查看: 2708|回复: 9
收起左侧

[讨论] 红伞竟然把魔兽世界的登录文件给杀了!

[复制链接]
jojo8008
发表于 2008-9-10 08:09:59 | 显示全部楼层 |阅读模式
昨天升级过之后发现红伞竟然把魔兽世界的登录文件给杀了,大家看看是不是误报啊。
fongfc
发表于 2008-9-10 09:15:45 | 显示全部楼层
檢查档案md5碼
確認一下到底登錄文件有否被修改[:1:]
@wat@
发表于 2008-9-10 09:18:12 | 显示全部楼层
能否把登录上传,给我试一试。楼主的是什么版本来着
dadingdading
发表于 2008-9-10 09:20:18 | 显示全部楼层
上传病毒文件上来,到多引擎扫描看看有毒没有?
http://www.virustotal.com/zh-cn/

如果是误杀的话,就先排除一下
把报毒文件上报红伞解决
7506318
发表于 2008-9-10 09:21:30 | 显示全部楼层
我的也报了,应该是误报
iceray_ah
发表于 2008-9-10 12:30:31 | 显示全部楼层
我的魔兽没有报啊。
北木向南
发表于 2008-9-10 13:09:16 | 显示全部楼层
我的wow正常
sky123456
发表于 2008-9-10 15:54:27 | 显示全部楼层
我的WOW报了
jojo8008
 楼主| 发表于 2008-9-11 12:59:57 | 显示全部楼层
用多引擎查了一下,只有三个报,应该是误报,具体情况如下:
文件 Launcher.exe 接收于 2008.09.10 06:21:28 (CET)
当前状态: 完成
结果: 3/36 (8.33%)

格式化文本
打印结果



反病毒引擎版本最后更新扫描结果
AhnLab-V32008.9.6.02008.09.09-
AntiVir7.8.1.282008.09.09TR/Dldr.Agent.afta
Authentium5.1.0.42008.09.10-
Avast4.8.1195.02008.09.05-
AVG8.0.0.1612008.09.09Downloader.Agent.AKIO
BitDefender7.22008.09.10-
CAT-QuickHeal9.502008.09.10-
ClamAV0.93.12008.09.10-
DrWeb4.44.0.091702008.09.10-
eSafe7.0.17.02008.09.09-
eTrust-Vet31.6.60802008.09.09-
Ewido4.02008.09.09-
F-Prot4.4.4.562008.09.09-
F-Secure8.0.14332.02008.09.10-
Fortinet3.112.0.02008.09.09-
GData192008.09.10-
IkarusT3.1.1.34.02008.09.10-
K7AntiVirus7.10.4482008.09.09-
Kaspersky7.0.0.1252008.09.10-
McAfee53802008.09.09-
Microsoft1.39032008.09.10-
NOD32v234292008.09.09-
Norman5.80.022008.09.09-
Panda9.0.0.42008.09.09-
PCTools4.4.2.02008.09.09-
Prevx1V22008.09.10-
Rising20.61.20.002008.09.10-
Sophos4.33.02008.09.10-
Sunbelt3.1.1616.12008.09.09-
Symantec102008.09.10-
TheHacker6.3.0.8.0722008.09.04-
TrendMicro8.700.0.10042008.09.10-
VBA323.12.8.52008.09.09-
ViRobot2008.9.10.13702008.09.10-
VirusBuster4.5.11.02008.09.09-
Webwasher-Gateway6.6.22008.09.09Trojan.Dldr.Agent.afta
附加信息
File size: 2143744 bytes
MD5...: ac0974170d380c67f33cca52ce0cefe8
SHA1..: bb3f6d250e1ed7b194eccbfb569a0ed14a199158
SHA256: aee09d29a173394ceb123e525b32fcab14a5c3cde2708ad4030e969de193e402
SHA512: a588e3fe73a82a48c6514e1e4d89182a8dd52824ecdb27038404a0d21af447ba
6fbf49143e629dae4856d1162732416e2cee8186566ad9aaa4052c885e0b1f29
PEiD..: -
TrID..: File type identification
Win32 Executable Borland Delphi 7 (54.2%)
Win32 Executable Borland Delphi 5 (36.5%)
InstallShield setup (3.4%)
Win32 EXE PECompact compressed (generic) (3.3%)
Win32 Executable Delphi generic (1.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x502c68
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x101cec 0x101e00 6.53 d81a43d60af05d0a7f6d197a1a454336
DATA 0x103000 0x3ca4 0x3e00 4.85 45f3e37c467f8acf6cef87c206c62e0c
BSS 0x107000 0x167d 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x109000 0x2cd8 0x2e00 4.99 53f478d20efc8ed8e708d61a70e7010a
.tls 0x10c000 0x10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0x10d000 0x18 0x200 0.20 6ef0cb38ae20210ee043e1dc317979ef
.reloc 0x10e000 0x11330 0x11400 6.66 e6fa9de75ac1410ab8a92de3c1212612
.rsrc 0x120000 0xf1200 0xf1200 6.99 ba7c6232548e60b006fde0f24c29eb56

( 21 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, SetCurrentDirectoryA, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle
> user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA
> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen
> kernel32.dll: TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
> advapi32.dll: RegQueryValueExA, RegQueryInfoKeyA, RegOpenKeyExA, RegFlushKey, RegEnumValueA, RegEnumKeyExA, RegCreateKeyExA, RegCloseKey, GetUserNameA
> kernel32.dll: lstrcpyA, lstrcmpA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualAlloc, TerminateThread, Sleep, SizeofResource, SetThreadPriority, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, SetCurrentDirectoryA, ResumeThread, ResetEvent, RemoveDirectoryA, ReadFile, QueryPerformanceFrequency, QueryPerformanceCounter, MultiByteToWideChar, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalSize, GlobalReAlloc, GlobalMemoryStatus, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetUserDefaultLCID, GetTimeZoneInformation, GetTickCount, GetThreadLocale, GetTempPathA, GetSystemInfo, GetSystemDirectoryA, GetSystemDefaultLangID, GetStringTypeExA, GetStdHandle, GetProcessAffinityMask, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeThread, GetEnvironmentVariableA, GetEnvironmentStringsA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess, GetCurrentDirectoryA, GetComputerNameA, GetCPInfo, GetACP, FreeResource, InterlockedIncrement, InterlockedExchange, InterlockedDecrement, FreeLibrary, FreeEnvironmentStringsA, FormatMessageA, FindResourceA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, FileTimeToDosDateTime, ExpandEnvironmentStringsA, EnumCalendarInfoA, EnterCriticalSection, DosDateTimeToFileTime, DeleteFileA, DeleteCriticalSection, CreateThread, CreateProcessA, CreateFileA, CreateEventA, CompareStringA, CloseHandle
> version.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
> gdi32.dll: UnrealizeObject, TextOutA, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SelectClipRgn, SaveDC, RoundRect, RestoreDC, Rectangle, RectVisible, RealizePalette, Polyline, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetViewportOrgEx, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionA, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, ExtTextOutA, ExcludeClipRect, Ellipse, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRoundRectRgn, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateEnhMetaFileA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, CombineRgn, CloseEnhMetaFile, BitBlt, Arc
> user32.dll: CreateWindowExA, WindowFromPoint, WindowFromDC, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowRgn, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClipboardData, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OpenClipboard, OffsetRect, OemToCharA, MsgWaitForMultipleObjects, MessageBoxA, MessageBeep, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadImageA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMessageTime, GetMessagePos, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EnumDisplaySettingsA, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, EmptyClipboard, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, CopyImage, CloseClipboard, ClientToScreen, ChildWindowFromPoint, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharUpperBuffA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout
> kernel32.dll: Sleep
> oleaut32.dll: SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayGetElement, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopyInd, VariantCopy, VariantClear, VariantInit
> ole32.dll: CreateStreamOnHGlobal, IsAccelerator, OleDraw, OleSetMenuDescriptor, CoTaskMemFree, CoTaskMemAlloc, CLSIDFromProgID, ProgIDFromCLSID, StringFromCLSID, CoCreateInstance, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID
> oleaut32.dll: GetErrorInfo, GetActiveObject, SysFreeString
> comctl32.dll: ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create, InitCommonControls
> shell32.dll: ShellExecuteA
> shell32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc
> kernel32.dll: GetVersionExA
> kernel32.dll: -, -, -
> wsock32.dll: WSACleanup, WSAStartup, gethostname, gethostbyname, inet_ntoa
> netapi32.dll: Netbios

( 0 exports )
ThreatExpert info: http://www.threatexpert.com/repo ... c67f33cca52ce0cefe8
mitsubi
发表于 2008-9-11 17:44:10 | 显示全部楼层
这个情况好像很多
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-25 12:12 , Processed in 0.153030 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表