查看: 3292|回复: 10
收起左侧

[可疑文件] 这个是不是盗号病毒!

[复制链接]
tyyds
发表于 2008-10-7 22:50:45 | 显示全部楼层 |阅读模式
我玩冒险岛下栽了个外挂,很多杀软报病毒,因为很多外挂的写法疑似病毒,没什么好奇怪!但是有的朋友说容易被盗号!还请高手给鉴定下!主要看下是不是含有盗号木马!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
lingbo110120
发表于 2008-10-7 22:53:44 | 显示全部楼层
File swwV065_3_8k8e.rar received on 10.07.2008 16:52:15 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 3/36 (8.34%)

Loading server information...
Your file is queued in position: 1.
Estimated start time is between 37 and 53 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results


Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.  
Email:



AntivirusVersionLast UpdateResult
AhnLab-V32008.10.3.22008.10.07-
AntiVir7.8.1.342008.10.07-
Authentium5.1.0.42008.10.07-
Avast4.8.1248.02008.10.07-
AVG8.0.0.1612008.10.07-
BitDefender7.22008.10.07-
CAT-QuickHeal9.502008.10.07-
ClamAV0.93.12008.10.07-
DrWeb4.44.0.091702008.10.07-
eSafe7.0.17.02008.10.07-
eTrust-Vet31.6.61332008.10.07-
Ewido4.02008.10.07-
F-Prot4.4.4.562008.10.06-
F-Secure8.0.14332.02008.10.07-
Fortinet3.113.0.02008.10.07-
GData192008.10.07-
IkarusT3.1.1.34.02008.10.07VirTool.Win32.DelfInject.AF
K7AntiVirus7.10.4872008.10.07-
Kaspersky7.0.0.1252008.10.07-
McAfee53992008.10.07-
Microsoft1.40052008.10.07-
NOD3235002008.10.07-
Norman5.80.022008.10.06-
Panda9.0.0.42008.10.07-
PCTools4.4.2.02008.10.07-
Prevx1V22008.10.07CE
Rising20.65.12.002008.10.07-
SecureWeb-Gateway6.7.62008.10.07-
Sophos4.34.02008.10.07-
Sunbelt3.1.1707.12008.10.07-
Symantec102008.10.07-
TheHacker6.3.1.0.1022008.10.07-
TrendMicro8.700.0.10042008.10.07-
VBA323.12.8.62008.10.07suspected of Backdoor.XiaoBird.67 (paranoid heuristics)
ViRobot2008.10.7.14102008.10.07-
VirusBuster4.5.11.02008.10.07-

谁说很多少软报毒的?
tyyds
 楼主| 发表于 2008-10-7 22:55:55 | 显示全部楼层
不好意思,我就用个卡把!我的朋友也说报出!我就说很多杀软了 抱歉!
还请给个明确的结论,这个我看不懂
yuanliu 该用户已被删除
发表于 2008-10-7 22:56:38 | 显示全部楼层
呵呵---路过,不发表看法
theboyfromchina
发表于 2008-10-7 22:59:38 | 显示全部楼层
爽歪歪嘛?我坚决不用~~~~~~~应该是有毒的~~~~~见到SWW就知道了…………
lingbo110120
发表于 2008-10-7 22:59:46 | 显示全部楼层
首先上面的报告卡巴没有报....
我的绿色卡巴KAV8.0也没报

还有 我不是测试人员- -
我不能明确给你答复
我不是毒组的

这个东西多半不是毒
lingbo110120
发表于 2008-10-7 23:06:51 | 显示全部楼层
报告来了 明确给你回复 不是毒  没有明确可疑动作
  • Submission details:
    • Submission received: 8 October 2008, 01:56:55
    • Processing time: 5 min 22 sec
    • Submitted sample:
      • File MD5: 0x2DAC47080C94BAA00182BEACB5A03C9B
      • Filesize: 26,112 bytes
  • Summary of the findings:
What's been foundSeverity Level
Downloads/requests other files from Internet.


Technical Details:
  • The new window was created, as shown below:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.


File System Modifications

  • The following file was created in the system:
#Filename(s)File SizeFile MD5
1[file and pathname of the sample #1] 26,112 bytes0x2DAC47080C94BAA00182BEACB5A03C9B


Memory Modifications

  • There was a new process created in the system:
Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]49,152 bytes


Other details

  • Analysis of the file resources indicate the following possible country of origin:
China
  • The following Internet Connection was established:
Server NameServer PortConnect as UserConnection Password
bbs.bb1314.com80(null)(null)

  • The following GET requests were made:
    • index.html
    • index.jpg


[ 本帖最后由 lingbo110120 于 2008-10-7 23:07 编辑 ]
tyyds
 楼主| 发表于 2008-10-7 23:08:19 | 显示全部楼层
多谢!我用着放心了
08红伞威点
发表于 2008-10-8 12:10:04 | 显示全部楼层
红伞Pass,上报提交分析。
wusuobuzai
发表于 2008-10-8 12:11:43 | 显示全部楼层
报的不是很多,应该是误报吧~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-10 08:49 , Processed in 0.161826 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表