查看: 1876|回复: 8
收起左侧

[病毒样本] 一个

[复制链接]
kikyo9527
头像被屏蔽
发表于 2008-8-31 17:12:53 | 显示全部楼层 |阅读模式
有毒没?
sam.to
发表于 2008-8-31 17:14:42 | 显示全部楼层
放上來
Palkia
发表于 2008-8-31 17:19:48 | 显示全部楼层
金山 -
Palkia
发表于 2008-8-31 17:21:01 | 显示全部楼层
金山毒霸互联网可信认证   可疑的
kikyo9527
头像被屏蔽
 楼主| 发表于 2008-8-31 18:21:34 | 显示全部楼层
两个扫的

1--------------------------------------------------------------------------------
文件信息            
文件名称 :  1974cn.exe
文件大小 :  1577451 byte
文件类型 :  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :  6a1f2883aaec088032323ad9611f21f0
SHA1 :  275286ee670d85ec473fde2b8d3e1b9b87d35e1a
                                  扫描结果            
扫描结果 :  44%的杀软(16/36)报告发现病毒
            
软件名称 引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared3.5.0.222008.08.292008-08-29-
2.511
AntiVir7.8.1.237.0.6.932008-08-30TR/PSW.QQpass.DU.30
2.253
Arcavir1.0.52008083016542008-08-30Trojan.Psw.Qqpass
1.281
AVAST!3.0.1080830-02008-08-30Win32:Trojan-gen {Other}
0.070
AVG7.5.51.442270.6.14/16432008-08-30Generic2.NVW
1.566
BitDefender7.60825.16861517.207482008-08-31Trojan.Pws.Qqpass.DU
2.936
CA (VET)9.0.0.14331.6.60572008-08-29-
5.019
ClamAV0.93.381222008-08-31-
0.322
Comodo2.112.0.0.6322008-08-30-
0.442
CP Secure1.1.0.7152008.08.312008-08-31Troj.Dropper.W32.Agent.amm
6.505
Dr.Web4.44.0.91702008.08.302008-08-30-
3.122
ewido4.0.0.22008.08.302008-08-30-
2.482
F-Prot4.4.4.56200808302008-08-30W32/Trojan5.CGG (exact)
0.989
F-Secure5.51.61002008.08.30.012008-08-30-
3.275
IkarusT3.1.01.342008.08.31.713712008-08-31Virus.Win32.QQPass.MJ
3.273
Microsoft1.38072008.08.312008-08-31-
4.257
mks_vir2.012008.08.252008-08-25Trojan.Pws.Qqpass.DU
2.552
Norman5.93.015.93.002008-08-29-
4.983
nProtect2008-08-29.0019933882008-08-29Trojan-PWS/W32.QQPass.250459
3.571
Quick Heal9.502008.08.292008-08-29TrojanPSW.QQpass.du
1.671
Sophos2.78.04.332008-08-31-
1.746
Sunbelt3.1.1592.122102008-08-29-
0.523
The Hacker6.3.0.6v000682008-08-29-
0.419
VBA323.12.8.420080830.06092008-08-30-
1.266
ViRobot200808292008.08.292008-08-29-
0.396
VirusBuster4.5.11.1010.85.1/6232632008-08-30Trojan.Agent.DZUM
0.797
卡巴斯基5.5.102008.08.312008-08-31-
0.078
安博士V32008.08.30.002008.08.302008-08-30Win-Trojan/Xema.variant
0.887
江民杀毒11.0.7062008.08.312008-08-31-
1.199
熊猫卫士9.05.012008.08.302008-08-30Generic Trojan      
2.100
瑞星20.020.59.60.002008-08-31-
1.007
赛门铁克1.3.0.2420080830.0362008-08-30Trojan Horse
0.121
趋势科技8.700-10045.508.152008-08-30TROJ_QQPASS.BCU
0.027
迈克菲5.3.0053732008-08-29-
2.138
金山毒霸2008.1.14.152008.8.31.152008-08-31-
0.594
飞塔2.81-3.119.4952008-08-31-
0.344
         










































































2-----------------------------------------------------------------------------------------


                File 1974cn.exe received on 08.31.2008 11:00:53 (CET)
                                Current status:                        finished
Result: 21/36 (58.33%)

Compact
Print results



AntivirusVersionLast UpdateResult
AhnLab-V32008.8.29.02008.08.29Win-Trojan/Xema.variant
AntiVir7.8.1.232008.08.30TR/PSW.QQpass.DU.30
Authentium5.1.0.42008.08.30W32/Trojan5.CGG
Avast4.8.1195.02008.08.30Win32:Trojan-gen {Other}
AVG8.0.0.1612008.08.30PSW.QQpass.DG
BitDefender7.22008.08.31Trojan.Pws.Qqpass.DU
CAT-QuickHeal9.502008.08.29TrojanPSW.QQpass.du
ClamAV0.93.12008.08.31-
DrWeb4.44.0.091702008.08.31-
eSafe7.0.17.02008.08.28Suspicious File
eTrust-Vet31.6.60572008.08.29-
Ewido4.02008.08.31-
F-Prot4.4.4.562008.08.30W32/Trojan5.CGG
F-Secure7.60.13501.02008.08.31-
Fortinet3.14.0.02008.08.31W32/QQPASS.BCU!tr
GData192008.08.31Win32:Trojan-gen
IkarusT3.1.1.34.02008.08.31Virus.Win32.QQPass.MJ
K7AntiVirus7.10.4332008.08.30Trojan-PSW.Win32.QQPass.du
Kaspersky7.0.0.1252008.08.31-
McAfee53732008.08.29-
Microsoft1.38072008.08.25-
NOD32v234012008.08.30probably a variant of Win32/Agent
Norman5.80.022008.08.29-
Panda9.0.0.42008.08.30Generic Trojan
PCTools4.4.2.02008.08.30Trojan.Agent.DZUM
Prevx1V22008.08.31-
Rising20.59.61.002008.08.31-
Sophos4.33.02008.08.31-
Sunbelt3.1.1592.12008.08.30-
Symantec102008.08.31Trojan Horse
TheHacker6.3.0.6.0682008.08.30-
TrendMicro8.700.0.10042008.08.29TROJ_QQPASS.BCU
VBA323.12.8.42008.08.30-
ViRobot2008.8.30.13572008.08.30Trojan.Win32.PSWQQPass.14511
VirusBuster4.5.11.02008.08.30Trojan.Agent.DZUM
Webwasher-Gateway6.6.22008.08.30Trojan.PSW.QQpass.DU.30
Additional information
File size: 1577451 bytes
MD5...: 6a1f2883aaec088032323ad9611f21f0
SHA1..: 275286ee670d85ec473fde2b8d3e1b9b87d35e1a
SHA256: 6872d5beeed79322d623a9dd861bdfe65fe66852a4c93539a8da4c495fd45c20
SHA512: 2989f3a5d9aaa3d3093d98b3372c1cff7a16441992ca219fae53b4f840f586da
363a8169032a04525195f5a2e4f3a93ee66637f733bc4765ea049f873721611d
PEiD..: Crypto-Lock v2.02 (Eng) -> Ryan Thian
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40b3d0
timedatestamp.....: 0x3cc56d92 (Tue Apr 23 14:20:02 2002)
machinetype.......: 0x14c (I386)

( 3 sections )
name        viradd    virsiz   rawdsiz  ntrpy  md5
UPX0        0x1000    0x8000       0x0   0.00  d41d8cd98f00b204e9800998ecf8427e
UPX1        0x9000    0x3000    0x2600   7.74  88390d7bfb9da2b736e7e8d0d164252f
.rsrc       0xc000    0x1000     0xe00   3.15  74070a4d5bfa4cc17caaaac73058705a

( 6 imports )  
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> COMCTL32.dll: -
> comdlg32.dll: GetOpenFileNameA
> GDI32.dll: LineTo
> SHELL32.dll: ShellExecuteA
> USER32.dll: EndPaint

( 0 exports )
packers (Kaspersky): UPX
packers (F-Prot): UPX
packers (Authentium): UPX


ATTENTION:VirusTotal is a free service offered by Hispasec Sistemas. There are noguarantees about the availability and continuity of this service.Although the detection rate afforded by the use of multiple antivirusengines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
挪威的冬天
发表于 2008-8-31 18:24:59 | 显示全部楼层
gosh 看起来像误报

只是一个汉化补丁?
qigang
发表于 2008-8-31 18:35:34 | 显示全部楼层

3/0

RS20.59.62未杀!
wangjay1980
发表于 2008-8-31 19:39:50 | 显示全部楼层
28654621
头像被屏蔽
发表于 2008-8-31 19:44:49 | 显示全部楼层
D:\download\1974cn.zip>>1974cn\1974cn.exe        Trojan.Pgkdhx.jrna.for        木马        还未处理
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-10 18:22 , Processed in 0.225757 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表