查看: 2932|回复: 9
收起左侧

[可疑文件] ....这个到底是不是毒...

[复制链接]
lingbo110120
发表于 2008-10-7 18:26:40 | 显示全部楼层 |阅读模式
File CF________.rar received on 10.07.2008 12:24:25 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 17/36 (47.23%)

Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___
.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results


Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.  
Email:



AntivirusVersionLast UpdateResult
AhnLab-V32008.10.3.22008.10.07-
AntiVir7.8.1.342008.10.07-
Authentium5.1.0.42008.10.07W32/Nuj.A.gen!Eldorado
Avast4.8.1248.02008.10.06Win32:Trojan-gen {Other}
AVG8.0.0.1612008.10.06Downloader.Agent.ALZL
BitDefender7.22008.10.07-
CAT-QuickHeal9.502008.10.07-
ClamAV0.93.12008.10.07Trojan.Dropper-2514
DrWeb4.44.0.091702008.10.07-
eSafe7.0.17.02008.10.07-
eTrust-Vet31.6.61332008.10.07-
Ewido4.02008.10.06-
F-Prot4.4.4.562008.10.06W32/Nuj.A.gen!Eldorado
F-Secure8.0.14332.02008.10.07Trojan-Downloader:W32/VB.BUE
Fortinet3.113.0.02008.10.07W32/Dropr.K!tr
GData192008.10.07Win32:Trojan-gen {Other}
IkarusT3.1.1.34.02008.10.07Worm.Win32.Nuj.A
K7AntiVirus7.10.4862008.10.06Trojan-Spy.Win32.FlyStudio.eo
Kaspersky7.0.0.1252008.10.07-
McAfee53982008.10.04Generic.dx
Microsoft1.40052008.10.07-
NOD3234992008.10.07-
Norman5.80.022008.10.06W32/Lineage.BKDF
Panda9.0.0.42008.10.07Generic Malware
PCTools4.4.2.02008.10.06-
Prevx1V22008.10.07Worm
Rising20.65.12.002008.10.07-
SecureWeb-Gateway6.7.62008.10.07-
Sophos4.34.02008.10.07Troj/Dropr-K
Sunbelt3.1.1707.12008.10.07-
Symantec102008.10.07-
TheHacker6.3.1.0.1022008.10.07-
TrendMicro8.700.0.10042008.10.07WORM_LINEAGE.NH
VBA323.12.8.62008.10.07Constructor.Win32.HTMLCrypt.a
ViRobot2008.10.7.14102008.10.07-
VirusBuster4.5.11.02008.10.06-

毒组的来帮个帮
这扫描结果 我有点看不懂啦   
主流的几个都没报  其他的报了一大堆


[ 本帖最后由 lingbo110120 于 2008-10-7 18:28 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
thering111
发表于 2008-10-7 18:37:00 | 显示全部楼层
如果没异常那肯定不是病毒了撒
lingbo110120
 楼主| 发表于 2008-10-7 18:44:32 | 显示全部楼层
难道还要叫我双击运行后 再看有没有异常?
我没装HIPS  没装沙盘 没装虚拟机...实机运行 - -
只是想叫有这些装备的人 测试下罢了
再说卡巴 红伞 NOD 铁壳 这些都没报

[ 本帖最后由 lingbo110120 于 2008-10-7 18:45 编辑 ]
wangjay1980
发表于 2008-10-7 19:49:34 | 显示全部楼层
等一会看TF报告
BING126
头像被屏蔽
发表于 2008-10-7 19:52:10 | 显示全部楼层
分析一下  没发现异常行为  
1688388728
发表于 2008-10-7 20:00:18 | 显示全部楼层

创建文件

文件夹: C:\Documents And Settings\Administrator\Local Settings\Temp\E_4\
文件: Krnln.fnr
文件: EThread.fne
文件: Spec.fne
文件: Script.fne
文件夹: C:\Documents And Settings\Administrator\Application Data\SogouPY\
文件: Env.ini
wangjay1980
发表于 2008-10-7 20:01:03 | 显示全部楼层
Visit ThreatExpert web site|Close Report
Submission Summary:
  • Submission details:
    • Submission received: 7 October 2008, 22:51:21
    • Processing time: 6 min 4 sec
    • Submitted sample:
  • Summary of the findings:
What's been foundSeverity Level
Downloads/requests other files from Internet.


Technical Details:
  • The new window was created, as shown below:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.


File System Modifications
  • The following files were created in the system:
#Filename(s)File SizeFile MD5Alias
1%Temp%\E_4\EThread.fne 49,152 bytes0xD20B00BF558574821727FE2F643A41FA(not available)
2%Temp%\E_4\krnln.fnr 1,105,920 bytes0x71520E2E016F657E0131181C093AF6E0(not available)
3%Temp%\E_4\script.fne 167,936 bytes0x17710FE9929EE5FC01A8E2889625609D(not available)
4%Temp%\E_4\spec.fne 81,920 bytes0xED586B64D307C7C23733EA45CC0D588B(not available)
5[file and pathname of the sample #1] 728,077 bytes0x6019CD23AF444794F210B410C1066701Generic.dx [McAfee]
Troj/Dropr-K [Sophos]
Worm:Win32/Nuj.A [Microsoft]

  • Note:
    • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • The following directory was created:
    • %Temp%\E_4

Memory Modifications
  • There was a new process created in the system:
Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]94,208 bytes


Registry Modifications
  • The following Registry Keys were created:
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
  • The newly created Registry Value is:
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings]
      • JITDebug = 0x00000000

Other details
  • Analysis of the file resources indicate the following possible country of origin:
China
  • The following port was open in the system:
PortProtocolProcess
1056TCP[file and pathname of the sample #1]

  • The following Host Name was requested from a host database:
    • ptlogin2.qq.com
  • The following HTTP URL was started reading:
    • http://ptlogin2.qq.com/getimage?518

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2008 ThreatExpert. All rights reserved.
雨宫优子
发表于 2008-10-7 20:04:28 | 显示全部楼层
波波的头,像NB啊...
————————————————————————
报的都是傻子...
这个是易语言编写的,干嘛易语言那么喜欢被误报...


PS:刚才清理沙盘时,电脑蓝屏了,结果帖子发晚了..
08红伞威点
发表于 2008-10-8 11:08:54 | 显示全部楼层
红伞Pass,上报提交分析。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-16 20:35 , Processed in 0.139275 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表