费尔说:
D:\Downloads\bt\8\8ddd.rar>>as.css TrojanDownloader.Agent.rqj.kwvf 木马 还未处理
D:\Downloads\bt\8\8ddd.rar>>ms.css TrojanDownloader.Small.ybw.tjka 木马 还未处理
借隔壁网友“jun0717”说
ht tp://user999.78-10.net/as.css
ht tp://user999.78-10.net/ms.css
...
PS:挂得很失败,下载的马儿,60%可以报。。。
文件 as.css 接收于 2008.09.30 10:40:18 (CET)
结果: 23/36 (63.89%)
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2008.9.25.0 2008.09.30 Win-Trojan/Agent.13840.B
AntiVir 7.8.1.34 2008.09.30 -
Authentium 5.1.0.4 2008.09.29 -
Avast 4.8.1195.0 2008.09.29 Win32:Trojan-gen {Other}
AVG 8.0.0.161 2008.09.29 Downloader.Generic7.QRM
BitDefender 7.2 2008.09.30 Trojan.Downloader.Small.AAPP
CAT-QuickHeal 9.50 2008.09.30 TrojanDownloader.Agent.rqj
ClamAV 0.93.1 2008.09.30 Trojan.Downloader-41951
DrWeb 4.44.0.09170 2008.09.30 Trojan.DownLoader.63104
eSafe 7.0.17.0 2008.09.29 -
eTrust-Vet 31.6.6118 2008.09.30 Win32/SillyDl.EVD
Ewido 4.0 2008.09.29 Downloader.Small.xpd
F-Prot 4.4.4.56 2008.09.29 -
F-Secure 8.0.14332.0 2008.09.30 Trojan-Downloader.Win32.Small.ybw
Fortinet 3.113.0.0 2008.09.30 -
GData 19 2008.09.30 Trojan.Downloader.Small.AAPP
Ikarus T3.1.1.34.0 2008.09.30 Trojan-Downloader.Win32.Agent.rqj
K7AntiVirus 7.10.473 2008.09.25 Trojan-Downloader.Win32.Agent.rqj
Kaspersky 7.0.0.125 2008.09.30 Trojan-Downloader.Win32.Small.ybw
McAfee 5394 2008.09.30 -
Microsoft 1.4005 2008.09.30 TrojanDownloader:Win32/Mickdo.A
NOD32 3481 2008.09.29 probably a variant of Win32/TrojanDownloader.Small.WGA
Norman 5.80.02 2008.09.29 -
Panda 9.0.0.4 2008.09.29 Trj/Downloader.TYL
PCTools 4.4.2.0 2008.09.29 -
Prevx1 V2 2008.09.30 Malicious Software
Rising 20.63.62.00 2008.09.28 Trojan.DL.Win32.Small.vtg
SecureWeb-Gateway 6.7.6 2008.09.30 -
Sophos 4.34.0 2008.09.30 -
Sunbelt 3.1.1668.1 2008.09.24 -
Symantec 10 2008.09.30 Downloader
TheHacker 6.3.0.9.097 2008.09.29 -
TrendMicro 8.700.0.1004 2008.09.30 Possible_DLDER
VBA32 3.12.8.6 2008.09.29 Trojan.DownLoader.63104
ViRobot 2008.9.30.1397 2008.09.30 -
VirusBuster 4.5.11.0 2008.09.29 Trojan.DL.Agent.ETBH
附加信息
File size: 13840 bytes
MD5...: 1037f5b38b4764eb15aa67ffccf94830
SHA1..: ca10ae0b7fb4d0bae9ea9c172b9b77184efac3f1
SHA256: 0f5bd44184a0e77d6ddd4a20521bdaa158938ce984c836285a54f497ca9e61d4
SHA512: 4399078582c7df2aad83c91da7e4ca8ff54aedf62353d9ae41281eeb6c97bbef
a576a7188e6e663f2990beadc9e90c674a0c136c6365dbc9eabc173ae65e2254
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4015dc
timedatestamp.....: 0x3937bca7 (Fri Jun 02 13:54:47 2000)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x762 0x800 5.59 633538d30d7f82efd0da4be658b304e1
.rdata 0x2000 0x4ec 0x600 4.23 912eab2284e705c5794a7d5c582857d3
.data 0x3000 0xe8 0x200 2.28 bf5cd4b8e024f0983d6446dafa23df06
( 5 imports )
> KERNEL32.dll: CloseHandle, CreateProcessA, GetStartupInfoA, Sleep, GetTickCount, GetWindowsDirectoryA, SetEvent, WaitForMultipleObjects, WaitForSingleObject, CreateEventA, DeleteFileA, ExpandEnvironmentStringsA, SetFileAttributesA, CreateDirectoryA, GetLastError, CreateMutexA, GetModuleHandleA
> USER32.dll: LoadCursorA, SetSystemCursor, CopyIcon
> urlmon.dll: URLDownloadToFileA
> WININET.dll: DeleteUrlCacheEntry
> MSVCRT.dll: _XcptFilter, __set_app_type, __p__fmode, _controlfp, __p__commode, sprintf, _except_handler3, fprintf, _beginthreadex, fclose, fscanf, fopen, _exit, _adjust_fdiv, exit, _acmdln, __getmainargs, _initterm, __setusermatherr
( 0 exports )
VirSCAN.org Scanned Report :
Scanned time : 2008/09/30 16:40:27 (CST)
Scanner results: 70%的杀软(26/37)报告发现病毒
File Name : as.css
File Size : 13840 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 1037f5b38b4764eb15aa67ffccf94830
SHA1 : ca10ae0b7fb4d0bae9ea9c172b9b77184efac3f1
Online report : ht tp://virscan.org/report/c7d02ac8195f8f40d58608fdebcdf2d2.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.14 2008.09.29 2008-09-29 2.08 Trojan-Downloader.Win32.Agent.rqj!A2
安博士V3 2008.09.30.02 2008.09.30 2008-09-30 1.43 Win-Trojan/Agent.13840.B
AntiVir 7.8.1.34 7.0.6.225 2008-09-29 2.32 -
Arcavir 1.0.5 200809291247 2008-09-29 1.20 Trojan.Agent.Ms
Authentium 5.1.1 200809241708 2008-09-24 1.06 -
AVAST! 3.0.1 080929-1 2008-09-29 0.69 Win32:Trojan-gen {Other}
AVG 7.5.52.442 270.7.5/1698 2008-09-29 1.63 Downloader.Generic7.QRM
BitDefender 7.60825.1822271 7.21107 2008-09-30 3.10 Trojan.Downloader.Small.AAPP
CA (VET) 9.0.0.143 31.6.6117 2008-09-29 5.38 Win32/SillyDl.EVD trojan.
ClamAV 0.94 8356 2008-09-30 0.01 Trojan.Downloader-41951
Comodo 2.11 2.0.0.661 2008-09-29 0.44 -
CP Secure 1.1.0.715 2008.09.30 2008-09-30 5.94 Troj.Downloader.W32.Agent.rqj
Dr.Web 4.44.0.9170 2008.09.29 2008-09-29 3.25 Trojan.DownLoader.63104
ewido 4.0.0.2 2008.09.29 2008-09-29 2.88 Downloader.Small.xpd
F-Prot 4.4.4.56 20080929 2008-09-29 1.04 -
F-Secure 5.51.6100 2008.09.30.02 2008-09-30 3.44 Trojan-Downloader.Win32.Small.ybw [AVP]
飞塔 2.81-3.113 9.604 2008-09-29 0.21 -
ViRobot 20080929 2008.09.29 2008-09-29 0.40 -
Ikarus T3.1.01.34 2008.09.29.71552 2008-09-29 3.35 Trojan-Downloader.Win32.Agent.rqj
江民杀毒 11.0.706 2008.09.30 2008-09-30 1.22 TrojanDownloader.Small.aejq
卡巴斯基 5.5.10 2008.09.30 2008-09-30 0.02 Trojan-Downloader.Win32.Small.ybw
金山毒霸 2008.9.8.18 2008.9.30.14 2008-09-30 0.62 Win32.TrojDownloader.Agent.9970
迈克菲 5.3.00 5394 2008-09-29 2.01 -
Microsoft 1.4005 2008.09.29 2008-09-29 4.35 TrojanDownloader:Win32/Mickdo.A
mks_vir 2.01 2008.09.29 2008-09-29 2.57 Worm.Korgo
Norman 5.93.01 5.93.00 2008-09-18 5.36 -
熊猫卫士 9.05.01 2008.09.29 2008-09-29 2.31 Trj/Downloader.TYL
趋势科技 8.700-1004 5.572.02 2008-09-29 0.02 Possible_DLDER
Quick Heal 9.50 2008.09.30 2008-09-30 1.99 TrojanDownloader.Agent.rqj
瑞星 20.0 20.63.62.00 2008-09-28 1.00 Trojan.DL.Win32.Small.vtg
Sophos 2.79.0 4.34 2008-09-30 1.70 -
Sunbelt 3.1.1675.1 2261 2008-09-26 0.64 -
赛门铁克 1.3.0.24 20080929.003 2008-09-29 0.06 Downloader
nProtect 2008-09-30.01 2186999 2008-09-30 4.32 Trojan-Downloader/W32.Agent.13840.B
The Hacker 6.3.0.9 v00096 2008-09-28 0.44 -
VBA32 3.12.8.6 20080929.0843 2008-09-29 1.25 Trojan.DownLoader.63104
VirusBuster 4.5.11.10 10.89.2/633609 2008-09-29 0.86 Trojan.DL.Agent.ETBH
文件 ms.css 接收于 2008.09.30 10:49:08 (CET)
结果: 32/36 (88.89%)
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2008.9.25.0 2008.09.30 Win-Trojan/Agent.13840.B
AntiVir 7.8.1.34 2008.09.30 TR/Crypt.NSPI.Gen
Authentium 5.1.0.4 2008.09.29 W32/Downloader-Sml-based!Maximus
Avast 4.8.1195.0 2008.09.29 -
AVG 8.0.0.161 2008.09.29 Downloader.Generic7.AUQD
BitDefender 7.2 2008.09.30 Trojan.Downloader.Small.AAPP
CAT-QuickHeal 9.50 2008.09.30 TrojanDownloader.Small.ybw
ClamAV 0.93.1 2008.09.30 PUA.Packed.NPack-3
DrWeb 4.44.0.09170 2008.09.30 Trojan.DownLoader.63104
eSafe 7.0.17.0 2008.09.29 Suspicious File
eTrust-Vet 31.6.6118 2008.09.30 -
Ewido 4.0 2008.09.29 Downloader.Small.xpd
F-Prot 4.4.4.56 2008.09.29 W32/Downloader-Sml-based!Maximus
F-Secure 8.0.14332.0 2008.09.30 Trojan-Downloader.Win32.Small.ybw
Fortinet 3.113.0.0 2008.09.30 W32/Heuri.E!tr.dldr
GData 19 2008.09.30 Trojan.Downloader.Small.AAPP
Ikarus T3.1.1.34.0 2008.09.30 Backdoor.Win32.Agent.ahj
K7AntiVirus 7.10.476 2008.09.27 Trojan-Downloader.Win32.Small.ybw
Kaspersky 7.0.0.125 2008.09.30 Trojan-Downloader.Win32.Small.ybw
McAfee 5394 2008.09.30 New Malware.hr
Microsoft 1.4005 2008.09.30 TrojanDownloader:Win32/Mickdo.A
NOD32 3481 2008.09.29 probably a variant of Win32/TrojanDownloader.Small.WGA
Norman 5.80.02 2008.09.29 W32/Packed_NSPack.B
Panda 9.0.0.4 2008.09.29 Trj/Downloader.TYL
PCTools 4.4.2.0 2008.09.29 Packed/NSPack
Prevx1 V2 2008.09.30 -
Rising 20.63.62.00 2008.09.28 Trojan.DL.Win32.Small.vtg
SecureWeb-Gateway 6.7.6 2008.09.30 Trojan.Crypt.NSPI.Gen
Sophos 4.34.0 2008.09.30 Mal/Heuri-E
Sunbelt 3.1.1675.1 2008.09.27 Trojan.Win32.Packed.gen (v)
Symantec 10 2008.09.30 Downloader
TheHacker 6.3.0.9.097 2008.09.29 W32/Behav-Heuristic-067
TrendMicro 8.700.0.1004 2008.09.30 PAK_Generic.001
VBA32 3.12.8.6 2008.09.29 Trojan.DownLoader.63104
ViRobot 2008.9.30.1397 2008.09.30 -
VirusBuster 4.5.11.0 2008.09.29 Trojan.DL.MultiLoad.L
附加信息
File size: 5678 bytes
MD5...: 58aaadbac2753544beebcfb6c0c18c75
SHA1..: 861a7ccd3314df7e88f7bc3540a31f8e35b80c7a
SHA256: d87e666b39c69c53ade29ebeed9a432c1e77fff9035710c1739f5078de3c2c17
SHA512: 55c106a497cf8226f342cd77aba7453616e5f51e79a1c58d785998312577ceea
4f203ebb45967804061cda70ce138c1617bc0f67344ea5abe69fe5a93c9a88b9
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x405250
timedatestamp.....: 0x3937bca7 (Fri Jun 02 13:54:47 2000)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.nsp0 0x1000 0x4000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.nsp1 0x5000 0x2000 0x122e 7.45 f85fcdb26faa6d4b86e21453b01e65c6
.nsp2 0x7000 0x56e 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
( 5 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> USER32.DLL: LoadCursorA
> URLMON.DLL: URLDownloadToFileA
> WININET.DLL: DeleteUrlCacheEntry
> MSVCRT.DLL: _XcptFilter
( 0 exports )
packers (F-Prot): NSPack, PE_Patch
packers (Kaspersky): NSPack
packers (Authentium): NSPack, PE_Patch
VirSCAN.org Scanned Report :
Scanned time : 2008/09/30 16:48:57 (CST)
Scanner results: 76%的杀软(28/37)报告发现病毒
File Name : ms.css
File Size : 5678 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 58aaadbac2753544beebcfb6c0c18c75
SHA1 : 861a7ccd3314df7e88f7bc3540a31f8e35b80c7a
Online report : ht tp://virscan.org/report/85dd05d86521044b64ba340e34c21481.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.14 2008.09.29 2008-09-29 1.43 -
安博士V3 2008.09.30.02 2008.09.30 2008-09-30 0.93 Win-Trojan/Agent.13840.B
AntiVir 7.8.1.34 7.0.6.225 2008-09-29 2.34 TR/Crypt.NSPI.Gen
Arcavir 1.0.5 200809291247 2008-09-29 1.21 -
Authentium 5.1.1 200809241708 2008-09-24 1.15 W32/Heuristic-DL2!Eldorado (Heuristic)
AVAST! 3.0.1 080929-1 2008-09-29 0.01 -
AVG 7.5.52.442 270.7.5/1698 2008-09-29 1.60 Downloader.Generic7.AUQD
BitDefender 7.60825.1822271 7.21107 2008-09-30 3.11 Trojan.Downloader.Small.AAPP
CA (VET) 9.0.0.143 31.6.6117 2008-09-29 4.74 -
ClamAV 0.94 8356 2008-09-30 0.00 PUA.Packed.NPack-3
Comodo 2.11 2.0.0.661 2008-09-29 0.43 -
CP Secure 1.1.0.715 2008.09.30 2008-09-30 5.94 -
Dr.Web 4.44.0.9170 2008.09.29 2008-09-29 3.29 Trojan.DownLoader.63104
ewido 4.0.0.2 2008.09.29 2008-09-29 4.59 Downloader.Small.xpd
F-Prot 4.4.4.56 20080929 2008-09-29 1.12 Possible W32/Heuristic-DL2!Eldorado (not disinfectable)
F-Secure 5.51.6100 2008.09.30.02 2008-09-30 0.05 Trojan-Downloader.Win32.Small.ybw [AVP]
飞塔 2.81-3.113 9.604 2008-09-29 0.16 W32/Heuri.E!tr.dldr
ViRobot 20080929 2008.09.29 2008-09-29 0.40 -
Ikarus T3.1.01.34 2008.09.29.71552 2008-09-29 3.37 Backdoor.Win32.Agent.ahj
江民杀毒 11.0.706 2008.09.30 2008-09-30 1.23 TrojanDownloader.Small.aejq
卡巴斯基 5.5.10 2008.09.30 2008-09-30 0.04 Trojan-Downloader.Win32.Small.ybw
金山毒霸 2008.9.8.18 2008.9.30.14 2008-09-30 0.62 Win32.TrojDownloader.Agent.9970
迈克菲 5.3.00 5394 2008-09-29 2.09 New Malware.hr
Microsoft 1.4005 2008.09.29 2008-09-29 7.14 TrojanDownloader:Win32/Mickdo.A
mks_vir 2.01 2008.09.29 2008-09-29 2.67 -
Norman 5.93.01 5.93.00 2008-09-18 5.38 W32/Packed_NSPack.B
熊猫卫士 9.05.01 2008.09.29 2008-09-29 4.43 Trj/Downloader.TYL
趋势科技 8.700-1004 5.572.02 2008-09-29 0.02 -
Quick Heal 9.50 2008.09.30 2008-09-30 3.13 TrojanDownloader.Small.ybw
瑞星 20.0 20.63.62.00 2008-09-28 2.28 Trojan.DL.Win32.Small.vtg
Sophos 2.79.0 4.34 2008-09-30 1.74 Mal/Heuri-E
Sunbelt 3.1.1675.1 2261 2008-09-26 0.43 Trojan.Win32.Packed.gen (v)
赛门铁克 1.3.0.24 20080929.003 2008-09-29 0.05 Downloader
nProtect 2008-09-30.01 2186999 2008-09-30 5.66 Trojan.Downloader.Small.AAPP
The Hacker 6.3.0.9 v00096 2008-09-28 0.68 W32/Behav-Heuristic-067
VBA32 3.12.8.6 20080929.0843 2008-09-29 1.23 Trojan.DownLoader.63104
VirusBuster 4.5.11.10 10.89.2/633609 2008-09-29 0.85 Trojan.DL.MultiLoad.L |