查看: 4036|回复: 10
收起左侧

[病毒样本] 强悍的VirusTotal结果

[复制链接]
emutony
发表于 2008-8-12 09:11:54 | 显示全部楼层 |阅读模式
这不是百度工具条的组件吗?

反病毒引擎版本最后更新扫描结果
AhnLab-V32008.7.29.12008.08.02-
AntiVir7.8.1.152008.08.04TR/Rootkit.AK
Authentium5.1.0.42008.08.03W32/Backdoor.ARKX
Avast4.8.1195.02008.08.03Win32:Trojan-gen {Other}
AVG8.0.0.1562008.08.03Generic2.KHD
BitDefender7.22008.08.04-
CAT-QuickHeal9.502008.08.02AdWare.Boran.w (Not a Virus)
ClamAV0.93.12008.08.04-
DrWeb4.44.0.091702008.08.04Adware.Borlander
eSafe7.0.17.02008.08.03-
eTrust-Vet31.6.60022008.08.02-
Ewido4.02008.08.03Not-A-Virus.Adware.BDSearch
F-Prot4.4.4.562008.08.03W32/Backdoor.ARKX
F-Secure7.60.13501.02008.08.04-
Fortinet3.14.0.02008.08.03Adware/Boran
GData2.0.7306.10232008.08.03Win32:Trojan-gen
IkarusT3.1.1.34.02008.08.04not-a-virus:AdWare.Win32.Boran.w
K7AntiVirus7.10.4022008.08.02Rootkit.Win32.Agent.Family
Kaspersky7.0.0.1252008.08.04-
McAfee53522008.08.01potentially unwanted program Adware-BDSearch
Microsoft1.38072008.08.04BrowserModifier:Win32/BaiduSobar
NOD32v233232008.08.04-
Norman5.80.022008.08.01W32/Rootkit.CHW
Panda9.0.0.42008.08.03Rootkit/Baidu
PCTools4.4.2.02008.08.03-
Prevx1V22008.08.04Adware
Rising20.55.62.002008.08.03-
Sophos4.31.02008.08.03Baidu Bar
Sunbelt3.1.1537.12008.08.01-
TheHacker6.2.96.3922008.08.02-
TrendMicro8.700.0.10042008.08.01-
VBA323.12.8.22008.08.02-
ViRobot2008.8.1.13212008.08.01Adware.Baidu.28672
VirusBuster4.5.11.02008.08.03-
Webwasher-Gateway6.6.22008.08.04Trojan.Rootkit.AK
附加信息
File size: 28672 bytes
MD5...: d8ad2f959208197455aa4a2a67be9f69
SHA1..: 928c73a689a9cda6f82b1cb59fd6882221cf4ebb
SHA256: bf5168f26685a6c0ec9b16f8dc4671d877d8aaaf137a6a3509452a1ff9898f97
SHA512: 03f98af586cea700b0a9ca3a9746c453e8cf32d8eb20e7c3f1d0062abdadd031
c6104c1baefa4133188ea51d2f37c867509b4ca8bc0e03095cec6e2b47d6115e
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x113cd
timedatestamp.....: 0x455537d1 (Sat Nov 11 02:39:13 2006)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4928 0x4a00 6.35 9db8eba7563ac4a6845fd4b46289174d
.rdata 0x6000 0x7c5 0x800 4.31 7f84f3c40c8332b4233cfc131b0a68c4
.data 0x7000 0x5c0 0x200 0.04 24203b33b9a53a29261d0ee9f94f2085
INIT 0x8000 0xa14 0xc00 4.85 96092ad28ffe9e9295d5923d041c4a71
.rsrc 0x9000 0x330 0x400 2.73 a86d63d5e4da66383543f98c521a32fb
.reloc 0xa000 0x618 0x800 4.95 1c66fd91c5e8b3e957534eb14de1f967

( 2 imports )
> ntoskrnl.exe: RtlInitUnicodeString, IoRegisterDriverReinitialization, ObfDereferenceObject, RtlCompareUnicodeString, IoGetDeviceObjectPointer, IoCreateDevice, RtlAppendUnicodeToString, ExAllocatePoolWithTag, IoDeleteSymbolicLink, IoCreateSymbolicLink, PsSetCreateThreadNotifyRoutine, PsSetCreateProcessNotifyRoutine, IoRegisterShutdownNotification, IoRegisterFsRegistrationChange, _wcslwr, memcpy, memset, ExInitializeNPagedLookasideList, KeInitializeEvent, ExFreePoolWithTag, IoDeleteDevice, InitSafeBootMode, _strnicmp, _stricmp, _snprintf, wcscpy, MmIsAddressValid, PsGetCurrentProcessId, PsGetCurrentThreadId, ExInitializeResourceLite, KeLeaveCriticalRegion, ExAcquireResourceSharedLite, KeEnterCriticalRegion, ExAcquireResourceExclusiveLite, ExReleaseResourceLite, _snwprintf, ZwQueryInformationFile, ZwDeleteValueKey, ZwQueryValueKey, ZwOpenKey, strncmp, strlen, IoGetCurrentProcess, IoDetachDevice, MmGetSystemRoutineAddress, ZwCreateFile, InterlockedPushEntrySList, ExGetPreviousMode, wcsncpy, IoAttachDeviceToDeviceStack, ExQueueWorkItem, KeSetEvent, KeWaitForSingleObject, IofCallDriver, IoBuildDeviceIoControlRequest, RtlEqualUnicodeString, ObQueryNameString, ObfReferenceObject, KeDelayExecutionThread, RtlCopyUnicodeString, RtlFreeUnicodeString, ZwReadFile, strncpy, strrchr, ZwEnumerateValueKey, ZwSetSystemInformation, KeServiceDescriptorTable, ZwQuerySystemInformation, IoGetBaseFileSystemDeviceObject, ObReferenceObjectByHandle, IoFileObjectType, RtlFreeAnsiString, RtlUnicodeStringToAnsiString, wcslen, RtlAnsiStringToUnicodeString, RtlAppendStringToString, RtlCompareString, _strlwr, RtlAppendUnicodeStringToString, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, IoFreeIrp, wcscat, KeGetCurrentThread, IoAllocateIrp, memmove, ZwTerminateProcess, ZwRestoreKey, ZwDeleteKey, ZwEnumerateKey, ZwSetValueKey, ZwClose, _except_handler3, InterlockedPopEntrySList, IofCompleteRequest
> HAL.dll: ExReleaseFastMutex, KeGetCurrentIrql, ExAcquireFastMutex

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogr ... 092558790008129553B
emutony
 楼主| 发表于 2008-8-12 09:13:06 | 显示全部楼层
Sophos 4.31.0 2008.08.03 Baidu Bar
cruiyong
发表于 2008-8-12 09:13:29 | 显示全部楼层
看不见那里是百度的工具条
Tynox
发表于 2008-8-12 09:13:45 | 显示全部楼层
Access to the data has been denied!
Warning: A virus or unwanted program has been found in the HTTP Data.

Requested URL:         http://bbs.kafan.cn/attachment.p ... e2&t=1218503549
Information:         Is the TR/Rootkit.AK Trojan

Generated by AntiVir WebGuard 8.0.15.0, AVE 8.1.1.19, VDF 7.0.5.240

看名字感觉都已经是入库的产品了
百毒不用.
Palkia
发表于 2008-8-12 09:26:13 | 显示全部楼层
金山 0
ranguangning
头像被屏蔽
发表于 2008-8-12 13:21:06 | 显示全部楼层
看见rootkit的影子
woai_jolin
发表于 2008-8-12 13:29:46 | 显示全部楼层
深刻怀疑是百度搜霸
看看卡巴不报 又有其他av报百度 就知道了
david-2008
发表于 2008-8-12 17:33:48 | 显示全部楼层
就是广告软件
qigang
发表于 2008-8-12 17:36:33 | 显示全部楼层

2/0

RS20.57.11未杀!
BING126
头像被屏蔽
发表于 2008-8-12 21:03:41 | 显示全部楼层
McAfee  Adware-BDSearch
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-14 13:23 , Processed in 0.139817 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表