查看: 3031|回复: 6
收起左侧

[病毒样本] 帮忙分析下是否病毒?

[复制链接]
xxvvxxvv
发表于 2009-8-12 11:39:50 | 显示全部楼层 |阅读模式
下载地址:http://g.zhubajie.com/urllink.php?id=56829967gf6jskjt88ey1qm                                                                                                                                                                                                                                                         
软件名称 引擎版本病毒库版本病毒库时间扫描结果时间
a-squared4.5.0.3200908120001432009-08-12Virus.Win32.Agent!IK
0.529
AntiVir8.2.1.07.1.5.1002009-08-11DR/Agent.qcf
0.524
Arcavir20092009081114032009-08-11-
0.278
Authentium5.1.12009081200412009-08-12W32/Trojan2.HEAU (Exact)
1.867
AVAST!4.7.4090811-02009-08-11BV:Malware-gen
0.136
AVG8.5.288270.13.51/22972009-08-12BackDoor.Hupigon4.AUAW
0.473
BitDefender7.81008.38357717.271212009-08-12-
3.560
CA (VET)9.0.0.14331.6.6670 2009-08-11-
7.439
ClamAV0.95.296772009-08-11Trojan.Hupigon-21517
0.090
Comodo3.1019492009-08-12-
2.106
CP Secure1.1.0.7152009.08.112009-08-11BackDoor.W32.Huigezi.E
13.302
Dr.Web4.44.0.91702009.08.112009-08-11-
5.542
F-Prot4.4.4.56200908112009-08-11W32/Trojan2.HEAU (exact)
1.224
F-Secure7.02.738072009.08.11.172009-08-11Trojan.Win32.Chifrax.a [AVP]
0.121
GData19.7043/19.436200908122009-08-12Trojan.Win32.Chifrax.a [Engine:A]
8.915
IkarusT3.1.01.642009.08.12.732232009-08-12Virus.Win32.Agent
3.804
Microsoft1.49032009.08.122009-08-12PWS:Win32/Prast!rts
9.724
Norman6.01.096.01.002009-08-11-
4.007
nProtect20090812.0149945862009-08-12-
6.216
Quick Heal10.002009.08.112009-08-11-
1.604
Sophos2.89.14.442009-08-12Mal/Dropper-AE
5.497
Sunbelt532553252009-08-11-
1.728
The Hacker6.3.4.3v003812009-08-11Trojan/Chifrax.a
0.678
VBA323.12.10.920090811.14322009-08-11Backdoor.Win32.Hupigon.eqti
2.445
ViRobot200908112009.08.112009-08-11-
0.492
VirusBuster4.5.11.1010.112.2/18448762009-08-11-
2.854
卡巴斯基5.5.102009.08.122009-08-12Trojan.Win32.Chifrax.a
0.054
安博士V32009.08.11.072009.08.112009-08-11-
0.804
安天2.0.1820090810.26957462009-08-10-
0.194
江民杀毒11.0.8002009.08.112009-08-11-
12.730
熊猫卫士9.05.012009.08.112009-08-11-
2.960
瑞星20.021.42.14.002009-08-11-
1.054
赛门铁克1.3.0.2420090811.0042009-08-11-
0.058
趋势科技8.700-10046.356.092009-08-11-
0.046
迈克菲5.3.0057062009-08-11-
3.153
金山毒霸2009.2.5.152009.8.11.202009-08-11Win32.Troj.TrsRarSfxT.a.1038181
0.951
飞塔2.81-3.12010.7072009-08-11-
1.404

AntivirusVersionLast UpdateResult
a-squared4.5.0.242009.08.11Virus.Win32.Agent!IK
AhnLab-V35.0.0.22009.08.11-
AntiVir7.9.0.2482009.08.11DR/Agent.qcf
Antiy-AVL2.0.3.72009.08.11-
Authentium5.1.2.42009.08.11W32/Trojan2.HEAU
Avast4.8.1335.02009.08.10VBS:Malware-gen
AVG8.5.0.4062009.08.11BackDoor.Hupigon4.AUAW
BitDefender7.22009.08.11-
CAT-QuickHeal10.002009.08.11-
ClamAV0.94.12009.08.11Trojan.Hupigon-21517
Comodo19432009.08.11-
DrWeb5.0.0.121822009.08.11-
eSafe7.0.17.02009.08.10-
eTrust-Vet31.6.66722009.08.11-
F-Prot4.4.4.562009.08.10W32/Trojan2.HEAU
F-Secure8.0.14470.02009.08.11Trojan.Win32.Chifrax.a
Fortinet3.120.0.02009.08.11-
GData192009.08.11VBS:Malware-gen
IkarusT3.1.1.64.02009.08.11Virus.Win32.Agent
Jiangmin11.0.8002009.08.11Heur:TrojanDropper.WinRar
K7AntiVirus7.10.8162009.08.11-
Kaspersky7.0.0.1252009.08.11Trojan.Win32.Chifrax.a
McAfee57052009.08.10-
McAfee+Artemis57052009.08.10-
McAfee-GW-Edition6.8.52009.08.11Heuristic.BehavesLike.Win32.Dropper.J
Microsoft1.49032009.08.11PWS:Win32/Prast!rts
NOD3243262009.08.11BAT/TrojanDownloader.Agent.NAE
Norman6.01.092009.08.11-
nProtect2009.1.8.02009.08.11-
Panda10.0.0.142009.08.10-
PCTools4.4.2.02009.08.11-
Prevx3.02009.08.11-
Rising21.42.14.002009.08.11-
Sophos4.44.02009.08.11Mal/Dropper-AE
Sunbelt3.2.1858.22009.08.11-
Symantec1.4.4.122009.08.11-
TheHacker6.3.4.3.3802009.08.11Trojan/Chifrax.a
TrendMicro8.950.0.10942009.08.11-
VBA323.12.10.92009.08.10Backdoor.Win32.Hupigon.eqti
ViRobot2009.8.11.18792009.08.11-
VirusBuster4.6.5.02009.08.10-
Additional information
File size: 576566 bytes
MD5   : 347124124c4ab46dac2dbde9999456dc
SHA1  : 9a23794ea5fc2ff38b85579135916f2059ffa10d
SHA256: a3854e3f8479d52a30f5316f8e8c3b541b49c96c8df62270f4c0c2b38c2a3273
PEInfo: PE Structure information
        
        ( base data )
        entrypointaddress.: 0x1000
        timedatestamp.....: 0x48CFC008 (Tue Sep 16 16:17:44 2008)
        machinetype.......: 0x14C (Intel I386)
        
        ( 4 sections )
        name viradd virsiz rawdsiz ntrpy md5
        .text 0x1000 0x14000 0x13A00 6.48 cb357e69289cb7cf26dfea61eaea1985
.data 0x15000 0x8000 0xA00 4.93 568dd221456d807ca821813c84d65e70
.idata 0x1D000 0x2000 0x1200 4.79 bc7806e1c1ce9ebfd00ad834c1f7a647
.rsrc 0x1F000 0x28DC 0x2A00 5.47 497e5fdc01e78cc51ec9270471b960d0
        
        ( 8 imports )
        
>advapi32.dll: AdjustTokenPrivileges, LookupPrivilegeValueA,OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA,RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> comctl32.dll: -
> comdlg32.dll: CommDlgExtendedError, GetOpenFileNameA, GetSaveFileNameA
> gdi32.dll: DeleteObject
>kernel32.dll: CloseHandle, CompareStringA, CreateDirectoryA,CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW,DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA,FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose,FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW,FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA,GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA,GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA,GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleFileNameW,GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap,GetStdHandle, GetSystemTime, GetTempPathA, GetTickCount,GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree,HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime,MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile,SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA,SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime,SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject,WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> ole32.dll: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize
>shell32.dll: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA,SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation,ShellExecuteExA, SHGetPathFromIDListA
> user32.dll: CharToOemA,CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA,DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA,EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect,GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor,GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect,GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA,LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA,OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA,SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu,SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow,TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA
        
        ( 0 exports )
        
TrID  : File type identification
WinRAR Self Extracting archive (96.2%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Generic Win/DOS Executable (0.3%)
DOS Executable Generic (0.3%)
ssdeep: 12288:YlOLilaWWgrHqkCpkQrQ72P6ZPSmpVAe/40dhgG5ir5lGsyg:YUseEKfVM722PSSFASY58syg
PEiD  : -
RDS   : NSRL Reference Data Set


[ 本帖最后由 xxvvxxvv 于 2009-8-12 11:45 编辑 ]
honeymoonhelene 该用户已被删除
发表于 2009-8-12 11:46:23 | 显示全部楼层
这还用说吗,毒啊
悠柚
发表于 2009-8-12 11:58:34 | 显示全部楼层
网盘速度好慢,下次最好换个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +3 收起 理由
aarwwefdds + 3 感谢打包

查看全部评分

江湖的fans
发表于 2009-8-12 12:07:25 | 显示全部楼层
TO  RISING
左手
发表于 2009-8-12 17:09:24 | 显示全部楼层

回复 3楼 悠柚 的帖子



[ 本帖最后由 左手 于 2009-8-12 17:11 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
813kr
发表于 2009-8-12 17:34:43 | 显示全部楼层
NIS09扫描nothing……
雨夜狂风
发表于 2009-8-12 18:26:42 | 显示全部楼层
费尔报木马
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-18 16:20 , Processed in 0.092972 second(s), 6 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表