查看: 2761|回复: 5
收起左侧

[误报文件] 红伞误报autoguarder新版升级程序

[复制链接]
真.菲戈
发表于 2008-6-23 10:03:10 | 显示全部楼层 |阅读模式
用来清理办公电脑U盘病毒的……
昨天升级程序更新到5.0后险些被红伞干掉~
ms是因为加了UPX的壳引起的,已上报

File ID Filename Size (Byte)Result
25055010 LiveUpdate.exe 327.5 KB UNDER ANALYSIS

文件 LiveUpdate.exe 接收于 2008.06.23 03:53:48 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.6.22.02008.06.22-
AntiVir7.8.0.592008.06.22ADSPY/AdSpy.Gen
Authentium5.1.0.42008.06.21-
Avast4.8.1195.02008.06.23-
AVG7.5.0.5162008.06.22-
BitDefender7.22008.06.23-
CAT-QuickHeal9.502008.06.20-
ClamAV0.93.12008.06.23-
DrWeb4.44.0.091702008.06.22-
eSafe7.0.15.02008.06.22suspicious Trojan/Worm
eTrust-Vet31.6.58922008.06.21-
Ewido4.02008.06.22-
F-Prot4.4.4.562008.06.21-
F-Secure7.60.13501.02008.06.20-
Fortinet3.14.0.02008.06.22-
GData2.0.7306.10232008.06.23-
IkarusT3.1.1.26.02008.06.23-
Kaspersky7.0.0.1252008.06.23-
McAfee53222008.06.20-
Microsoft1.36042008.06.23-
NOD32v232072008.06.22-
Norman5.80.022008.06.20-
Panda9.0.0.42008.06.22-
Prevx1V22008.06.23-
Rising20.49.62.002008.06.22-
Sophos4.30.02008.06.23-
Sunbelt3.0.1153.12008.06.15-
Symantec102008.06.22-
TheHacker6.2.92.3582008.06.21-
TrendMicro8.700.0.10042008.06.20-
VBA323.12.6.72008.06.22-
VirusBuster4.3.26:92008.06.12-
Webwasher-Gateway6.6.22008.06.23-

附加信息
File size: 335360 bytes
MD5...: af868a1fc0a3b3ffeeec8232545f761f
SHA1..: 4302328c85914a96d5f858deb8765770ce7ed429
SHA256: 11117eb0ccd059a7f6285a34716bc7f3f0beae7282065819245fcaf1d2e4eda8
SHA512:32e32e222c07325f5805635b454d62a48613d93db3509b499044efba0d3b74fe<br>59f04e23a64a2eea05cce26cfa783230900c9b3554d86b166173c465c6a66f49
PEiD..: -
PEInfo:PE Structure information<br><br>( base data)<br>entrypointaddress.: 0x49bcb0<br>timedatestamp.....:0x485e4309 (Sun Jun 22 12:18:17 2008)<br>machinetype.......:0x14c (I386)<br><br>( 3 sections )<br>name viraddvirsiz rawdsiz ntrpy md5<br>UPX0 0x1000 0x71000 0x0 0.00d41d8cd98f00b204e9800998ecf8427e<br>UPX1 0x72000 0x2a000 0x2a0007.92 58ac2fb4131121ee7825de91bf30fd4a<br>.rsrc 0x9c000 0x280000x27a00 6.65 c644c016f6e5d986d42dbd8b95d56dc1<br><br>( 14imports ) <br>&gt; KERNEL32.DLL: LoadLibraryA,GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree,ExitProcess<br>&gt; ADVAPI32.dll:RegOpenKeyW<br>&gt; COMCTL32.dll:InitCommonControlsEx<br>&gt; COMDLG32.dll:GetFileTitleW<br>&gt; GDI32.dll: Escape<br>&gt;ole32.dll: CoTaskMemFree<br>&gt; OLEAUT32.dll:-<br>&gt; oledlg.dll: OleUIBusyW<br>&gt; PSAPI.DLL:EnumProcessModules<br>&gt; SHELL32.dll:ShellExecuteW<br>&gt; SHLWAPI.dll:PathIsUNCW<br>&gt; USER32.dll: GetDC<br>&gt;WINSPOOL.DRV: OpenPrinterW<br>&gt; WS2_32.dll:-<br><br>( 0 exports ) <br>
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX




本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
小邪邪
发表于 2008-6-23 10:33:42 | 显示全部楼层
UPX 可是一款很普遍可执行程序文件压缩器,连这也报?强
SIGKILL
发表于 2008-6-23 10:36:19 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\桌面\LiveUpdate.rar'
C:\Documents and Settings\Administrator\桌面\


End of the scan: 2008年6月23日星期一  10:35
Used time: 00:03 min

The scan has been done completely.

      0 Scanning directories
      2 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      2 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
残缺的唯美
发表于 2008-6-23 10:38:09 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
曲中求
发表于 2008-6-23 12:53:01 | 显示全部楼层

回复 1楼 真.菲戈 的帖子

呵呵,非UPX引起,ADSPY广谱,光一个UPX,红伞是不会报的。

已上报,等结果看看。

Suspicious Files and Miscellaneous Uploads

Thank you for your submission. Below you can see the current status of the uploaded files.



We received the following archive files:
File ID         Filename        Size (Byte)        Result
25055092         LiveUpdate.rar        272.87 KB        OK


A listing of files contained inside archives alongside their results can be found below:File ID         Filename        Size (Byte)        Result
25055010         LiveUpdate.exe         327.5 KB         UNDER ANALYSIS



Please find a detailed report concerning each individual sample below: Filename        Result
 LiveUpdate.exe         UNDER ANALYSIS


The file 'LiveUpdate.exe' has been determined to be 'UNDER ANALYSIS'. 

Please note that you will receive an email which will contain the results shown above. In case the final outcome of the analysis is not yet finished for all files the notification will be sent once ready.

[ 本帖最后由 曲中求 于 2008-6-23 12:57 编辑 ]
真.菲戈
 楼主| 发表于 2008-6-23 21:30:47 | 显示全部楼层
md,死不悔改~
?Filename         Result
LiveUpdate.exe          MALWARE

The file 'LiveUpdate.exe' has been determined to be 'MALWARE'. Our analysts named the threat ADSPY/AdSpy.Gen. The term "ADSPY/" denotes adware or spyware. This type of malware is able to change browser settings for example by manipulating registry settings or by using of NTFS-streams. Very often IEexploits are used to manipulate the browserhelp.dll.This malware is detected by a special detection routine from the engine module.

只好加排除了~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-27 23:33 , Processed in 0.118917 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表