查看: 1681|回复: 7
收起左侧

[病毒样本] 最新木马~今天抓的~!

[复制链接]
修罗珈
发表于 2008-8-21 19:49:21 | 显示全部楼层 |阅读模式
症状 ,只要打开IE浏览就会出现 应用程序出错的预警,然后自动关闭IE ,IE就不能使用。

File WSOCK32.rar received on 08.21.2008 13:45:21 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 4/36 (11.12%)

Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___
.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results


Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.  
Email:



AntivirusVersionLast UpdateResult
AhnLab-V32008.8.21.02008.08.21-
AntiVir7.8.1.232008.08.21-
Authentium5.1.0.42008.08.21-
Avast4.8.1195.02008.08.20-
AVG8.0.0.1612008.08.21PSW.Generic6.XZW
BitDefender7.22008.08.21-
CAT-QuickHeal9.502008.08.20-
ClamAV0.93.12008.08.21-
DrWeb4.44.0.091702008.08.21-
eSafe7.0.17.02008.08.21-
eTrust-Vet31.6.60392008.08.21-
Ewido4.02008.08.21-
F-Prot4.4.4.562008.08.20-
F-Secure7.60.13501.02008.08.21-
Fortinet3.14.0.02008.08.21-
GData2.0.7306.10232008.08.20-
IkarusT3.1.1.34.02008.08.21-
K7AntiVirus7.10.4222008.08.20-
Kaspersky7.0.0.1252008.08.21-
McAfee53662008.08.21PWS-QQPass.dll
Microsoft1.38072008.08.21-
NOD32v233742008.08.21-
Norman5.80.022008.08.20-
Panda9.0.0.42008.08.21Suspicious file
PCTools4.4.2.02008.08.20-
Prevx1V22008.08.21-
Rising20.58.32.002008.08.21-
Sophos4.32.02008.08.21-
Sunbelt3.1.1564.12008.08.21-
Symantec102008.08.21-
TheHacker6.3.0.6.0562008.08.21-
TrendMicro8.700.0.10042008.08.21-
VBA323.12.8.32008.08.20suspected of Win32 Shadow Socket Open
ViRobot2008.8.21.13442008.08.21-
VirusBuster4.5.11.02008.08.20-
Webwasher-Gateway6.6.22008.08.21-
Additional information
File size: 102533 bytes
MD5...: d495ae435e36b847533529a23f54e392
SHA1..: f1bdc90518e941ea07a3cd6993ee5b52e5a5518a
SHA256: af1ee0b0828f7abe65d9115e98d636db3998f69959a1599b288de784526ad6cc
SHA512: 359bfa8cf4d5d693375817c7a31a10f7172b96298c05639564ee99c687e685af
0c3053f90e69cd450759819b3f7a454a5bbc905c35690c6a7bbb299cecc3322a
PEiD..: -
PEInfo: -

ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
BING126
头像被屏蔽
发表于 2008-8-21 19:50:20 | 显示全部楼层
McAfee   PWS-QQPass.dll  
Kitman
发表于 2008-8-21 19:58:49 | 显示全部楼层
The file 'WSOCK32.DLL' has been determined to be 'UNDER ANALYSIS'.
郭襄
头像被屏蔽
发表于 2008-8-21 20:03:28 | 显示全部楼层
这个东西有什么用?又不会自动运行,一个DLL,有什么问题?
尤金卡巴斯基
发表于 2008-8-21 22:16:26 | 显示全部楼层
MISS,上报
qigang
发表于 2008-8-21 22:18:05 | 显示全部楼层
wsock32 - wsock32.dll - DLL文件信息

DLL 文件: wsock32 或者 wsock32.dll
DLL 名称: WinSock API Library
  
描述:
wsock32.dll是Windows Sockets应用程序接口,用于支持很多Internet和网络应用程序。


属于: Windows Sockets
系统 DLL文件: 是

常见错误: File Not Found, Missing File, Exception Errors

安全等级 (0-5): 0
间谍软件: 否
广告软件: 否
Kitman
发表于 2008-8-21 22:42:32 | 显示全部楼层
The file 'WSOCK32.DLL' has been determined to be 'MALWARE'. Our analysts named the threat TR/PSW.QQpass.czc. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
allinwonderi
发表于 2008-8-21 22:46:34 | 显示全部楼层

ArcaVir2008, F-Prot 4.4.4,NVC 5.99

to lab
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-19 01:51 , Processed in 0.111192 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表