查看: 4199|回复: 12
收起左侧

[误报文件] 误报吗?一个播放东西

[复制链接]
post8
头像被屏蔽
发表于 2009-9-16 12:39:57 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
失落的手链
发表于 2009-9-16 12:44:46 | 显示全部楼层
瑞星2010
Win32.Parite.a
benq80282
发表于 2009-9-16 12:47:40 | 显示全部楼层
Avira AntiVir
S-Player.rar
  [0] Archive type: RAR
    --> S-Player.exe
      [DETECTION] Contains code of the W32/Parite Windows virus
    [NOTE]      A backup was created as '4ad0f6c4.qua'  ( QUARANTINE )
    [NOTE]      The file was deleted!
coldwinter
发表于 2009-9-16 12:52:53 | 显示全部楼层
• File Info
NameValue
Size274174
MD5658cd46b3e2c8630722d72ee2497c59e
SHA1c93bec3d931955cadeb304b0246efbdd283ee064
SHA256a19126e91724e4c59e47b3b446814deac2855fda61a9d60960855b8c277630fd
ProcessActive
• Keys Created
NameLast Write Time
CU\Software\Microsoft\Multimedia\DrawDib2009.01.12 14:48:03.734
• Keys Changed• Keys Deleted• Values Created
NameTypeSizeValue
CU\Software\Microsoft\Multimedia\DrawDib\vga.drv 800x600x32(BGR 0)REG_SZ24"31,31,31,31"
CU\Software\Microsoft\Windows\CurrentVersion\Explorer\PINFREG_BINARY42?
• Values Changed• Values Deleted• Directories Created• Directories Changed• Directories Deleted• Files Created
NameSizeLast Write TimeCreation TimeLast Access TimeAttr
C:\Documents and Settings\User\Local Settings\Temp\axa1.tmp1761282009.01.12 14:48:01.0152009.01.12 14:48:00.9212009.01.12 14:48:00.9210x20
• Files Changed
NameSizeLast Write TimeCreation TimeLast Access TimeAttr
C:\Documents and Settings\User\NTUSER.DAT524288/7864322009.01.12 13:45:13.906/2009.01.12 14:48:03.7342008.08.01 05:31:04.546/2008.08.01 05:31:04.5462009.01.12 13:45:13.906/2009.01.12 13:45:13.9060x22/0x22
C:\WINDOWS\system32\config\software8912896/89128962009.01.12 13:45:17.156/2009.01.12 14:48:02.3432008.07.31 16:55:51.593/2008.07.31 16:55:51.5932009.01.12 13:45:17.156/2009.01.12 13:45:17.1560x20/0x20
• Files Deleted• Directories Hidden• Files Hidden• Drivers Loaded• Drivers Unloaded• Processes Created• Processes Terminated• Threads Created
PIdProcess NameTIdStartStart MemWin32 StartWin32 Start Mem
0x344svchost.exe0x1700x7c810856MEM_IMAGE0x7c910760MEM_IMAGE
0x404svchost.exe0x7a80x7c810856MEM_IMAGE0x77e76bf0MEM_IMAGE
0x404svchost.exe0x7d80x7c810856MEM_IMAGE0x7c929faeMEM_IMAGE
0x490svchost.exe0x7bc0x7c810856MEM_IMAGE0x77e76bf0MEM_IMAGE
0x73cexplorer.exe0x7d00x7c810856MEM_IMAGE0x179778cMEM_IMAGE
0x73cexplorer.exe0x7dc0x7c810856MEM_IMAGE0x71a5d5afMEM_IMAGE
• Modules Loaded
PIdProcess NameBaseSizeFlagsImage Name
0x73cexplorer.exe0x17500000x740000x80284004C:\DOCUME~1\User\LOCALS~1\Temp\axa1.tmp
0x73cexplorer.exe0x662b00000x580000x800c4004C:\WINDOWS\system32\hnetcfg.dll
0x73cexplorer.exe0x71a500000x3f0000x80084004C:\WINDOWS\system32\mswsock.dll
0x73cexplorer.exe0x71a900000x80000x800c4004C:\WINDOWS\System32\wshtcpip.dll
• Windows Api Calls• DNS Queries• HTTP Queries• Verdict
Auto Analysis Verdict
Undetected
• Events Created or Opened
PIdImage NameAddressEvent Name
0x374C:\TEST\sample.exe0x77de5f48Global\SvcctrlStartEvent_A3752DX


C:\DOCUME~1\User\LOCALS~1\Temp\axa1.tmp多半有问题~~~
有木马程序~~~
post8
头像被屏蔽
 楼主| 发表于 2009-9-16 13:12:37 | 显示全部楼层
啊。我windwos 很多文件感染了。。。。。。。。。。。。。
62590423
发表于 2009-9-16 17:34:43 | 显示全部楼层
蠕虫名称:Worm.Win32.Agent.fmf

程序:
C:\SANDBOX\ADMINISTRATOR\DEFAULTBOX\USER\CURRENT\LOCAL SETTINGS\TEMP\PHBA.TMP
是蠕虫程序!
已成功阻止其运行,是否要删除此文件?
wliao
发表于 2009-9-16 18:31:12 | 显示全部楼层
Norton AntiVirus

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
尤金卡巴斯基
发表于 2009-9-16 21:54:26 | 显示全部楼层
2009/9/16 21:53:58        已清除        病毒 Virus.Win32.Parite.a        G:\Temp\Virus\S-Player.rar/S-Player.exe
BING126
头像被屏蔽
发表于 2009-9-16 22:06:15 | 显示全部楼层
McAfee        W32/Pate.a
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2026-4-20 09:40 , Processed in 2.218666 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表