查看: 4016|回复: 24
收起左侧

[误报文件] 估计很多杀软误报,帮我用手动hips测试下

[复制链接]
germany05400
发表于 2009-1-23 03:08:42 | 显示全部楼层 |阅读模式
压缩包里是3个互不相关的单独文件。”重建图标缓存.exe“从“博士WIN7风格包 1.0 Build 090106”提取出来的;“疑难杂症处理.exe”从推荐的辅助杀毒的“疑难杂症处理合集”里提取的;”fix.exe“从“通用病毒杀灭机1.2动物家园版”作者的网盘里提取出来的。

都是红伞报,卡巴未报。帮我用手动hips测试下是否都是误报,最好能给出具体的恶意动作。谢谢了!


更新:”重建图标缓存.exe“小红伞又发邮件过来说是误报!!!

[ 本帖最后由 germany05400 于 2009-1-23 16:48 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
saga3721
发表于 2009-1-23 03:54:45 | 显示全部楼层
手动HIPS没有,上报红伞就比较方便,看来红伞认为是毒。
We received the following archive files:



File ID  Filename Size (Byte) Result
25239975  files.rar 70.01 KB OK

A listing of files contained inside archives alongside their results can be found below:

File ID  Filename Size (Byte) Result
3718903  fix.exe  50 KB  MALWARE
25231693  ############.exe  9.29 KB  MALWARE
25216557  ############.exe  52 KB  MALWARE


Please find a detailed report concerning each individual sample below:

Filename Result
fix.exe  MALWARE

The file 'fix.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Doreg. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.00.02.51.

Filename Result
############.exe  MALWARE

The file '############.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Packed.7599. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.00.06.105.

Filename Result
############.exe  MALWARE

The file '############.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/Agent.awpw. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.01.01.15.


--------------------------------------------------------------------------------
Please note that you will receive an email which will contain the results shown above. In case the final outcome of the analysis is not yet finished for all files the notification will be sent once ready.
germany05400
 楼主| 发表于 2009-1-23 09:43:31 | 显示全部楼层
上传给Automated Analysis System没看出来什么动作呀
江湖的fans
发表于 2009-1-23 09:48:12 | 显示全部楼层
TO  KL    看看!

TO  KV
germany05400
 楼主| 发表于 2009-1-23 09:50:25 | 显示全部楼层
希望有人帮偶分析下恶意的动作
JusticeH
发表于 2009-1-23 10:26:55 | 显示全部楼层
疑難雜症處理.exe:
在c:根目錄下建立文件 met.bat
調用cmd、regsvr32進程
修改登錄值、刪除登錄值
結束後刪除met.bat

重建圖標.exe:
調用csrss.exe

fix.exe:
調用conime...就沒了

以上三個都沒連網動作
germany05400
 楼主| 发表于 2009-1-23 10:31:16 | 显示全部楼层

回复 6楼 JusticeH 的帖子

觉得不像病毒丫???
czf610632747
发表于 2009-1-23 10:34:48 | 显示全部楼层
ESS不报
JusticeH
发表于 2009-1-23 10:42:09 | 显示全部楼层

回复 7楼 germany05400 的帖子

疑難雜症被報病毒,倒是覺得情有可原

補一下BitDefender的掃描結果
重建图标缓存.exe Trojan.Agent.ALNY
疑难杂症处理.exe Trojan.Packed.7599
germany05400
 楼主| 发表于 2009-1-23 10:44:19 | 显示全部楼层

回复 9楼 JusticeH 的帖子

就是不知道是不是杀毒软件集体误报
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 11:08 , Processed in 0.130193 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表