查看: 3284|回复: 10
收起左侧

[病毒样本] 好像是误报?

[复制链接]
基哥
发表于 2008-2-5 20:18:53 | 显示全部楼层 |阅读模式
文件信息
文件名称 :  perfmte.rar
文件大小 :  47070 byte
文件类型 :  RAR archive data, v1d, os
MD5 :  86ab6e1362e4b37d5c5d31d8752c2037
SHA1 :  807af911824abef0fe5a3ea451a66b9049992e68
扫描结果
扫描结果 :  6%的杀软(2/35)报告发现病毒
时间 :  2008/02/05 20:12:56 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared3.0.0.1262008.02.042008-02-04-
4.521
AntiVir7.6.0.627.0.2.932008-02-05HEUR/Malware
11.415
Arcavir1.0.42008020416352008-02-04-
9.080
AVAST1.0.8080204-02008-02-04-
14.008
AVG7.5.51.442269.19.20/12602008-02-05-
8.966
BitDefender7.60825.9789977.173392008-02-05-
16.367
CA (VET)9.0.0.14331.3.55122008-02-05-
22.829
ClamAV 0.9256922008-02-05-
0.069
Comodo2.112.0.0.4262008-02-05-
1.521
CP Secure1.1.0.6952008.02.042008-02-04-
21.995
Dr.WEB4.44.0.91702008.02.052008-02-05-
10.703
ewido4.0.0.22008.02.052008-02-05-
2.703
F-PROT4.4.1.52200802042008-02-04-
2.205
F-SECURE5.51.61002008.02.04.042008-02-04-
3.299
IKARUST3.1.01.152008.02.05.702612008-02-05-
1.864
MKS_VIR2.012008.02.052008-02-05-
10.086
NORMAN5.91.105.902008-02-04-
7.982
nProtect2008-02-05.0011624972008-02-05-
5.117
PrevxV2200802052008-02-05-
3.578
QuickHeal9.002008.02.042008-02-04-
3.908
SOPHOS2.53.14.252008-02-04-
3.984
The Hacker6.2.9v002092008-02-04-
1.218
VBA323.12.6.020080204.22232008-02-04-
3.097
ViRobot200802052008.02.052008-02-05-
0.732
VirusBuster4.3.19:99.121.1/11.02008-02-04-
3.758
卡巴斯基5.5.102008.02.052008-02-05-
13.606
安博士V32008.02.05.102008.02.052008-02-05-
1.973
江民杀毒10.00.6502008.02.052008-02-05-
1.604
熊猫卫士9.04.03.00012008.02.042008-02-04-
2.838
瑞星20.020.31.50.002008-02-16-
1.507
赛门铁克1.3.0.2420080204.0032008-02-04-
0.273
趋势8.500-10014.978.082008-02-04-
0.045
迈克菲5.2.0052222008-02-04-
5.010
金山毒霸2007.6.20.2492008.2.52008-02-05-
1.094
飞塔2.81-3.118.7142008-02-05Suspicious
2.445
注意: 就算报告发现病毒,也可能是杀软误报,请根据查毒结果自行判断
复制到剪贴板

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Graybird
发表于 2008-2-5 20:20:30 | 显示全部楼层
The file 'perfmte.exe' has been determined to be 'UNDER ANALYSIS'.

上报~
冷冷
发表于 2008-2-5 20:28:09 | 显示全部楼层
SBie 跑了下

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Graybird
发表于 2008-2-5 20:30:34 | 显示全部楼层

回复 3楼 冷_冷 的帖子

Starting the file scan:

Begin scan in 'E:\system32.rar'
E:\system32.rar
  [0] Archive type: RAR
  --> system32\javaiehlp.dll
      [DETECTION] Contains suspicious code HEUR/Malware
  --> system32\wmpdvdex.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [WARNING]   The file was ignored!

上报~
leonfg
发表于 2008-2-5 20:32:41 | 显示全部楼层
原帖由 冷_冷 于 2008-2-5 20:28 发表
SBie 跑了下

196821196822

nod 蜘蛛 继续过
Graybird
发表于 2008-2-5 20:39:08 | 显示全部楼层

回复 2楼 Graybird 的帖子

The file 'perfmte.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Agent.135203. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates. Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: HEUR/Malware.
wangjay1980
发表于 2008-2-5 20:39:17 | 显示全部楼层
可能是某个音频软件的,扔给KL
Graybird
发表于 2008-2-5 21:31:04 | 显示全部楼层

回复 4楼 Graybird 的帖子

The file 'wmpdvdex.dll' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates

FALSE POSITIVE~
基哥
 楼主| 发表于 2008-2-5 21:40:18 | 显示全部楼层
真的是误报
wangjay1980
发表于 2008-2-5 21:49:54 | 显示全部楼层
Hello,

msfv32.dll, perfmte.exe_

No malicious code were found in these files.

Please quote all when answering.

--
Best regards, Goncharov Ilya
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: msfv32.rar
> Attachment: perfmte.rar
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-2-3 22:30 , Processed in 0.082336 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表