查看: 2648|回复: 17
收起左侧

[可疑文件] 下载的工作软件辅助,帮忙看下

[复制链接]
sunnyjianna
发表于 2014-8-7 10:54:53 | 显示全部楼层 |阅读模式
本帖最后由 sunnyjianna 于 2014-8-7 12:22 编辑

今天不明原因的mapgis画好的图坏掉了,下载了mapgis伴侣来修复,直接被eset拦截了,关闭后又被金山卫士杀了,请各位看下这个是不是安全的软件

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Dust-;羅錠
发表于 2014-8-7 10:57:48 | 显示全部楼层
本帖最后由 Dust-;羅錠 于 2014-8-7 11:00 编辑

VIPRE

https://www.virustotal.com/zh-cn ... nalysis/1407380373/

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
XywCloud
发表于 2014-8-7 11:04:50 | 显示全部楼层
bav云杀
jordanbear
发表于 2014-8-7 11:08:28 | 显示全部楼层
Target:

C:\Users\JordanBear\Desktop\Vir

Options:


File types to scan All files
Heuristic analysis Enabled
Sandbox Enabled
Scanning compressed files Enabled
Use excluded extensions Disabled
Excluded extensions Not defined
Use excluded objects Disabled
Excluded objects Not defined



Antivirus version:

TrustPort Antivirus 5.1.0.4225


Results:

Files:
File path Scanning result Virus name Cleaning action
C:\Users\JordanBear\Desktop\Vir\test.exe Infected! Gen:Variant.Strictor.57962 (BitDefender) Quarantined
skyboybone
发表于 2014-8-7 11:08:55 | 显示全部楼层
都报了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
落漠
发表于 2014-8-7 11:11:44 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
消停
头像被屏蔽
发表于 2014-8-7 11:12:03 | 显示全部楼层
Filename: mapgis文件伴侣.exe
Threat name: SONAR.Heuristic.120
Full Path: Not Available
____________________________
____________________________
____________________________
mapgis文件伴侣.exe Threat name: SONAR.Heuristic.120
Locate

Few Users
Hundreds of users in the Norton Community have used this file.

Mature
This file was released 3 months ago.

High
This file risk is high.
____________________________

Source: External Media

Source File:
mapgis文件伴侣.exe
____________________________

File Actions

File: f:\norton样本\ mapgis文件伴侣.exe Threat Removed
File: c:\users\administrator\appdata\locallow\sogoupy\components\ componentconfig.ini Threat Removed
____________________________

Registry Actions

Registry change: HKEY_USERS\S-1-5-21-1071228153-3121885108-811120218-500\Software\ SogouInput.user->SogouComponentFirstLoad:1407381026 Repaired
Registry change: HKEY_USERS\S-1-5-21-1071228153-3121885108-811120218-500\Software\ SogouInput.user->Used:1407381026 Repaired
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32 Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->EnableFileTracing No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->EnableConsoleTracing No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->FileTracingMask No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->ConsoleTracingMask No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->MaxFileSize No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASAPI32->FileDirectory No Action Required
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->EnableFileTracing No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->EnableConsoleTracing No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->FileTracingMask No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->ConsoleTracingMask No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->MaxFileSize No Action Required
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ MapGIS文件伴侣_RASMANCS->FileDirectory No Action Required
Registry change: HKEY_USERS\S-1-5-21-1071228153-3121885108-811120218-500\Software\Microsoft\Windows\CurrentVersion\ Internet Settings->ProxyEnable:0 Repaired
Registry change: HKEY_USERS\S-1-5-21-1071228153-3121885108-811120218-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Connections->SavedLegacySettings:... Repaired
____________________________

Network Actions

Event: Network activity (Performed by f:\norton样本\mapgis文件伴侣.exe, PID:948) No action taken
____________________________

System Settings Actions

Event: Process start (Performed by f:\norton样本\mapgis文件伴侣.exe, PID:948) No action taken
(Performed by f:\norton样本\mapgis文件伴侣.exe, PID:948) No action taken
Event: Process start: f:\norton样本\ mapgis文件伴侣.exe, PID:948 (Performed by f:\norton样本\mapgis文件伴侣.exe, PID:948) No action taken
____________________________

Suspicious Actions

(Performed by f:\norton样本\mapgis文件伴侣.exe, PID:948) No action taken
____________________________

File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available
sunnyjianna
 楼主| 发表于 2014-8-7 11:16:31 | 显示全部楼层
看来用不了了。。。。。。。。。。。。。。。。。
欧阳宣
头像被屏蔽
发表于 2014-8-7 11:17:50 | 显示全部楼层
G DATA 互联网安全套装已阻止访问此网站。
该站点包含被感染的代码:Gen:Variant.Strictor.57962 (引擎A)。
656635525
发表于 2014-8-7 11:26:07 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-18 02:33 , Processed in 0.137713 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表