Re: Found virus? Post it here!
Thanks for the samples guys, they're really appreciated
Thanks for the samples guys, they're really appreciated
Adware - Eorezo
unpacked included
password : infected
regards,
icr
Last edited by icr (2011-10-19 18:00:17)
Parite.b
bm._exe
MD5 : 8ba1ffda341cef5347b4a075e934e84f
igb2._tmp
MD5 : 685f1cbd4af30a1d0c25f252d399a666
Password : infected
regards,
icr
Last edited by icr (2011-10-21 18:59:21)
variants of security shield
MD5 : 327A5F001B9F922912E6DCE239B2CB98 [Register or log in to view the URL]
MD5 : EA77763BDC21F76166A056BD6360DF26 [Register or log in to view the URL]
Password : infected
regards,
icr
Some recent samples (caught within last 10 days):
Kaspersky: Backdoor.Win32.Floder.elz
md5: 01D4E581F18D2B74FCFEFFEB7C2A5C3B
[Register or log in to view the URL]
pass: infected
regards,
koczyn
Last edited by koczyn (2011-11-28 16:29:27)
Kaspersky: Backdoor.Sdbot
md5: 2A5D5761D7E21EAAB597BF92A210B9EE
[Register or log in to view the URL]
pass: infected
regards,
koczyn
Kaspersky: Trojan.Win32.Scar.fbxo
md5: 4D719C252CEF15D7FC339218B405E464
[Register or log in to view the URL]
pass: infected
regards,
koczyn
Symantec: W32.IRCBot.NG!gen5
md5: 95B56F63196F4C67381272F5F14C435E
[Register or log in to view the URL]
pass: infected
regards,
koczyn
Last edited by koczyn (2011-11-28 16:38:40)
Not recognized
md5: 1E852DB01D659763BA6757263373E85A
[Register or log in to view the URL]
pass: infected
regards,
korczyn
what'd you use to compress it? I've tried 3 programs so far and I get errors with all of them.
what'd you use to compress it? I've tried 3 programs so far and I get errors with all of them.
[Register or log in to view the URL]
command: zip -9 -e file.zip file
thanks koczyn:)
the only problem is i cant see the links because of forum's rules:(
Last edited by Nima SSto (2011-12-01 11:41:36)
thanks koczyn:)
the only problem is i cant see the links because of forum's rules:(
I have the same problem, but hope to get some karma soon
Another sample from last days:
Recognized only by Sophos as Inject-CY,
md5: 74361572832D8A3B03691DBD570DF2F8
[Register or log in to view the URL]
link: [Register or log in to view the URL]
pass: infected
...and the file (qx200.exe) requested from the remote server by Inject-CY:
Not recognized
md5: 7D60EA1A8A3238177EAACB8D93FC8F4B
[Register or log in to view the URL]
link: [Register or log in to view the URL]
pass: infected
regards,
koczyn
VB Worm Aka Cintaku.A included VB original Source Code
[Register or log in to view the URL]
Best Regards,
Win7 Antispyware 2012:
-------------------------------
Antivirus Version Last Update Result
AhnLab-V3 2011.12.11.00 2011.12.12 Trojan/Win32.Jorik
AntiVir 7.11.19.67 2011.12.12 TR/FakeAV.arc
Antiy-AVL 2.0.3.7 2011.12.12 -
Avast 6.0.1289.0 2011.12.12 Win32:Downloader-LSL [Trj]
AVG 10.0.0.1190 2011.12.12 -
BitDefender 7.2 2011.12.12 Gen:Variant.Graftor.6553
ByteHero 1.0.0.1 2011.12.07 Trojan.Win32.Heur.Gen
CAT-QuickHeal 12.00 2011.12.12 -
ClamAV 0.97.3.0 2011.12.12 -
Commtouch 5.3.2.6 2011.12.11 -
Comodo 10932 2011.12.12 TrojWare.Win32.Kryptik.BBB
DrWeb 5.0.2.03300 2011.12.12 -
Emsisoft 5.1.0.11 2011.12.12 Trojan.Win32.Sirefef!IK
eSafe 7.0.17.0 2011.12.11 -
eTrust-Vet 37.0.9619 2011.12.12 -
F-Prot 4.6.5.141 2011.12.12 -
F-Secure 9.0.16440.0 2011.12.12 Gen:Variant.Graftor.6553
Fortinet 4.3.388.0 2011.12.12 -
GData 22 2011.12.12 Gen:Variant.Graftor.6553
Ikarus T3.1.1.109.0 2011.12.12 Trojan.Win32.Sirefef
Jiangmin 13.0.900 2011.12.11 -
K7AntiVirus 9.119.5640 2011.12.09 Trojan
Kaspersky 9.0.0.837 2011.12.12 Trojan.Win32.Menti.jiwo
McAfee 5.400.0.1158 2011.12.12 FakeAlert-Rena.p
McAfee-GW-Edition 2010.1E 2011.12.12 FakeAlert-Rena.p
Microsoft 1.7903 2011.12.12 -
NOD32 6703 2011.12.12 a variant of Win32/Kryptik.WXW
Norman 6.07.13 2011.12.12 W32/Hiloti.GAT
nProtect 2011-12-12.01 2011.12.12 -
Panda 10.0.3.5 2011.12.11 Trj/CI.A
PCTools 8.0.0.5 2011.12.12 -
Prevx 3.0 2011.12.12 -
Rising 23.88.00.02 2011.12.12 -
Sophos 4.72.0 2011.12.12 Mal/FakeAV-MQ
SUPERAntiSpyware 4.40.0.1006 2011.12.10 -
Symantec 20111.2.0.82 2011.12.12 -
TheHacker 6.7.0.1.356 2011.12.11 -
TrendMicro 9.500.0.1008 2011.12.12 -
TrendMicro-HouseCall 9.500.0.1008 2011.12.12 -
VBA32 3.12.16.4 2011.12.12 -
VIPRE 11239 2011.12.12 Trojan.Win32.Generic.pak!cobra
ViRobot 2011.12.12.4821 2011.12.12 -
VirusBuster 14.1.111.0 2011.12.12 -