【警告】KAVO變種病毒樣本



贊助商連結


hohobear
2008-01-02, 11:28 AM
最近公司同仁的隨身碟,與其他人交換資料後中毒
發現是新的KAVO變種

ntdeIect.com
xadeIect.com


附上樣本,請各位參考使用

贊助商連結


haol
2008-01-02, 01:34 PM
不算新...
f-secure found Trojan-PSW.Win32.OnLineGames.kxo(ntdeIect.com) and
Worm.Win32.AutoRun.bhx(XAdeIect.com)

kk_pczone
2008-01-02, 01:44 PM
avira二支都捉到

a9000220102
2008-01-02, 04:48 PM
C:\Documents and Settings\*\桌面\ntdeIect_xadeIect.zip >>ZIP >>ntdeIect.com - Win32/Pacex.Gen virus
C:\Documents and Settings\*\桌面\ntdeIect_xadeIect.zip >>ZIP >>XAdeIect.com - Win32/Pacex.Gen trojan

NOD32 病毒碼2759

yuping
2008-01-03, 09:57 AM
檔案 ntdeIect_xadeIect.zip 接收於 2008.01.03 02:53:12 (CET)
反病毒引擎 版本 最後更新 掃瞄結果
AhnLab-V3 2008.1.3.10 2008.01.02 -
AntiVir 7.6.0.46 2008.01.02 TR/Crypt.NSPM.Gen
Authentium 4.93.8 2008.01.02 -
Avast 4.7.1098.0 2008.01.02 -
AVG 7.5.0.516 2008.01.02 Obfustat.ADPF
BitDefender 7.2 2008.01.03 Packer.Malware.NSAnti.J
CAT-QuickHeal 9.00 2008.01.02 Win32.Packed.NSAnti.r
ClamAV 0.91.2 2008.01.02 Trojan.Spy-18063
DrWeb 4.44.0.09170 2008.01.02 modification of Win32.Besso
eSafe 7.0.15.0 2008.01.02 suspicious Trojan/Worm
eTrust-Vet 31.3.5426 2008.01.03 -
Ewido 4.0 2008.01.02 -
FileAdvisor 1 2008.01.03 -
Fortinet 3.14.0.0 2008.01.02 W32/OnLineGames.KXO!tr.pws
F-Prot 4.4.2.54 2008.01.02 -
F-Secure 6.70.13030.0 2008.01.02 Worm.Win32.AutoRun.bhx
Ikarus T3.1.1.15 2008.01.03 Trojan-PWS.Win32.OnLineGames.kxo
Kaspersky 7.0.0.125 2008.01.03 Trojan-PSW.Win32.OnLineGames.kxo
McAfee 5198 2008.01.03 New Malware.hw
Microsoft 1.3109 2008.01.03 VirTool:Win32/Obfuscator!Mal
NOD32v2 2762 2008.01.03 Win32/Pacex.Gen
Norman 5.80.02 2008.01.02 W32/Smalltroj.BSIC
Panda 9.0.0.4 2008.01.03 W32/Lineage.GWF.worm
Prevx1 V2 2008.01.03 Generic.Malware
Rising 20.25.22.00 2008.01.02 -
Sophos 4.24.0 2008.01.03 W32/Autorun-AB
Sunbelt 2.2.907.0 2008.01.03 Trojan.Crypt.NSPM.Gen
Symantec 10 2008.01.03 W32.SillyDC
TheHacker 6.2.9.178 2008.01.03 Trojan/PSW.OnLineGames.kxo
VBA32 3.12.2.5 2008.01.02 Trojan-PSW.Win32.OnLineGames.kxo
VirusBuster 4.3.26:9 2008.01.02 -
Webwasher-Gateway 6.6.2 2008.01.03 Trojan.Crypt.NSPM.Gen
附加訊息
File size: 229688 bytes
MD5: 3312137a6563db07720692c41b790854
SHA1: 748e3299c7cfb8212c2d08427d4fde9de4df1741
PEiD: -
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=5FFFF4FF730D84B2C71B01789ED9D00062CB5066

反病毒引擎 版本 最後更新 掃瞄結果
AhnLab-V3 2008.1.3.10 2008.01.02 -
AntiVir 7.6.0.46 2008.01.02 TR/Crypt.NSPM.Gen
Authentium 4.93.8 2008.01.02 -
Avast 4.7.1098.0 2008.01.02 -
AVG 7.5.0.516 2008.01.02 Obfustat.ADPF
BitDefender 7.2 2008.01.03 Packer.Malware.NSAnti.J
CAT-QuickHeal 9.00 2008.01.02 Win32.Packed.NSAnti.r
ClamAV 0.91.2 2008.01.02 Trojan.Spy-18063
DrWeb 4.44.0.09170 2008.01.02 modification of Win32.Besso
eSafe 7.0.15.0 2008.01.02 suspicious Trojan/Worm
eTrust-Vet 31.3.5426 2008.01.03 -
Ewido 4.0 2008.01.02 -
FileAdvisor 1 2008.01.03 -
Fortinet 3.14.0.0 2008.01.02 W32/OnLineGames.KXO!tr.pws
F-Prot 4.4.2.54 2008.01.02 -
F-Secure 6.70.13030.0 2008.01.02 Worm.Win32.AutoRun.bhx
Ikarus T3.1.1.15 2008.01.03 Trojan-PWS.Win32.OnLineGames.kxo
Kaspersky 7.0.0.125 2008.01.03 Trojan-PSW.Win32.OnLineGames.kxo
McAfee 5198 2008.01.03 New Malware.hw
Microsoft 1.3109 2008.01.03 VirTool:Win32/Obfuscator!Mal
NOD32v2 2762 2008.01.03 Win32/Pacex.Gen
Norman 5.80.02 2008.01.02 W32/Smalltroj.BSIC
Panda 9.0.0.4 2008.01.03 W32/Lineage.GWF.worm
Prevx1 V2 2008.01.03 Generic.Malware
Rising 20.25.22.00 2008.01.02 -
Sophos 4.24.0 2008.01.03 W32/Autorun-AB
Sunbelt 2.2.907.0 2008.01.03 Trojan.Crypt.NSPM.Gen
Symantec 10 2008.01.03 W32.SillyDC
TheHacker 6.2.9.178 2008.01.03 Trojan/PSW.OnLineGames.kxo
VBA32 3.12.2.5 2008.01.02 Trojan-PSW.Win32.OnLineGames.kxo
VirusBuster 4.3.26:9 2008.01.02 -
Webwasher-Gateway 6.6.2 2008.01.03 Trojan.Crypt.NSPM.Gen

附加訊息
File size: 229688 bytes
MD5: 3312137a6563db07720692c41b790854
SHA1: 748e3299c7cfb8212c2d08427d4fde9de4df1741
PEiD: -
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=5FFFF4FF730D84B2C71B01789ED9D00062CB5066