查看: 4834|回复: 21
收起左侧

[病毒样本] 一样本 , 红伞,小A,卡巴,AVK,BD,DRWEB,NOD32,熊猫,瑞星,全过

[复制链接]
efreebird
发表于 2008-11-12 09:27:34 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kuqing_ren
发表于 2008-11-12 09:44:48 | 显示全部楼层
等待高手分析

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
llgiggs
头像被屏蔽
发表于 2008-11-12 10:08:12 | 显示全部楼层
這個是一個在線漫畫下載器




  • Submission details:
    • Submission received: 12 November 2008, 12:58:17
    • Processing time: 7 min 29 sec
    • Submitted sample:
      • File MD5: 0xECE96F77AED0BC1AD2B3B74CFABE3426
      • Filesize: 324,544 bytes
      • Packer info: packed with: PE_Patch [Kaspersky Lab]
  • Summary of the findings:
What's been foundSeverity Level
Downloads/requests other files from Internet.
Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection).


Technical Details:
  • The new window was created, as shown below:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.


File System Modifications
  • The following file was created in the system:
#Filename(s)File SizeFile MD5Alias
1[file and pathname of the sample #1] 324,544 bytes0xECE96F77AED0BC1AD2B3B74CFABE3426packed with PE_Patch [Kaspersky Lab]

  • The following directory was created:
    • %System%\data
  • Note:
    • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Memory Modifications
  • There was a new process created in the system:
Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]1,466,368 bytes


Other details
  • Analysis of the file resources indicate the following possible country of origin:
China
  • The following Host Name was requested from a host database:
    • www.tortinita.org
  • The following HTTP URL was started reading:
    • http://www.tortinita.org/update/md_630.html


[ 本帖最后由 llgiggs 于 2008-11-12 10:09 编辑 ]
megakotaro
发表于 2008-11-12 10:25:32 | 显示全部楼层
回報紅傘
啊弥陀佛
发表于 2008-11-12 10:29:37 | 显示全部楼层
什么东东?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wwzh2003
发表于 2008-11-12 11:42:30 | 显示全部楼层
不是病毒或木马,微点没反应啊
phm
发表于 2008-11-12 16:08:39 | 显示全部楼层
小白分析了下,没有什么恶意行为.
htyhzd 该用户已被删除
发表于 2008-11-12 16:12:44 | 显示全部楼层

不是病毒,绝对误报

fzz8848
头像被屏蔽
发表于 2008-11-12 16:20:54 | 显示全部楼层
Filename                        Result
MangaDowner.exe        CLEAN
ollydbg 该用户已被删除
发表于 2008-11-12 17:10:44 | 显示全部楼层
好毒,等待高手的分析。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-14 05:23 , Processed in 0.134423 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表