32.101.44:80
Program Guard: client.exe        2011/5/4 20:52        Blocked        C:\Users\xxxx\Desktop\client\client.exe wants to get a list of the files E:\*
Firewall: User decision        2011/5/4 20:52        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: (xfstat.qq.com) 127.0.0.1:50191
Program Guard: client.exe        2011/5/4 20:51        Blocked        C:\Users\xxxx\Desktop\client\client.exe wants to get a list of the files D:\*
Firewall: User decision        2011/5/4 20:51        Allowed        C:\Users\xxxx\Desktop\client\client.exe, Outgoing TCP access allowed to: (xfstat.qq.com) 127.0.0.1:50191
Program Guard: client.exe        2011/5/4 20:51        Blocked        C:\Users\xxxx\Desktop\client\client.exe wants to get a list of the files C:\*
Program Guard: client.exe        2011/5/4 20:51        Allowed        C:\Windows\explorer.exe -> C:\Users\xxxx\Desktop\client\client.exe
594157544
发表于 2011-5-4 22:28:52 | 显示全部楼层
本帖最后由 594157544 于 2011-5-4 22:53 编辑



卡巴斯基一点都不给力啊!!


kurakimai
 楼主| 发表于 2011-5-4 22:30:42 | 显示全部楼层
回复 18楼 594157544 的帖子

我等你做行为分析呢
594157544
发表于 2011-5-4 22:34:40 | 显示全部楼层
kurakimai 发表于 2011-5-4 22:30
回复 18楼 594157544 的帖子

我等你做行为分析呢

⊙﹏⊙b汗  今天恐怕不行啦,卡巴扫描都是到66%就卡住了,电脑都有点假死啦
  
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-14 13:59 , Processed in 0.095996 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表