查看: 2359|回复: 9
收起左侧

[误报文件] 求大家帮忙验证下是否有毒【已确认为误报】

[复制链接]
飘渺虚无
头像被屏蔽
发表于 2008-8-4 01:23:36 | 显示全部楼层 |阅读模式
有这么几个原因使我对它迷惑。
该样本被加过北斗壳,不知是否是壳引起的误报
我用avk里的BD引擎扫会报,但是在线多引擎里的BD却不报,不知是引擎版本差异引起的还是因为BD已经把它入了白名单
由于我现在的条件限制无法自己验证,so请众卡饭帮忙验证下
附多引擎扫描结果
File CHS.exe received on 08.03.2008 18:44:54 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 22/36 (61.12%)

Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___
.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results


Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.  
Email:



AntivirusVersionLast UpdateResult
AhnLab-V32008.7.29.12008.08.02Win-Trojan/Xema.variant
AntiVir7.8.1.152008.08.01TR/FlyStudio.AI.1975
Authentium5.1.0.42008.08.03W32/Nuj.A.gen!Eldorado
Avast4.8.1195.02008.08.03Win32:Neptunia-IH
AVG8.0.0.1562008.08.03-
BitDefender7.22008.08.03-
CAT-QuickHeal9.502008.08.02(Suspicious) - DNAScan
ClamAV0.93.12008.08.03PUA.Packed.NPack-4
DrWeb4.44.0.091702008.08.03-
eSafe7.0.17.02008.08.03Suspicious File
eTrust-Vet31.6.60022008.08.02-
Ewido4.02008.08.03-
F-Prot4.4.4.562008.08.03W32/Nuj.A.gen!Eldorado
F-Secure7.60.13501.02008.08.03W32/Hupigon.gen67
Fortinet3.14.0.02008.08.03-
GData2.0.7306.10232008.08.03Win32:Neptunia-IH
IkarusT3.1.1.34.02008.08.03Backdoor.Win32.Agent.ahj
K7AntiVirus7.10.4022008.08.02Trojan.Win32.Malware.New
Kaspersky7.0.0.1252008.08.03-
McAfee53522008.08.01New Malware.hr
Microsoft1.38072008.08.03Worm:Win32/Nuj.A
NOD32v233222008.08.03-
Norman5.80.022008.08.01W32/Hupigon.gen67
Panda9.0.0.42008.08.03-
PCTools4.4.2.02008.08.03Packed/NSPack
Prevx1V22008.08.03Malicious Software
Rising20.55.62.002008.08.03-
Sophos4.31.02008.08.03Troj/Dropr-K
Sunbelt3.1.1537.12008.08.01-
Symantec102008.08.03Trojan.Dropper
TheHacker6.2.96.3922008.08.02-
TrendMicro8.700.0.10042008.08.01WORM_HUPIGON.MKR
VBA323.12.8.22008.08.02-
ViRobot2008.8.1.13212008.08.01-
VirusBuster4.5.11.02008.08.02Packed/NSPack
Webwasher-Gateway6.6.22008.08.03Trojan.FlyStudio.AI.1975
Additional information
File size: 587634 bytes
MD5...: 280e6de3ac00e133f72d3c0dd1b05161
SHA1..: 4c8472b68604ace80f527bebc5da6ea6ca63b490
SHA256: 7624d34b1dcd51a11f6706e1dbb0a40dcbfe7b282f7ccd005e0834cdaa9238d7
SHA512: 7cdc99903c972af91d040a04ba887951f29e4e335bdb26820f1709a11a34c31e
0980da5b36c36a4e6f0d70ee3c6996fa8e8d6ffb59cf8abcf5a36063b45b46c9
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x427e29
timedatestamp.....: 0x3925136b (Fri May 19 10:11:55 2000)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.nsp0 0x1000 0x1c000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.nsp1 0x1d000 0x15000 0x14446 7.12 e9cbe3456c6e934dd859114f38eaa8cb
.nsp2 0x32000 0xafe 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e

( 2 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> USER32.DLL: MessageBoxA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogr ... 843ECBACF000E5F6CA2
packers (Kaspersky): PE_Patch, NSPack
packers (Authentium): NSPack, PE_Patch
packers (F-Prot): NSPack, PE_Patch


[ 本帖最后由 飘渺虚无 于 2008-8-4 13:50 编辑 ]
Palkia
发表于 2008-8-4 09:25:07 | 显示全部楼层
金山 0
303898443
发表于 2008-8-4 09:29:44 | 显示全部楼层
454无事。
csliss
发表于 2008-8-4 09:31:21 | 显示全部楼层
應該是誤報
tgzw1680
发表于 2008-8-4 09:35:40 | 显示全部楼层
误报
twtpy93123
发表于 2008-8-4 12:29:17 | 显示全部楼层
本人以身试毒,发现是个nero的双语转换软件而已~
Kitman
发表于 2008-8-4 12:35:13 | 显示全部楼层
The file 'CHS.exe' has been determined to be 'UNDER ANALYSIS'.
飘渺虚无
头像被屏蔽
 楼主| 发表于 2008-8-4 13:49:49 | 显示全部楼层
原帖由 twtpy93123 于 2008-8-4 12:29 发表
本人以身试毒,发现是个nero的双语转换软件而已~
饿,这个我本来就是在nero一个精简版里挖出来的样本。
多谢各位,最终确定这是一个误报。看看那多引擎扫描图很是壮观啊。
ps:费尔很囧,今天凌晨我发样本的时候还是不报的,结果我早上过来却发现报毒了,我喜爱的费尔啊。。。。。
qigang
发表于 2008-8-4 20:49:20 | 显示全部楼层
不知道误报修正没?
Kitman
发表于 2008-8-5 00:08:46 | 显示全部楼层
The file 'CHS.exe' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 21:05 , Processed in 0.122093 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表