查看: 1617|回复: 7
收起左侧

[病毒样本] 几只!!!!!!!

[复制链接]
yss870
发表于 2008-11-19 01:16:54 | 显示全部楼层
文件 AgentM.rar 接收于 2008.11.18 18:00:01 (CET)
                                当前状态:                        完成
结果: 8/34 (23.53%)

格式化文本
打印结果



反病毒引擎版本最后更新扫描结果
AhnLab-V32008.11.18.22008.11.18-
AntiVir7.9.0.312008.11.18HEUR/Malware
Authentium5.1.0.42008.11.18-
Avast4.8.1281.02008.11.18-
AVG8.0.0.1992008.11.18-
BitDefender7.22008.11.18-
CAT-QuickHeal10.002008.11.18-
ClamAV0.94.12008.11.18-
DrWeb4.44.0.091702008.11.18BACKDOOR.Trojan
eSafe7.0.17.02008.11.18-
eTrust-Vet31.6.62092008.11.14-
Ewido4.02008.11.18-
F-Prot4.4.4.562008.11.18-
F-Secure8.0.14332.02008.11.18W32/Malware
Fortinet3.117.0.02008.11.18-
GData192008.11.18-
IkarusT3.1.1.45.02008.11.18-
K7AntiVirus7.10.5272008.11.18-
Kaspersky7.0.0.1252008.11.18-
McAfee54372008.11.17-
Microsoft1.41042008.11.17-
NOD3236222008.11.18-
Norman5.80.022008.11.18W32/Malware
Panda9.0.0.42008.11.17Suspicious file
Prevx1V22008.11.18-
Rising21.04.12.002008.11.18-
SecureWeb-Gateway6.7.62008.11.18Heuristic.Malware
Sophos4.35.02008.11.18Sus/Behav-1003
Sunbelt3.1.1801.22008.11.14Backdoor.Win32.S (vf)
Symantec102008.11.18-
TheHacker6.3.1.1.1572008.11.18-
TrendMicro8.700.0.10042008.11.18-
ViRobot2008.11.18.14742008.11.18-
VirusBuster4.5.11.02008.11.18-
附加信息
File size: 100252 bytes
MD5...: e95925609177398d8ba57de03da9ba9e
SHA1..: 01ec58f3bf7e24044d56118315497e59d04f9a4d
SHA256: e0fd78c6dae94f7c226ce3e4bf8a2313964677812ecd66fcb7feb5ab9d1e22ed
SHA512: 8e653f6bea6f2a1a833fc5a44155ecc62c98b5f294f77a83344d9b142ca7560b
1327fb970b67746910cef872b6ecc86ae1027e7da5db8669308ceb83b5efd7cc
PEiD..: -
TrID..: File type identification
RAR Archive (83.3%)
REALbasic Project (16.6%)
PEInfo: -
Norman Sandbox: [ General information ]
    * **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
    * Application uses MFC.DLL.
    * File length:        20480 bytes.

[ Changes to filesystem ]
    * Creates directory C:\WINDOWS\SYSTEM32\agentm.

[ Changes to registry ]
    * Accesses Registry key \"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\".
* Modifies value\"UserInit\"=\"C:\WINDOWS\SYSTEM32\config\agentms.exe,\" in key\"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\".
    * Creates key \"HKLM\System\CurrentControlSet\Services\AgentMNormalService\".
* Sets value \"ImagePath\"=\"C:\WINDOWS\SYSTEM32\agentm\AgentM.exe\" inkey \"HKLM\System\CurrentControlSet\Services\AgentMNormalService\".
    * Sets value \"DisplayName\"=\"AgentMNormalService\" in key \"HKLM\System\CurrentControlSet\Services\AgentMNormalService\".
* Accesses Registry key \"HKLM\SYSTEM\CurrentControlSet\HardwareProfiles\Current\System\CurrentControlSet\Enum\ROOT\LEGACY_AGENTMNORMALSERVICE\0000\".
    * Accesses Registry key \"HKLM\SYSTEM\CurrentControlSet\Services\AgentMNormalService\".

[ Process/window information ]
    * Enumerates running processes.
    * Will automatically restart after boot (I'll be back...).
    * Attempts to access service \"AgentMNormalService\".
    * Creates service \"AgentMNormalService (AgentMNormalService)\" as \"C:\WINDOWS\SYSTEM32\agentm\AgentM.exe\".
BING126
头像被屏蔽
发表于 2008-11-19 20:19:23 | 显示全部楼层
McAfee  miss
wxb1994
头像被屏蔽
发表于 2008-11-19 20:21:46 | 显示全部楼层
小红伞——KILL
Palkia
发表于 2008-11-19 20:25:19 | 显示全部楼层
kv 0
sam.to
发表于 2008-11-19 20:52:50 | 显示全部楼层
to kl

[ 本帖最后由 sam.to 于 2008-11-19 20:54 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
luxiao200888
发表于 2008-11-20 13:27:40 | 显示全部楼层
C:\Documents and Settings\Owner\桌面\agentm.rar » RAR » AgentM.exe - Win32/Agent.OLH trojan
C:\Documents and Settings\Owner\桌面\agentm.rar » RAR » agentms.exe - Win32/Agent.OLH trojan
C:\Documents and Settings\Owner\桌面\agentm.rar » RAR » HookApiM.dll - Win32/Agent.OLH trojan
C:\Documents and Settings\Owner\桌面\agentm.rar » RAR » HookApiMon.dll - Win32/Agent.OLH trojan
sam.to
发表于 2008-11-23 16:36:21 | 显示全部楼层
卡巴:
No malicious software was found in the attached file.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-14 09:15 , Processed in 0.118502 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表