查看: 2237|回复: 2
收起左侧

DOS之家的GHOST8.3被AVG报木马?

[复制链接]
Whitlack
发表于 2007-1-11 20:24:44 | 显示全部楼层 |阅读模式
今天用AVG全盘扫描时发现C:\Documents and Settings\用户名\Local Settings\Temp下有两个木马

分别是:dropper.ag.d(这种恶意软件将有害的软件如后门程序与无害的程序捆绑在一起,被捆绑的有害的部分,如后门程序,将被安装并在用户不知道的情况下运行)


logger.agent.vs(记录程序是非常危险的,会记录用户击键或偷取如银行数据,许可号码或密码等个人数据)


请问大家有没有遇到过这种情况?

我是昨天从DOS之家下载的这个ghost8.3的版本的,按理说应该不会是故意放入的恶意软件吧?但是还是查出来了,有点怕怕

到底有没有危险呢?附上样本,还请大家指教

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Whitlack
 楼主| 发表于 2007-1-11 20:45:08 | 显示全部楼层
Complete scanning result of "eAPI.fne", received in VirusTotal at 01.11.2007, 13:41:39 (CET).
AntivirusVersionUpdateResult
AntiVir7.3.0.2101.09.2007TR/Spy.Agent.VS
Authentium4.93.801.10.2007 [td]no virus found
Avast4.7.892.012.30.2006 [td]no virus found
AVG38601.10.2007 [td]no virus found
BitDefender7.201.11.2007 [td]no virus found
CAT-QuickHeal9.0001.10.2007 [td]no virus found
ClamAVdevel-2006042601.11.2007 [td]no virus found
DrWeb4.3301.11.2007 [td]no virus found
eSafe7.0.14.001.10.2007suspicious Trojan/Worm
eTrust-InoculateIT23.73.11101.10.2007 [td]no virus found
eTrust-Vet30.3.331901.11.2007 [td]no virus found
Ewido4.001.10.2007Logger.Agent.vs
Fortinet2.82.0.001.10.2007 [td]no virus found
F-Prot3.16f01.10.2007 [td]no virus found
F-Prot44.2.1.2901.10.2007 [td]no virus found
IkarusT3.1.0.2701.09.2007 [td]no virus found
Kaspersky4.0.2.2401.11.2007 [td]no virus found
McAfee493601.10.2007 [td]no virus found
Microsoft1.190401.11.2007 [td]no virus found
NOD32v2197101.11.2007 [td]no virus found
Norman5.80.0201.10.2007 [td]no virus found
Panda9.0.0.401.10.2007Trj/Lineage.ALO
Prevx1V201.11.2007 [td]no virus found
Sophos4.13.001.11.2007Mal/Behav-027
Sunbelt2.2.907.001.05.2007 [td]no virus found
TheHacker6.0.3.14701.11.2007 [td]no virus found
UNA1.8301.10.2007 [td]no virus found
VBA323.11.201.10.2007 [td]no virus found
VirusBuster4.3.19:901.10.2007 [td]no virus found

Aditional Information
File size: 159232 bytes
MD5: b50431868e7f138b5c7ec330ac5bc34f
SHA1: 0c98317cf8a8826d0e8a68f2bf4376ed8c7cff5e
packers: ASPACK, UPX
packers: Aspack

VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.



> Go to: Home Contactar En Español www.virustotal.com :: ©Hispasec Sistemas 2004-06:: e-mail info@virustotal.com

Whitlack
 楼主| 发表于 2007-1-11 20:50:52 | 显示全部楼层
Complete scanning result of "com.run", received in VirusTotal at 01.11.2007, 13:51:56 (CET).
AntivirusVersionUpdateResult
AntiVir7.3.0.2101.09.2007TR/Drop.Ag.943694.D
Authentium4.93.801.10.2007 [td]no virus found
Avast4.7.892.012.30.2006 [td]no virus found
AVG38601.10.2007 [td]no virus found
BitDefender7.201.11.2007 [td]no virus found
CAT-QuickHeal9.0001.10.2007 [td]no virus found
ClamAVdevel-2006042601.11.2007 [td]no virus found
DrWeb4.3301.11.2007 [td]no virus found
eSafe7.0.14.001.10.2007suspicious Trojan/Worm
eTrust-InoculateIT23.73.11101.10.2007 [td]no virus found
eTrust-Vet30.3.331901.11.2007 [td]no virus found
Ewido4.001.10.2007Dropper.Ag.d
Fortinet2.82.0.001.10.2007 [td]no virus found
F-Prot3.16f01.10.2007 [td]no virus found
F-Prot44.2.1.2901.10.2007 [td]no virus found
IkarusT3.1.0.2701.09.2007 [td]no virus found
Kaspersky4.0.2.2401.11.2007 [td]no virus found
McAfee493601.10.2007 [td]no virus found
Microsoft1.190401.11.2007 [td]no virus found
NOD32v2197101.11.2007 [td]no virus found
Norman5.80.0201.10.2007 [td]no virus found
Panda9.0.0.401.10.2007 [td]no virus found
Prevx1V201.11.2007 [td]no virus found
Sophos4.13.001.11.2007 [td]no virus found
Sunbelt2.2.907.001.05.2007 [td]no virus found
TheHacker6.0.3.14701.11.2007 [td]no virus found
UNA1.8301.10.2007 [td]no virus found
VBA323.11.201.10.2007 [td]no virus found
VirusBuster4.3.19:901.10.2007 [td]no virus found

Aditional Information
File size: 155136 bytes
MD5: 62b3c0b49d2e076ef798d9600094116c
SHA1: 15dfaf115d0a3fd77f196bbbf78a2a8bf4064cd6
packers: ASPACK, UPX
packers: Aspack

VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.



> Go to: Home Contactar En Español www.virustotal.com :: ©Hispasec Sistemas 2004-06:: e-mail info@virustotal.com

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-23 05:21 , Processed in 0.137140 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表